Library
My library

+ Add to library

Profile

Android.Xiny.1723

Added to the Dr.Web virus database: 2018-05-15

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Xiny.240.origin
Prompts to install third-party applications.
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) stra####.be####.qq.com:80
  • TCP(HTTP/1.1) pa.angs####.com:8003
  • TCP(HTTP/1.1) ws####.qq.com:80
  • TCP(HTTP/1.1) 1####.206.227.63:80
  • TCP(HTTP/1.1) i####.api.zhifa####.net:10001
  • TCP(HTTP/1.1) 1####.159.103.205:8090
  • TCP(HTTP/1.1) c####.api.zhifa####.net:10101
  • TCP(HTTP/1.1) wn.qiazhiw####.cn.####.net:80
  • TCP(HTTP/1.1) i####.api.zhifa####.net:10002
  • TCP(HTTP/1.1) gdv.a.s####.com:80
  • TCP(HTTP/1.1) c####.api.zhifa####.net:10201
  • TCP(HTTP/1.1) 1####.76.96.62:30310
  • TCP(HTTP/1.1) and####.5####.com:8077
  • TCP(HTTP/1.1) dsds####.qq.com.####.net:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) to####.ifunt####.com:80
  • TCP(HTTP/1.1) pin####.qq.com:80
  • TCP(HTTP/1.1) 2####.73.211.68:5292
  • TCP(HTTP/1.1) 1####.55.89.238:8977
  • TCP(HTTP/1.1) u####.9####.cn:80
  • TCP(HTTP/1.1) 1####.159.180.48:8090
  • TCP(HTTP/1.1) i####.api.zhifa####.net:10101
  • TCP(HTTP/1.1) 1####.76.96.62:30320
  • TCP(HTTP/1.1) dow####.g####.uc.cn:80
  • TCP(HTTP/1.1) i####.api.zhifa####.net:10201
  • TCP(HTTP/1.1) e.angs####.com:6284
  • TCP(HTTP/1.1) 1####.178.116.121:9999
  • TCP(HTTP/1.1) p1.i####.cc:80
  • TCP(HTTP/1.1) c####.api.zhifa####.net:10003
  • TCP(HTTP/1.1) a####.angs####.com.####.com:5285
  • TCP(HTTP/1.1) oth.str.mdt.####.com:8080
  • TCP(HTTP/1.1) d.angs####.com:5284
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) 1####.75.56.106:10201
  • TCP(HTTP/1.1) sm####.hej####.com:80
  • TCP(HTTP/1.1) 1####.159.152.136:8090
  • TCP(HTTP/1.1) c####.qq.com:80
  • TCP(HTTP/1.1) 1####.144.244.125:80
  • TCP(HTTP/1.1) int.d####.s####.####.cn:80
  • TCP 1####.196.192.72:9920
  • UDP 2####.255.255.250:1900
  • TCP c####.qq.com:443
  • TCP c####.qq.com:80
DNS requests:
  • a####.angs####.com
  • a####.u####.com
  • and####.5####.com
  • c####.api.zhifa####.net
  • c####.qq.com
  • d.angs####.com
  • dl####.qq.com
  • dow####.g####.uc.cn
  • e.angs####.com
  • gd.unicomm####.g####.com
  • i####.api.zhifa####.net
  • i####.api.zhifa####.net
  • imgc####.qq.com
  • int.d####.s####.####.cn
  • l####.i####.cc
  • mon####.uu.qq.com
  • oth.str.mdt.####.com
  • p1.i####.cc
  • pa.angs####.com
  • pin####.qq.com
  • pv.s####.com
  • re####.api.zhifa####.net
  • sdk.api.zhifa####.net
  • sm####.hej####.com
  • stra####.be####.qq.com
  • to####.ifunt####.com
  • u####.9####.cn
  • wn.qiazhiw####.cn
  • ws####.qq.com
HTTP GET requests:
  • a####.angs####.com.####.com:5285/AppDownLoad/apk/downloadAPK?appId=####
  • dow####.g####.uc.cn/s/2/2/201805111637523c8dc5_SoulKnight-21-1.7.6-relea...
  • dsds####.qq.com.####.net/music/clntupate/QQMusic.apk
  • gdv.a.s####.com/cityjson?ie=####
  • int.d####.s####.####.cn/iplookup/iplookup.php?format=####&ip=####
  • p####.tc.qq.com/zljk/one.png
  • pin####.qq.com/
  • pin####.qq.com/?s=####&k=####
  • sm####.hej####.com/getAd.php?apiKey=####&imsi=####&mobile=####&apiKey=##...
  • sm####.hej####.com/getMobile.php?apiKey=####&imsi=####&net=####&net2=####
  • sm####.hej####.com/getSP135.php?echoName=####&appName=####&productName=#...
  • to####.ifunt####.com/piwik.php?e_a=####&_idvc=####&apiv=####&uid=####&re...
  • u####.9####.cn/game/downloadGame?pack.cooperateModelId=####&pack.id=####
  • wn.qiazhiw####.cn.####.net/update/up01036465_66
HTTP POST requests:
  • a####.u####.com/app_logs
  • and####.5####.com:8077/query-plat/log/error/upload.do
  • c####.api.zhifa####.net:10003/v2/chis
  • c####.api.zhifa####.net:10101/v2/order/get?app_id=####&t=####
  • c####.api.zhifa####.net:10101/v2/splog/config?app_id=####&t=####
  • c####.api.zhifa####.net:10201/v2/sdk/report?app_id=####&t=####
  • c####.qq.com/upload
  • d.angs####.com:5284/android.frontserver/pcsvc
  • e.angs####.com:6284/android.frontserver/pcsvc
  • i####.api.zhifa####.net:10001/v2/adconfig/get?app_id=####&t=####
  • i####.api.zhifa####.net:10001/v2/bag/monitor?app_id=####&t=####
  • i####.api.zhifa####.net:10001/v2/sdk/init?app_id=####&t=####
  • i####.api.zhifa####.net:10001/v2/update/check?app_id=####&t=####
  • i####.api.zhifa####.net:10002/v2/callback/message?app_id=####&t=####
  • i####.api.zhifa####.net:10101/v2/order/get?app_id=####&t=####
  • i####.api.zhifa####.net:10201/v2/sdk/report?app_id=####&t=####
  • oth.str.mdt.####.com:8080/analytics/upload
  • p1.i####.cc/index.php/MC/HB
  • p1.i####.cc/index.php/MC/LP
  • p1.i####.cc/index.php/MC/RP
  • pa.angs####.com:8003/pps
  • pin####.qq.com/?s=####&k=####
  • stra####.be####.qq.com/analytics/upload
  • ws####.qq.com/w.cgi
Modified file system:
Creates the following files:
  • /data/anr/traces.txt
  • /data/data/####/.imprint
  • /data/data/####/.nomedia
  • /data/data/####/01.23.16-43998.stacktrace
  • /data/data/####/0C3E1782C1F853AF.jar.i
  • /data/data/####/0C3E1782C1F853AFwh.jar
  • /data/data/####/1B3A2967E5FD862EFD957606C65C8122
  • /data/data/####/2.zip
  • /data/data/####/2887A00B589C85A5FF5607D7EB45E7C8
  • /data/data/####/30592A6B8B0C769E3F7FDE6E1A033DF5
  • /data/data/####/347781996620052-journal
  • /data/data/####/AEE69129416B4F5D.jar.i
  • /data/data/####/AEE69129416B4F5Dwh.jar
  • /data/data/####/APPSTART.xml
  • /data/data/####/D99494BB10D048C393648C204AF8AA38
  • /data/data/####/DENGTA_META.xml
  • /data/data/####/EXTRA_DATAV1
  • /data/data/####/F85C58A2196623557E8A00D8A4680702
  • /data/data/####/PlayMonitor.xml
  • /data/data/####/PlayerProcessPref.xml
  • /data/data/####/QQMusic-journal
  • /data/data/####/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml
  • /data/data/####/SimpleMode.xml
  • /data/data/####/UserPreference.xml
  • /data/data/####/WnsDBHelper-journal
  • /data/data/####/WnsDebugManager.xml
  • /data/data/####/_listen_count_sp.xml
  • /data/data/####/action_add_to_list_disable.png
  • /data/data/####/action_add_to_list_normal.png
  • /data/data/####/action_add_to_list_pressed.png
  • /data/data/####/action_bg_normal.png
  • /data/data/####/action_bg_press.png
  • /data/data/####/action_blacklist_disable.png
  • /data/data/####/action_blacklist_normal.png
  • /data/data/####/action_blacklist_pressed.png
  • /data/data/####/action_check_album_disable.png
  • /data/data/####/action_check_album_normal.png
  • /data/data/####/action_check_album_pressed.png
  • /data/data/####/action_check_singer_disable.png
  • /data/data/####/action_check_singer_normal.png
  • /data/data/####/action_check_singer_pressed.png
  • /data/data/####/action_comment_disable.png
  • /data/data/####/action_comment_normal.png
  • /data/data/####/action_comment_normal_count_long.png
  • /data/data/####/action_comment_normal_count_short.png
  • /data/data/####/action_comment_pressed.png
  • /data/data/####/action_copy_to_folder.png
  • /data/data/####/action_copy_to_folder_disable.png
  • /data/data/####/action_copy_to_folder_select.png
  • /data/data/####/action_create_radio_disable.png
  • /data/data/####/action_create_radio_normal.png
  • /data/data/####/action_create_radio_pressed.png
  • /data/data/####/action_delete_disable.png
  • /data/data/####/action_delete_normal.png
  • /data/data/####/action_delete_pressed.png
  • /data/data/####/action_download_disable.png
  • /data/data/####/action_download_finish_normal.png
  • /data/data/####/action_download_finish_pressed.png
  • /data/data/####/action_download_normal.png
  • /data/data/####/action_download_pay_normal.png
  • /data/data/####/action_download_pay_pressed.png
  • /data/data/####/action_download_pressed.png
  • /data/data/####/action_download_upgrade_normal.png
  • /data/data/####/action_download_upgrade_pressed.png
  • /data/data/####/action_edit_normal.png
  • /data/data/####/action_edit_pressed.png
  • /data/data/####/action_icon_clock.png
  • /data/data/####/action_icon_clock_disable.png
  • /data/data/####/action_icon_clock_pressed.png
  • /data/data/####/action_icon_desc.png
  • /data/data/####/action_icon_desc_disable.png
  • /data/data/####/action_icon_desc_pressed.png
  • /data/data/####/action_icon_info.png
  • /data/data/####/action_icon_info_disable.png
  • /data/data/####/action_icon_info_pressed.png
  • /data/data/####/action_icon_qzone.png
  • /data/data/####/action_icon_qzone_pressed.png
  • /data/data/####/action_icon_ring.png
  • /data/data/####/action_icon_ring_disable.png
  • /data/data/####/action_icon_ring_pressed.png
  • /data/data/####/action_icon_submit.png
  • /data/data/####/action_icon_submit_disable.png
  • /data/data/####/action_icon_submit_pressed.png
  • /data/data/####/action_icon_user.png
  • /data/data/####/action_icon_user_disable.png
  • /data/data/####/action_icon_user_pressed.png
  • /data/data/####/action_lyric_poster_disable.png
  • /data/data/####/action_lyric_poster_normal.png
  • /data/data/####/action_lyric_poster_pressed.png
  • /data/data/####/action_manage_songs_normal.png
  • /data/data/####/action_manage_songs_pressed.png
  • /data/data/####/action_mv_normal.png
  • /data/data/####/action_mv_pressed.png
  • /data/data/####/action_play_next_disable.png
  • /data/data/####/action_play_next_normal.png
  • /data/data/####/action_play_next_pressed.png
  • /data/data/####/action_play_normal.png
  • /data/data/####/action_play_pressed.png
  • /data/data/####/action_qzone_disable.png
  • /data/data/####/action_ring_disable.png
  • /data/data/####/action_ring_normal.png
  • /data/data/####/action_ring_pressed.png
  • /data/data/####/action_search_disable.png
  • /data/data/####/action_search_normal.png
  • /data/data/####/action_search_pressed.png
  • /data/data/####/action_share_disable.png
  • /data/data/####/action_share_normal.png
  • /data/data/####/action_share_pressed.png
  • /data/data/####/action_sheet_favorite_disable.png
  • /data/data/####/action_sheet_favorite_normal.png
  • /data/data/####/action_sheet_favorite_pressed.png
  • /data/data/####/action_sheet_favorited_disable.png
  • /data/data/####/action_sheet_favorited_normal.png
  • /data/data/####/action_sheet_favorited_pressed.png
  • /data/data/####/action_sing_this_song_disable.png
  • /data/data/####/action_sing_this_song_normal.png
  • /data/data/####/action_sing_this_song_pressed.png
  • /data/data/####/actionsheet_folder.png
  • /data/data/####/actionsheet_pplayer_normal.png
  • /data/data/####/actionsheet_pplayer_pressed.png
  • /data/data/####/anchor_cell_bg_new.png
  • /data/data/####/arrow_gdt_go.png
  • /data/data/####/arrow_right_normal.png
  • /data/data/####/b.d
  • /data/data/####/beacon_db-journal
  • /data/data/####/bg_recognize_result.png
  • /data/data/####/cb.d
  • /data/data/####/cbn.d
  • /data/data/####/cbn_d.d
  • /data/data/####/cbs.d
  • /data/data/####/chinaunicom.xml
  • /data/data/####/classes.jar
  • /data/data/####/clear_all_playlist.xml
  • /data/data/####/clear_all_recent_playlist.png
  • /data/data/####/close_normal.png
  • /data/data/####/close_press.png
  • /data/data/####/cloud_local_new.png
  • /data/data/####/color_b1.png
  • /data/data/####/color_b1.xml
  • /data/data/####/color_b10.png
  • /data/data/####/color_b11.png
  • /data/data/####/color_b12.png
  • /data/data/####/color_b13.png
  • /data/data/####/color_b14.png
  • /data/data/####/color_b15.png
  • /data/data/####/color_b16.png
  • /data/data/####/color_b16.xml
  • /data/data/####/color_b17.png
  • /data/data/####/color_b18.xml
  • /data/data/####/color_b2.png
  • /data/data/####/color_b2.xml
  • /data/data/####/color_b20.xml
  • /data/data/####/color_b21.png
  • /data/data/####/color_b3.xml
  • /data/data/####/color_b30.xml
  • /data/data/####/color_b4.png
  • /data/data/####/color_b4.xml
  • /data/data/####/color_b4_solid.png
  • /data/data/####/color_b5.png
  • /data/data/####/color_b5.xml
  • /data/data/####/color_b6.xml
  • /data/data/####/color_b7.xml
  • /data/data/####/color_b8.png
  • /data/data/####/color_b8.xml
  • /data/data/####/color_b9.png
  • /data/data/####/color_network_banner.xml
  • /data/data/####/color_t1.xml
  • /data/data/####/color_t10.xml
  • /data/data/####/color_t2.xml
  • /data/data/####/color_t4.xml
  • /data/data/####/color_t5.xml
  • /data/data/####/color_t6.xml
  • /data/data/####/color_t7.png
  • /data/data/####/color_t7.xml
  • /data/data/####/color_t8.xml
  • /data/data/####/com.V88918FUUBZQ62_preferences.xml
  • /data/data/####/com.tencent.qqmusic-1.apk.classes2.zip
  • /data/data/####/com.tencent.qqmusic-1.apk.classes3.zip
  • /data/data/####/com.tencent.qqmusic_preferences.xml
  • /data/data/####/com.tencent.wns.data.xml
  • /data/data/####/com_android_command_nn_v.xml
  • /data/data/####/comment_score_star_unselected.png
  • /data/data/####/comments_empty.png
  • /data/data/####/common_grid_title_color_selector.xml
  • /data/data/####/config
  • /data/data/####/config50109.xml
  • /data/data/####/config_rule.txt
  • /data/data/####/config_zip
  • /data/data/####/core_info
  • /data/data/####/custom_portrait_normal.png
  • /data/data/####/custom_portrait_press.png
  • /data/data/####/d_h_d.d
  • /data/data/####/default_album_mid.png
  • /data/data/####/default_album_small.png
  • /data/data/####/default_avatar.png
  • /data/data/####/default_avatar_rectangle.png
  • /data/data/####/default_music_album.png
  • /data/data/####/default_mv_album.png
  • /data/data/####/delete_text.png
  • /data/data/####/delete_text_click.png
  • /data/data/####/discovery_voice_search_button_normal.png
  • /data/data/####/discovery_voice_search_button_pressed.png
  • /data/data/####/dts_actionsheet_logo.png
  • /data/data/####/dts_switch_off.png
  • /data/data/####/dtsupgrade.xml
  • /data/data/####/emoji_delete.png
  • /data/data/####/eup_db
  • /data/data/####/eup_db-journal
  • /data/data/####/fake.zip
  • /data/data/####/flag_background_normal_2.9.png
  • /data/data/####/flag_background_normal_3.9.png
  • /data/data/####/flag_background_normal_4.9.png
  • /data/data/####/flag_background_normal_5.9.png
  • /data/data/####/flag_background_normal_6.9.png
  • /data/data/####/flag_background_normal_8.9.png
  • /data/data/####/flag_background_normal_9.9.png
  • /data/data/####/folder_desc_edit_click.png
  • /data/data/####/folder_desc_edit_normal.png
  • /data/data/####/global_comment_add_comment.png
  • /data/data/####/global_comment_like.png
  • /data/data/####/global_comment_like_selected.png
  • /data/data/####/hh_db_pay-journal
  • /data/data/####/ic_download_list_edit.png
  • /data/data/####/ic_download_list_item_more.png
  • /data/data/####/ic_edit_add_disable.png
  • /data/data/####/ic_edit_add_normal.png
  • /data/data/####/ic_edit_add_pressed.png
  • /data/data/####/ic_edit_delete_disable.png
  • /data/data/####/ic_edit_delete_normal.png
  • /data/data/####/ic_edit_delete_pressed.png
  • /data/data/####/ic_edit_download_disable.png
  • /data/data/####/ic_edit_download_normal.png
  • /data/data/####/ic_edit_download_pressed.png
  • /data/data/####/ic_edit_qzone_disable.png
  • /data/data/####/ic_edit_qzone_normal.png
  • /data/data/####/ic_edit_qzone_pressed.png
  • /data/data/####/ic_my_music_cell_arrow_right.png
  • /data/data/####/ic_my_music_cell_more_btn.9.png
  • /data/data/####/ic_radio_channel.png
  • /data/data/####/ic_radio_channel_footer.png
  • /data/data/####/ic_radio_channel_header.png
  • /data/data/####/ic_recognize_delete.png
  • /data/data/####/ic_recognize_retry.png
  • /data/data/####/ic_right_arrow.png
  • /data/data/####/icon_actionsheet_blacklist_normal.png
  • /data/data/####/icon_actionsheet_blacklist_pressed.png
  • /data/data/####/icon_add_song_list.png
  • /data/data/####/icon_download_song_list.png
  • /data/data/####/icon_folder_action_sheet.png
  • /data/data/####/icon_list_ring.png
  • /data/data/####/icon_radio_refresh.png
  • /data/data/####/icon_song_action_sheet_normal.png
  • /data/data/####/icon_song_action_sheet_pressed.png
  • /data/data/####/icon_song_action_sheet_up.png
  • /data/data/####/input_emoji_icon.png
  • /data/data/####/input_keyboard_icon.png
  • /data/data/####/ipmap
  • /data/data/####/item_lyric_cloud.png
  • /data/data/####/jmsdk.dat.xml
  • /data/data/####/kb_idle.ini
  • /data/data/####/kb_sn.ini
  • /data/data/####/kv_cf.ini
  • /data/data/####/landscape_entrance_normal.png
  • /data/data/####/landscape_entrance_press.png
  • /data/data/####/level_speed_off.png
  • /data/data/####/level_speed_tips.png
  • /data/data/####/libMiniQPlay.so
  • /data/data/####/libMiniQPlay.so1526425778194
  • /data/data/####/libSuperSound_v7a.so
  • /data/data/####/libSuperSound_v7a.so1526425778498
  • /data/data/####/libexec.so
  • /data/data/####/listen_guide_music.png
  • /data/data/####/local_album_scan.xml
  • /data/data/####/local_dir.db-journal
  • /data/data/####/lt.d
  • /data/data/####/main_bg.png
  • /data/data/####/minibar_album_default.png
  • /data/data/####/mobclick_agent_cached_com.V88918FUUBZQ6212316
  • /data/data/####/mobclick_agent_online_setting_com.V88918FUUBZQ62.xml
  • /data/data/####/more_button_background_normal.png
  • /data/data/####/more_button_background_pressed.png
  • /data/data/####/more_button_flag.png
  • /data/data/####/more_version_arrow.png
  • /data/data/####/more_version_arrow_up.png
  • /data/data/####/multidex.version.xml
  • /data/data/####/music_circle_comment_sanjiao.png
  • /data/data/####/music_icon.png
  • /data/data/####/musichall_default_mv_album.png
  • /data/data/####/musichall_postpone_refresh.png
  • /data/data/####/mv_item_default_img.png
  • /data/data/####/net_work_connect_tips_bg.9.png
  • /data/data/####/net_work_connect_tips_cancel.png
  • /data/data/####/net_work_connect_tips_right.png
  • /data/data/####/new_md.jar
  • /data/data/####/nn.jar.t.i
  • /data/data/####/nn.jaru
  • /data/data/####/nn_app.xml
  • /data/data/####/nn_data_s.xml
  • /data/data/####/options.for.com.tencent.qqmusic.xml
  • /data/data/####/options.for.com.tencent.qqmusic;QQPlayerService.xml
  • /data/data/####/org.piwik.sdk_FE8DB41078DFFC3D9751687595C3B837.xml
  • /data/data/####/pc2device_connected.png
  • /data/data/####/pc2device_finished.png
  • /data/data/####/pc2device_import_icon.png
  • /data/data/####/pc2device_import_icon_new.png
  • /data/data/####/pc2device_progress_bg.9.png
  • /data/data/####/pcn.d
  • /data/data/####/pcs.d
  • /data/data/####/pgb.d
  • /data/data/####/player_lyr_a24.png
  • /data/data/####/player_lyr_a28.png
  • /data/data/####/player_lyr_a32.png
  • /data/data/####/player_lyr_a36.png
  • /data/data/####/player_lyr_a40.png
  • /data/data/####/player_lyr_icon_advance.png
  • /data/data/####/player_lyr_icon_advance_pressed.png
  • /data/data/####/player_lyr_icon_delayed.png
  • /data/data/####/player_lyr_icon_delayed_pressed.png
  • /data/data/####/player_lyr_icon_reduction.png
  • /data/data/####/player_lyr_icon_reduction_pressed.png
  • /data/data/####/playing_volumn_slide_icon.png
  • /data/data/####/playing_volumn_slide_nosound_icon.png
  • /data/data/####/playlist_soso_icon.png
  • /data/data/####/ppashow.dat
  • /data/data/####/push_id_save_name.xml
  • /data/data/####/push_local_save_time.xml
  • /data/data/####/push_notification_disable_normal.png
  • /data/data/####/push_notification_disable_pressed.png
  • /data/data/####/push_notification_enable_normal.png
  • /data/data/####/push_notification_enable_pressed.png
  • /data/data/####/qqmusic.xml
  • /data/data/####/qqmusic_media_scanner.xml
  • /data/data/####/qqmusicadvertisementrecord.xml
  • /data/data/####/qqmusicfloatadvertisementrecord.xml
  • /data/data/####/qqmusicfloatyearvipmsgrecord.xml
  • /data/data/####/qqmusicplayer.xml
  • /data/data/####/qqmusicplayer.xml.bak
  • /data/data/####/recogniz.db-journal
  • /data/data/####/recognize_hengchang_normal.png
  • /data/data/####/recognize_no_network_bg.xml
  • /data/data/####/recognize_no_network_retry_button.png
  • /data/data/####/recognize_no_network_retry_button_bg.png
  • /data/data/####/recommen_item_more.png
  • /data/data/####/ring_btnplay.png
  • /data/data/####/ring_btnplay_pressed.png
  • /data/data/####/ring_btnstop.png
  • /data/data/####/ring_btnstop_pressed.png
  • /data/data/####/ring_time_arrow.png
  • /data/data/####/scanning_icon_up.png
  • /data/data/####/scanning_icon_up_disable.png
  • /data/data/####/search_add_next_song.png
  • /data/data/####/search_arrow_right.png
  • /data/data/####/search_bg.9.png
  • /data/data/####/search_edit_magnifier.png
  • /data/data/####/search_edit_top_img.png
  • /data/data/####/search_edit_view_bottom_color.xml
  • /data/data/####/search_history_icon.png
  • /data/data/####/search_hot_word_text.xml
  • /data/data/####/search_icon_up.png
  • /data/data/####/search_smart_song_play_icon.png
  • /data/data/####/setting_about_header.png
  • /data/data/####/skin_cache.tmp
  • /data/data/####/smart_direct_album.png
  • /data/data/####/smart_direct_singer.png
  • /data/data/####/smart_direct_song.png
  • /data/data/####/smart_direct_song_downloaded.png
  • /data/data/####/supersdk_main.db-journal
  • /data/data/####/switch_off_clicked.png
  • /data/data/####/switching_off.png
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/theme.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/up01036465_66
  • /data/data/####/up01036465_66.jar
  • /data/data/####/verify.jar
  • /data/data/####/version.dat.xml
  • /data/data/####/video_icon.png
  • /data/data/####/w285D0x06276o6D969i1r817571493.xml
  • /data/data/####/webview.db-journal
  • /data/data/####/wns_share_data.xml
  • /data/data/####/wx.d
  • /data/data/####/z_color_b19.png
  • /data/data/####/z_color_b3.png
  • /data/data/####/z_color_l1.png
  • /data/data/####/z_color_l1_solid.png
  • /data/data/####/zfb.d
  • /data/data/####/zip_size
  • /data/data/####/{6109AB2B-769CFABF}_{E1DE94CE-5F4C0C2B}.P2
  • /data/data/####/{BE2355DB-D785E335}.PC1
  • /data/data/####/{E1DE94CE-5F4C0C2B}.P1
  • /data/data/####/{E1DE94CE-5F4C0C2B}.P3
  • /data/media/####/-1622791856
  • /data/media/####/.nomedia
  • /data/media/####/2056145405
  • /data/media/####/373396853
  • /data/media/####/681112129
  • /data/media/####/UniqueGame.apk
  • /data/media/####/common_statics.log
  • /data/media/####/journal.tmp
  • /data/media/####/meta.dat
  • /data/media/####/pConifg.ini
  • /data/media/####/playLog
  • /data/media/####/qmSfile
  • /data/media/####/storage.cfg
Miscellaneous:
Executes next shell scripts:
  • /system/bin/cat /proc/cpuinfo
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/sh -c getprop ro.board.platform
  • cat /sys/block/mmcblk0/device/cid
  • getprop
  • getprop net.dns1
  • getprop net.dns2
  • getprop ro.board.platform
  • getprop ro.product.cpu.abi
Loads the following dynamic libraries:
  • libexec
  • paylib
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5PADDING
  • AES-CBC-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • DES-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-PKCS5PADDING
  • AES-CBC-PKCS5Padding
  • DES
  • DES-ECB-NoPadding
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.
Parses information from SMS messages.
Gains access to information about sent/received SMS messages.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android