Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.Triada.682

Добавлен в вирусную базу Dr.Web: 2018-03-10

Описание добавлено:

Техническая информация

Вредоносные функции:
Загружает на исполнение код следующих детектируемых угроз:
  • Android.Triada.222.origin
Осуществляет доступ к приватному интерфейсу телефонии (ITelephony).
Сетевая активность:
Подключается к:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) mti.3####.com.####.com:80
  • TCP(HTTP/1.1) m.ed####.com.####.cn:80
  • TCP(HTTP/1.1) 1####.42.157.151:8080
  • TCP(HTTP/1.1) cm.b####.com:80
  • TCP(HTTP/1.1) wn.pos.b####.com:80
  • TCP(HTTP/1.1) terr####.oss-cn-####.aliy####.com:80
  • TCP(HTTP/1.1) s####.jom####.com:80
  • TCP(HTTP/1.1) g.al####.com:80
  • TCP(HTTP/1.1) 59.1####.19.6:9321
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) log.mm####.com:80
  • TCP(HTTP/1.1) m.rd####.com:80
  • TCP(HTTP/1.1) ad-sh-s####.wagbr####.t####.####.com:80
  • TCP(HTTP/1.1) n####.ed####.com.####.com:80
  • TCP(HTTP/1.1) u####.u####.uc.cn:80
  • TCP(HTTP/1.1) d####.uc.cn:80
  • TCP(HTTP/1.1) si####.jom####.com:80
  • TCP(HTTP/1.1) app.joy-r####.com:9080
  • TCP(HTTP/1.1) cc0####.s.cnc.####.cn:80
  • TCP(HTTP/1.1) pag####.googles####.com:80
  • TCP(HTTP/1.1) np####.ed####.com.####.com:80
  • TCP(HTTP/1.1) b####.b####.com:80
  • TCP(HTTP/1.1) bird####.oss-cn-####.aliy####.com:80
  • TCP(HTTP/1.1) wild####.al####.com.####.net:80
  • TCP(HTTP/1.1) image####.b####.com:80
  • TCP(HTTP/1.1) e####.b####.com:80
  • TCP(HTTP/1.1) c####.baidust####.com:80
  • TCP(HTTP/1.1) ope.t####.com:80
  • TCP(HTTP/1.1) c####.ed####.com:80
  • TCP(HTTP/1.1) pco####.t####.com:80
  • TCP(HTTP/1.1) a####.ed####.com:80
  • TCP(TLS/1.0) s####.al####.com:443
  • TCP(TLS/1.0) e####.b####.com:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
  • TCP(TLS/1.0) c####.baidust####.com:443
  • TCP(TLS/1.0) pag####.googles####.com:443
  • TCP(TLS/1.0) s####.m.sm.cn:443
  • TCP(TLS/1.0) adser####.go####.com:443
  • TCP(TLS/1.0) y####.m.sm.cn:443
  • TCP(TLS/1.0) l####.m.sm.cn:443
  • TCP(TLS/1.0) owe.joy-r####.com:9050
  • TCP(TLS/1.0) g.al####.com:443
  • TCP(TLS/1.0) z####.s####.cn:443
Запросы DNS:
  • a####.ed####.com
  • a####.m.sm.cn
  • adser####.go####.com
  • adser####.go####.nl
  • and####.b####.qq.com
  • api.s####.b####.com
  • app.joy-r####.com
  • at####.al####.com
  • b####.b####.com
  • bird####.oss-cn-####.aliy####.com
  • c####.baidust####.com
  • c####.baidust####.com
  • c####.ed####.com
  • c####.ed####.com
  • cdn.t####.com
  • cm.b####.com
  • d####.uc.cn
  • df.t####.com
  • e####.b####.com
  • f10.b####.com
  • f11.b####.com
  • f12.b####.com
  • g.al####.com
  • googl####.g.doublec####.net
  • hm.b####.com
  • hz.ed####.com
  • i####.u####.cn
  • image####.b####.com
  • img.al####.com
  • l####.m.sm.cn
  • log.mm####.com
  • m.ed####.com
  • m.rd####.com
  • mti.3####.com
  • n####.ed####.com
  • np####.ed####.com
  • ope.t####.com
  • owe.joy-r####.com
  • p####.zhanz####.b####.com
  • p.t####.com
  • pag####.googles####.com
  • pco####.t####.com
  • plb####.u####.com
  • res.ed####.com
  • s####.al####.com
  • s####.al####.com
  • s####.m.sm.cn
  • s####.m.sm.cn
  • s2.z####.cn
  • t11.b####.com
  • t12.b####.com
  • terr####.oss-cn-####.aliy####.com
  • u####.u####.com
  • u####.uc.cn
  • ubm####.ed####.com
  • wn.pos.b####.com
  • y####.m.sm.cn
  • z####.s####.cn
Запросы HTTP GET:
  • a####.ed####.com/Avatar//system/006.jpg
  • ad-sh-s####.wagbr####.t####.####.com/ex?i=####&m=####
  • app.joy-r####.com:9080/search/getList.do?aid=####
  • b####.b####.com/eye.php?t=####&actionid=####&attach=####&time=####&exp_l...
  • b####.b####.com/eye.php?t=####&start=####&site_api_loaded=####&opt=####&...
  • bird####.oss-cn-####.aliy####.com/img/58.png
  • bird####.oss-cn-####.aliy####.com/img/fenghuang.png
  • bird####.oss-cn-####.aliy####.com/img/ganji.png
  • bird####.oss-cn-####.aliy####.com/img/lvmama.png
  • bird####.oss-cn-####.aliy####.com/img/qq.png
  • bird####.oss-cn-####.aliy####.com/img/sogou.png
  • bird####.oss-cn-####.aliy####.com/img/sohu.png
  • bird####.oss-cn-####.aliy####.com/img/taobao.png
  • bird####.oss-cn-####.aliy####.com/img/wangyi.png
  • bird####.oss-cn-####.aliy####.com/img/zilian.png
  • c####.baidust####.com/cpro/ui/mi.js
  • c####.baidust####.com/cpro/ui/noexpire/img/2.0.1/bd-logo4.png
  • c####.ed####.com/bnqjsm?wtx=####&lxs=####&sx=####&aij=####&sgx=####&ieg=...
  • c####.ed####.com/bwlycsecc.js
  • c####.ed####.com/bwoccfeyl.js
  • c####.ed####.com/cwaeqau.js
  • c####.ed####.com/hbaqyt?wtx=####&lxs=####&sx=####&aij=####&sib=####&exh=...
  • c####.ed####.com/m.html?mediaid=####&cookie_version=####&timestamp=####&...
  • c####.ed####.com/ryyq/km?c=####
  • c####.ed####.com/ryyq/xv?c=####
  • c####.ed####.com/ryyq/y?c=####
  • c####.ed####.com/sarhons?wtx=####&lxs=####&sx=####&aij=####&sxh=####&pgx...
  • cc0####.s.cnc.####.cn/bang/info/2-15-n4319458.html
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/css/common_7.0.css
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/css/detail_7.0.css
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/images/logo.png
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/images/share_btn.png
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/images/sprite_icon.png
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/images/sprite_icon_d.png
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/js/Detail.min.js
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/js/common.min.js
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/js/jquery-1.8.3.min.js
  • cc0####.s.cnc.####.cn/www/touch/v7/asset/js/scrollload.min.js
  • cm.b####.com/pixel?media_sign=####&media_site=####
  • d####.uc.cn/uclite/down.php?id=####&pub=####
  • e####.b####.com/public03/imageplus/m/title_img_only/pa_lu_moreclkzone.ap...
  • g.al####.com/L1/272/6837/static/wap/img/index/v6/haodongxi3.png
  • g.al####.com/L1/272/6837/static/wap/img/index/v7/logo2.png
  • g.al####.com/L1/272/6837/static/wap/img/index/v7/navs4.png
  • g.al####.com/L1/272/6837/static/wap/img/uc-32.png
  • g.al####.com/L1/272/6837/static/wap/img/uc.png
  • g.al####.com/g/mm/tanx-cdn2/t/tanxmobile/tanxssp.js?_v=####
  • g.al####.com/ims?kt=####&at=####&key=####&sign=yx####&tv=####&x####
  • g.al####.com/ims?kt=####&at=####&key=aHR####&sign=yx####&tv=####&x####&d...
  • g.al####.com/ims?kt=####&at=####&key=aHR####&sign=yx####&tv=####&x####&h...
  • g.al####.com/t/acookie/acbeacon2.html
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.js?99a36e5####
  • image####.b####.com/imgs/showcase-1.jpg
  • image####.b####.com/ui?api=####&prot=####&tu=####&pic=####&vn=####&callb...
  • image####.b####.com/ui?dri=####&formId=####&src=####&k=####&iurl[]=####&...
  • image####.b####.com/ui?dri=####&is_small_pic=####&src=####&k=####&iurl[]...
  • log.mm####.com/t.gif
  • m.ed####.com.####.cn/bang/info/2-15-n4319458.html
  • m.ed####.com.####.cn/user/asset/css/homepage.css
  • m.ed####.com.####.cn/user/asset/images/hp_icon.png
  • m.ed####.com.####.cn/user/asset/images/logo.png
  • m.ed####.com.####.cn/user/asset/images/sprite_icon.png
  • m.ed####.com.####.cn/user/asset/js/common.js
  • m.ed####.com.####.cn/user/asset/js/jquery-1.8.3.min.js
  • m.ed####.com.####.cn/user/asset/js/scrollLoad.min.js
  • m.ed####.com.####.cn/user/index/1-874086.html
  • m.rd####.com/tuku/hot/139306.html?f=####
  • mti.3####.com.####.com/data/materiel/20180205104728.jpg
  • n####.ed####.com.####.com/cn/tu/zh-chs/2018-03/09/s2c634c5b28334840ad3f8...
  • n####.ed####.com.####.com/cn/tu/zh-chs/2018-03/09/s9c648b49d7a343ec9f07c...
  • n####.ed####.com.####.com/cn/tu/zh-chs/2018-03/09/sa525cddfab7844ff844f8...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/07/s16e9dae0018240f58a...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/07/sfbe7422901694b5e8e...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/a882d1024cb1465181c...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/faa2a6470a374952ad1...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/ffcbc4e578004e2ab54...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/s1eef77b633d646cc88...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/s27c4ee2b2e7c4b6ea0...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/s600a23a90a694a07ae...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/s6a8fe9173e104a1b93...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/s8d8bd0d9991841678a...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/08/sfee32edc52524a3db4...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/58fb227ce5474842be3...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/72eed76f6e2c4166bd9...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/7a80d974ac2e43c3994...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/a6e800d5d1c54f21911...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/d62259e1e57d4941ab0...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s018ca2fefc3d4dfab2...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s09d28b34223f4e8197...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s101a298a157446219a...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s10f4287c91db4275b7...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s14b42a5baeed4db9a8...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s16b80d92fde64274bb...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s1bf98b2914fa4fcc8a...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s1e434e79a2294fd783...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s1f524b0042c14d1b86...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s1f909ff8c5574acb86...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s2277c7deac784425bd...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s2786632ef4564fe3a5...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s35b13aa13ee94354a8...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s3bd0b01c63e245ff83...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s4318317-2018030910...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s4318357-2018030911...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s4343bced3c134d1f84...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s4879fec0f9d241f1b8...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s503b329b18cf484180...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s566f698b89f8414da9...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s58959b3ee5fa48ff96...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s5f0e6184ce66452b9f...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s5f61c67c3c53463390...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s66590bb0566e4aa88f...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s6e2f1286f8e54e599f...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s72fba7485c4246ea82...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s775c4ebbaf1046c3a0...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s7a80d974ac2e43c399...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s7ea7f32309c8405a8c...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s85580d91eba2483687...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s8c7db8ae476e467285...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s9341ecc065b94c559e...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s964ad3b6962741d9aa...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/s99b1fc6295544679a3...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sa1ed5d1c5c9541068d...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sa476d7a0401d427093...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sad778111fa2b4bb69a...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sb9fc4d265e5c4ac583...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/scd1b464aaf984bc089...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sd2c93238190342f3b5...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sd81f948338c24b6092...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sfdd20b1f4d514abdb1...
  • n####.ed####.com.####.com/cn/zixun/zh-chs/2018-03/09/sffb4c24e6ed04417a8...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2017-03/24/b64e7b80d0e746c797ba1f...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2017-04/14/2f5ab2dc4ec54c8aaf74f6...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2017-12/08/8be17bb7d167446899d98b...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2018-01/27/0170d76653d94a7fa1ea8a...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2018-01/31/698df6d5d46142a1ad91c5...
  • n####.ed####.com.####.com/cn/zt/zh-chs/2018-02/09/d924010910ef4238b33286...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2017-08/16/0626378b9d3644aba5...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2017-12/19/8bb8b3ff33ff47f290...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-01/19/0072d36e00f34fd097...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-02/06/9ad78e271b8d41d6b2...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-02/07/c8f66716eabd413eab...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-02/09/72af76c50a544d36a4...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-02/09/dfeb03d8c91e44c398...
  • np####.ed####.com.####.com/jm/zixun/zh-chs/2018-02/26/ea999045995748b0ab...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-02/24/09a9f1de5408470ba6...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-02/24/4d106e5ccc0b436cb9...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-02/24/7ed1d447e1dc4ea1a5...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-02/27/ebdba071407a4004b9...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-03/02/7d9f65e7570c4f22ac...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-03/02/d354dcc9fa524784a2...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-03/03/81a88bed428946f4a5...
  • np####.ed####.com.####.com/rw/zixun/zh-chs/2018-03/07/7f39c404a2e94229b3...
  • ope.t####.com/wap?i=####&cb=####&callback=####&userid=####&o=####&f=####...
  • pag####.googles####.com/pagead/js/adsbygoogle.js
  • pag####.googles####.com/pagead/js/r20180307/r20170110/show_ads_impl.js
  • pco####.t####.com/app.gif?&cna=####
  • s####.jom####.com/push.js
  • s####.jom####.com/s.gif?l=####
  • si####.jom####.com/it/u=1130617034,1673256959&fm=76
  • si####.jom####.com/it/u=1427648914,1616939950&fm=76
  • si####.jom####.com/it/u=170590329,1136620447&fm=76
  • si####.jom####.com/it/u=1851076564,1149525094&fm=76
  • si####.jom####.com/it/u=2102452602,3374994301&fm=76
  • si####.jom####.com/it/u=213520238,4133588317&fm=76
  • si####.jom####.com/it/u=2309378326,4221714074&fm=76
  • si####.jom####.com/it/u=235560470,1665058060&fm=76
  • si####.jom####.com/it/u=3138743507,3728806229&fm=76
  • si####.jom####.com/it/u=3281037176,3197509276&fm=76
  • si####.jom####.com/it/u=3300541970,3520359300&fm=76
  • si####.jom####.com/it/u=3322877525,737632979&fm=76
  • si####.jom####.com/it/u=3553052062,3966362701&fm=76
  • si####.jom####.com/it/u=3631708702,3929097240&fm=76
  • si####.jom####.com/it/u=369861874,4118192394&fm=76
  • si####.jom####.com/it/u=3701994385,2305095443&fm=76
  • si####.jom####.com/it/u=371246763,2030543604&fm=76
  • si####.jom####.com/it/u=3753754915,3881824082&fm=76
  • si####.jom####.com/it/u=3790080839,3812911281&fm=76
  • si####.jom####.com/it/u=3953913646,4205139502&fm=76
  • si####.jom####.com/it/u=42536834,4053587854&fm=76
  • si####.jom####.com/it/u=438460409,4240305271&fm=76
  • si####.jom####.com/it/u=589546862,2241888480&fm=76
  • si####.jom####.com/it/u=701360227,37420598&fm=76
  • si####.jom####.com/it/u=821146689,3999765574&fm=76
  • terr####.oss-cn-####.aliy####.com/11/load.bat
  • u####.u####.uc.cn/down4/tangzhihan/shenmaceshi/UCLite_V11.6.8.10_android...
  • wild####.al####.com.####.net/tfs/TB1K4sVLXXXXXbQaXXXXXXXXXXX-36-20.png
  • wn.pos.b####.com/adx.php?c=####
Запросы HTTP POST:
  • and####.b####.qq.com/rqd/async
  • m.ed####.com.####.cn/GetIsAttentioned.htm
  • m.ed####.com.####.cn/GetIsAttentioned.htm?r=####
  • m.ed####.com.####.cn/GetIsFavorites.htm?r=####
  • m.ed####.com.####.cn/GetIsUpvoteDownvote.htm?r=####
  • m.ed####.com.####.cn/UpdateAttentionOfUpdateDate.htm
Изменения в файловой системе:
Создает следующие файлы:
  • <Package Folder>/app_aqPVSg3/tMS866P3hcq
  • <Package Folder>/app_bird_plugin/bird_plugin.dex
  • <Package Folder>/app_bird_plugin/bird_plugin.jar
  • <Package Folder>/app_bird_plugin/bird_plugin.jar.sig
  • <Package Folder>/app_bird_plugin/update_lc
  • <Package Folder>/cache/####/0cf83b29c2b54fe0975438a492a5368084a....0.tmp
  • <Package Folder>/cache/####/38e57404da5f79596c5f0eabf4bad6b689b....0.tmp
  • <Package Folder>/cache/####/42196122849317dea640027366161553966....0.tmp
  • <Package Folder>/cache/####/61b2a8370d98c19192cc58639545633bad9....0.tmp
  • <Package Folder>/cache/####/6d82b89f59ef4940d747ffacc1936546223....0.tmp
  • <Package Folder>/cache/####/6e4b0f32d9f57aea3f18002ad4cfdad77b9....0.tmp
  • <Package Folder>/cache/####/780216c66fcbba8fe1e05b54f301fce1102....0.tmp
  • <Package Folder>/cache/####/79b7c1cc3a4e0004926d31378ab576618c1....0.tmp
  • <Package Folder>/cache/####/9299bbb9fd13c842f431c397226a5834127....0.tmp
  • <Package Folder>/cache/####/CachedGeoposition.db
  • <Package Folder>/cache/####/CachedGeoposition.db-journal
  • <Package Folder>/cache/####/bba1d34bf8bd1db60aa86b12a8749debe75....0.tmp
  • <Package Folder>/cache/####/data_0
  • <Package Folder>/cache/####/data_1
  • <Package Folder>/cache/####/data_2
  • <Package Folder>/cache/####/data_3
  • <Package Folder>/cache/####/f_000001
  • <Package Folder>/cache/####/f_000002
  • <Package Folder>/cache/####/f_000003
  • <Package Folder>/cache/####/f_000004
  • <Package Folder>/cache/####/f_000005
  • <Package Folder>/cache/####/f_000006
  • <Package Folder>/cache/####/f_000007
  • <Package Folder>/cache/####/f_000008
  • <Package Folder>/cache/####/f_000009
  • <Package Folder>/cache/####/f_00000a
  • <Package Folder>/cache/####/f_00000b
  • <Package Folder>/cache/####/f_00000c
  • <Package Folder>/cache/####/f_00000d
  • <Package Folder>/cache/####/f_00000e
  • <Package Folder>/cache/####/f_00000f
  • <Package Folder>/cache/####/f_000010
  • <Package Folder>/cache/####/f_000011
  • <Package Folder>/cache/####/f_000012
  • <Package Folder>/cache/####/f_000013
  • <Package Folder>/cache/####/f_000014
  • <Package Folder>/cache/####/f_000015
  • <Package Folder>/cache/####/f_000016
  • <Package Folder>/cache/####/f_000017
  • <Package Folder>/cache/####/f_000018
  • <Package Folder>/cache/####/f_000019
  • <Package Folder>/cache/####/f_00001a
  • <Package Folder>/cache/####/f_00001b
  • <Package Folder>/cache/####/f_00001c
  • <Package Folder>/cache/####/f_00001d
  • <Package Folder>/cache/####/f_00001e
  • <Package Folder>/cache/####/f_00001f
  • <Package Folder>/cache/####/f_000020
  • <Package Folder>/cache/####/f_000021
  • <Package Folder>/cache/####/f_000022
  • <Package Folder>/cache/####/f_000023
  • <Package Folder>/cache/####/f_000024
  • <Package Folder>/cache/####/f_000025
  • <Package Folder>/cache/####/f_000026
  • <Package Folder>/cache/####/f_000027
  • <Package Folder>/cache/####/f_000028
  • <Package Folder>/cache/####/f_000029
  • <Package Folder>/cache/####/f_00002a
  • <Package Folder>/cache/####/f_00002b
  • <Package Folder>/cache/####/f_00002c
  • <Package Folder>/cache/####/f_00002d
  • <Package Folder>/cache/####/f_00002e
  • <Package Folder>/cache/####/f_00002f
  • <Package Folder>/cache/####/f_000030
  • <Package Folder>/cache/####/f_000031
  • <Package Folder>/cache/####/f_000032
  • <Package Folder>/cache/####/f_000033
  • <Package Folder>/cache/####/f_000034
  • <Package Folder>/cache/####/f_000035
  • <Package Folder>/cache/####/f_000036
  • <Package Folder>/cache/####/f_000037
  • <Package Folder>/cache/####/f_000038
  • <Package Folder>/cache/####/f_000039
  • <Package Folder>/cache/####/f_00003a
  • <Package Folder>/cache/####/f_00003b
  • <Package Folder>/cache/####/f_00003c
  • <Package Folder>/cache/####/f_00003d
  • <Package Folder>/cache/####/f_00003e
  • <Package Folder>/cache/####/f_00003f
  • <Package Folder>/cache/####/f_000040
  • <Package Folder>/cache/####/f_000041
  • <Package Folder>/cache/####/f_000042
  • <Package Folder>/cache/####/f_000043
  • <Package Folder>/cache/####/f_000044
  • <Package Folder>/cache/####/f_000045
  • <Package Folder>/cache/####/f_000046
  • <Package Folder>/cache/####/f_000047
  • <Package Folder>/cache/####/f_000048
  • <Package Folder>/cache/####/f_000049
  • <Package Folder>/cache/####/f_00004a
  • <Package Folder>/cache/####/f_00004b
  • <Package Folder>/cache/####/f_00004c
  • <Package Folder>/cache/####/f_00004d
  • <Package Folder>/cache/####/f_00004e
  • <Package Folder>/cache/####/f_00004f
  • <Package Folder>/cache/####/http_m.edushi.com_0.localstorage-journal
  • <Package Folder>/cache/####/https_so.m.sm.cn_0.localstorage-journal
  • <Package Folder>/cache/####/https_yz.m.sm.cn_0.localstorage-journal
  • <Package Folder>/cache/####/index
  • <Package Folder>/cache/####/journal.tmp
  • <Package Folder>/databases/Fast.db-journal
  • <Package Folder>/databases/bugly_db_legu-journal
  • <Package Folder>/databases/ua.db
  • <Package Folder>/databases/ua.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/webviewCookiesChromium.db-journal
  • <Package Folder>/databases/xUtils_http_cache.db
  • <Package Folder>/databases/xUtils_http_cache.db-journal
  • <Package Folder>/databases/xUtils_http_cookie.db
  • <Package Folder>/databases/xUtils_http_cookie.db-journal
  • <Package Folder>/files/####/a==7.4.0&&2.1.2_1510835482072_envelope.log
  • <Package Folder>/files/####/exchangeIdentity.json
  • <Package Folder>/files/####/i==1.2.0&&2.1.2_1510835481836_envelope.log
  • <Package Folder>/files/.imprint
  • <Package Folder>/files/H4O783l.apk
  • <Package Folder>/files/exid.dat
  • <Package Folder>/files/local_crash_lock
  • <Package Folder>/files/native_record_lock
  • <Package Folder>/files/sdk.jar
  • <Package Folder>/files/security_info
  • <Package Folder>/files/umeng_it.cache
  • <Package Folder>/mix.dex
  • <Package Folder>/shared_prefs/1314|account_file.xml
  • <Package Folder>/shared_prefs/STORE_MAIN.xml
  • <Package Folder>/shared_prefs/UM_PROBE_DATA.xml
  • <Package Folder>/shared_prefs/abs.xml
  • <Package Folder>/shared_prefs/info.xml
  • <Package Folder>/shared_prefs/spUtils.xml
  • <Package Folder>/shared_prefs/um_pri.xml
  • <Package Folder>/shared_prefs/umdat.xml
  • <Package Folder>/shared_prefs/umeng_common_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/tx_shell/libnfix.so
  • <Package Folder>/tx_shell/libshella-2.10.7.1.so
  • <SD-Card>/.a.dat
  • <SD-Card>/.cc/.adfwe.dat
  • <SD-Card>/.um/.umm.dat
  • <SD-Card>/.uxx/.cca.dat
  • <SD-Card>/Android/####/UCLite_V11.6.8.10_android_pf245_bi36452_...3).apk
  • <SD-Card>/BIRDDOWNLOAD/####/429ab0ec8839118df6d183772bcf909e.temp
  • <SD-Card>/BIRDDOWNLOAD/####/Badinfo.xml
  • <SD-Card>/BIRDDOWNLOAD/####/YvscMPs.xml
  • <SD-Card>/BIRDDOWNLOAD/####/rinsWPVPycqVPSq38.db
  • <SD-Card>/BIRDDOWNLOAD/####/rinsWPVPycqVPSq38.db-journal
  • <SD-Card>/BIRDDOWNLOAD/####/webinfo.xml
  • <SD-Card>/Download/####/load.bat
  • <SD-Card>/Download/####/ver.txt
Другие:
Запускает следующие shell-скрипты:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/app_aqPVSg3/tMS866P3hcq -p <Package> -s com.birdads.out.BGService -t 600
  • cat /sys/class/net/wlan0/address
  • chmod 0755 <Package Folder>/app_aqPVSg3/tMS866P3hcq
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.10.7.1.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • ls /
  • ls /sys/class/thermal
Загружает динамические библиотеки:
  • Bugly
  • libnfix
  • libshella-2.10.7.1
  • libufix
  • nfix
  • ufix
Использует следующие алгоритмы для шифрования данных:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS7Padding
  • AES-GCM-NoPadding
  • DES-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Использует следующие алгоритмы для расшифровки данных:
  • AES-CBC-NoPadding
  • AES-GCM-NoPadding
  • DES-ECB-NoPadding
Использует специальную библиотеку для скрытия исполняемого байткода.
Осуществляет доступ к информации о геолокации.
Осуществляет доступ к информации о сети.
Осуществляет доступ к информации о телефоне (номер, imei и тд.).
Осуществляет доступ к информации о настроках APN.
Осуществляет доступ к информации об установленных приложениях.
Отрисовывает собственные окна поверх других приложений.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке