Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.35803

Добавлен в вирусную базу Dr.Web: 2018-02-07

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.DownLoader.589.origin
Осуществляет доступ к приватному интерфейсу телефонии (ITelephony).
Сетевая активность:
Подключается к:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) h####.a####.com:80
  • TCP(HTTP/1.1) kvt####.m####.a####.com:80
  • TCP(HTTP/1.1) t####.dmp.y####.net:80
  • TCP(HTTP/1.1) www.a####.com.####.com:80
  • TCP(HTTP/1.1) nb3197-####.a####.com:80
  • TCP(HTTP/1.1) cs228-####.a####.com:80
  • TCP(HTTP/1.1) ip.ta####.com:80
  • TCP(HTTP/1.1) c34.a####.com:80
  • TCP(HTTP/1.1) nb4052-####.a####.com:80
  • TCP(HTTP/1.1) c32.a####.com:80
  • TCP(HTTP/1.1) qs.lago####.com:8982
  • TCP(HTTP/1.1) g####.a####.com.####.com:80
  • TCP(HTTP/1.1) a####.m.ta####.com:80
  • TCP(HTTP/1.1) sdk.st####.y####.com:80
  • TCP(HTTP/1.1) c36.a####.com:80
  • TCP(HTTP/1.1) l####.v####.b####.com:80
  • TCP(HTTP/1.1) c31.a####.com:80
  • TCP(HTTP/1.1) aos.w####.y####.net:80
  • TCP(HTTP/1.1) a####.a####.com:80
  • TCP(HTTP/1.1) 47.92.1####.96:80
  • TCP(HTTP/1.1) nb3196-####.a####.com:80
  • TCP(HTTP/1.1) s####.gw.y####.####.com:80
  • TCP(HTTP/1.1) 1####.76.224.67:80
  • TCP(HTTP/1.1) pc.videoc####.b####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) nb3200-####.a####.com:80
  • TCP(HTTP/1.1) cs230-####.a####.com:80
  • TCP(HTTP/1.1) au.y####.net:80
  • TCP(HTTP/1.1) nb4051-####.a####.com:80
  • TCP(HTTP/1.1) cdn.app.e####.####.com:80
  • TCP(HTTP/1.1) cdn.game####.org:80
  • TCP(HTTP/1.1) app.w####.cn:80
  • TCP(HTTP/1.1) fu1.a####.com:80
  • TCP(HTTP/1.1) s.y####.net:80
  • TCP(HTTP/1.1) nb4520-####.a####.com:80
  • TCP(TLS/1.0) y####.e####.top:443
  • TCP(TLS/1.0) i####.ww.ta####.com:443
  • UDP 2####.0.0.1:9998
Запросы DNS:
  • 5####.nd####.y####.com
  • a####.a####.com
  • a####.m.ta####.com
  • a####.u####.com
  • aos.w####.y####.net
  • app.w####.cn
  • au.y####.net
  • c####.im.ta####.com
  • c31.a####.com
  • c32.a####.com
  • c34.a####.com
  • c36.a####.com
  • cdn.app.e####.top
  • cdn.game####.org
  • cs228-####.a####.com
  • cs230-####.a####.com
  • fu1.a####.com
  • g####.a####.com
  • g####.a####.com
  • g####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • i####.ww.ta####.com
  • ip.ta####.com
  • j####.a####.com
  • j####.a####.com
  • kvt####.m####.a####.com
  • l####.v####.b####.com
  • m####.a####.com
  • m.a####.com
  • mt####.go####.com
  • nb3196-####.a####.com
  • nb3196-####.a####.com
  • nb3197-####.a####.com
  • nb3197-####.a####.com
  • nb3200-####.a####.com
  • nb4051-####.a####.com
  • nb4051-####.a####.com
  • nb4052-####.a####.com
  • nb4520-####.a####.com
  • pc.videoc####.b####.com
  • policyc####.a####.com
  • qs.lago####.com
  • res.we####.cn
  • res11-a####.we####.cn
  • s####.gw.y####.net
  • s.y####.net
  • sdk.st####.y####.com
  • so.a####.com
  • t####.dmp.y####.net
  • www.a####.com
  • x####.a####.com
  • y####.e####.top
Запросы HTTP GET:
  • a####.a####.com/atiws/atiapp?category=####&platform=####&appver=####&gam...
  • a####.a####.com/atiws/atiappcommon?platform=####&appver=####&gameid=####...
  • aos.w####.y####.net/v3/zip_upd?s=####
  • app.w####.cn/action/connect/active?app_id=####&udid=####&imsi=####&net=#...
  • au.y####.net/offer/dist/aos/pkg/2.6.1/offers_2.6.1.zip
  • c31.a####.com/user/379/37149379/7513359/card/29148907/29148907_800.jpg
  • c31.a####.com/user/379/37149379/7513359/card/29148907/card.mp4?l=####&ip...
  • c31.a####.com/user/379/37149379/7513359/card/29148907/info.xml
  • c31.a####.com/user/379/37149379/7556931/card/28859995/28859995_800.jpg
  • c32.a####.com/user/379/37149379/7513359/card/28763720/28763720_800.jpg
  • c32.a####.com/user/379/37149379/7513359/card/29051598/29051598_800.jpg
  • c32.a####.com/user/379/37149379/7556931/card/28814702/28814702_800.jpg
  • c32.a####.com/user/379/37149379/7556931/card/28814955/28814955_800.jpg
  • c32.a####.com/user/379/37149379/7556931/card/28921333/28921333_800.jpg
  • c34.a####.com/user/379/37149379/1006/card/44131214/44131214_800.jpg
  • c36.a####.com/user/379/37149379/1006/card/45936979/45936979_800.jpg
  • c36.a####.com/user/379/37149379/1006/card/45936979/card.mp4?l=####&to=####
  • c36.a####.com/user/379/37149379/1006/card/45936979/info.xml
  • cdn.app.e####.####.com/sfile/201711/16/all/cp_V3.0.2.txt
  • cdn.game####.org/strategy/UnknownDev
  • cdn.game####.org/strategy/base
  • cdn.game####.org/strategy/dev_root
  • cdn.game####.org/strategy/dev_root2
  • cdn.game####.org/strategy/larger4.3
  • cdn.game####.org/strategy/loss_4.3
  • cdn.game####.org/strategy/sul18
  • cdn.game####.org/strategy/symlink-adbd
  • cs228-####.a####.com/user/379/37149379/1006/card/45936979/info.xml
  • cs230-####.a####.com/user/379/37149379/7556931/card/28814702/28814702_80...
  • fu1.a####.com/account/379/37149379/account/37149379_normal.jpg
  • fu1.a####.com/account/914/17001914/account/17001914_normal.jpg
  • g####.a####.com.####.com/aipai/page/pic/1517834390214244c24281517834390....
  • g####.a####.com.####.com/aipai/page/pic/151783479351143702c241517834793....
  • g####.a####.com.####.com/aipai/page/pic/1517910495813323c24281517910495....
  • g####.a####.com.####.com/aipai/page/pic/15179105238893024283a1517910523....
  • g####.a####.com.####.com/user/185/10844185/1006/card/47451224/47451224_4...
  • g####.a####.com.####.com/user/379/37149379/1005/card/46839222/46839222_8...
  • g####.a####.com.####.com/user/379/37149379/7513359/card/29148907/card.mp...
  • g####.a####.com.####.com/user/642/59822642/5001/card/47454871/47454871_4...
  • g####.a####.com.####.com/user/660/34571660/1006/card/47453431/47453431_4...
  • g####.a####.com.####.com/user/914/17001914/1006/card/47453907/47453907_4...
  • g####.a####.com.####.com/user/914/17001914/1006/card/47453907/47453907_8...
  • g####.a####.com.####.com/user/914/17001914/1006/card/47453907/card.mp4?l...
  • g####.a####.com.####.com/user/914/17001914/1006/card/47453907/info.xml
  • h####.a####.com/user/185/10844185/1006/card/47451224/47451224_400.jpg
  • h####.a####.com/user/379/37149379/1005/card/46839222/46839222_800.jpg
  • h####.a####.com/user/379/37149379/1006/card/44131214/44131214_800.jpg
  • h####.a####.com/user/379/37149379/1006/card/45936979/45936979_800.jpg
  • h####.a####.com/user/379/37149379/1006/card/45936979/card.mp4?l=####
  • h####.a####.com/user/379/37149379/1006/card/45936979/info.xml
  • h####.a####.com/user/379/37149379/7513359/card/28763720/28763720_800.jpg
  • h####.a####.com/user/379/37149379/7513359/card/29051598/29051598_800.jpg
  • h####.a####.com/user/379/37149379/7513359/card/29148907/29148907_800.jpg
  • h####.a####.com/user/379/37149379/7513359/card/29148907/info.xml
  • h####.a####.com/user/379/37149379/7556931/card/28814702/28814702_800.jpg
  • h####.a####.com/user/379/37149379/7556931/card/28814955/28814955_800.jpg
  • h####.a####.com/user/379/37149379/7556931/card/28859995/28859995_800.jpg
  • h####.a####.com/user/379/37149379/7556931/card/28921333/28921333_800.jpg
  • h####.a####.com/user/642/59822642/5001/card/47454871/47454871_400.jpg
  • h####.a####.com/user/660/34571660/1006/card/47453431/47453431_400.jpg
  • h####.a####.com/user/914/17001914/1006/card/47453907/47453907_400.jpg
  • h####.a####.com/user/914/17001914/1006/card/47453907/47453907_800.jpg
  • h####.a####.com/user/914/17001914/1006/card/47453907/card.mp4?l=####
  • h####.a####.com/user/914/17001914/1006/card/47453907/info.xml
  • ip.ta####.com/service/getIpInfo2.php?ip=####
  • kvt####.m####.a####.com/kvinfo.php
  • l####.v####.b####.com/corp/corpframe.html
  • nb3196-####.a####.com/user/379/37149379/7513359/card/29148907/29148907_8...
  • nb3196-####.a####.com/user/379/37149379/7556931/card/28921333/28921333_8...
  • nb3197-####.a####.com/user/379/37149379/1006/card/44131214/44131214_800....
  • nb3197-####.a####.com/user/379/37149379/7556931/card/28859995/28859995_8...
  • nb3200-####.a####.com/user/379/37149379/7513359/card/29051598/29051598_8...
  • nb4051-####.a####.com/user/379/37149379/1006/card/45936979/45936979_800....
  • nb4051-####.a####.com/user/379/37149379/1006/card/45936979/card.mp4?l=##...
  • nb4051-####.a####.com/user/379/37149379/7513359/card/28763720/28763720_8...
  • nb4051-####.a####.com/user/379/37149379/7556931/card/28814955/28814955_8...
  • nb4052-####.a####.com/user/379/37149379/7513359/card/29148907/29148907_8...
  • nb4052-####.a####.com/user/379/37149379/7513359/card/29148907/info.xml
  • nb4520-####.a####.com/user/379/37149379/1006/card/45936979/45936979_800....
  • pc.videoc####.b####.com/p.gif?pid=####&tn=####&tpl=####&t=####
  • qs.lago####.com:8982/loadtime.shtml?clientIp=180.97.172.115&st=android&l...
  • qs.lago####.com:8982/notify.shtml?saddr=aipai-android500002&definition=4...
  • qs.lago####.com:8982/notify.shtml?saddr=jhc-android500002&definition=480...
  • s####.gw.y####.####.com/aos/v3/initf?s=####
  • s####.gw.y####.####.com/stat/v3/udt2?appid=####&s=####
  • s.y####.net/stat/aos/v3/pkc?s=####
  • s.y####.net/stat/aos/v3/pku?s=####
  • sdk.st####.y####.com/core/aos-dex/1701/7011/6f830529.jar
  • sdk.st####.y####.com/core/aos-so/1611/7000/ad389c56.so
  • www.a####.com.####.com/aipai_platform/mobile/common/dist/apm/manifest_v2...
  • www.a####.com.####.com/aipai_platform/mobile/common/dist/apm/sea.js
  • www.a####.com.####.com/aipai_platform/mobile/common/dist/mobile/xifen/js...
  • www.a####.com.####.com/aipai_platform/mobile/common/dist/weixin/1.0.0/jw...
  • www.a####.com.####.com/aipai_platform/mobile/xifen/css/img/video/aipai.png
  • www.a####.com.####.com/aipai_platform/mobile/xifen/css/img/video/icon_cl...
  • www.a####.com.####.com/aipai_platform/mobile/xifen/css/img/video/stance_...
  • www.a####.com.####.com/aipai_platform/mobile/xifen/css/video.css
  • www.a####.com.####.com/api/aipaiApp_action-getCommentNew_mobile-1_type-2...
  • www.a####.com.####.com/api/framework/adConf/35?platform=####&appver=####...
  • www.a####.com.####.com/api/framework/jifen/enter/35?platform=####&appver...
  • www.a####.com.####.com/api/gonglue/list/12541?appId=####&platform=####&a...
  • www.a####.com.####.com/api/hot/bannerItem/661?platform=####&appver=####&...
  • www.a####.com.####.com/api/hot/titleItem/662?platform=####&appver=####&o...
  • www.a####.com.####.com/api/hot/videos/12541?appId=####&xifenId=####&plat...
  • www.a####.com.####.com/api/jifen/firstInstallInit?platform=####&appver=#...
  • www.a####.com.####.com/api/specialTopic/itemList/664?platform=####&appve...
  • www.a####.com.####.com/api/specialTopic/view/217
  • www.a####.com.####.com/api/specialTopic/viewData/217
  • www.a####.com.####.com/app/www/templates/aipai_platform/mobile/_public/c...
  • www.a####.com.####.com/app/www/templates/cdn_policy_telecom.txt?platform...
  • www.a####.com.####.com/common/img/upload/xifen/1482997937_519.png
  • www.a####.com.####.com/common/img/upload/xifen/1482998127_603.png
  • www.a####.com.####.com/common/img/upload/xifen/1482998153_427.jpg
  • www.a####.com.####.com/common/img/upload/xifen/1482998168_150.png
  • www.a####.com.####.com/common/img/upload/xifen/1482998183_982.png
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&app=##...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&os=###...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&platfo...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&test=#...
  • www.a####.com.####.com/mobile/apps/apps_module-badDomain.html
  • www.a####.com.####.com/pc/operator
Запросы HTTP POST:
  • a####.m.ta####.com/rest/gc?dd=####&nsgs=####&ak=####&av=####&c=####&v=##...
  • a####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=####&...
  • a####.u####.com/app_logs
  • app.w####.cn/action/user_info
  • kvt####.m####.a####.com/i.gif
  • t####.dmp.y####.net/v1/android/packages?rt=####&sign=####
  • t####.dmp.y####.net/v2/android/pkgtime?rt=####&sign=####
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/Matrix
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/ddexe
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/debuggerd
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/fileWork
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/insta...ery.sh
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/pidof
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/su
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/supolicy
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/toolbox
  • <Package Folder>/app_21fc5767-7dcd-4ed5-b978-fc32a1246ed0/wsroot.sh
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/Matrix
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/ddexe
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/debuggerd
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/fileWork
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/insta...ery.sh
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/pidof
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/su
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/supolicy
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/toolbox
  • <Package Folder>/app_6528017f-683c-40e2-8d74-26bf3cd443a3/wsroot.sh
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/Matrix
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/ddexe
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/debuggerd
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/fileWork
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/insta...ery.sh
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/pidof
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/su
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/supolicy
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/toolbox
  • <Package Folder>/app_b6426f2b-d93e-41ea-aed8-eb20cfaede61/wsroot.sh
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/Matrix
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/ddexe
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/debuggerd
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/device.db
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/fileWork
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/insta...ery.sh
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/pidof
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/root3
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/su
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/supolicy
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/toolbox
  • <Package Folder>/app_e1633db8-51af-47bf-9988-dcc09efb7c1a/wsroot.sh
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/Matrix
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/ddexe
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/debuggerd
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/fileWork
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/insta...ery.sh
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/pidof
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/su
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/supolicy
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/toolbox
  • <Package Folder>/app_ea340701-d347-4631-a9a4-6e9c595559a5/wsroot.sh
  • <Package Folder>/app_f2a1bc58-1136-48fe-8928-2467d6920726/18f6c...830eb8
  • <Package Folder>/app_f2a1bc58-1136-48fe-8928-2467d6920726/758cf...94.jar
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/Matrix
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/ddexe
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/debuggerd
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/fileWork
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/insta...ery.sh
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/pidof
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/su
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/supolicy
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/toolbox
  • <Package Folder>/app_ff11aba1-2d1f-4ec8-89f2-7a2e72d14e1c/wsroot.sh
  • <Package Folder>/app_libs/libabcdefgh.so.new
  • <Package Folder>/app_libs/ymdex.jar
  • <Package Folder>/app_libs/ymdex.jar.new
  • <Package Folder>/app_subox/1740c449fc10be62df60ba0f18696c9f
  • <Package Folder>/app_subox/32edd79a240b5f1e461d069caab1ec3e
  • <Package Folder>/app_subox/8b6f263391259b7a8e5f58ee71852ca8
  • <Package Folder>/app_subox/b0141e478b25af7c40a8cca8de6c4708
  • <Package Folder>/app_subox/b18a021d11a3004d25017230b681476b
  • <Package Folder>/app_subox/c61913b615fb6224701377a119081f36
  • <Package Folder>/app_subox_download/1f2ee354-775f-486f-8f62-3c8a0bc49cb8
  • <Package Folder>/app_subox_download/1fa60cdf-30eb-4c97-8396-e6e4f62bb2ea
  • <Package Folder>/app_subox_download/366786f3-21f8-4648-8c7c-d7b75a33c4e3
  • <Package Folder>/app_subox_download/8c7abfd1-4ff5-4542-8271-25ac5f587dbe
  • <Package Folder>/app_subox_download/9e35b9cc-0d72-4640-8af1-b0b65fa468bf
  • <Package Folder>/app_subox_download/a16f0c78-2cd2-4995-92f3-00d5bf3d886c
  • <Package Folder>/app_subox_download/cc61b932-216f-44cc-8c44-af73a61f7d6e
  • <Package Folder>/app_subox_download/ff23af4c-865f-400c-ad4b-8e797f5652e3
  • <Package Folder>/cache/####/2b03320cb2c1304c1e08d346d556d15ed5b....0.tmp
  • <Package Folder>/cache/####/53663b44199ebfe71572ef2cceb5d407a44....0.tmp
  • <Package Folder>/cache/####/59e813dd6491868f078e2300fd38f3c5be8....0.tmp
  • <Package Folder>/cache/####/5cc232554739957fbea32a52096ade2db4a....0.tmp
  • <Package Folder>/cache/####/60fd5787b52de01f837733c3af12397265c....0.tmp
  • <Package Folder>/cache/####/6c80407d6c798b485bd2792a0d86dc62cf3....0.tmp
  • <Package Folder>/cache/####/737287c15f4c1a71bc0b4ec016e437670ee....0.tmp
  • <Package Folder>/cache/####/80b0c14244a5712e6660a0e0091e6260bbd....0.tmp
  • <Package Folder>/cache/####/84f9653d122c5e9250ae902afea372c8897....0.tmp
  • <Package Folder>/cache/####/8a6115ae50ef21dc9753c6b58691f9180f4....0.tmp
  • <Package Folder>/cache/####/8c1f343cd6b3fb49b163803f355aa6d74e8....0.tmp
  • <Package Folder>/cache/####/a4e0c38184c79dec24194a7b157f7af88ac....0.tmp
  • <Package Folder>/cache/####/bb2da6a07eaa22ecf0c817fa37b899c0898....0.tmp
  • <Package Folder>/cache/####/ca77995485d574712c02c557cee7eaabfb3....0.tmp
  • <Package Folder>/cache/####/ca89a8606f7acab74b13dc9dad1ee4b05bb....0.tmp
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/f82f4acd0334def261159a93fe8bd7af327....0.tmp
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/f_000004
  • <Package Folder>/cache/####/f_000005
  • <Package Folder>/cache/####/f_000006
  • <Package Folder>/cache/####/f_000007
  • <Package Folder>/cache/####/f_000008
  • <Package Folder>/cache/####/f_000009
  • <Package Folder>/cache/####/f_00000a
  • <Package Folder>/cache/####/f_00000b
  • <Package Folder>/cache/####/f_00000c
  • <Package Folder>/cache/####/fd3d457e7c972161eece778eee9e34eb362....0.tmp
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/cache/00b18bb0e2585cf613e094f1a2cb4472.0.tmp
  • <Package Folder>/cache/00b18bb0e2585cf613e094f1a2cb4472.1.tmp
  • <Package Folder>/cache/01dd2290154641d04f9f99c70596a3d9.0.tmp
  • <Package Folder>/cache/01dd2290154641d04f9f99c70596a3d9.1.tmp
  • <Package Folder>/cache/02e7f3010253137a230666c8ba16ee5b.0.tmp
  • <Package Folder>/cache/02e7f3010253137a230666c8ba16ee5b.1.tmp
  • <Package Folder>/cache/1469d12b33e13167e21bfeb6e405a57c.0.tmp
  • <Package Folder>/cache/1469d12b33e13167e21bfeb6e405a57c.1.tmp
  • <Package Folder>/cache/22cf34b32127f99265f822d2f37e015d.0.tmp
  • <Package Folder>/cache/22cf34b32127f99265f822d2f37e015d.1.tmp
  • <Package Folder>/cache/3a714008ee1eea820cea5ea848dfc96e.0.tmp
  • <Package Folder>/cache/3a714008ee1eea820cea5ea848dfc96e.1.tmp
  • <Package Folder>/cache/4a4fdb743ca2d8d9a491a023dc23411e.0.tmp
  • <Package Folder>/cache/4a4fdb743ca2d8d9a491a023dc23411e.1.tmp
  • <Package Folder>/cache/4fa2f9fc6693fd179a24e3dbfddcbd03.0.tmp
  • <Package Folder>/cache/4fa2f9fc6693fd179a24e3dbfddcbd03.1.tmp
  • <Package Folder>/cache/5ee52074f5b3c06fbaf2c4ef46f9d537.0.tmp
  • <Package Folder>/cache/5ee52074f5b3c06fbaf2c4ef46f9d537.1.tmp
  • <Package Folder>/cache/5f6c657ce913e8be49880d7107e20d26.0.tmp
  • <Package Folder>/cache/5f6c657ce913e8be49880d7107e20d26.1.tmp
  • <Package Folder>/cache/71293d5526380b656675d9e847d06eb8.0.tmp
  • <Package Folder>/cache/71293d5526380b656675d9e847d06eb8.1.tmp
  • <Package Folder>/cache/9bace69237ebbf48d5181f5615cd9e8e.0.tmp
  • <Package Folder>/cache/9bace69237ebbf48d5181f5615cd9e8e.1.tmp
  • <Package Folder>/cache/9f9a0fccef02a521b1ac904569983c0b.0.tmp
  • <Package Folder>/cache/9f9a0fccef02a521b1ac904569983c0b.1.tmp
  • <Package Folder>/cache/V3.0.2.txt
  • <Package Folder>/cache/b54fb18407b79a99f522e543f786f725.0.tmp
  • <Package Folder>/cache/b54fb18407b79a99f522e543f786f725.1.tmp
  • <Package Folder>/cache/ccd25a35ba712f5fc5b4d5f4ccb02c38.0.tmp
  • <Package Folder>/cache/ccd25a35ba712f5fc5b4d5f4ccb02c38.1.tmp
  • <Package Folder>/cache/e0888850d29ef11a195e5b377efd4265.0.tmp
  • <Package Folder>/cache/e0888850d29ef11a195e5b377efd4265.1.tmp
  • <Package Folder>/cache/f1bce5bb35f7ede6bbba12519959d2c3.0.tmp
  • <Package Folder>/cache/f1bce5bb35f7ede6bbba12519959d2c3.1.tmp
  • <Package Folder>/cache/journal.tmp
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes-1649541301.zip
  • <Package Folder>/code_cache/####/<Package>-1.apk.classes881057963.zip
  • <Package Folder>/databases/8ba3c48a7f0b79f9935bf2fddc5ba8a8-journal
  • <Package Folder>/databases/OxgHkj2lz09F
  • <Package Folder>/databases/OxgHkj2lz09F-journal
  • <Package Folder>/databases/P15pKIjsm64m
  • <Package Folder>/databases/P15pKIjsm64m-journal
  • <Package Folder>/databases/T1oX0rhhuXWt
  • <Package Folder>/databases/T1oX0rhhuXWt-journal
  • <Package Folder>/databases/XKwVoK0huy3R
  • <Package Folder>/databases/XKwVoK0huy3R-journal
  • <Package Folder>/databases/aipai.db
  • <Package Folder>/databases/aipai.db-journal
  • <Package Folder>/databases/d8305c5b3d6c8db862c69f2760ab1f81
  • <Package Folder>/databases/d8305c5b3d6c8db862c69f2760ab1f81-journal
  • <Package Folder>/databases/e57c34b26a4c8e1b872a8608bae7c4ed
  • <Package Folder>/databases/e57c34b26a4c8e1b872a8608bae7c4ed-journal
  • <Package Folder>/databases/jqIqJYOT3JpT
  • <Package Folder>/databases/jqIqJYOT3JpT-journal
  • <Package Folder>/databases/t_u.db-journal
  • <Package Folder>/databases/wIU6pTyUBYWX
  • <Package Folder>/databases/wIU6pTyUBYWX-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/wsUL1uCdKvjD
  • <Package Folder>/databases/wsUL1uCdKvjD-journal
  • <Package Folder>/files/####/arrow-left.png
  • <Package Folder>/files/####/arrow-right.png
  • <Package Folder>/files/####/blank.gif
  • <Package Folder>/files/####/close-icon.png
  • <Package Folder>/files/####/config.json
  • <Package Folder>/files/####/default.png
  • <Package Folder>/files/####/detail-wx.html
  • <Package Folder>/files/####/detail-wx.js
  • <Package Folder>/files/####/detail.html
  • <Package Folder>/files/####/detail.js
  • <Package Folder>/files/####/exchangeIdentity.json
  • <Package Folder>/files/####/feedback.html
  • <Package Folder>/files/####/feedback.js
  • <Package Folder>/files/####/form.css
  • <Package Folder>/files/####/global.js
  • <Package Folder>/files/####/lists.css
  • <Package Folder>/files/####/lists.html
  • <Package Folder>/files/####/lists.js
  • <Package Folder>/files/####/md5.js
  • <Package Folder>/files/####/pic_m.png
  • <Package Folder>/files/####/pic_tips_01.png
  • <Package Folder>/files/####/pic_tips_02.png
  • <Package Folder>/files/####/result.png
  • <Package Folder>/files/####/rule.html
  • <Package Folder>/files/####/sdetail.html
  • <Package Folder>/files/####/share.css
  • <Package Folder>/files/####/share.html
  • <Package Folder>/files/####/share.js
  • <Package Folder>/files/####/sprite-face.png
  • <Package Folder>/files/####/sprite-icons.png
  • <Package Folder>/files/####/sprite-icons2.png
  • <Package Folder>/files/####/wx-step1.jpg
  • <Package Folder>/files/####/wx-step2.jpg
  • <Package Folder>/files/####/wx-step3.jpg
  • <Package Folder>/files/####/wx-step4.jpg
  • <Package Folder>/files/####/wx-step5.jpg
  • <Package Folder>/files/.imprint
  • <Package Folder>/files/CacheTime.dat
  • <Package Folder>/files/RptKVStrategy.txt
  • <Package Folder>/files/SUBOXLOG_
  • <Package Folder>/files/abfe50788e0441183760bf44156bea6c.zip
  • <Package Folder>/files/aipai.btconfig
  • <Package Folder>/files/aipai.guid
  • <Package Folder>/files/bp.jar
  • <Package Folder>/files/ml.jar
  • <Package Folder>/files/sp.lock
  • <Package Folder>/files/umeng_it.cache
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/AppSettings.xml
  • <Package Folder>/shared_prefs/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
  • <Package Folder>/shared_prefs/CE94557724F842149D690D0E8CBB1CBD.xml
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/CookiePersistence.xml
  • <Package Folder>/shared_prefs/OFFERSCONFIG1.xml
  • <Package Folder>/shared_prefs/ShowAdFlag.xml
  • <Package Folder>/shared_prefs/UTCommon.xml
  • <Package Folder>/shared_prefs/UTMCConf132867741.xml
  • <Package Folder>/shared_prefs/UTMCLog132867741.xml
  • <Package Folder>/shared_prefs/V3.0.2.xml
  • <Package Folder>/shared_prefs/ad_system_config.xml
  • <Package Folder>/shared_prefs/count.xml
  • <Package Folder>/shared_prefs/kr.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/rx_sf_account.xml
  • <Package Folder>/shared_prefs/rx_sf_app.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/vbz.xml
  • <Package Folder>/shared_prefs/ywPrefsTools.xml
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.com.taobao.dp/6c709c11d2d46a7b
  • <SD-Card>/.com.taobao.dp/dd7893586a493dc3
  • <SD-Card>/Android/####/373240561418738c721572c1da14b85e
  • <SD-Card>/Android/####/373240561418738c721572c1da14b85e.ymtf
  • <SD-Card>/Android/####/AppPackage.dat
  • <SD-Card>/Android/####/CacheTime.dat
  • <SD-Card>/Android/####/DXTX902KJZX9JASLDJF
  • <SD-Card>/Android/####/DXTX902KJZX9JASLDJF.ymtf
  • <SD-Card>/Android/####/SOX90123JSOALK2098SD
  • <SD-Card>/Android/####/SOX90123JSOALK2098SD.ymtf
  • <SD-Card>/Android/####/UnPackage.dat
  • <SD-Card>/Android/####/android
  • <SD-Card>/Android/####/i42d45df023jnkdd93la483f9xGFKXI
  • <SD-Card>/Android/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
Другие:
Запускает следующие shell-скрипты:
  • /system/bin/cat /sys/devices/system/cpu/kernel_max
  • cat /proc/cpuinfo | grep Serial
  • chmod 777 Matrix ddexe debuggerd device.db fileWork install-recovery.sh pidof root3 su supolicy toolbox wsroot.sh
  • chmod 777 Matrix ddexe debuggerd fileWork install-recovery.sh pidof su supolicy toolbox wsroot.sh
  • ls -l /system/xbin/su
  • sh
Загружает динамические библиотеки:
  • abcdefgh
  • securitysdk-3.1
  • xifen
Использует следующие алгоритмы для шифрования данных:
  • AES
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Использует следующие алгоритмы для расшифровки данных:
  • DES
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Осуществляет доступ к информации о геолокации.
Осуществляет доступ к информации о сети.
Осуществляет доступ к информации о телефоне (номер, imei и тд.).
Осуществляет доступ к информации об установленных приложениях.
Осуществляет доступ к информации о запущенных приложениях.
Добавляет задания в системный планировщик.
Отрисовывает собственные окна поверх других приложений.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке