Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Android.SmsSend.20200

Добавлен в вирусную базу Dr.Web: 2017-06-26

Описание добавлено:

Technical information

Malicious functions:
Sends SMS messages:
  • 10658000: BYTJY
  • 106584211: 3b6e36b3c0a86a606261639130775431
  • 1065842232: BN2[bbbbDlDznvAFKzGC0DDDkD_zbbxcvT>CUvb+DGEucpCFF?GYIqM)8Qbu7bKMgDzGvlvbFb?vb&0bbbP5l-Ogp@g39D'~9I/v&3W2k?Wl9t=
  • 1065842232: BN2[bblGxbzcKD[:{HvL0v<HqcUlbbFzz\HpTxx(GxHPFDQxSeViYnx.LQbu7bKMgDzGvlvFFb?vb&0bbbP6iFvh-Gfsi+QH/N2uVseVanKk3f=
  • 10658423: mvwlan,a9342bb62e6188d4a192526fd302780f,Z5TY
  • 10658423: mvwlan,f337b75b64ec2f57d1f1f01c271ac39f,ovxV
  • 10691009: @8XMLD#MjUwMDI2Njk5MTg3NzQz
Network activity:
Connecting to:
  • 1####.####.147
  • 1####.####.147:8080
  • 1####.####.91
  • 1####.####.91:8080
  • a####.####.com
  • oa5cv####.####.com
  • p####.####.com
  • p####.####.com:8080
  • u####.####.com
HTTP GET requests:
  • 1####.####.147/xmld/HttpService!service?paramMap=####
  • 1####.####.91/mm/HttpService!service?paramMap=####
  • 1####.####.91:8080/mm/HttpService!service?paramMap=####
  • oa5cv####.####.com/ic_huobao.png
  • p####.####.com/sdk/dp_1.5.0.jar
  • p####.####.com:8080/sdk/spaycoredex_so_1990.jar
  • u####.####.com/apka/q300132.apk
HTTP POST requests:
  • 1####.####.147:8080/xmld/HttpService
  • a####.####.com/app_logs
Modified file system:
Creates the following files:
  • <Package Folder>/app_payload_odex/<Package>.jar
  • <Package Folder>/app_process_lock/1122153100826.87
  • <Package Folder>/app_process_lock/1122153100826.87 (deleted)
  • <Package Folder>/app_process_lock/1122153100924.86
  • <Package Folder>/app_process_lock/1122153100924.86 (deleted)
  • <Package Folder>/app_process_lock/1122153101089.59
  • <Package Folder>/app_process_lock/1122153101089.59 (deleted)
  • <Package Folder>/app_process_lock/1122153101094.58
  • <Package Folder>/app_process_lock/1122153101094.58 (deleted)
  • <Package Folder>/app_process_lock/1122153101162.38
  • <Package Folder>/app_process_lock/1122153101162.38 (deleted)
  • <Package Folder>/app_process_lock/1122153101211.06
  • <Package Folder>/app_process_lock/1122153101211.06 (deleted)
  • <Package Folder>/app_process_lock/1122153101267.07
  • <Package Folder>/app_process_lock/1122153101267.07 (deleted)
  • <Package Folder>/app_process_lock/1122153101544.93
  • <Package Folder>/app_process_lock/1122153101544.93 (deleted)
  • <Package Folder>/app_process_lock/1122153101545.84
  • <Package Folder>/app_process_lock/1122153101545.84 (deleted)
  • <Package Folder>/app_process_lock/1122153101700.9
  • <Package Folder>/app_process_lock/1122153101700.9 (deleted)
  • <Package Folder>/app_process_lock/1122153101720.68
  • <Package Folder>/app_process_lock/1122153101720.68 (deleted)
  • <Package Folder>/app_process_lock/1122153101853.57
  • <Package Folder>/app_process_lock/1122153101853.57 (deleted)
  • <Package Folder>/app_process_lock/161.918512514603
  • <Package Folder>/app_process_lock/161.918512514603 (deleted)
  • <Package Folder>/app_process_lock/2325855151322.17
  • <Package Folder>/app_process_lock/2325855151322.17 (deleted)
  • <Package Folder>/app_process_lock/2325855152863.92
  • <Package Folder>/app_process_lock/2325855152863.92 (deleted)
  • <Package Folder>/app_process_lock/2325855154056.06
  • <Package Folder>/app_process_lock/2325855154056.06 (deleted)
  • <Package Folder>/app_process_lock/2325855154419.96
  • <Package Folder>/app_process_lock/2325855154419.96 (deleted)
  • <Package Folder>/app_process_lock/2325855154992.42
  • <Package Folder>/app_process_lock/2325855154992.42 (deleted)
  • <Package Folder>/app_process_lock/2325855155703.72
  • <Package Folder>/app_process_lock/2325855155703.72 (deleted)
  • <Package Folder>/app_process_lock/2325855156470.78
  • <Package Folder>/app_process_lock/2325855156470.78 (deleted)
  • <Package Folder>/app_process_lock/2325855157190.72
  • <Package Folder>/app_process_lock/2325855157190.72 (deleted)
  • <Package Folder>/app_process_lock/2325855157283.05
  • <Package Folder>/app_process_lock/2325855157283.05 (deleted)
  • <Package Folder>/app_process_lock/2325855157761.92
  • <Package Folder>/app_process_lock/2325855157761.92 (deleted)
  • <Package Folder>/app_process_lock/2325855160896.83
  • <Package Folder>/app_process_lock/2325855160896.83 (deleted)
  • <Package Folder>/app_process_lock/2325855161364.02
  • <Package Folder>/app_process_lock/2325855161364.02 (deleted)
  • <Package Folder>/app_process_lock/261210723137.221
  • <Package Folder>/app_process_lock/261210723137.221 (deleted)
  • <Package Folder>/app_process_lock/261210723310.37
  • <Package Folder>/app_process_lock/261210723310.37 (deleted)
  • <Package Folder>/app_process_lock/261210723444.256
  • <Package Folder>/app_process_lock/261210723444.256 (deleted)
  • <Package Folder>/app_process_lock/261210723485.125
  • <Package Folder>/app_process_lock/261210723485.125 (deleted)
  • <Package Folder>/app_process_lock/261210723549.417
  • <Package Folder>/app_process_lock/261210723549.417 (deleted)
  • <Package Folder>/app_process_lock/261210723629.301
  • <Package Folder>/app_process_lock/261210723629.301 (deleted)
  • <Package Folder>/app_process_lock/261210723715.447
  • <Package Folder>/app_process_lock/261210723715.447 (deleted)
  • <Package Folder>/app_process_lock/261210723796.302
  • <Package Folder>/app_process_lock/261210723796.302 (deleted)
  • <Package Folder>/app_process_lock/261210723806.671
  • <Package Folder>/app_process_lock/261210723806.671 (deleted)
  • <Package Folder>/app_process_lock/261210723860.452
  • <Package Folder>/app_process_lock/261210723860.452 (deleted)
  • <Package Folder>/app_process_lock/261210724212.525
  • <Package Folder>/app_process_lock/261210724212.525 (deleted)
  • <Package Folder>/app_process_lock/261210724264.995
  • <Package Folder>/app_process_lock/261210724264.995 (deleted)
  • <Package Folder>/app_process_lock/2965465343700.74
  • <Package Folder>/app_process_lock/2965465343700.74 (deleted)
  • <Package Folder>/app_process_lock/2965465343959.68
  • <Package Folder>/app_process_lock/2965465343959.68 (deleted)
  • <Package Folder>/app_process_lock/2965465344395.02
  • <Package Folder>/app_process_lock/2965465344395.02 (deleted)
  • <Package Folder>/app_process_lock/2965465344408.19
  • <Package Folder>/app_process_lock/2965465344408.19 (deleted)
  • <Package Folder>/app_process_lock/2965465344587.39
  • <Package Folder>/app_process_lock/2965465344587.39 (deleted)
  • <Package Folder>/app_process_lock/2965465344716.03
  • <Package Folder>/app_process_lock/2965465344716.03 (deleted)
  • <Package Folder>/app_process_lock/2965465344864.04
  • <Package Folder>/app_process_lock/2965465344864.04 (deleted)
  • <Package Folder>/app_process_lock/2965465345598.32
  • <Package Folder>/app_process_lock/2965465345598.32 (deleted)
  • <Package Folder>/app_process_lock/2965465345600.73
  • <Package Folder>/app_process_lock/2965465345600.73 (deleted)
  • <Package Folder>/app_process_lock/2965465346010.5
  • <Package Folder>/app_process_lock/2965465346010.5 (deleted)
  • <Package Folder>/app_process_lock/2965465346062.77
  • <Package Folder>/app_process_lock/2965465346062.77 (deleted)
  • <Package Folder>/app_process_lock/2965465346413.95
  • <Package Folder>/app_process_lock/2965465346413.95 (deleted)
  • <Package Folder>/app_process_lock/524125.03940853
  • <Package Folder>/app_process_lock/524125.03940853 (deleted)
  • <Package Folder>/app_process_lock/524125.339863105
  • <Package Folder>/app_process_lock/524125.339863105 (deleted)
  • <Package Folder>/app_process_lock/668266.292786374
  • <Package Folder>/app_process_lock/668266.292786374 (deleted)
  • <Package Folder>/app_process_lock/690290252103.709
  • <Package Folder>/app_process_lock/690290252103.709 (deleted)
  • <Package Folder>/app_process_lock/690290252561.284
  • <Package Folder>/app_process_lock/690290252561.284 (deleted)
  • <Package Folder>/app_process_lock/690290252915.098
  • <Package Folder>/app_process_lock/690290252915.098 (deleted)
  • <Package Folder>/app_process_lock/690290253023.101
  • <Package Folder>/app_process_lock/690290253023.101 (deleted)
  • <Package Folder>/app_process_lock/690290253193.001
  • <Package Folder>/app_process_lock/690290253193.001 (deleted)
  • <Package Folder>/app_process_lock/690290253404.108
  • <Package Folder>/app_process_lock/690290253404.108 (deleted)
  • <Package Folder>/app_process_lock/690290253631.763
  • <Package Folder>/app_process_lock/690290253631.763 (deleted)
  • <Package Folder>/app_process_lock/690290253845.434
  • <Package Folder>/app_process_lock/690290253845.434 (deleted)
  • <Package Folder>/app_process_lock/690290253872.837
  • <Package Folder>/app_process_lock/690290253872.837 (deleted)
  • <Package Folder>/app_process_lock/690290254014.961
  • <Package Folder>/app_process_lock/690290254014.961 (deleted)
  • <Package Folder>/app_process_lock/690290254945.369
  • <Package Folder>/app_process_lock/690290254945.369 (deleted)
  • <Package Folder>/app_process_lock/690290255084.029
  • <Package Folder>/app_process_lock/690290255084.029 (deleted)
  • <Package Folder>/app_process_lock/852048.333815873
  • <Package Folder>/app_process_lock/852048.333815873 (deleted)
  • <Package Folder>/databases/cc.db
  • <Package Folder>/databases/cc.db-journal
  • <Package Folder>/databases/ua.db
  • <Package Folder>/databases/ua.db-journal
  • <Package Folder>/databases/webview.db-journal
  • <Package Folder>/databases/xUtils_http_cache.db
  • <Package Folder>/databases/xUtils_http_cache.db-journal
  • <Package Folder>/databases/xUtils_http_cookie.db
  • <Package Folder>/databases/xUtils_http_cookie.db-journal
  • <Package Folder>/databases/xUtils_http_cookie.db-journal (deleted)
  • <Package Folder>/files/####/exchangeIdentity.json
  • <Package Folder>/files/.imprint
  • <Package Folder>/files/exid.dat
  • <Package Folder>/files/umeng_it.cache
  • <Package Folder>/shared_prefs/pay.xml
  • <Package Folder>/shared_prefs/spay.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml
  • <Package Folder>/shared_prefs/umeng_general_config.xml.bak
  • <SD-Card>/Android/####/052ba33096843816e27148509d051eea
  • <SD-Card>/Android/####/06b42a48b21180dd8e4801ff7584b76b
  • <SD-Card>/Android/####/292044569eeb4d7b92f05539d6eade8c
  • <SD-Card>/Android/####/29a530de6d3b8861f3e490e3f39b7086
  • <SD-Card>/Android/####/32aac9c3e0346a1cccdcebba20ddfb97
  • <SD-Card>/Android/####/49cf1c9a8a0e60553334622cb32b19cf
  • <SD-Card>/Android/####/6009c7fe27ff18dbb6818bc52059db2f
  • <SD-Card>/Android/####/96c812fbc07de91a3915e00f8da40329
  • <SD-Card>/Android/####/9f77a473fb13475b601fa3887dc0ea85
  • <SD-Card>/Android/####/a24707c6393c405b9f91c132f79b9378
  • <SD-Card>/Android/####/b031cfd49807b1503a541a4f6dc7414d
  • <SD-Card>/Android/####/ba91b1abe79d793f7cb219d672d031c0
  • <SD-Card>/Android/####/bcf10226b0dc40d13b2a71a377a884ca
  • <SD-Card>/Android/####/c731664123d180db9414931381cb353c
  • <SD-Card>/Android/####/cf90ac6fc237e7772a0017196fa6d7ae
  • <SD-Card>/Android/####/e00b45d3bc80cd67a19342e8e54beba9
  • <SD-Card>/Android/####/e1be95d91ce8e6896771ca930bd57eef
  • <SD-Card>/Android/####/e2aab9e7b0bad79927d1a498e8781e0f
  • <SD-Card>/Android/####/e524dcf609303e9b289a270d3f4846ab
  • <SD-Card>/Android/####/e57531a1aa87da470611e5b83c89660e
  • <SD-Card>/Android/####/ea3cee77ef9f716a89431c5aaba681d8
  • <SD-Card>/Android/####/f22486cca8ed667804efd38a68001378
  • <SD-Card>/Android/####/f41a28647405ea0f78a0418178cf6c3f
  • <SD-Card>/Android/####/f7dd5cc31e4cd271dd703855e864fbae
  • <SD-Card>/Android/com.exga.sielzy.apk.tmp
  • <SD-Card>/Android/com.exga.sielzy.png.tmp
  • <SD-Card>/Android/com.mmzb.wrw.yol.png.tmp
  • <SD-Card>/Android/com.molove.mobile.png.tmp
  • <SD-Card>/dp.jar.tmp
  • <SD-Card>/updateApkDemo/FrameCore.jar
Miscellaneous:
Executes next shell scripts:
  • <dexopt>
  • <su-internal:request>
  • <su-internal:result>
  • app_process /system/bin com.android.commands.pm.Pm install -r /system/app/com.exga.sielzy.apk
  • chmod 644 /system/app/com.exga.sielzy.apk
  • cp /storage/emulated/0/Android/com.exga.sielzy.apk /system/app/
  • sh
  • su
Uses elevated priveleges.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке