Library
My library

+ Add to library

Profile

Android.Joker.66

Added to the Dr.Web virus database: 2020-01-03

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Joker.60.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) api.face####.com:80
  • TCP(HTTP/1.1) mobil####.f####.com:80
  • TCP(TLS/1.0) game####.f####.net:443
  • TCP(TLS/1.0) instant####.google####.com:443
  • TCP(TLS/1.0) api.face####.com:443
  • TCP(TLS/1.0) myf####.oss-eu-####.aliy####.com:443
  • TCP(TLS/1.0) app-mea####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) sett####.crashly####.com:443
  • TCP(TLS/1.0) 1####.217.168.238:443
  • TCP(TLS/1.0) 1####.217.17.74:443
  • TCP(TLS/1.2) 1####.217.168.238:443
  • TCP(TLS/1.2) 1####.217.17.74:443
DNS requests:
  • and####.google####.com
  • app-mea####.com
  • g####.face####.com
  • game####.f####.net
  • instant####.google####.com
  • m####.go####.com
  • mobil####.f####.com
  • myf####.oss-eu-####.aliy####.com
  • p####.google####.com
  • sett####.crashly####.com
HTTP GET requests:
  • api.face####.com/
  • mobil####.f####.com/gameApp/uploads/category/1527931139178771.jpeg
  • mobil####.f####.com/gameApp/uploads/category/1527931782card games.png
  • mobil####.f####.com/gameApp/uploads/category/1527931899Driving games.jpg
  • mobil####.f####.com/gameApp/uploads/category/1527932210Sports Ball.png
  • mobil####.f####.com/gameApp/uploads/category/1527934221puzzle games.jpeg
  • mobil####.f####.com/gameApp/uploads/category/1527934704shooting1.png
  • mobil####.f####.com/gameApp/uploads/category/1527935745girls game1.png
  • mobil####.f####.com/gameApp/uploads/category/1527935869Other Games.jpeg
  • mobil####.f####.com/gameApp/uploads/category/1527939605collecting games....
  • mobil####.f####.com/gameApp/uploads/category/1527940122Skills Game.png
  • mobil####.f####.com/gameApp/uploads/category/15316020661527935643.jpg
  • mobil####.f####.com/gameApp/uploads/category/15316024491531207537.jpg
  • mobil####.f####.com/gameApp/uploads/game/1528122286.jpg
  • mobil####.f####.com/gameApp/uploads/game/1528126854.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1528534636.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1528543672.png
  • mobil####.f####.com/gameApp/uploads/game/1528546782.png
  • mobil####.f####.com/gameApp/uploads/game/1528547882.png
  • mobil####.f####.com/gameApp/uploads/game/1530612762.png
  • mobil####.f####.com/gameApp/uploads/game/1531214160.png
  • mobil####.f####.com/gameApp/uploads/game/1533110132.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533110414.png
  • mobil####.f####.com/gameApp/uploads/game/1533110613.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533110834.png
  • mobil####.f####.com/gameApp/uploads/game/1533111091.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533111330.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533112765.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533113034.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533113238.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533113442.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533113553.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533113739.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533286517.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533287032.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533287171.png
  • mobil####.f####.com/gameApp/uploads/game/1533287317.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533287491.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533287675.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533289308.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533289433.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533289650.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533289968.png
  • mobil####.f####.com/gameApp/uploads/game/1533290302.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1533290778.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1536306835.png
  • mobil####.f####.com/gameApp/uploads/game/1536308208.jpg
  • mobil####.f####.com/gameApp/uploads/game/1536310203.jpeg
  • mobil####.f####.com/gameApp/uploads/game/1536310502.jpg
HTTP POST requests:
  • mobil####.f####.com/gameApp/webservice/ghdfsanss234dssf/fetchAllGame
  • mobil####.f####.com/gameApp/webservice/ghdfsanss234dssf/fetchCategory
  • mobil####.f####.com/gameApp/webservice/ghdfsanss234dssf/fetchGame
File system changes:
Creates the following files:
  • /data/data/####/000001.dbtmp
  • /data/data/####/013888a1cda32b90_0
  • /data/data/####/014259b73b6b2379_0
  • /data/data/####/035aa9dff41235ca_0
  • /data/data/####/0391a6ac7a9250b9593b4bad1d6f535a.0.tmp
  • /data/data/####/0391a6ac7a9250b9593b4bad1d6f535a.1.tmp
  • /data/data/####/070f0d5b6923ff59_0
  • /data/data/####/070f0d5b6923ff59_1
  • /data/data/####/08b99d499107ba17_0
  • /data/data/####/0ae129c33e7a30bd_0
  • /data/data/####/0b3d59c1b2221f76_0
  • /data/data/####/0d3086d7cda635d4_0
  • /data/data/####/0de83cb9b5d30ef9_0
  • /data/data/####/10b2ce41b45fc5a2ed6e262169df903d.0.tmp
  • /data/data/####/10b2ce41b45fc5a2ed6e262169df903d.1.tmp
  • /data/data/####/14d9579db3cecf92_0
  • /data/data/####/1e35d31a471c76b5c48b764d2bb74284.0.tmp
  • /data/data/####/1e35d31a471c76b5c48b764d2bb74284.1.tmp
  • /data/data/####/1e653c53fcdf5ccc_0
  • /data/data/####/1f1f2b652ad1fed8_0
  • /data/data/####/1faef82c4b92f47c8d66fb8f62200633.0.tmp
  • /data/data/####/1faef82c4b92f47c8d66fb8f62200633.1.tmp
  • /data/data/####/1fdfad069e4666325efd7a141927cce9.0.tmp
  • /data/data/####/1fdfad069e4666325efd7a141927cce9.1.tmp
  • /data/data/####/20fe125ffbb5b0701669df9cbaa3fbb4.0.tmp
  • /data/data/####/20fe125ffbb5b0701669df9cbaa3fbb4.1.tmp
  • /data/data/####/2167dda60ca085f90c8547aab8bb0897.0.tmp
  • /data/data/####/2167dda60ca085f90c8547aab8bb0897.1.tmp
  • /data/data/####/2276eb3cde9c8d481145e0d1ee141fa6.0.tmp
  • /data/data/####/2276eb3cde9c8d481145e0d1ee141fa6.1
  • /data/data/####/23469ac906fcc612_0
  • /data/data/####/2687cdb408524ecb_0
  • /data/data/####/26fdccf584caf961489c85ddea34c25e.0.tmp
  • /data/data/####/26fdccf584caf961489c85ddea34c25e.1.tmp
  • /data/data/####/297ecea5cebb5dfe_0
  • /data/data/####/2a0afd649b00527b_0
  • /data/data/####/2beb0213504d07fc_0
  • /data/data/####/2c1b012e5665498b_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2cc80dabc69f58b6_1
  • /data/data/####/2d14d1fbd322f3a9_0
  • /data/data/####/2fcdcb73b1d81e80_0
  • /data/data/####/3038b430384d1bdb_0
  • /data/data/####/319f67e5051af6bb_0
  • /data/data/####/34ae72cc83475fab2d2fc34ca70b5ac3.0.tmp
  • /data/data/####/34ae72cc83475fab2d2fc34ca70b5ac3.1.tmp
  • /data/data/####/35deebbacc406487_0
  • /data/data/####/3eef6dc0e4993122bcdab4dbb5d1e48f.0.tmp
  • /data/data/####/3eef6dc0e4993122bcdab4dbb5d1e48f.1.tmp
  • /data/data/####/3ef2ebed6c12e1f6_0
  • /data/data/####/3f7f407e1e3fafc6177f44a631bab463.0.tmp
  • /data/data/####/3f7f407e1e3fafc6177f44a631bab463.1.tmp
  • /data/data/####/40bdd9dc9d1b0110cca115a02ce3c996.0.tmp
  • /data/data/####/40bdd9dc9d1b0110cca115a02ce3c996.1.tmp
  • /data/data/####/42d845b7e9fe7967_0
  • /data/data/####/43e66d4b161977ad_0
  • /data/data/####/44bf95306f22f8252e18f60a5b661a87.0.tmp
  • /data/data/####/44bf95306f22f8252e18f60a5b661a87.1.tmp
  • /data/data/####/45c2f2fcb9072b47_0
  • /data/data/####/483eb7e50ac944b1_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/511c33571a363c2ddb9d80a3966c9e75.0.tmp
  • /data/data/####/511c33571a363c2ddb9d80a3966c9e75.1
  • /data/data/####/529735cd13314468_0
  • /data/data/####/558c962b12e5059e_0
  • /data/data/####/558c962b12e5059e_1
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53BeginSession.cls_temp
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53BeginSession.json
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionApp.cls_temp
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionApp.json
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionDevice.cls_temp
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionDevice.json
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionOS.cls_temp
  • /data/data/####/5E0ECA9E0370-0001-0CD3-07A654B61E53SessionOS.json
  • /data/data/####/5abdc8300165fbbaf57b66ff21ae7598.0.tmp
  • /data/data/####/5abdc8300165fbbaf57b66ff21ae7598.1.tmp
  • /data/data/####/5baead2654fb6b9b_0
  • /data/data/####/5ce2b92834133eaf_0
  • /data/data/####/602a847bca2f3c35_0
  • /data/data/####/6121ad13c099ad44_0
  • /data/data/####/619cfb6fdbb00c71_0
  • /data/data/####/6443993e2527badb_0
  • /data/data/####/653e56b4b6556a9e_0
  • /data/data/####/678b00d0aee78ade_0
  • /data/data/####/67a473248953641b_0
  • /data/data/####/68b3d12bae551d77dd67f900c0cc3796.0.tmp
  • /data/data/####/68b3d12bae551d77dd67f900c0cc3796.1.tmp
  • /data/data/####/6b4b3775cd6f0f53_0
  • /data/data/####/6c038e3570d6abf1_0
  • /data/data/####/6df532097362df57_0
  • /data/data/####/6f8ac775dbbd7415_0
  • /data/data/####/6fc459ba53cb570a_0
  • /data/data/####/720ef52d18c06a1d_0
  • /data/data/####/7314935dd388433a533f14cf41bd9b79.0.tmp
  • /data/data/####/7314935dd388433a533f14cf41bd9b79.1.tmp
  • /data/data/####/74494c309e720a36_0
  • /data/data/####/7b4fd8111178d5b1_0
  • /data/data/####/816a05173971da00e7f80ea4ab882092.0.tmp
  • /data/data/####/816a05173971da00e7f80ea4ab882092.1.tmp
  • /data/data/####/83efbe48d0097388_0
  • /data/data/####/8a729281c4672a97_0
  • /data/data/####/8e82379d6289c6a0_0
  • /data/data/####/91baa182c7a11977_0
  • /data/data/####/91e1639f610f6bdce91a29500144d362.0.tmp
  • /data/data/####/91e1639f610f6bdce91a29500144d362.1.tmp
  • /data/data/####/9249e0304dd218632edcd7b65c487b31.0.tmp
  • /data/data/####/9249e0304dd218632edcd7b65c487b31.1.tmp
  • /data/data/####/9417e2571fcc81a2f44d996edbb27f87.0.tmp
  • /data/data/####/9417e2571fcc81a2f44d996edbb27f87.1.tmp
  • /data/data/####/946532930bc4dd08b645b7b7dce12f22.0.tmp
  • /data/data/####/946532930bc4dd08b645b7b7dce12f22.1.tmp
  • /data/data/####/96aaacf92ca2a4684622e8378be8bef7.0.tmp
  • /data/data/####/96aaacf92ca2a4684622e8378be8bef7.1.tmp
  • /data/data/####/983d9c890fc9430f_0
  • /data/data/####/99a9e7b6beca4803_0
  • /data/data/####/9aea9b2c55dd8602_0
  • /data/data/####/9b8191d38a57d91cb8622ccf29bc9e61.0.tmp
  • /data/data/####/9b8191d38a57d91cb8622ccf29bc9e61.1.tmp
  • /data/data/####/9ee6aba265d94aae_0
  • /data/data/####/AppEventsLogger.persistedevents
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/Index-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/Proguard
  • /data/data/####/Proguard.dex
  • /data/data/####/Proguard.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/TwitterAdvertisingInfoPreferences.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a1b31603de662834_0
  • /data/data/####/ad0c92dfa52e69b6_0
  • /data/data/####/ad1174eccad7b9928a862944b2525061.0.tmp
  • /data/data/####/ad1174eccad7b9928a862944b2525061.1.tmp
  • /data/data/####/afe1e5264eea33bc_0
  • /data/data/####/b2efa64ecb36f8f1_0
  • /data/data/####/b3bd0d67f800d222_0
  • /data/data/####/b3f68f25d2784092_0
  • /data/data/####/b6c28cea6ed9dfc1_0
  • /data/data/####/ba23d8ecda68de77_0
  • /data/data/####/bb75980305d806e2_0
  • /data/data/####/bfe270da7b3c41d2d403d2e220ba2aaa.0.tmp
  • /data/data/####/bfe270da7b3c41d2d403d2e220ba2aaa.1.tmp
  • /data/data/####/c0ba5f6ac9262009a102dcd65bbb9545.0.tmp
  • /data/data/####/c0ba5f6ac9262009a102dcd65bbb9545.1.tmp
  • /data/data/####/c14aadd6a001d32aa613591ba5621bb9.0.tmp
  • /data/data/####/c14aadd6a001d32aa613591ba5621bb9.1.tmp
  • /data/data/####/c32b904dcb65605464ba52e4402857c2.0.tmp
  • /data/data/####/c32b904dcb65605464ba52e4402857c2.1.tmp
  • /data/data/####/c6425a7a82407a4d5be924ca40b72bc7.0.tmp
  • /data/data/####/c6425a7a82407a4d5be924ca40b72bc7.1.tmp
  • /data/data/####/ce2a2172c04b134d_0
  • /data/data/####/ced4ee95694d98e8_0
  • /data/data/####/com.box.home.sports.driving.shooting_preferences.xml
  • /data/data/####/com.crashlytics.prefs.xml
  • /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
  • /data/data/####/com.crashlytics.settings.json
  • /data/data/####/com.facebook.internal.preferences.APP_GATEKEEPERS.xml
  • /data/data/####/com.facebook.internal.preferences.APP_SETTINGS.xml
  • /data/data/####/com.facebook.sdk.USER_SETTINGS.xml
  • /data/data/####/com.facebook.sdk.appEventPreferences.xml
  • /data/data/####/com.facebook.sdk.attributionTracking.xml
  • /data/data/####/com.google.InstanceId.properties
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml.bak
  • /data/data/####/com.trackmood.xml
  • /data/data/####/com.trackmood.xml.bak
  • /data/data/####/d0757ff92c7cde0a_0
  • /data/data/####/d10f805e771d7acb_0
  • /data/data/####/d17df1b61112fa40_0
  • /data/data/####/d2dc5907810bf9d6469636ee36fa8e0c.0.tmp
  • /data/data/####/d2dc5907810bf9d6469636ee36fa8e0c.1.tmp
  • /data/data/####/d2f2583341e8819f_0
  • /data/data/####/d36a06838d86b96510cb450382fcbedd.0.tmp
  • /data/data/####/d36a06838d86b96510cb450382fcbedd.1.tmp
  • /data/data/####/d524c14e22bcfdf8bbb4dce826fb6670.0.tmp
  • /data/data/####/d524c14e22bcfdf8bbb4dce826fb6670.1.tmp
  • /data/data/####/d652edce398cd1f1_0
  • /data/data/####/d712602fac5b5a6d_0
  • /data/data/####/d852358f0547c047_0
  • /data/data/####/da979ecade5ec5d34ef16afee5768753.0.tmp
  • /data/data/####/da979ecade5ec5d34ef16afee5768753.1.tmp
  • /data/data/####/db6d308a581c6fcfab9bcd23ca149687.0.tmp
  • /data/data/####/db6d308a581c6fcfab9bcd23ca149687.1.tmp
  • /data/data/####/dc65d925e8d719bc_0
  • /data/data/####/dcb9475f55f996eb464175c131c14090.0.tmp
  • /data/data/####/dcb9475f55f996eb464175c131c14090.1.tmp
  • /data/data/####/ddc81248140bbfab60cb4a3957fe8d50.0.tmp
  • /data/data/####/ddc81248140bbfab60cb4a3957fe8d50.1.tmp
  • /data/data/####/df3fd57066df14a7_0
  • /data/data/####/e0d37c7e54672663_0
  • /data/data/####/e1faac71364ae734f012eab8b036c877.0.tmp
  • /data/data/####/e1faac71364ae734f012eab8b036c877.1.tmp
  • /data/data/####/e39cb32e17f744d56fd777bbcbb633f1.0.tmp
  • /data/data/####/e39cb32e17f744d56fd777bbcbb633f1.1.tmp
  • /data/data/####/e6b4847055fb0116_0
  • /data/data/####/e6b841bc18b7d4b2aa694b9ec561841d.0.tmp
  • /data/data/####/e6b841bc18b7d4b2aa694b9ec561841d.1.tmp
  • /data/data/####/e7f703b39e0386b0_0
  • /data/data/####/eb63df014c679789166b677e8d26dcf1.0.tmp
  • /data/data/####/eb63df014c679789166b677e8d26dcf1.1.tmp
  • /data/data/####/ee06d428398126f321c6c1d6b0a03854.0.tmp
  • /data/data/####/ee06d428398126f321c6c1d6b0a03854.1.tmp
  • /data/data/####/ef23a807d6eb1acc_0
  • /data/data/####/f0526a9ba3d22e24460f3a42d742cf85.0.tmp
  • /data/data/####/f0526a9ba3d22e24460f3a42d742cf85.1.tmp
  • /data/data/####/f0de8c2de34c385b_0
  • /data/data/####/f0e521efe38e25e56cd8c4f30c37f85e.0.tmp
  • /data/data/####/f0e521efe38e25e56cd8c4f30c37f85e.1.tmp
  • /data/data/####/f13a76bbf6c7f0b3_0
  • /data/data/####/f1cdccba37924bda_0
  • /data/data/####/f265ab04a87097d7_0
  • /data/data/####/f3ab1e1292e135fa_0
  • /data/data/####/f492b69bbbf44b759cb56b502a03e5d9.0.tmp
  • /data/data/####/f492b69bbbf44b759cb56b502a03e5d9.1.tmp
  • /data/data/####/f76ccbbbd72a0391_0
  • /data/data/####/fa813c9ad67834ac_0
  • /data/data/####/fad417454155a749_0
  • /data/data/####/fb1f328d70d91607_0
  • /data/data/####/fbfaa72360830375742971fcfa7fc3e3.0.tmp
  • /data/data/####/fbfaa72360830375742971fcfa7fc3e3.1.tmp
  • /data/data/####/fe84559f864429f676e122182d61d275.0.tmp
  • /data/data/####/fe84559f864429f676e122182d61d275.1.tmp
  • /data/data/####/ffc4f27a1915b4500b839bfa47a9d8c0.0.tmp
  • /data/data/####/ffc4f27a1915b4500b839bfa47a9d8c0.1.tmp
  • /data/data/####/google_app_measurement_local.db
  • /data/data/####/google_app_measurement_local.db-journal
  • /data/data/####/index
  • /data/data/####/index.txt
  • /data/data/####/initialization_marker
  • /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.andr...ng.xml
  • /data/data/####/journal.tmp
  • /data/data/####/metrics_guid
  • /data/data/####/session_analytics.tap
  • /data/data/####/session_analytics.tap.tmp
  • /data/data/####/setting.xml
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86_64 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86_64 --instruction-set-features=default --dex-file=/data/user/0/<Package>/cache/Proguard --oat-fd=86 --oat-location=/data/user/0/<Package>/files/Proguard/Proguard.dex --compiler-filter=speed
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android