Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Packed.35837

Добавлен в вирусную базу Dr.Web: 2018-02-10

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.DownLoader.589.origin
Сетевая активность:
Подключается к:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) h####.a####.com:80
  • TCP(HTTP/1.1) kvt####.m####.a####.com:80
  • TCP(HTTP/1.1) t####.dmp.y####.net:80
  • TCP(HTTP/1.1) www.a####.com.####.com:80
  • TCP(HTTP/1.1) nb3197-####.a####.com:80
  • TCP(HTTP/1.1) cs228-####.a####.com:80
  • TCP(HTTP/1.1) nb3195-####.a####.com:80
  • TCP(HTTP/1.1) ip.ta####.com:80
  • TCP(HTTP/1.1) nb4051-####.a####.com:80
  • TCP(HTTP/1.1) au.y####.net:80
  • TCP(HTTP/1.1) qs.lago####.com:8982
  • TCP(HTTP/1.1) sdk.st####.y####.com:80
  • TCP(HTTP/1.1) aos.w####.y####.net:80
  • TCP(HTTP/1.1) a####.a####.com:80
  • TCP(HTTP/1.1) c47.a####.com:80
  • TCP(HTTP/1.1) s####.gw.y####.####.com:80
  • TCP(HTTP/1.1) 1####.76.224.67:80
  • TCP(HTTP/1.1) 47.92.1####.96:80
  • TCP(HTTP/1.1) fu1.a####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) res11-a####.we####.cn.####.com:80
  • TCP(HTTP/1.1) nb3200-####.a####.com:80
  • TCP(HTTP/1.1) nb4050-####.a####.com:80
  • TCP(HTTP/1.1) nb4500-####.a####.com:80
  • TCP(HTTP/1.1) cs230-####.a####.com:80
  • TCP(HTTP/1.1) a####.m.ta####.com:80
  • TCP(HTTP/1.1) c49.a####.com:80
  • TCP(HTTP/1.1) nb3201-####.a####.com:80
  • TCP(HTTP/1.1) cdn.app.e####.####.com:80
  • TCP(HTTP/1.1) nb4510-####.a####.com:80
  • TCP(HTTP/1.1) app.w####.cn:80
  • TCP(HTTP/1.1) c50.a####.com:80
  • TCP(HTTP/1.1) s.y####.net:80
  • TCP(HTTP/1.1) cdn.game####.org:80
  • TCP(TLS/1.0) c####.im.ta####.com:443
  • TCP(TLS/1.0) y####.e####.top:443
  • TCP(TLS/1.0) i####.ww.ta####.com:443
  • UDP 2####.0.0.1:9998
Запросы DNS:
  • 5####.nd####.y####.com
  • a####.a####.com
  • a####.m.ta####.com
  • a####.u####.com
  • aos.w####.y####.net
  • app.w####.cn
  • au.y####.net
  • c####.im.ta####.com
  • c47.a####.com
  • c49.a####.com
  • c50.a####.com
  • cdn.app.e####.top
  • cdn.game####.org
  • cs228-####.a####.com
  • cs230-####.a####.com
  • fu1.a####.com
  • g####.a####.com
  • g####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • i####.ww.ta####.com
  • ip.ta####.com
  • j####.a####.com
  • j####.a####.com
  • j####.a####.com
  • kvt####.m####.a####.com
  • m####.a####.com
  • m.a####.com
  • mt####.go####.com
  • nb3195-####.a####.com
  • nb3195-####.a####.com
  • nb3197-####.a####.com
  • nb3200-####.a####.com
  • nb3201-####.a####.com
  • nb4050-####.a####.com
  • nb4051-####.a####.com
  • nb4500-####.a####.com
  • nb4500-####.a####.com
  • nb4510-####.a####.com
  • policyc####.a####.com
  • qs.lago####.com
  • res.we####.cn
  • res11-a####.we####.cn
  • s####.gw.y####.net
  • s.y####.net
  • sdk.st####.y####.com
  • so.a####.com
  • t####.dmp.y####.net
  • www.a####.com
  • x####.a####.com
  • y####.e####.top
Запросы HTTP GET:
  • a####.a####.com/atiws/atiapp?category=####&platform=####&appver=####&gam...
  • a####.a####.com/atiws/atiappcommon?platform=####&appver=####&gameid=####...
  • aos.w####.y####.net/v3/zip_upd?s=####
  • app.w####.cn/action/connect/active?app_id=####&udid=####&imsi=####&net=#...
  • au.y####.net/offer/dist/aos/pkg/2.6.1/offers_2.6.1.zip
  • c47.a####.com/user/181/13493181/1005/card/47467299/47467299_800.jpg
  • c47.a####.com/user/181/13493181/1005/card/47467299/card.mp4?l=####&to=####
  • c49.a####.com/user/485/31201485/1004/card/47476621/47476621_800.jpg
  • c49.a####.com/user/485/31201485/1004/card/47476621/info.xml
  • c49.a####.com/user/872/37800872/1004/card/47471367/card.mp4?l=####&to=####
  • c49.a####.com/user/872/37800872/1004/card/47471367/info.xml
  • c50.a####.com/user/185/10844185/1006/card/47469137/47469137_800.jpg
  • c50.a####.com/user/20/21066020/1006/card/47470965/47470965_800.jpg
  • c50.a####.com/user/20/21066020/1006/card/47470965/info.xml
  • cdn.app.e####.####.com/sfile/201711/16/all/cp_V3.0.2.txt
  • cdn.game####.org/strategy/UnknownDev
  • cdn.game####.org/strategy/base
  • cdn.game####.org/strategy/dev_root
  • cdn.game####.org/strategy/dev_root2
  • cdn.game####.org/strategy/larger4.3
  • cdn.game####.org/strategy/loss_4.3
  • cdn.game####.org/strategy/sul18
  • cdn.game####.org/strategy/symlink-adbd
  • cs228-####.a####.com/user/185/10844185/1006/card/47469137/47469137_400.jpg
  • cs228-####.a####.com/user/385/6353385/1006/card/47471787/47471787_400.jpg
  • cs230-####.a####.com/user/146/32324146/1006/card/47473391/47473391_400.jpg
  • fu1.a####.com/account/116/43486116/account/43486116_normal.jpg
  • fu1.a####.com/account/129/63989129/account/63989129_normal.jpg
  • fu1.a####.com/account/146/32324146/account/32324146_normal.jpg
  • fu1.a####.com/account/181/13493181/account/13493181_normal.jpg
  • fu1.a####.com/account/185/10844185/account/10844185_normal.jpg
  • fu1.a####.com/account/20/21066020/account/21066020_normal.jpg
  • fu1.a####.com/account/282/47030282/account/47030282_normal.jpg
  • fu1.a####.com/account/485/31201485/account/31201485_normal.jpg
  • fu1.a####.com/account/704/19467704/account/19467704_normal.jpg
  • fu1.a####.com/account/872/37800872/account/37800872_normal.jpg
  • h####.a####.com/user/146/32324146/1006/card/47473391/47473391_400.jpg
  • h####.a####.com/user/181/13493181/1005/card/47467299/47467299_800.jpg
  • h####.a####.com/user/181/13493181/1005/card/47467299/card.mp4?l=####
  • h####.a####.com/user/181/13493181/1005/card/47467299/info.xml
  • h####.a####.com/user/185/10844185/1006/card/47469137/47469137_400.jpg
  • h####.a####.com/user/185/10844185/1006/card/47469137/47469137_800.jpg
  • h####.a####.com/user/20/21066020/1006/card/47470965/47470965_400.jpg
  • h####.a####.com/user/20/21066020/1006/card/47470965/47470965_800.jpg
  • h####.a####.com/user/20/21066020/1006/card/47470965/card.mp4?l=####
  • h####.a####.com/user/20/21066020/1006/card/47470965/info.xml
  • h####.a####.com/user/385/6353385/1006/card/47471787/47471787_400.jpg
  • h####.a####.com/user/485/31201485/1004/card/47476621/47476621_800.jpg
  • h####.a####.com/user/485/31201485/1004/card/47476621/card.mp4?l=####
  • h####.a####.com/user/485/31201485/1004/card/47476621/info.xml
  • h####.a####.com/user/872/37800872/1004/card/47471367/card.mp4?l=####
  • h####.a####.com/user/872/37800872/1004/card/47471367/info.xml
  • ip.ta####.com/service/getIpInfo2.php?ip=####
  • kvt####.m####.a####.com/kvinfo.php
  • nb3195-####.a####.com/user/20/21066020/1006/card/47470965/47470965_400.jpg
  • nb3195-####.a####.com/user/872/37800872/1004/card/47471367/card.mp4?l=##...
  • nb3197-####.a####.com/user/485/31201485/1004/card/47476621/info.xml
  • nb3200-####.a####.com/user/185/10844185/1006/card/47469137/47469137_800....
  • nb3201-####.a####.com/user/181/13493181/1005/card/47467299/47467299_800....
  • nb3201-####.a####.com/user/181/13493181/1005/card/47467299/card.mp4?l=##...
  • nb4050-####.a####.com/user/146/32324146/1006/card/47473391/47473391_400....
  • nb4051-####.a####.com/user/181/13493181/1005/card/47467299/info.xml
  • nb4500-####.a####.com/user/20/21066020/1006/card/47470965/47470965_800.jpg
  • nb4500-####.a####.com/user/20/21066020/1006/card/47470965/info.xml
  • nb4500-####.a####.com/user/872/37800872/1004/card/47471367/info.xml
  • nb4510-####.a####.com/user/485/31201485/1004/card/47476621/47476621_800....
  • qs.lago####.com:8982/loadtime.shtml?clientIp=&st=android&lt=7170&fip=61....
  • qs.lago####.com:8982/loadtime.shtml?clientIp=&st=android&lt=8240&fip=183...
  • qs.lago####.com:8982/notify.shtml?saddr=aipai-android500004&definition=4...
  • qs.lago####.com:8982/notify.shtml?saddr=jhc-android500004&definition=480...
  • res11-a####.we####.cn.####.com/aipai/page/pic/15181864854254992c24215181...
  • res11-a####.we####.cn.####.com/aipai/page/pic/1518186635975866d902c15181...
  • res11-a####.we####.cn.####.com/aipai/page/pic/1518186752508797c242815181...
  • res11-a####.we####.cn.####.com/aipai/page/pic/151818722512175483ab815181...
  • res11-a####.we####.cn.####.com/aipai/page/pic/1518187257165092c242815181...
  • res11-a####.we####.cn.####.com/user/20/21066020/1006/card/47470965/card....
  • res11-a####.we####.cn.####.com/user/485/31201485/1004/card/47476621/card...
  • s####.gw.y####.####.com/aos/v3/initf?s=####
  • s####.gw.y####.####.com/stat/v3/udt2?appid=####&s=####
  • s.y####.net/stat/aos/v3/pkc?s=####
  • s.y####.net/stat/aos/v3/pku?s=####
  • sdk.st####.y####.com/core/aos-dex/1701/7011/6f830529.jar
  • sdk.st####.y####.com/core/aos-so/1611/7000/ad389c56.so
  • www.a####.com.####.com/api/aipaiApp_action-getCommentNew_mobile-1_type-2...
  • www.a####.com.####.com/api/framework/adConf/35?platform=####&appver=####...
  • www.a####.com.####.com/api/framework/jifen/enter/35?platform=####&appver...
  • www.a####.com.####.com/api/hot/bannerItem/661?platform=####&appver=####&...
  • www.a####.com.####.com/api/hot/titleItem/662?platform=####&appver=####&o...
  • www.a####.com.####.com/api/hot/videos/12541?appId=####&xifenId=####&plat...
  • www.a####.com.####.com/api/jifen/firstInstallInit?platform=####&appver=#...
  • www.a####.com.####.com/api/specialTopic/itemList/664?platform=####&appve...
  • www.a####.com.####.com/app/www/templates/cdn_policy_telecom.txt?platform...
  • www.a####.com.####.com/common/img/upload/xifen/1482998183_982.png
  • www.a####.com.####.com/common/img/upload/xifen/1483429773_541.png
  • www.a####.com.####.com/common/img/upload/xifen/1495889588_39.jpg
  • www.a####.com.####.com/common/img/upload/xifen/1496931177_676.jpg
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&app=##...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&os=###...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&platfo...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&test=#...
  • www.a####.com.####.com/mobile/apps/apps_module-badDomain.html
  • www.a####.com.####.com/pc/operator
Запросы HTTP POST:
  • a####.m.ta####.com/rest/gc?dd=####&nsgs=####&ak=####&av=####&c=####&v=##...
  • a####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=####&...
  • a####.u####.com/app_logs
  • app.w####.cn/action/user_info
  • kvt####.m####.a####.com/i.gif
  • t####.dmp.y####.net/v1/android/packages?rt=####&sign=####
  • t####.dmp.y####.net/v2/android/pkgtime?rt=####&sign=####
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/.jiagu/libjiagu.so
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/Matrix
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/ddexe
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/debuggerd
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/fileWork
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/insta...ery.sh
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/pidof
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/su
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/supolicy
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/toolbox
  • <Package Folder>/app_1ee9a0c3-e95b-41e2-96b6-bb1bc8f2641b/wsroot.sh
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/Matrix
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/ddexe
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/debuggerd
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/fileWork
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/insta...ery.sh
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/pidof
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/su
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/supolicy
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/toolbox
  • <Package Folder>/app_8af18945-9c62-4d51-a422-992eb93fc40f/wsroot.sh
  • <Package Folder>/app_b0d84ed1-c303-4a7b-95ea-1a6f9cfe4076/5d658...be.jar
  • <Package Folder>/app_b0d84ed1-c303-4a7b-95ea-1a6f9cfe4076/fdce0...1c5b2a
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/Matrix
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/ddexe
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/debuggerd
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/fileWork
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/insta...ery.sh
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/pidof
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/su
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/supolicy
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/toolbox
  • <Package Folder>/app_d29f14e7-d70f-45ee-9fa9-0be3e319e32f/wsroot.sh
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/Matrix
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/ddexe
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/debuggerd
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/fileWork
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/insta...ery.sh
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/pidof
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/su
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/supolicy
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/toolbox
  • <Package Folder>/app_dfc270cc-ddfa-4435-83b1-22c3c3ebb9ff/wsroot.sh
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/Matrix
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/ddexe
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/debuggerd
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/device.db
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/fileWork
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/insta...ery.sh
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/pidof
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/root3
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/su
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/supolicy
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/toolbox
  • <Package Folder>/app_e9c2a353-f751-462a-9fdf-68847c78ea84/wsroot.sh
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/Matrix
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/ddexe
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/debuggerd
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/fileWork
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/insta...ery.sh
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/pidof
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/su
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/supolicy
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/toolbox
  • <Package Folder>/app_f0e62c6a-b0fd-4363-80b8-62c416f8d64d/wsroot.sh
  • <Package Folder>/app_libs/libabcdefgh.so.new
  • <Package Folder>/app_libs/ymdex.jar
  • <Package Folder>/app_libs/ymdex.jar.new
  • <Package Folder>/app_subox/1740c449fc10be62df60ba0f18696c9f
  • <Package Folder>/app_subox/32edd79a240b5f1e461d069caab1ec3e
  • <Package Folder>/app_subox/8b6f263391259b7a8e5f58ee71852ca8
  • <Package Folder>/app_subox/b0141e478b25af7c40a8cca8de6c4708
  • <Package Folder>/app_subox/b18a021d11a3004d25017230b681476b
  • <Package Folder>/app_subox/c61913b615fb6224701377a119081f36
  • <Package Folder>/app_subox_download/0ecd8951-2e71-4aee-beea-c82b6a4b2fdb
  • <Package Folder>/app_subox_download/3495b876-7830-48f7-ae51-be0387b5b2d3
  • <Package Folder>/app_subox_download/a0f3321c-a334-4bd9-922e-a38dfaaab444
  • <Package Folder>/app_subox_download/ac645aae-4a80-4409-89fa-dac0572aedc3
  • <Package Folder>/app_subox_download/b3674408-2d2f-4b20-bbad-ffc70ba80fec
  • <Package Folder>/app_subox_download/bc0f84f7-c4f6-4fe4-857b-9a56effd6837
  • <Package Folder>/app_subox_download/bdab1e92-a96e-4fee-958a-3d462dae070f
  • <Package Folder>/app_subox_download/f5f83b27-aa1b-45b2-a921-e230de20d2eb
  • <Package Folder>/cache/####/093175406b32453ac8a8697de741ed6e6ca....0.tmp
  • <Package Folder>/cache/####/137585c5ee91ea6c1fa2dc1df369b18e838....0.tmp
  • <Package Folder>/cache/####/17139868a9f52c38d321ab23fd6b8653aad....0.tmp
  • <Package Folder>/cache/####/1ed6df8283ca11401cb9d000bd5a8a38bf9....0.tmp
  • <Package Folder>/cache/####/287caf5e5cd481a8ac237bf05eb2d1023d3....0.tmp
  • <Package Folder>/cache/####/42ca4345b2d85338f7820564092507e875d....0.tmp
  • <Package Folder>/cache/####/4b169ac7607a7b19d511d164c2c5e0988f0....0.tmp
  • <Package Folder>/cache/####/4ea2ccc23671c40ae9d3c0030f351d0af95....0.tmp
  • <Package Folder>/cache/####/5ce6aaabddb2783032cc5b2d113c8c01a32....0.tmp
  • <Package Folder>/cache/####/6cb309463ca8f76bbd4c26b99ccc818ccdc....0.tmp
  • <Package Folder>/cache/####/77ab5d6cc319858a884d324920160cb7881....0.tmp
  • <Package Folder>/cache/####/83a7a69d6a868bcc65f81c5bb62327983e9....0.tmp
  • <Package Folder>/cache/####/85e8effd26542756640ed3c421a3b9e5a38....0.tmp
  • <Package Folder>/cache/####/873a5b978ad981c9e31b1e8ffe636243597....0.tmp
  • <Package Folder>/cache/####/8a6115ae50ef21dc9753c6b58691f9180f4....0.tmp
  • <Package Folder>/cache/####/add35a64dbf79d7edd98a73417ce9df886a....0.tmp
  • <Package Folder>/cache/####/beef06084026662de89e2c91ea2e0be6012....0.tmp
  • <Package Folder>/cache/####/ca8f5dd5f84519e80844b24c5dbcedb696d....0.tmp
  • <Package Folder>/cache/####/ca9a940bd9dc59a657d089a684fd9a4587d....0.tmp
  • <Package Folder>/cache/####/dafeb7418ac1f824d7b5519e8f34de93d11....0.tmp
  • <Package Folder>/cache/####/db670328d9bfe45865ee1a1800db91d8008....0.tmp
  • <Package Folder>/cache/####/e33fc7e9964af3fa4152edb00ca8d44cf7d....0.tmp
  • <Package Folder>/cache/####/e9b1c61ae2c5b607e97392b19d4613d1392....0.tmp
  • <Package Folder>/cache/####/eca5e35783dce1ff50223f9ff4f941ca0e1....0.tmp
  • <Package Folder>/cache/####/f6208aae138df83f7cfabf74a4a743ac532....0.tmp
  • <Package Folder>/cache/####/fa638f7e92464bcae4c31182464f6705d8f....0.tmp
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/cache/29d88b7f6b44e813ee07425e14c0b15d.0.tmp
  • <Package Folder>/cache/29d88b7f6b44e813ee07425e14c0b15d.1.tmp
  • <Package Folder>/cache/39a80a737c15447955bb73781bb7adb1.0.tmp
  • <Package Folder>/cache/39a80a737c15447955bb73781bb7adb1.1.tmp
  • <Package Folder>/cache/39dba2e219088d14d2e0b9d0941a9b30.0.tmp
  • <Package Folder>/cache/39dba2e219088d14d2e0b9d0941a9b30.1.tmp
  • <Package Folder>/cache/451e52f562361fb901ecc560826814a5.0.tmp
  • <Package Folder>/cache/451e52f562361fb901ecc560826814a5.1.tmp
  • <Package Folder>/cache/45451cb2f4a3eb5c59a55e1620902172.0.tmp
  • <Package Folder>/cache/45451cb2f4a3eb5c59a55e1620902172.1.tmp
  • <Package Folder>/cache/4bac37460eb5b9d5c659ca04a76848cd.0.tmp
  • <Package Folder>/cache/4bac37460eb5b9d5c659ca04a76848cd.1.tmp
  • <Package Folder>/cache/5519ae17bd7620834dcec1c61998ca9f.0.tmp
  • <Package Folder>/cache/5519ae17bd7620834dcec1c61998ca9f.1.tmp
  • <Package Folder>/cache/5f8411a3fcb3aaf908f5e8062930251b.0.tmp
  • <Package Folder>/cache/5f8411a3fcb3aaf908f5e8062930251b.1.tmp
  • <Package Folder>/cache/8ae1215630bd0820246c1d40c1167585.0.tmp
  • <Package Folder>/cache/8ae1215630bd0820246c1d40c1167585.1.tmp
  • <Package Folder>/cache/V3.0.2.txt
  • <Package Folder>/cache/a40ab4e9025597df4265cb71462e5c6b.0.tmp
  • <Package Folder>/cache/a40ab4e9025597df4265cb71462e5c6b.1.tmp
  • <Package Folder>/cache/b5c4c74bd559c741dbc0ab53cc92bd90.0.tmp
  • <Package Folder>/cache/b5c4c74bd559c741dbc0ab53cc92bd90.1.tmp
  • <Package Folder>/cache/b695e2ae07fc48e6f1d683a547afa509.0.tmp
  • <Package Folder>/cache/b695e2ae07fc48e6f1d683a547afa509.1.tmp
  • <Package Folder>/cache/b8063d0adb2d21754787cd781bdc7262.0.tmp
  • <Package Folder>/cache/b8063d0adb2d21754787cd781bdc7262.1.tmp
  • <Package Folder>/cache/c361ceba950dba3ea1d3c7d73e8943aa.0.tmp
  • <Package Folder>/cache/c361ceba950dba3ea1d3c7d73e8943aa.1.tmp
  • <Package Folder>/cache/e0888850d29ef11a195e5b377efd4265.0.tmp
  • <Package Folder>/cache/e0888850d29ef11a195e5b377efd4265.1.tmp
  • <Package Folder>/cache/f1129943d35e640527869c83f47d7aa6.0.tmp
  • <Package Folder>/cache/f1129943d35e640527869c83f47d7aa6.1.tmp
  • <Package Folder>/cache/journal.tmp
  • <Package Folder>/databases/OxgHkj2lz09F
  • <Package Folder>/databases/OxgHkj2lz09F-journal
  • <Package Folder>/databases/P15pKIjsm64m
  • <Package Folder>/databases/P15pKIjsm64m-journal
  • <Package Folder>/databases/T1oX0rhhuXWt
  • <Package Folder>/databases/T1oX0rhhuXWt-journal
  • <Package Folder>/databases/XKwVoK0huy3R
  • <Package Folder>/databases/XKwVoK0huy3R-journal
  • <Package Folder>/databases/aipai.db
  • <Package Folder>/databases/aipai.db-journal
  • <Package Folder>/databases/c848cefe7049727e9ad8cd9b48832f2a-journal
  • <Package Folder>/databases/d8305c5b3d6c8db862c69f2760ab1f81
  • <Package Folder>/databases/d8305c5b3d6c8db862c69f2760ab1f81-journal
  • <Package Folder>/databases/e57c34b26a4c8e1b872a8608bae7c4ed
  • <Package Folder>/databases/e57c34b26a4c8e1b872a8608bae7c4ed-journal
  • <Package Folder>/databases/jqIqJYOT3JpT
  • <Package Folder>/databases/jqIqJYOT3JpT-journal
  • <Package Folder>/databases/t_u.db-journal
  • <Package Folder>/databases/wIU6pTyUBYWX
  • <Package Folder>/databases/wIU6pTyUBYWX-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/wsUL1uCdKvjD
  • <Package Folder>/databases/wsUL1uCdKvjD-journal
  • <Package Folder>/files/####/.jg.ic
  • <Package Folder>/files/####/arrow-left.png
  • <Package Folder>/files/####/arrow-right.png
  • <Package Folder>/files/####/blank.gif
  • <Package Folder>/files/####/close-icon.png
  • <Package Folder>/files/####/config.json
  • <Package Folder>/files/####/default.png
  • <Package Folder>/files/####/detail-wx.html
  • <Package Folder>/files/####/detail-wx.js
  • <Package Folder>/files/####/detail.html
  • <Package Folder>/files/####/detail.js
  • <Package Folder>/files/####/exchangeIdentity.json
  • <Package Folder>/files/####/feedback.html
  • <Package Folder>/files/####/feedback.js
  • <Package Folder>/files/####/form.css
  • <Package Folder>/files/####/global.js
  • <Package Folder>/files/####/lists.css
  • <Package Folder>/files/####/lists.html
  • <Package Folder>/files/####/lists.js
  • <Package Folder>/files/####/md5.js
  • <Package Folder>/files/####/pic_m.png
  • <Package Folder>/files/####/pic_tips_01.png
  • <Package Folder>/files/####/pic_tips_02.png
  • <Package Folder>/files/####/result.png
  • <Package Folder>/files/####/rule.html
  • <Package Folder>/files/####/sdetail.html
  • <Package Folder>/files/####/share.css
  • <Package Folder>/files/####/share.html
  • <Package Folder>/files/####/share.js
  • <Package Folder>/files/####/sprite-face.png
  • <Package Folder>/files/####/sprite-icons.png
  • <Package Folder>/files/####/sprite-icons2.png
  • <Package Folder>/files/####/wx-step1.jpg
  • <Package Folder>/files/####/wx-step2.jpg
  • <Package Folder>/files/####/wx-step3.jpg
  • <Package Folder>/files/####/wx-step4.jpg
  • <Package Folder>/files/####/wx-step5.jpg
  • <Package Folder>/files/.imprint
  • <Package Folder>/files/CacheTime.dat
  • <Package Folder>/files/RptKVStrategy.txt
  • <Package Folder>/files/SUBOXLOG_
  • <Package Folder>/files/aipai.btconfig
  • <Package Folder>/files/aipai.guid
  • <Package Folder>/files/bb2a6a41513297cba18448271408e919.zip
  • <Package Folder>/files/dc.jar
  • <Package Folder>/files/em.jar
  • <Package Folder>/files/sp.lock
  • <Package Folder>/files/umeng_it.cache
  • <Package Folder>/shared_prefs/<Package>_preferences.xml
  • <Package Folder>/shared_prefs/Alvin2.xml
  • <Package Folder>/shared_prefs/AppSettings.xml
  • <Package Folder>/shared_prefs/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
  • <Package Folder>/shared_prefs/CE94557724F842149D690D0E8CBB1CBD.xml
  • <Package Folder>/shared_prefs/ContextData.xml
  • <Package Folder>/shared_prefs/CookiePersistence.xml
  • <Package Folder>/shared_prefs/OFFERSCONFIG1.xml
  • <Package Folder>/shared_prefs/ShowAdFlag.xml
  • <Package Folder>/shared_prefs/UTCommon.xml
  • <Package Folder>/shared_prefs/UTMCConf1787671270.xml
  • <Package Folder>/shared_prefs/UTMCLog1787671270.xml
  • <Package Folder>/shared_prefs/V3.0.2.xml
  • <Package Folder>/shared_prefs/ad_system_config.xml
  • <Package Folder>/shared_prefs/count.xml
  • <Package Folder>/shared_prefs/kr.xml
  • <Package Folder>/shared_prefs/multidex.version.xml
  • <Package Folder>/shared_prefs/rx_sf_account.xml
  • <Package Folder>/shared_prefs/rx_sf_app.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/vbz.xml
  • <Package Folder>/shared_prefs/ywPrefsTools.xml
  • <SD-Card>/.DataStorage/ContextData.xml
  • <SD-Card>/.UTSystemConfig/####/Alvin2.xml
  • <SD-Card>/.com.taobao.dp/6c709c11d2d46a7b
  • <SD-Card>/.com.taobao.dp/dd7893586a493dc3
  • <SD-Card>/Android/####/373240561418738c721572c1da14b85e
  • <SD-Card>/Android/####/373240561418738c721572c1da14b85e.ymtf
  • <SD-Card>/Android/####/AppPackage.dat
  • <SD-Card>/Android/####/CacheTime.dat
  • <SD-Card>/Android/####/DXTX902KJZX9JASLDJF
  • <SD-Card>/Android/####/DXTX902KJZX9JASLDJF.ymtf
  • <SD-Card>/Android/####/SOX90123JSOALK2098SD
  • <SD-Card>/Android/####/SOX90123JSOALK2098SD.ymtf
  • <SD-Card>/Android/####/UnPackage.dat
  • <SD-Card>/Android/####/android
  • <SD-Card>/Android/####/i42d45df023jnkdd93la483f9xGFKXI
  • <SD-Card>/Android/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
Другие:
Запускает следующие shell-скрипты:
  • /system/bin/cat /sys/devices/system/cpu/kernel_max
  • cat /proc/cpuinfo | grep Serial
  • chmod 755 <Package Folder>/.jiagu/libjiagu.so
  • chmod 777 Matrix ddexe debuggerd device.db fileWork install-recovery.sh pidof root3 su supolicy toolbox wsroot.sh
  • chmod 777 Matrix ddexe debuggerd fileWork install-recovery.sh pidof su supolicy toolbox wsroot.sh
  • ls -l /system/xbin/su
  • sh
Загружает динамические библиотеки:
  • abcdefgh
  • libjiagu
  • securitysdk-3.1
  • xifen
Использует следующие алгоритмы для шифрования данных:
  • AES
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Использует следующие алгоритмы для расшифровки данных:
  • DES
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Использует специальную библиотеку для скрытия исполняемого байткода.
Осуществляет доступ к информации о геолокации.
Осуществляет доступ к информации о сети.
Осуществляет доступ к информации о телефоне (номер, imei и тд.).
Осуществляет доступ к информации об установленных приложениях.
Осуществляет доступ к информации о запущенных приложениях.
Добавляет задания в системный планировщик.
Отрисовывает собственные окна поверх других приложений.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке