Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.BankBot.TgToxic.32

Добавлен в вирусную базу Dr.Web: 2023-09-03

Описание добавлено:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.BankBot.TgToxic.1
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) c####.x####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) rr5---s####.g####.com:443
  • TCP(TLS/1.0) rr18---####.g####.com:443
  • TCP(TLS/1.2) 1####.194.222.102:443
  • TCP(TLS/1.2) and####.google####.com:443
  • UDP and####.google####.com:443
  • UDP rr5---s####.g####.com:443
  • UDP rr18---####.g####.com:443
  • UDP rr2---s####.g####.com:443
DNS requests:
  • and####.google####.com
  • c####.x####.com
  • connect####.gst####.com
  • m####.go####.com
  • rr18---####.g####.com
  • rr2---s####.g####.com
  • rr5---s####.g####.com
  • rr9---s####.g####.com
  • sqs.ap-nort####.amazo####.com
File system changes:
Creates the following files:
  • /data/data/####/.com_kixswl_dbxrewns.meta
  • /data/data/####/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.dex (deleted)
  • /data/data/####/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.dex.flock (deleted)
  • /data/data/####/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.zip
  • /data/data/####/0G0T8QV5BJTCYE2ON4GQAFL5KN2HNV2B.dex
  • /data/data/####/135KR9C1PF3MI3DT6G781484XCLZA82.dex (deleted)
  • /data/data/####/135KR9C1PF3MI3DT6G781484XCLZA82.dex.flock (deleted)
  • /data/data/####/135KR9C1PF3MI3DT6G781484XCLZA82.zip
  • /data/data/####/150035
  • /data/data/####/1693774339221_4333
  • /data/data/####/1693774344609_4516
  • /data/data/####/1693774356922_4955
  • /data/data/####/1693774360409_5070
  • /data/data/####/1693774364712_5198
  • /data/data/####/1693774369515_5321
  • /data/data/####/19
  • /data/data/####/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.dex (deleted)
  • /data/data/####/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.dex.flock (deleted)
  • /data/data/####/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.zip
  • /data/data/####/2023-09-03PM115135.rt
  • /data/data/####/2023-09-03PM115135.str
  • /data/data/####/2023-09-03PM115143.so.rt
  • /data/data/####/2023-09-03PM115151.so.rt
  • /data/data/####/2023-09-03PM115158.so.rt
  • /data/data/####/2023-09-03PM115207.so.rt
  • /data/data/####/2023-09-03PM115213.so.rt
  • /data/data/####/2023-09-03PM115220.so.rt
  • /data/data/####/2023-09-03PM115226.so.rt
  • /data/data/####/2023-09-03PM115231.so.rt
  • /data/data/####/2023-09-03PM115234.so.rt
  • /data/data/####/2023-09-03PM115238.so.rt
  • /data/data/####/2023-09-03PM115242.so.rt
  • /data/data/####/2023-09-03PM115246.so.rt
  • /data/data/####/2023-09-03PM115252.so.rt
  • /data/data/####/250035
  • /data/data/####/29
  • /data/data/####/3XZQX3MB7X184XRRO6TU3IMYZQR9OYS.dex (deleted)
  • /data/data/####/3XZQX3MB7X184XRRO6TU3IMYZQR9OYS.dex.flock (deleted)
  • /data/data/####/3XZQX3MB7X184XRRO6TU3IMYZQR9OYS.zip
  • /data/data/####/5M2A8GT4MXBDVDDBFECEDBHFQRY2U7M.dex (deleted)
  • /data/data/####/5M2A8GT4MXBDVDDBFECEDBHFQRY2U7M.dex.flock (deleted)
  • /data/data/####/5M2A8GT4MXBDVDDBFECEDBHFQRY2U7M.zip
  • /data/data/####/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex
  • /data/data/####/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex.flock (deleted)
  • /data/data/####/7GWWEQJEKFTZH7R9XKYKFPF985KCOXC.dex (deleted)
  • /data/data/####/7GWWEQJEKFTZH7R9XKYKFPF985KCOXC.dex.flock (deleted)
  • /data/data/####/7GWWEQJEKFTZH7R9XKYKFPF985KCOXC.zip
  • /data/data/####/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex
  • /data/data/####/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex.flock (deleted)
  • /data/data/####/8O0IIBUCN1ZDNRXDKQSB97XG9SGSXKE.dex (deleted)
  • /data/data/####/8O0IIBUCN1ZDNRXDKQSB97XG9SGSXKE.dex.flock (deleted)
  • /data/data/####/8O0IIBUCN1ZDNRXDKQSB97XG9SGSXKE.zip
  • /data/data/####/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex
  • /data/data/####/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex.flock (deleted)
  • /data/data/####/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex
  • /data/data/####/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex.flock (deleted)
  • /data/data/####/Archimedes_p1
  • /data/data/####/Archimedes_p2
  • /data/data/####/Archimedes_p3
  • /data/data/####/Archimedes_p4
  • /data/data/####/Archimedes_p5
  • /data/data/####/BDN29RIBB1DS8TF3OU92ZUUEVARX864.dex (deleted)
  • /data/data/####/BDN29RIBB1DS8TF3OU92ZUUEVARX864.dex.flock (deleted)
  • /data/data/####/BDN29RIBB1DS8TF3OU92ZUUEVARX864.zip
  • /data/data/####/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.dex (deleted)
  • /data/data/####/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.dex.flock (deleted)
  • /data/data/####/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.zip
  • /data/data/####/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex
  • /data/data/####/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex.flock (deleted)
  • /data/data/####/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex
  • /data/data/####/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex.flock (deleted)
  • /data/data/####/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex
  • /data/data/####/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex.flock (deleted)
  • /data/data/####/IECPkgStoreInfo
  • /data/data/####/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex
  • /data/data/####/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex.flock (deleted)
  • /data/data/####/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex
  • /data/data/####/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex.flock (deleted)
  • /data/data/####/Lock0
  • /data/data/####/Lock2
  • /data/data/####/Lock7
  • /data/data/####/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex
  • /data/data/####/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex.flock (deleted)
  • /data/data/####/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex
  • /data/data/####/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex.flock (deleted)
  • /data/data/####/MX981LN47CDWKE5F61FYNTXF8MPHY5AV.dex
  • /data/data/####/OCCU67EGRDJ1JF9XS6075ZXCTC4C5WI.dex (deleted)
  • /data/data/####/OCCU67EGRDJ1JF9XS6075ZXCTC4C5WI.dex.flock (deleted)
  • /data/data/####/OCCU67EGRDJ1JF9XS6075ZXCTC4C5WI.zip
  • /data/data/####/PR9C3DW15VZAQR556CFG5W08HKDZIOY.dex (deleted)
  • /data/data/####/PR9C3DW15VZAQR556CFG5W08HKDZIOY.dex.flock (deleted)
  • /data/data/####/PR9C3DW15VZAQR556CFG5W08HKDZIOY.zip
  • /data/data/####/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex
  • /data/data/####/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex.flock (deleted)
  • /data/data/####/TDCloud_Control_Cache_Param1
  • /data/data/####/TD_AES_DATA_LOCK
  • /data/data/####/TD_AES_IV_LOCK
  • /data/data/####/TD_AES_SALT_LOCK
  • /data/data/####/TD_app_pefercen_profile.xml
  • /data/data/####/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.dex (deleted)
  • /data/data/####/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.dex.flock (deleted)
  • /data/data/####/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.zip
  • /data/data/####/VO0O6U3EKVP3PVJLX0MS3H7D8DCCWT8.dex (deleted)
  • /data/data/####/VO0O6U3EKVP3PVJLX0MS3H7D8DCCWT8.dex.flock (deleted)
  • /data/data/####/VO0O6U3EKVP3PVJLX0MS3H7D8DCCWT8.zip
  • /data/data/####/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex
  • /data/data/####/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex.flock (deleted)
  • /data/data/####/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex
  • /data/data/####/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex.flock (deleted)
  • /data/data/####/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.dex (deleted)
  • /data/data/####/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.dex.flock (deleted)
  • /data/data/####/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.zip
  • /data/data/####/adc76816cd01c3b39cd37ad2ddf47111ts99nb.gtae
  • /data/data/####/com.android.launcher3.prefs.xml
  • /data/data/####/empty_classes.dex
  • /data/data/####/empty_classes.zip
  • /data/data/####/iv
  • /data/data/####/proc_auxv
  • /data/data/####/salt
  • /data/data/####/sealed1.obk
  • /data/data/####/sealed2.obk
  • /data/data/####/sealed3.obk
  • /data/data/####/sealeh.bdc
  • /data/data/####/spUtils.xml
  • /data/data/####/stat1
  • /data/data/####/stat2
  • /data/data/####/stat3
  • /data/data/####/tdid.xml
  • /data/data/####/working
Miscellaneous:
Executes the following shell scripts:
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/135KR9C1PF3MI3DT6G781484XCLZA82.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/BDN29RIBB1DS8TF3OU92ZUUEVARX864.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.zip.cur.prof
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/135KR9C1PF3MI3DT6G781484XCLZA82.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/135KR9C1PF3MI3DT6G781484XCLZA82.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/BDN29RIBB1DS8TF3OU92ZUUEVARX864.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/BDN29RIBB1DS8TF3OU92ZUUEVARX864.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.vdex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.odex
  • chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.vdex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/02GZ6K7G8QY1HA0453MRKN73OFCYLF9.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/135KR9C1PF3MI3DT6G781484XCLZA82.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/1BL0RP011RNQ2F1TMOZOTKSSL0TBYGM.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/3XZQX3MB7X184XRRO6TU3IMYZQR9OYS.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/5M2A8GT4MXBDVDDBFECEDBHFQRY2U7M.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/7GWWEQJEKFTZH7R9XKYKFPF985KCOXC.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/BDN29RIBB1DS8TF3OU92ZUUEVARX864.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/DNH8FLG1LBR2U7PH68RG5SGO1S1BQ0Q.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/OCCU67EGRDJ1JF9XS6075ZXCTC4C5WI.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/PR9C3DW15VZAQR556CFG5W08HKDZIOY.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/UFVN5PA97AGY4Q2WWZ9VUKMOBSVZJSV.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/VO0O6U3EKVP3PVJLX0MS3H7D8DCCWT8.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/ZDBELFEBF5PCW5JFO29UBQ2ERUB5SEW.zip
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/0G0T8QV5BJTCYE2ON4GQAFL5KN2HNV2B.dex --oat-file=/data/user/0/<Package>/cache/<Package>/0G0T8QV5BJTCYE2ON4GQAFL5KN2HNV2B.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex --oat-file=/data/user/0/<Package>/cache/<Package>/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex --oat-file=/data/user/0/<Package>/cache/<Package>/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MX981LN47CDWKE5F61FYNTXF8MPHY5AV.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MX981LN47CDWKE5F61FYNTXF8MPHY5AV.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex --compiler-filter=verify-none --instruction-set=x86
  • getprop ro.dalvik.vm.isa.arm
  • getprop ro.dalvik.vm.isa.arm64
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/0G0T8QV5BJTCYE2ON4GQAFL5KN2HNV2B.dex --oat-file=/data/user/0/<Package>/cache/<Package>/0G0T8QV5BJTCYE2ON4GQAFL5KN2HNV2B.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/79ZYW7JYVT4L54LAI5GZ59LV74UZM11L.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7N3GF5U8IMW7XXLN2RVPX2CCJ2DGU2HE.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex --oat-file=/data/user/0/<Package>/cache/<Package>/8WW1CAR5NJXKEAMWFK0UYF9DWRUHFJ6R.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AP18DHFWR0HO0Y5JU9F2VTDRKA59MPE7.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/EXTOPDROBO5G0I5NYXF63TT3CELHA9YZ.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/F9F60RFE7T8T505IAL0JT99338MJEP5L.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GWCPGAN5ZJH8E6M47GKEMFX1SVM17NQR.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LCOBCKIREFGRJH0M54YD2G4YJHWO54TY.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LIWPPMALEECPS0DWDNZBZFOOCS872ZYC.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex --oat-file=/data/user/0/<Package>/cache/<Package>/M4RIL4W55WRWUROH8EICQ25OEU8J7QFF.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MS7UDWKP50FW63WPSAE4YMTK2AKBJUVB.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MX981LN47CDWKE5F61FYNTXF8MPHY5AV.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MX981LN47CDWKE5F61FYNTXF8MPHY5AV.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QP3GKPSUODM2HTBUSSXPLFCIHGFP3WRH.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XQ49DQYTAQOHSGDSPFZ7RF8CK48ZEFEK.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/YGQPV2Q1EGZ48VK9DGRAGW06IB5Y9GSS.dex --compiler-filter=verify-none --instruction-set=x86
Loads the following dynamic libraries:
  • libcovault-appsec
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Intercepts notifications.
Requests the system alert window permission.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке