Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.30635

Добавлен в вирусную базу Dr.Web: 2017-09-25

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.Click.171.origin
  • Android.DownLoader.478.origin
  • Android.RemoteCode.93.origin
  • Android.Xiny.1.origin
  • Android.Xiny.116.origin
  • Android.Xiny.197
Осуществляет доступ к приватному интерфейсу телефонии (ITelephony).
Сетевая активность:
Подключается к:
  • UDP(DNS) <Google DNS>
  • TCP(GCM) <Google Host>
  • TCP(HTTP/1.1) api.info####.me:80
  • TCP(HTTP/1.1) serv####.m####.com:80
  • TCP(HTTP/1.1) log.t####.in:80
  • TCP(HTTP/1.1) www.admobim####.com:80
  • TCP(HTTP/1.1) c11.la4.down####.####.com:7080
  • TCP(HTTP/1.1) f####.google####.com:80
  • TCP(HTTP/1.1) 2####.177.13.68:8288
  • TCP(HTTP/1.1) dpl.b####.com:80
  • TCP(HTTP/1.1) c7.la4.down####.####.com:7080
  • TCP(HTTP/1.1) www.technol####.co.uk:80
  • TCP(HTTP/1.1) sl####.1####.com:8111
  • TCP(HTTP/1.1) c4.la4.down####.####.com:7080
  • TCP(HTTP/1.1) api.br####.com:80
  • TCP(HTTP/1.1) www.face####.com:80
  • TCP(HTTP/1.1) c12.la4.down####.####.com:7080
  • TCP(HTTP/1.1) f####.cdn.1####.com:80
  • TCP(HTTP/1.1) api.mob####.b####.com:80
  • TCP(HTTP/1.1) d####.9####.com:7080
  • TCP(HTTP/1.1) o####.d####.9####.com:80
  • TCP(HTTP/1.1) wild####.9appsin####.com.####.net:80
  • TCP(HTTP/1.1) s####.mob####.b####.com:80
  • TCP(HTTP/1.1) c5.la4.down####.####.com:7080
  • TCP(HTTP/1.1) f####.gst####.com:80
  • TCP(HTTP/1.1) pic.a####.com:80
  • TCP(HTTP/1.1) mo.freeind####.com:80
  • TCP(HTTP/1.1) g####.u####.com:80
  • TCP(HTTP/1.1) api.l####.com:80
  • TCP(HTTP/1.1) 8.37.2####.19:80
  • TCP(HTTP/1.1) www.mmmmmm####.com:80
  • TCP(HTTP/1.1) 1####.179.9.106:80
  • TCP(HTTP/1.1) l.a####.com:80
  • TCP(HTTP/1.1) pag####.googles####.com:80
  • TCP(HTTP/1.1) real####.icec####.org:80
  • TCP(HTTP/1.1) ea.sno####.1####.com:18088
  • TCP(HTTP/1.1) u####.b####.com:80
  • TCP(HTTP/1.1) 1####.254.223.129:80
  • TCP(HTTP/1.1) c####.mobiupm####.com:80
  • TCP(HTTP/1.1) en.sno####.1####.com:18088
  • TCP(HTTP/1.1) pl####.mob####.b####.com:80
  • TCP(HTTP/1.1) ak.icec####.org:80
  • TCP(HTTP/1.1) c10.la4.down####.####.com:7080
  • TCP(HTTP/1.1) c3.la4.down####.####.com:7080
  • TCP(HTTP/1.1) p####.u####.com:80
  • TCP(HTTP/1.1) c1.la4.down####.####.com:7080
  • TCP(HTTP/1.1) en.sno####.1####.com:8088
  • TCP(TLS/1.0) p####.lead####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) 1####.168.58.254:41695
  • TCP(TLS/1.0) go4.mob####.xyz:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.0) tpc.googles####.com:443
  • TCP(TLS/1.0) and####.cli####.go####.com:443
  • TCP(TLS/1.0) pag####.googles####.com:443
  • TCP(TLS/1.0) 1####.168.58.254:38002
  • TCP(TLS/1.0) 1####.168.58.254:38917
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) y####.ali####.com:443
  • TCP(TLS/1.0) www.face####.com:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) st####.xx.f####.net:443
  • TCP(TLS/1.0) 1####.254.223.129:443
Запросы DNS:
  • ak.icec####.org
  • and####.cli####.go####.com
  • api.br####.com
  • api.info####.me
  • api.l####.com
  • api.mob####.b####.com
  • c####.mobiupm####.com
  • c1.la4.down####.####.com
  • c10.la4.down####.####.com
  • c11.la4.down####.####.com
  • c12.la4.down####.####.com
  • c3.la4.down####.####.com
  • c4.la4.down####.####.com
  • c5.la4.down####.####.com
  • c7.la4.down####.####.com
  • d####.9####.com
  • dpl.b####.com
  • ea.sno####.1####.com
  • en.sno####.1####.com
  • f####.cdn.1####.com
  • f####.google####.com
  • f####.gst####.com
  • g####.u####.com
  • go4.mob####.xyz
  • googl####.g.doublec####.net
  • hl####.down####.9appsin####.com
  • l.a####.com
  • log.t####.in
  • mo.freeind####.com
  • na####.sno####.1####.com
  • o####.d####.9####.com
  • p####.lead####.com
  • p####.u####.com
  • pag####.googles####.com
  • pic.a####.com
  • pl####.mob####.b####.com
  • real####.icec####.org
  • s####.mob####.b####.com
  • serv####.m####.com
  • st####.xx.f####.net
  • tpc.googles####.com
  • u####.b####.com
  • us.y####.al####.com
  • www.admobim####.com
  • www.face####.com
  • www.google-####.com
  • www.mmmmmm####.com
  • www.technol####.co.uk
Запросы HTTP GET:
  • api.br####.com/click?tid=####
  • api.info####.me/api/s2s/goto?id=####&channel=####&provider=####&appkey=#...
  • api.mob####.b####.com/index.php?r=####&al=####&l=####&p=####&hp=####&lc=...
  • api.mob####.b####.com/strategy/api/v1/rule/get?p=####&hp=####&l=####&c=#...
  • c####.mobiupm####.com/?utm_medium=####&utm_campaign=####&1=####&cid=####
  • c####.mobiupm####.com/?utm_term=####&clickverify=####&utm_content=####
  • c####.mobiupm####.com/proc.php?3a7e7f2####
  • c1.la4.down####.####.com:7080/group1/M00/18/26/pYYBAFfuN8GAS0P2AAAC0c0UW...
  • c1.la4.down####.####.com:7080/group1/M00/3C/F4/p4YBAFfWC0eAFrvGAAAKdmCuB...
  • c1.la4.down####.####.com:7080/group1/M00/84/27/qYYBAFgN05KANzdLAAAB1tPaT...
  • c1.la4.down####.####.com:7080/group1/M01/64/AD/qYYBAFfuOBiAboOoAAAC1Bn3v...
  • c1.la4.down####.####.com:7080/group1/M02/0A/C7/q4YBAFhmW9uAPRECAAAQyfKX2...
  • c1.la4.down####.####.com:7080/group2/M00/F4/6A/RA0DAFmvYT-AMQB9AAAUHRZh4...
  • c1.la4.down####.####.com:7080/group2/M02/3C/16/QQ0DAFnHERGALPX9AABzxl-xX...
  • c10.la4.down####.####.com:7080/group1/M01/18/2B/poYBAFfuN8OAGenKAAAJ_cFk...
  • c10.la4.down####.####.com:7080/group2/M00/2B/4D/RQ0DAFnCXQeAIz4cAAALkdyb...
  • c10.la4.down####.####.com:7080/group2/M00/34/1C/RQ0DAFnFaXuAXKYzAAAIBn5B...
  • c10.la4.down####.####.com:7080/group2/M00/9B/7B/RA0DAFllvmqAZwOEAAAVSL8D...
  • c10.la4.down####.####.com:7080/group2/M00/C3/FC/Qg0DAFmHemSAf-eoAAAME1U6...
  • c10.la4.down####.####.com:7080/group2/M01/26/FE/QQ0DAFnBCliAdR5HAAAKTseV...
  • c11.la4.down####.####.com:7080/group1/M00/7C/6C/qIYBAFkH_DWATu_FAAASB8Cw...
  • c11.la4.down####.####.com:7080/group2/M00/21/12/Qg0DAFm_ROmAQBZ7AAALw-kT...
  • c11.la4.down####.####.com:7080/group2/M01/26/B5/Qg0DAFnA9UKALvVCAAAMdyX3...
  • c11.la4.down####.####.com:7080/group2/M01/54/63/RQ0DAFk1NRKAIMzGAAAI6_mf...
  • c12.la4.down####.####.com:7080/group1/M01/D2/D8/poYBAFeqZxiACY5lAAAO2SSC...
  • c12.la4.down####.####.com:7080/group2/M00/08/81/QQ0DAFm3R_2AWn5xAAAE1ear...
  • c12.la4.down####.####.com:7080/group2/M00/25/8F/RA0DAFkbur-AcdbOAAAI51t9...
  • c12.la4.down####.####.com:7080/group2/M01/F3/29/QQ0DAFmvNL6AKIYrAAAQY7xK...
  • c12.la4.down####.####.com:7080/group2/M02/9B/7B/RA0DAFllvmeAFkGtAAAHVmAg...
  • c3.la4.down####.####.com:7080/group1/M01/84/27/qYYBAFgN05WAXw-uAAAITyh1r...
  • c3.la4.down####.####.com:7080/group2/M00/09/47/RQ0DAFm3paqAGM-aAAASP4Our...
  • c3.la4.down####.####.com:7080/group2/M00/0B/30/RA0DAFm4oseAegi3AAAQc4Dwz...
  • c3.la4.down####.####.com:7080/group2/M01/14/AD/RA0DAFm7r7aAP9vRAAAGUmb0q...
  • c4.la4.down####.####.com:7080/group2/M01/2D/56/RQ0DAFnC-zWAYeQPAAAaPeu8T...
  • c4.la4.down####.####.com:7080/group2/M02/0C/A5/RQ0DAFm5Z6uADRdNAAAfdYXNX...
  • c4.la4.down####.####.com:7080/group2/M02/18/F8/RQ0DAFkVe-6AMTLbAABpLUBZk...
  • c5.la4.down####.####.com:7080/group1/M01/1B/36/pYYBAFfwsmKANMpPAAAjMFKDG...
  • c5.la4.down####.####.com:7080/group2/M01/54/63/RA0DAFk1NPiAFronAAADKNTgE...
  • c5.la4.down####.####.com:7080/group2/M01/EC/CF/QQ0DAFmsmfGAFhEyAAAdhBfC7...
  • c5.la4.down####.####.com:7080/group2/M02/E0/E5/RQ0DAFmnommAGO5DAAAWcNIcb...
  • c7.la4.down####.####.com:7080/group1/M00/3A/FA/qoYBAFfuOBuAHHmVAAAJjVcyi...
  • c7.la4.down####.####.com:7080/group2/M00/18/F7/Qg0DAFkVe-iAe6AjAAALXksbw...
  • c7.la4.down####.####.com:7080/group2/M00/41/B7/QQ0DAFnIaWSAenepAABBMWgaJ...
  • c7.la4.down####.####.com:7080/group2/M00/AB/9D/QQ0DAFlxxyeAP4znAAASM3m85...
  • c7.la4.down####.####.com:7080/group2/M00/ED/12/Qg0DAFmsrwuAA00NAAAZ-2bBa...
  • c7.la4.down####.####.com:7080/group2/M01/27/15/RA0DAFnBEVeAGyTnAAAHVTZTQ...
  • c7.la4.down####.####.com:7080/group2/M02/2F/2D/RA0DAFnDkVGACPfbAAAPxNvsK...
  • dpl.b####.com/M01/01/AD/CvJJDVmj_4CAOZroAArECPaKkRM544.zip
  • f####.google####.com/css?family=####&ver=####
  • f####.gst####.com/s/lato/v13/MZ1aViPqjfvZwVD_tzjjkwLUuEpTyoUstqEm5AMlJo4...
  • f####.gst####.com/s/robotoslab/v6/dazS1PrQQuCxC3iOAJFEJTdGNerWpg2Hn6A-Bx...
  • o####.d####.9####.com/upload/common/2017/8/3/18/2e7dbecb-3488-4ef6-a942-...
  • o####.d####.9####.com/upload/common/2017/8/3/18/3b56422f-8543-44a4-b0ca-...
  • p####.u####.com/u1/hhjmqhkilmhnlipliqhikjhhlmopkhlpqqnhjpopoimhhhhhihhii...
  • pag####.googles####.com/pagead/js/adsbygoogle.js
  • pag####.googles####.com/pagead/js/r20170920/r20170110/reactive_library.js
  • pag####.googles####.com/pagead/js/r20170920/r20170110/show_ads_impl.js
  • pic.a####.com/img/t4963v731.png
  • serv####.m####.com/119987?t=0.7058979235589504&ref=&lu=http://www.techno...
  • u####.b####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&pro...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/11a57884335fab47f5930e4b...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/1bdc5d7dda1d86a683ca1d87...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/20669af1e2489eabb37d270b...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/21053219746c86dd2d207e2e...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/3aad2e401afef68052fe5bdc...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/450310489ac371ded2b1b4cd...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/52ec4ab6c0a1e3e1850b4863...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/6866ec7e044b8485ff642498...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/76a905276c0782219850d573...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/7d0a8a810a2e1c9016ebca44...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/88d0cd26a59bcd2f827d1158...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/8e4ac78852a9e9b5ec2aedf8...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/943d1498acc85f35c00ab32a...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/94de3ac28d8549bd058945ac...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/b0aa25d77dc4dab01bdaafc4...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/f4e1f28eefc438b54f25faf4...
  • wild####.9appsin####.com.####.net/9apps/rs/2017/f8a9992ccb4f50d98182d5cb...
  • www.face####.com/plugins/likebox.php?href=####&w####&height=####&colorsc...
Запросы HTTP POST:
  • api.info####.me/api/ads/connect
  • api.info####.me/api/ads/fetch?_s=####
  • api.info####.me/api/ads/vas?_s=####&
  • en.sno####.1####.com:18088/sdk/api/checklib
  • en.sno####.1####.com:8088/sdk/api/log/record
  • log.t####.in/i.php
  • log.t####.in/sal.php
  • mo.freeind####.com/detail/getOfferListNew?enc=####
  • pl####.mob####.b####.com/ad_dex.php
  • s####.mob####.b####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
  • sl####.1####.com:8111/native/api/v1/init
  • sl####.1####.com:8111/native/api/v1/update
  • sl####.1####.com:8111/native/sdk/api/ad/client_action
  • sl####.1####.com:8111/native/sdk/api/regclient
  • www.mmmmmm####.com/osp/oaen_get.action?tasktype=####&imei=####&imsi=####...
  • www.mmmmmm####.com/osp/oaen_reg.action
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.mbj/####/classes.zip
  • <Package Folder>/HasStarted
  • <Package Folder>/app_SGLib/####/libsgmainso-5.3.7011.so.tmp
  • <Package Folder>/app_SGLib/####/lock.lock
  • <Package Folder>/app_jniLibs/libcrash_1.5.0.0.so
  • <Package Folder>/app_libs/.atmp9.jar
  • <Package Folder>/app_libs/.atmp_8.log
  • <Package Folder>/app_osdk/adflash_shell.jar
  • <Package Folder>/app_osdk/t.zip
  • <Package Folder>/app_refresh_cache/f40cd568057278248a47d87960e8605d
  • <Package Folder>/app_stat_log3/1501849299956
  • <Package Folder>/app_stat_log3/1501849311324
  • <Package Folder>/app_stat_log3/1501849326371
  • <Package Folder>/app_stat_log3/1501849337596
  • <Package Folder>/app_stat_log3/1501849348175
  • <Package Folder>/app_stat_log3/1501849358999
  • <Package Folder>/app_wa/####/11gpsdfe_1501849323953002116.wa
  • <Package Folder>/app_wa/####/12hqtegf_1501849292091002116.wa
  • <Package Folder>/app_wa/####/14jsvgih_1501849292369002116.wa
  • <Package Folder>/app_wa/####/16luxikj_1501849294181002116.wa
  • <Package Folder>/app_wa/####/18nwzkml_1501849295078002116.wa
  • <Package Folder>/app_wa/####/41tztufn_1501849292090002116.wa
  • <Package Folder>/app_wa/####/42u0uvgo_1501849324114002116.wa
  • <Package Folder>/app_wa/####/43v1vwhp_1501849292368002116.wa
  • <Package Folder>/app_wa/####/45x3xyjr_1501849294180002116.wa
  • <Package Folder>/app_wa/####/47z5z0lt_1501849295077002116.wa
  • <Package Folder>/app_wa/####/491712nv_1501849323952002116.wa
  • <Package Folder>/cache/####/09f2ee0eb188104c5ce7bd2edbfe37cc.0.tmp
  • <Package Folder>/cache/####/09f2ee0eb188104c5ce7bd2edbfe37cc.1.tmp
  • <Package Folder>/cache/####/0d53d88a8cca4c94c590bc528157ed2c.0
  • <Package Folder>/cache/####/0d53d88a8cca4c94c590bc528157ed2c.1
  • <Package Folder>/cache/####/18584cba777b8afa4525808b6cbca366.0
  • <Package Folder>/cache/####/18584cba777b8afa4525808b6cbca366.1
  • <Package Folder>/cache/####/319f7afe226ea40993893de5dd14a79c.0
  • <Package Folder>/cache/####/319f7afe226ea40993893de5dd14a79c.0.tmp
  • <Package Folder>/cache/####/319f7afe226ea40993893de5dd14a79c.1
  • <Package Folder>/cache/####/4795a36516ace54183466fc70e9063a3.0
  • <Package Folder>/cache/####/4795a36516ace54183466fc70e9063a3.1
  • <Package Folder>/cache/####/57d3226012c6afcc9c7ffbfefd6c38e7.0
  • <Package Folder>/cache/####/57d3226012c6afcc9c7ffbfefd6c38e7.1
  • <Package Folder>/cache/####/7c682b9d22480a2b5685ae45fbc4bf2c.0
  • <Package Folder>/cache/####/7c682b9d22480a2b5685ae45fbc4bf2c.1
  • <Package Folder>/cache/####/883e5de96cadb9f665dd98234449c99f.0
  • <Package Folder>/cache/####/883e5de96cadb9f665dd98234449c99f.1
  • <Package Folder>/cache/####/8eaed2c2244140066ee78abb76b89c76.0
  • <Package Folder>/cache/####/8eaed2c2244140066ee78abb76b89c76.1
  • <Package Folder>/cache/####/946b685a5e99bc28d265f1d760198341.0
  • <Package Folder>/cache/####/946b685a5e99bc28d265f1d760198341.1
  • <Package Folder>/cache/####/9d52a51225351a9703398549509400e2.0
  • <Package Folder>/cache/####/9d52a51225351a9703398549509400e2.1
  • <Package Folder>/cache/####/a440d1187534fb7a3e5619897091e009.0.tmp
  • <Package Folder>/cache/####/a440d1187534fb7a3e5619897091e009.1
  • <Package Folder>/cache/####/af9360c0f5e611b81ca8dcb236ea05eb.0
  • <Package Folder>/cache/####/af9360c0f5e611b81ca8dcb236ea05eb.1
  • <Package Folder>/cache/####/afb76bb17e28a2892f78d30031b8fe3b.0
  • <Package Folder>/cache/####/afb76bb17e28a2892f78d30031b8fe3b.1
  • <Package Folder>/cache/####/c6876252dfe9aa05d00cea4e62e87ddc.0
  • <Package Folder>/cache/####/c6876252dfe9aa05d00cea4e62e87ddc.1
  • <Package Folder>/cache/####/cec8feb192b0b0dafa55014dec410c90.0
  • <Package Folder>/cache/####/cec8feb192b0b0dafa55014dec410c90.1
  • <Package Folder>/cache/####/d21b012e49307275039465403e5bbc13.0
  • <Package Folder>/cache/####/d21b012e49307275039465403e5bbc13.1
  • <Package Folder>/cache/####/d734ac46ac21868252598d9c52ad7df6.0
  • <Package Folder>/cache/####/d734ac46ac21868252598d9c52ad7df6.1
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/f2a94f61c6a590f3b2ea843f087274b1.0.tmp
  • <Package Folder>/cache/####/f2a94f61c6a590f3b2ea843f087274b1.1
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/f_000004
  • <Package Folder>/cache/####/f_000005
  • <Package Folder>/cache/####/f_000006
  • <Package Folder>/cache/####/f_000007
  • <Package Folder>/cache/####/f_000008
  • <Package Folder>/cache/####/f_000009
  • <Package Folder>/cache/####/f_00000a
  • <Package Folder>/cache/####/f_00000b
  • <Package Folder>/cache/####/f_00000c
  • <Package Folder>/cache/####/f_00000d
  • <Package Folder>/cache/####/f_00000e
  • <Package Folder>/cache/####/f_00000f
  • <Package Folder>/cache/####/febf3e6cbd46124706415b0dcced9aab.0
  • <Package Folder>/cache/####/febf3e6cbd46124706415b0dcced9aab.1
  • <Package Folder>/cache/####/ffeb395bfcd1569c50b9accff8a3369c.0
  • <Package Folder>/cache/####/ffeb395bfcd1569c50b9accff8a3369c.1
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.bb
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.ff
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.meminfo
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.pid
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.ps
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.start
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.time
  • <Package Folder>/crashsdk/####/PPAIDNI0ELIBOM0MOC.uptime
  • <Package Folder>/crashsdk/####/REKROW1PPAIDNI0ELIBOM0MOC.bb
  • <Package Folder>/crashsdk/####/unique
  • <Package Folder>/databases/9apps.db-journal
  • <Package Folder>/databases/WaValue.db-journal
  • <Package Folder>/databases/adblib.db-journal
  • <Package Folder>/databases/app.manager-journal
  • <Package Folder>/databases/arrkii.native.sdk.db-journal
  • <Package Folder>/databases/db_snowfox.db
  • <Package Folder>/databases/db_snowfox.db-journal
  • <Package Folder>/databases/downloader-journal
  • <Package Folder>/databases/im.database.ad-journal
  • <Package Folder>/databases/message-journal
  • <Package Folder>/databases/my.db-journal
  • <Package Folder>/databases/snowfoxad_msg.db
  • <Package Folder>/databases/snowfoxad_msg.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
  • <Package Folder>/files/####/AudienceNetwork-4.23.0-dex.jar
  • <Package Folder>/files/####/android-support-v4-dex.jar
  • <Package Folder>/files/####/android-support-v7-recyclerview-dex.jar
  • <Package Folder>/files/####/home_app_data_us.json
  • <Package Folder>/files/####/hookfbcode-dex.jar
  • <Package Folder>/files/0a231bd8575dcf72.txt
  • <Package Folder>/files/SGMANAGER_DATA2
  • <Package Folder>/files/SGMANAGER_DATA2.tmp
  • <Package Folder>/files/adflashcore.jar
  • <Package Folder>/files/daemon
  • <Package Folder>/files/dc6439ab122a15dfcb
  • <Package Folder>/files/google.db
  • <Package Folder>/files/lib.dat
  • <Package Folder>/files/mesosphere.jar
  • <Package Folder>/files/snowfox_v19f.jar
  • <Package Folder>/files/sp.lock
  • <Package Folder>/files/t.jar
  • <Package Folder>/no_backup/com.google.android.gms.appid-no-backup
  • <Package Folder>/shared_prefs/9apps.xml
  • <Package Folder>/shared_prefs/9apps.xml (deleted)
  • <Package Folder>/shared_prefs/9apps.xml.bak
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/<Package>_preferences.xml.bak
  • <Package Folder>/shared_prefs/ActivatePreUtil.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml
  • <Package Folder>/shared_prefs/AdsBusiness-data.xml.bak
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/BusinessPreUtil.xml
  • <Package Folder>/shared_prefs/BusinessPreUtil.xml.bak
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml
  • <Package Folder>/shared_prefs/LoginPreUtil.xml.bak
  • <Package Folder>/shared_prefs/LoginPreUtil.xml.bak (deleted)
  • <Package Folder>/shared_prefs/MO.xml
  • <Package Folder>/shared_prefs/MO.xml.bak
  • <Package Folder>/shared_prefs/OfferPreUtil.xml
  • <Package Folder>/shared_prefs/SYSTEM_CACHE.xml
  • <Package Folder>/shared_prefs/SYSTEM_CACHE.xml.bak
  • <Package Folder>/shared_prefs/adflash.xml
  • <Package Folder>/shared_prefs/adflash.xml.bak
  • <Package Folder>/shared_prefs/adflash.xml.bak (deleted)
  • <Package Folder>/shared_prefs/adflash_taboola.xml
  • <Package Folder>/shared_prefs/ak.native.sdk.xml
  • <Package Folder>/shared_prefs/ak.native.sdk.xml.bak
  • <Package Folder>/shared_prefs/aps.xml
  • <Package Folder>/shared_prefs/aps.xml.bak
  • <Package Folder>/shared_prefs/apsad.xml
  • <Package Folder>/shared_prefs/apscomm.xml
  • <Package Folder>/shared_prefs/arrkiiad.xml
  • <Package Folder>/shared_prefs/arrkiiad.xml.bak
  • <Package Folder>/shared_prefs/com.google.android.gms.appid.xml
  • <Package Folder>/shared_prefs/device_info.xml
  • <Package Folder>/shared_prefs/dns_cache.xml
  • <Package Folder>/shared_prefs/dns_cache.xml.bak
  • <Package Folder>/shared_prefs/ffc1d42b1ca5e3db2657d00b91997f6a.xml
  • <Package Folder>/shared_prefs/hunter_config.xml
  • <Package Folder>/shared_prefs/isupdate.xml
  • <Package Folder>/shared_prefs/other_config.xml
  • <Package Folder>/shared_prefs/s_sdk_pro_pref.xml
  • <Package Folder>/shared_prefs/s_sdk_pro_pref.xml.bak
  • <Package Folder>/shared_prefs/service_config.xml
  • <Package Folder>/shared_prefs/service_config.xml.bak
  • <Package Folder>/shared_prefs/settingsLog.xml
  • <Package Folder>/shared_prefs/settingsLog.xml.bak
  • <Package Folder>/shared_prefs/snowfoxprf.xml
  • <Package Folder>/shared_prefs/sp_cache.xml
  • <Package Folder>/shared_prefs/sp_cache.xml.bak
  • <Package Folder>/shared_prefs/sp_config.xml
  • <Package Folder>/shared_prefs/t_ini.xml
  • <Package Folder>/shared_prefs/v71.xml
  • <Package Folder>/shared_prefs/v71.xml.bak
  • <Package Folder>/shared_prefs/worker_preferences.xml
  • <Package Folder>/shared_prefs/worker_preferences.xml.bak
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.androidsystem/####/49.x-4.3.5-vs.apk
  • <SD-Card>/.androidsystem/####/PlugShareData
  • <SD-Card>/.androidsystem/####/plugxml.xml
  • <SD-Card>/.androidsystem/Plugin.zip
  • <SD-Card>/.com.taobao.dp/dd7893586a493dc3
  • <SD-Card>/.com.taobao.dp/hid.dat
  • <SD-Card>/9appsPro/####/libcrash_1.5.0.0.so.tmp
  • <SD-Card>/Android/####/.nomedia
  • <SD-Card>/Android/####/0153d21685c281d70a118499ba199b12ea1d57fc....0.tmp
  • <SD-Card>/Android/####/034b6d5e3fe1119b5eef1fe1945fc156415e590c....0.tmp
  • <SD-Card>/Android/####/0e487d691500a2d38f4ec405e48b5e8ad706e8e8....0.tmp
  • <SD-Card>/Android/####/13b749917479035a2a008d309f2402c879a871e4....0.tmp
  • <SD-Card>/Android/####/1588db1245a5463b8b2efbddb6ebc827b69b5556....0.tmp
  • <SD-Card>/Android/####/191a02b5cdc7680d7a5d16da119a88603032b478....0.tmp
  • <SD-Card>/Android/####/1b58443928f7b146cda49d5090a50501fa9998d9....0.tmp
  • <SD-Card>/Android/####/1babfb0fa71a988417dd0ae51fe7244fd461a1eb....0.tmp
  • <SD-Card>/Android/####/1e9aa6ff8b8a477b5d4d5526324a0321719a6957....0.tmp
  • <SD-Card>/Android/####/237af98a15dbd61e2551a55d9639ca12cd858219....0.tmp
  • <SD-Card>/Android/####/29a164915957f24fcd73d85127b6be5730771d21....0.tmp
  • <SD-Card>/Android/####/2c31e046b055ba9a978bd393d37f862190bfb0c3....0.tmp
  • <SD-Card>/Android/####/31ada6f81750db7194e50c1c497a720028f0436a....0.tmp
  • <SD-Card>/Android/####/3fae17a5a4cf2faf5bdb5f77e5707a533a94e544....0.tmp
  • <SD-Card>/Android/####/40dfa605f4e33f7484e3ced0907937e10d5c7d71....0.tmp
  • <SD-Card>/Android/####/4271542f41ee5e98f3f05833eab66ac332f1fab5....0.tmp
  • <SD-Card>/Android/####/46e427033c3f5346227ad812f979ed64662890df....0.tmp
  • <SD-Card>/Android/####/4bf8470e8ca19dc3a66497eaf62f0869d0c2202b....0.tmp
  • <SD-Card>/Android/####/54487331d10dec8ac88ca28ee8f0acadad8edd9a....0.tmp
  • <SD-Card>/Android/####/5b16bdf47e9cd70d40c841159c170b253162a560....0.png
  • <SD-Card>/Android/####/5b16bdf47e9cd70d40c841159c170b253162a560....0.tmp
  • <SD-Card>/Android/####/5ba2b13af74bcf92ca919fed4662069191b4b72d....0.tmp
  • <SD-Card>/Android/####/606a5e4a60c451dd5f9833233ce5be76e0f493c4....0.tmp
  • <SD-Card>/Android/####/62af85c78d05359b7e0cff79c24dc2b485671936....0.tmp
  • <SD-Card>/Android/####/6610b73c74547ca504ecca7bfe3882b11485131d....0.tmp
  • <SD-Card>/Android/####/6bb7044fd6d3e466891eea47c9d0411a9573261b....0.tmp
  • <SD-Card>/Android/####/6e51be3ad5ded5d3364f64ed77d03c4a6d531447....0.tmp
  • <SD-Card>/Android/####/6fe9e3fe44fc92faf65081f310bb7b300cfc73bc....0.tmp
  • <SD-Card>/Android/####/7317b40405eb2403a4fb1d5448d260d4213e2dc4....0.tmp
  • <SD-Card>/Android/####/775bb263d1012d26bef0674ab4d290a1828e45c8....0.tmp
  • <SD-Card>/Android/####/77c5c006b62778298dbee85f25985b7c586cafac....0.tmp
  • <SD-Card>/Android/####/7c7b2080e45fda4963452dbc2de806676e6886a6....0.tmp
  • <SD-Card>/Android/####/7e430fac53e28f97b2294c242bc8edd1d1df8646....0.tmp
  • <SD-Card>/Android/####/8e0a2b095861d5404b5fce31a2a318a1824bb9b3....0.tmp
  • <SD-Card>/Android/####/91d9685e18db7b0a7dfa0ec2c771bc4fb81d694b....0.tmp
  • <SD-Card>/Android/####/97e583c0446dcacd85e24eb1936470d5cff589f0....0.tmp
  • <SD-Card>/Android/####/99cdb87ab451ab422549e01f96692760194a3a9a....0.tmp
  • <SD-Card>/Android/####/9cee7914eb38b4ad1892dd7c6e13525ec01572eb....0.tmp
  • <SD-Card>/Android/####/9f577ba1b488222a234e437366f5d8503fad1813....0.tmp
  • <SD-Card>/Android/####/a196f4279ae445c6912510c2816b0c948642ebc9....0.tmp
  • <SD-Card>/Android/####/a6b7595683e97c390907c85866bbebf683ddf9ed....0.tmp
  • <SD-Card>/Android/####/a7f0e46119b827e971a83c2b1f4c840d048061a0....0.tmp
  • <SD-Card>/Android/####/aa681e965fb17174e7fd296724d4f19a7a34fec3....0.tmp
  • <SD-Card>/Android/####/af455465d7925951f106283f495f58cdc6c1671c....0.tmp
  • <SD-Card>/Android/####/b35d620949e5628883214351df844105174ab15a....0.tmp
  • <SD-Card>/Android/####/b4805ae5fd659e02b307ca277cf4f69ff6b3418e....0.tmp
  • <SD-Card>/Android/####/be8d55d334235d5876c8fe45ac6369930a0ea7d6....0.tmp
  • <SD-Card>/Android/####/bf09e3312570541ab6237bacb98d4c5028d1f883....0.tmp
  • <SD-Card>/Android/####/bf9ea917e8e728af03f1d2a03fd567807272b9e8....0.png
  • <SD-Card>/Android/####/bf9ea917e8e728af03f1d2a03fd567807272b9e8....0.tmp
  • <SD-Card>/Android/####/c1278112054f131e24f62a2a9ead06c7bb65b87d....0.tmp
  • <SD-Card>/Android/####/c342bae1f0889f1053f988aff9aeec0cf367b398....0.tmp
  • <SD-Card>/Android/####/c9f85dad2297ddafc4d720cc2e50f7aa70a851da....0.tmp
  • <SD-Card>/Android/####/d5069cd683f23c17e4216599716b9530620ccb80....0.tmp
  • <SD-Card>/Android/####/d53f75e431b562f98e9aefca689ce46ba287521a....0.tmp
  • <SD-Card>/Android/####/d798ddeb5af49ec0dc0a664ab1e8f95313d4be5a....0.tmp
  • <SD-Card>/Android/####/d846ecbfbca0a59c65b4cc6c8319321a0e89c50b....0.tmp
  • <SD-Card>/Android/####/d913cb9f0e7b7df2caa817a03432d72617dd3585....0.tmp
  • <SD-Card>/Android/####/de95ed6947f53989429d6c2dad13c61767227e76....0.tmp
  • <SD-Card>/Android/####/dev_4e2bd05.txt
  • <SD-Card>/Android/####/e73b848b540ddeadf78a1089edd5e2f162e29da4....0.tmp
  • <SD-Card>/Android/####/fad2cc2b7801d2c27a4b2d9a0261f237aec9af5c....0.tmp
  • <SD-Card>/Android/####/imei.txt
  • <SD-Card>/Android/####/inapp_dev.txt
  • <SD-Card>/Android/####/journal.tmp
  • <SD-Card>/Android/####/ua.dat
  • <SD-Card>/LogN/####/sp
  • <SD-Card>/baidu/####/journal.tmp
  • <SD-Card>/baidu/.cuid
Другие:
Запускает следующие shell-скрипты:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • <Package Folder>/files/dc6439ab122a15dfcb
  • chmod 777 <Package Folder>/files/daemon
  • ps
  • sh
Загружает динамические библиотеки:
  • IncrementalUpdate
  • libcrash_1.5.0.0
  • ppapkpatchso
  • sgmainso-5.3
  • uninstall
Использует следующие алгоритмы для шифрования данных:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-NoPadding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • desede-ECB-PKCS5Padding
Использует следующие алгоритмы для расшифровки данных:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • desede-ECB-PKCS5Padding
Осуществляет доступ к информации о геолокации.
Осуществляет доступ к информации о сети.
Осуществляет доступ к информации о телефоне (номер, imei и тд.).
Осуществляет доступ к информации об установленных приложениях.
Осуществляет доступ к информации о запущенных приложениях.
Осуществляет доступ к информации о зарегистрированных на устройстве аккаунтах (Google, Facebook и тд.).
Добавляет задания в системный планировщик.
Отрисовывает собственные окна поверх других приложений.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке