Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.23814

Добавлен в вирусную базу Dr.Web: 2017-06-27

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.HiddenAds.125.origin
Загружает из Интернета следующие детектируемые угрозы:
  • Android.HiddenAds.125.origin
Сетевая активность:
Подключается к:
  • a####.####.com
  • a####.####.net
  • a####.####.org
  • admobim####.com
  • api####.####.com
  • as####.####.com
  • b####.####.com
  • c####.####.com
  • d####.####.com
  • f####.####.com
  • face####.com
  • google-####.com
  • j####.####.com
  • m####.####.com
  • ma####.####.com
  • mmmmmm####.com
  • mobotoo####.####.com
  • n####.####.com
  • o####.####.com
  • p####.####.com
  • pag####.####.com
  • pass####.####.com
  • pl####.####.com
  • r####.####.com
  • real####.####.org
  • s####.####.com
  • sc####.####.com
  • se####.####.com
  • serv####.####.com
  • set####.####.com
  • technol####.net
  • u####.####.com
  • up####.####.com
Запросы HTTP GET:
  • a####.####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=####&sd...
  • a####.####.com/mpapi/ad?model=####&fomat=####&mcc=####&os_v=####&directi...
  • a####.####.net/api/v2/template/get?slot_id=####&update_time=####
  • a####.####.org/rule?platform=####&os_version=####&package_name=####&app_...
  • as####.####.com/playable/playable_loader.gif
  • b####.####.com/beacon.js
  • c####.####.com/i.js
  • d####.####.com/M00/01/AB/CvJMDVlBJNyAE3AUAAVgxYzjtNE875.zip
  • d####.####.com/mobile/img/41/58b5975ee4b05d7b7e3a9a59/image_148829616651...
  • f####.####.com/css?family=####&ver=####
  • f####.####.com/proc.php?426060f####
  • f####.####.com/s/lato/v13/MZ1aViPqjfvZwVD_tzjjkwLUuEpTyoUstqEm5AMlJo4.ttf
  • face####.com/plugins/likebox.php?href=####&w####&height=####&colorscheme...
  • google-####.com/collect?v=####&_v=####&a=####&t=####&_s=####&dl=####&ul=...
  • j####.####.com/t/e/technologycraze.net.105160.js?t=####
  • m####.####.com/client/home/get.do?local=####&density=####&language=####&...
  • m####.####.com/mghtml/framehtml/c/t/e/technologycraze.net.105160.html
  • ma####.####.com/frontend/cardList.htm?isrecmd=####&ran=####&ismsg=####&i...
  • mobotoo####.####.com/mobotoolpush/notibarpush.json?version_name=####&adi...
  • n####.####.com/mu/mobotoolpush_admin/icon/1498202284/splash_theme_store....
  • n####.####.com/openapi/ad/v3?app_id=####&unit_id=####&category=####&req_...
  • o####.####.com/ipo/api/gray/status?appvc=####&os=####&appvn=####&avn=###...
  • p####.####.com/notification/android/message.json?pname=####&version=####...
  • pag####.####.com/pagead/js/adsbygoogle.js
  • pass####.####.com/android/v2/getDoSignInfo.htm?uid=####&versionCode=####...
  • r####.####.com/nad?v1=####&model=####&dx=####&dy=####&accept=####&slot_c...
  • real####.####.org/realtime?platform=####&os_version=####&package_name=##...
  • sc####.####.com/v1/scheme/app?model=####&mcc=####&os_v=####&direction=##...
  • serv####.####.com/105160/1?w=####&h=####&cols=####&pv=####&cbuster=####&...
  • set####.####.com/setting?app_id=####&sign=####&platform=####&os_version=...
  • technol####.net/wp-content/plugins/wp-share-buttons/Front_end/js/custom_...
  • u####.####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&prod...
Запросы HTTP POST:
  • a####.####.com/detail/getOfferListNew?enc=####
  • admobim####.com/surl/api2_reg.action
  • api####.####.com/v3/log/init
  • mmmmmm####.com/osp/oaen_reg.action
  • p####.####.com/ads-service/ads/service/getListAd.do
  • p####.####.com/getList.htm
  • pl####.####.com/ad_dex.php
  • s####.####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
  • se####.####.com/getWeather.htm
  • se####.####.com/initRequestDomain.htm
  • up####.####.com/upload?orientation=####&platform=####&model=####&userage...
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.mbj/####/classes.zip
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/f_000004
  • <Package Folder>/cache/####/f_000005
  • <Package Folder>/cache/####/f_000006
  • <Package Folder>/cache/####/f_000007
  • <Package Folder>/cache/####/f_000008
  • <Package Folder>/cache/####/f_000009
  • <Package Folder>/cache/####/f_00000a
  • <Package Folder>/cache/####/f_00000b
  • <Package Folder>/cache/####/f_00000c
  • <Package Folder>/cache/####/f_00000d
  • <Package Folder>/cache/####/f_00000e
  • <Package Folder>/cache/####/f_00000f
  • <Package Folder>/cache/####/f_000010
  • <Package Folder>/cache/####/f_000011
  • <Package Folder>/cache/####/f_000012
  • <Package Folder>/cache/####/f_000013
  • <Package Folder>/cache/####/f_000014
  • <Package Folder>/cache/####/f_000015
  • <Package Folder>/cache/####/f_000016
  • <Package Folder>/cache/####/f_000017
  • <Package Folder>/cache/####/f_000018
  • <Package Folder>/cache/####/f_000019
  • <Package Folder>/cache/####/f_00001a
  • <Package Folder>/cache/####/f_00001b
  • <Package Folder>/cache/####/f_00001c
  • <Package Folder>/cache/####/f_00001d
  • <Package Folder>/cache/####/f_00001e
  • <Package Folder>/cache/####/f_00001f
  • <Package Folder>/cache/####/f_000020
  • <Package Folder>/cache/####/f_000021
  • <Package Folder>/cache/####/f_000022
  • <Package Folder>/cache/####/f_000023
  • <Package Folder>/cache/####/f_000024
  • <Package Folder>/cache/####/f_000025
  • <Package Folder>/cache/####/f_000026
  • <Package Folder>/cache/####/f_000027
  • <Package Folder>/cache/####/f_000028
  • <Package Folder>/cache/####/f_000029
  • <Package Folder>/cache/####/index
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes-1762323816.zip
  • <Package Folder>/databases/MessageStore.db-journal
  • <Package Folder>/databases/MsgLogStore.db-journal
  • <Package Folder>/databases/accs.db-journal
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/arrkii.asa.sdk.db-journal
  • <Package Folder>/databases/cc.db
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/databases/download_file.db-journal
  • <Package Folder>/databases/message_accs_db
  • <Package Folder>/databases/message_accs_db-journal
  • <Package Folder>/databases/mobogenie.db
  • <Package Folder>/databases/mobogenie.db-journal
  • <Package Folder>/databases/mobogenie_music.db
  • <Package Folder>/databases/mobogenie_music.db-journal
  • <Package Folder>/databases/mobogenie_update.db
  • <Package Folder>/databases/mobogenie_update.db-journal
  • <Package Folder>/databases/mobpower.db-journal
  • <Package Folder>/databases/mobvista.msdk.db-journal
  • <Package Folder>/databases/my.db
  • <Package Folder>/databases/my.db-journal
  • <Package Folder>/databases/self_ad_db
  • <Package Folder>/databases/self_ad_db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
  • <Package Folder>/databases/webviewCookiesChromiumPrivate.db-journal (deleted)
  • <Package Folder>/databases/ztrack.db-journal
  • <Package Folder>/eudemon
  • <Package Folder>/files/####/592E8919034B-0001-0854-5922701AC82BBeginSession.cls_temp
  • <Package Folder>/files/####/592E8919034B-0001-0854-5922701AC82BSessionApp.cls_temp
  • <Package Folder>/files/####/592E8919034B-0001-0854-5922701AC82BSessionDevice.cls_temp
  • <Package Folder>/files/####/592E8919034B-0001-0854-5922701AC82BSessionOS.cls
  • <Package Folder>/files/####/592E8919034B-0001-0854-5922701AC82BSessionUser.cls_temp
  • <Package Folder>/files/####/592E891A034A-0001-08A9-5922701AC82BBeginSession.cls_temp
  • <Package Folder>/files/####/592E891A034A-0001-08A9-5922701AC82BSessionApp.cls_temp
  • <Package Folder>/files/####/592E891A034A-0001-08A9-5922701AC82BSessionDevice.cls_temp
  • <Package Folder>/files/####/592E891A034A-0001-08A9-5922701AC82BSessionOS.cls_temp
  • <Package Folder>/files/####/592E891A034A-0001-08A9-5922701AC82BSessionUser.cls_temp
  • <Package Folder>/files/####/592E8924012A-0001-0A47-5922701AC82BBeginSession.cls_temp
  • <Package Folder>/files/####/592E8924012A-0001-0A47-5922701AC82BSessionApp.cls_temp
  • <Package Folder>/files/####/592E8924012A-0001-0A47-5922701AC82BSessionDevice.cls_temp
  • <Package Folder>/files/####/592E8924012A-0001-0A47-5922701AC82BSessionOS.cls_temp
  • <Package Folder>/files/####/com.crashlytics.settings.json
  • <Package Folder>/files/####/initialization_marker
  • <Package Folder>/files/####/mp_agent_log
  • <Package Folder>/files/####/sa_26900a5f-be7e-42b7-8e85-b6bcd3970cd0_1496221978156.tap
  • <Package Folder>/files/####/sa_caa2ce35-4cce-470b-9798-284983eb448b_1496221988794.tap
  • <Package Folder>/files/####/session_analytics.tap
  • <Package Folder>/files/####/session_analytics.tap.tmp
  • <Package Folder>/files/DaemonServer
  • <Package Folder>/files/agoo.pid
  • <Package Folder>/files/cwd
  • <Package Folder>/files/google.db
  • <Package Folder>/files/mobclick_agent_cached_<Package>302141
  • <Package Folder>/files/rk.jar
  • <Package Folder>/files/uninstall
  • <Package Folder>/files/watch_server
  • <Package Folder>/shared_prefs/0def24353a3d8f0f7144f3755d8f7744.xml
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/<Package>_ui_preferences.xml
  • <Package Folder>/shared_prefs/<Package>_ui_preferences.xml.bak
  • <Package Folder>/shared_prefs/ACCS_BIND.xml
  • <Package Folder>/shared_prefs/ACCS_SDK.xml
  • <Package Folder>/shared_prefs/ACCS_SDK.xml.bak
  • <Package Folder>/shared_prefs/ACCS_SDK_CHANNEL.xml
  • <Package Folder>/shared_prefs/AGOO_BIND.xml
  • <Package Folder>/shared_prefs/ActivatePreUtil.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/Agoo_AppStore.xml
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/FLOAT_WINDOW.xml
  • <Package Folder>/shared_prefs/FirstNewUninstallTime.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml
  • <Package Folder>/shared_prefs/MobogeniePrefsFile.xml.bak
  • <Package Folder>/shared_prefs/PUSH_PRE.xml
  • <Package Folder>/shared_prefs/PUSH_PRE.xml.bak
  • <Package Folder>/shared_prefs/SCORE_PRE.xml
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml
  • <Package Folder>/shared_prefs/SETTING_DOMAIN.xml.bak
  • <Package Folder>/shared_prefs/SETTING_PRE.xml
  • <Package Folder>/shared_prefs/SETTING_PRE.xml (deleted)
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml
  • <Package Folder>/shared_prefs/SUBSCRIBE_AD.xml.bak
  • <Package Folder>/shared_prefs/TOKEN.xml
  • <Package Folder>/shared_prefs/TwitterAdvertisingInfoPreferences.xml
  • <Package Folder>/shared_prefs/USERINFO.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml
  • <Package Folder>/shared_prefs/ak.salvia.sdk.xml.bak
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/shared_prefs/apsad.xml.bak
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/shared_prefs/clean.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml
  • <Package Folder>/shared_prefs/clean_version_sp.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.1.xml.bak
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml
  • <Package Folder>/shared_prefs/com.applovin.sdk.impl.postbackQueue.domain.xml.bak
  • <Package Folder>/shared_prefs/com.crashlytics.prefs.xml
  • <Package Folder>/shared_prefs/com.crashlytics.sdk.android;answers;settings.xml
  • <Package Folder>/shared_prefs/com.facebook.internal.preferences.APP_SETTINGS.xml
  • <Package Folder>/shared_prefs/com.mobpower.xml
  • <Package Folder>/shared_prefs/com.mobpower.xml.bak
  • <Package Folder>/shared_prefs/ct_default.xml
  • <Package Folder>/shared_prefs/dcSharedPreferences.dat.xml
  • <Package Folder>/shared_prefs/device_info.xml
  • <Package Folder>/shared_prefs/hunter_config.xml
  • <Package Folder>/shared_prefs/install.xml
  • <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.q.xml
  • <Package Folder>/shared_prefs/last_know_location.xml
  • <Package Folder>/shared_prefs/mobvista.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/other_config.xml
  • <Package Folder>/shared_prefs/self_adextend.xml
  • <Package Folder>/shared_prefs/self_adextend.xml.bak
  • <Package Folder>/shared_prefs/service_config.xml
  • <Package Folder>/shared_prefs/service_config.xml.bak
  • <Package Folder>/shared_prefs/share_date.xml
  • <Package Folder>/shared_prefs/share_date.xml.bak
  • <Package Folder>/shared_prefs/sp_config.xml
  • <Package Folder>/shared_prefs/sp_config.xml.bak
  • <Package Folder>/shared_prefs/strategy_sp.xml
  • <Package Folder>/shared_prefs/t_ini.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.androidsystem/####/49.x-3.0.1.apk
  • <SD-Card>/.androidsystem/####/PlugShareData
  • <SD-Card>/.androidsystem/####/files.db
  • <SD-Card>/.androidsystem/####/gads.db
  • <SD-Card>/.androidsystem/####/plugxml.xml
  • <SD-Card>/.androidsystem/####/syncfiles.db
  • <SD-Card>/.androidsystem/Plugin.zip
  • <SD-Card>/Android/####/.nomedia
  • <SD-Card>/Android/####/1380229154.js
  • <SD-Card>/Android/####/2394940e76a2e0ed4cae4ebdd4975357b95c3969_v23_phone.mp4
  • <SD-Card>/Android/####/da0aa96f0e8abd616b46c7377aa8769981aafd63_v23_phone.mp4
  • <SD-Card>/Android/####/inapp_20170531.log
  • <SD-Card>/Android/####/journal
  • <SD-Card>/Android/####/journal.tmp
  • <SD-Card>/Android/####/jquery-1.9.1.min.js
  • <SD-Card>/Android/####/jquery-2.1.1.min.js
  • <SD-Card>/Android/####/jquery.knob.js
  • <SD-Card>/Android/####/o903c61a_e49f325a0ff6347a4820c77a06c211bbbc99419a_raw11.gif
  • <SD-Card>/Android/####/playable_GnG_V3_l_03.js
  • <SD-Card>/Android/####/playable_GnG_V3_p_03.js
  • <SD-Card>/Android/####/playable_c2_pathfind_02.min.js
  • <SD-Card>/Android/####/playable_playable_close.png
  • <SD-Card>/Android/####/playable_playable_fallback.png
  • <SD-Card>/Android/####/playable_playable_loader.gif
  • <SD-Card>/Android/####/sound_off.png
  • <SD-Card>/Android/####/sound_on.png
  • <SD-Card>/Download/####/accs_election
  • <SD-Card>/LogN/####/sp
  • <SD-Card>/baidu/####/journal
  • <SD-Card>/baidu/.cuid
  • <SD-Card>/mobogenie/####/all_search_hotwords.json
  • <SD-Card>/mobogenie/####/facebook_ads_position.json
  • <SD-Card>/mobogenie/####/gl_app_home_all_json
  • <SD-Card>/mobogenie/####/mobogenie.uuid
  • <SD-Card>/mobogenie/####/splashbanner.png
  • <SD-Card>/mobogenie/mobosd.bin
  • <SD-Card>/mobogenie/mobosd.bin-journal
Другие:
Запускает следующие shell-скрипты:
  • /data/data/com.mobogenie/files/cwd 0
  • /data/data/com.mobogenie/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1031&uuid=0204c507-b775-49e8-88ae-70d366a321de&android=d8acaa6b5680a853&imei=356507059351895&versionCode=302141&versionName=3.2.14.1&site=GL
  • /data/data/com.mobogenie/files/watch_server /data/data/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302141&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • /data/user/0/com.mobogenie/files/watch_server /data/user/0/com.mobogenie http://redirect.mobogenie.com?pn=com.mobogenie&v=302141&an=com.mobogenie&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D %7B%22package%22%3A%22<Package>%22%2C%22appKey%22%3A%22%22%2C%22utdid%22%3A%22WS6JGl46npIDAGdzx1ErjVzg%22%2C%22sdkVersion%22%3A%22212%22%7D -I agoodm.m.taobao.com -O 80 -T -Z
  • <dexopt>
  • cat /proc/cpuinfo
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 755 /data/user/0/<Package>/files/watch_server
  • chmod 755 /data/user/0/com.mobogenie/files/watch_server
  • sh
  • sh <Package Folder>/files/cwd 0
  • sh <Package Folder>/files/uninstall 0 http://m.mobogenie.com/en/uninstall/uninstall.html?channel_id=1031&uuid=0204c507-b775-49e8-88ae-70d366a321de&android=d8acaa6b5680a853&imei=<IMEI>&versionCode=302141&versionName=3.2.14.1&site=GL
  • sh <Package Folder>/files/watch_server <Package Folder> http://redirect.mobogenie.com?pn=<Package>&v=302141&an=<Package>&lc=en_US&tag=mobogenie com.android.browser/com.android.browser.BrowserActivity 0

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке