Защити созданное

Другие наши ресурсы

  • free.drweb.kz — бесплатные утилиты, плагины, информеры
  • av-desk.com — интернет-сервис для поставщиков услуг Dr.Web AV-Desk
  • curenet.drweb.kz — сетевая лечащая утилита Dr.Web CureNet!
Закрыть

Библиотека
Моя библиотека

Чтобы добавить ресурс в библиотеку, войдите в аккаунт.

+ Добавить в библиотеку

Ресурсов: -

Последний: -

Моя библиотека

Поддержка
Круглосуточная поддержка | Правила обращения

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Глобальная поддержка:
+7 (495) 789-45-86

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Android.BankBot.TgToxic.63

Добавлен в вирусную базу Dr.Web: 2024-01-24

Описание добавлено:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.BankBot.TgToxic.1
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) connect####.gst####.com:80
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) rr18---####.g####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) sqs.ap-nort####.amazo####.com:443
  • TCP(TLS/1.0) and####.cli####.go####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.2) 74.1####.131.103:443
  • TCP(TLS/1.2) connect####.gst####.com:443
  • TCP(TLS/1.2) p####.google####.com:443
  • UDP www.gst####.com:443
  • UDP p####.google####.com:443
DNS requests:
  • and####.a####.go####.com
  • and####.cli####.go####.com
  • and####.google####.com
  • connect####.gst####.com
  • digital####.google####.com
  • f####.gst####.com
  • m####.go####.com
  • p####.google####.com
  • pla####.google####.com
  • pla####.googleu####.com
  • rr18---####.g####.com
  • rr2---s####.g####.com
  • rr9---s####.g####.com
  • sqs.ap-nort####.amazo####.com
  • www.gst####.com
File system changes:
Creates the following files:
  • /data/data/####/.com_zmherd_odiuvyra.meta
  • /data/data/####/19
  • /data/data/####/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex
  • /data/data/####/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex.flock (deleted)
  • /data/data/####/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex
  • /data/data/####/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex.flock (deleted)
  • /data/data/####/1QMM8G546XB1BLH7V2KQTRTNEV2QI7U.dex
  • /data/data/####/1QMM8G546XB1BLH7V2KQTRTNEV2QI7U.dex.flock (deleted)
  • /data/data/####/1QMM8G546XB1BLH7V2KQTRTNEV2QI7U.zip
  • /data/data/####/2024-01-24AM083308.str
  • /data/data/####/29
  • /data/data/####/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex
  • /data/data/####/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex.flock (deleted)
  • /data/data/####/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex
  • /data/data/####/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex.flock (deleted)
  • /data/data/####/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex
  • /data/data/####/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex.flock (deleted)
  • /data/data/####/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex
  • /data/data/####/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex.flock (deleted)
  • /data/data/####/6W6XBYU56SFC4VGD54364CK6IV5E9GKK.dex
  • /data/data/####/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex
  • /data/data/####/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex.flock (deleted)
  • /data/data/####/81JS8H98L5R07F0RSYYIAYF3BZRML6H3.dex
  • /data/data/####/991a41b1afbfe7db515db80024e5c3acts99nb.lvie
  • /data/data/####/991a41b1afbfe7db515db80024e5c3acts99nb.lvie (deleted)
  • /data/data/####/9KQZF4VXVGXPO0I5JV0C86FXGNEKQ3QS.dex
  • /data/data/####/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex
  • /data/data/####/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex.flock (deleted)
  • /data/data/####/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex
  • /data/data/####/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex.flock (deleted)
  • /data/data/####/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex
  • /data/data/####/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex.flock (deleted)
  • /data/data/####/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex
  • /data/data/####/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex.flock (deleted)
  • /data/data/####/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex
  • /data/data/####/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex.flock (deleted)
  • /data/data/####/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex
  • /data/data/####/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex.flock (deleted)
  • /data/data/####/DMYUWSX4EPFPNT9VFI0QLFT36ZMMMNI.dex
  • /data/data/####/DMYUWSX4EPFPNT9VFI0QLFT36ZMMMNI.dex.flock (deleted)
  • /data/data/####/DMYUWSX4EPFPNT9VFI0QLFT36ZMMMNI.zip
  • /data/data/####/DQYAWS942TZH7PDVVU4YHFLNIBI2YZI.dex
  • /data/data/####/DQYAWS942TZH7PDVVU4YHFLNIBI2YZI.dex.flock (deleted)
  • /data/data/####/DQYAWS942TZH7PDVVU4YHFLNIBI2YZI.zip
  • /data/data/####/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex
  • /data/data/####/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex.flock (deleted)
  • /data/data/####/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex
  • /data/data/####/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex.flock (deleted)
  • /data/data/####/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex
  • /data/data/####/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex.flock (deleted)
  • /data/data/####/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex
  • /data/data/####/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex.flock (deleted)
  • /data/data/####/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex
  • /data/data/####/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex.flock (deleted)
  • /data/data/####/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex
  • /data/data/####/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex.flock (deleted)
  • /data/data/####/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex
  • /data/data/####/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex.flock (deleted)
  • /data/data/####/H5XZZ8JH0UWESOUE971G6GEDULL9ET7.dex
  • /data/data/####/H5XZZ8JH0UWESOUE971G6GEDULL9ET7.dex.flock (deleted)
  • /data/data/####/H5XZZ8JH0UWESOUE971G6GEDULL9ET7.zip
  • /data/data/####/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex
  • /data/data/####/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex.flock (deleted)
  • /data/data/####/IECPkgStoreInfo
  • /data/data/####/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex
  • /data/data/####/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex.flock (deleted)
  • /data/data/####/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex
  • /data/data/####/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex.flock (deleted)
  • /data/data/####/M7BRT5A976GMCEUGWVPNA8UONSBR70N.dex
  • /data/data/####/M7BRT5A976GMCEUGWVPNA8UONSBR70N.dex.flock (deleted)
  • /data/data/####/M7BRT5A976GMCEUGWVPNA8UONSBR70N.zip
  • /data/data/####/MNBBDPY9ZIWUSYQGWJLFES24VGFVVON.dex
  • /data/data/####/MNBBDPY9ZIWUSYQGWJLFES24VGFVVON.dex.flock (deleted)
  • /data/data/####/MNBBDPY9ZIWUSYQGWJLFES24VGFVVON.zip
  • /data/data/####/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex
  • /data/data/####/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex.flock (deleted)
  • /data/data/####/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex
  • /data/data/####/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex.flock (deleted)
  • /data/data/####/OE1CYT6AO8VZ4UENHKXYL1DEDYO7L3Y.dex
  • /data/data/####/OE1CYT6AO8VZ4UENHKXYL1DEDYO7L3Y.dex.flock (deleted)
  • /data/data/####/OE1CYT6AO8VZ4UENHKXYL1DEDYO7L3Y.zip
  • /data/data/####/OL5DZZKJ5OE8Y88UELB9CM8IP6X11QD.dex
  • /data/data/####/OL5DZZKJ5OE8Y88UELB9CM8IP6X11QD.dex.flock (deleted)
  • /data/data/####/OL5DZZKJ5OE8Y88UELB9CM8IP6X11QD.zip
  • /data/data/####/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex
  • /data/data/####/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex.flock (deleted)
  • /data/data/####/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex
  • /data/data/####/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex.flock (deleted)
  • /data/data/####/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex
  • /data/data/####/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex.flock (deleted)
  • /data/data/####/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex
  • /data/data/####/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex.flock (deleted)
  • /data/data/####/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex
  • /data/data/####/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex.flock (deleted)
  • /data/data/####/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex
  • /data/data/####/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex.flock (deleted)
  • /data/data/####/SAWNEKBG0YEHPI8O57EB4VNJO3WUXB1.dex
  • /data/data/####/SAWNEKBG0YEHPI8O57EB4VNJO3WUXB1.dex.flock (deleted)
  • /data/data/####/SAWNEKBG0YEHPI8O57EB4VNJO3WUXB1.zip
  • /data/data/####/SCK26JEKBTNPBJTX0UCVDN9K50KC54U.dex
  • /data/data/####/SCK26JEKBTNPBJTX0UCVDN9K50KC54U.dex.flock (deleted)
  • /data/data/####/SCK26JEKBTNPBJTX0UCVDN9K50KC54U.zip
  • /data/data/####/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex
  • /data/data/####/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex.flock (deleted)
  • /data/data/####/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex
  • /data/data/####/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex.flock (deleted)
  • /data/data/####/T314FLG1177YAJ9DMKV0PS0SXK9JMOY.dex
  • /data/data/####/T314FLG1177YAJ9DMKV0PS0SXK9JMOY.dex.flock (deleted)
  • /data/data/####/T314FLG1177YAJ9DMKV0PS0SXK9JMOY.zip
  • /data/data/####/TZ1OF54LDJNMQ3PD68RSTS88L8XNACE.dex
  • /data/data/####/TZ1OF54LDJNMQ3PD68RSTS88L8XNACE.dex.flock (deleted)
  • /data/data/####/TZ1OF54LDJNMQ3PD68RSTS88L8XNACE.zip
  • /data/data/####/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex
  • /data/data/####/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex.flock (deleted)
  • /data/data/####/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex
  • /data/data/####/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex.flock (deleted)
  • /data/data/####/X2IUWCL4Q1VD3DPVF6WYPZ1JUNAQARY.dex
  • /data/data/####/X2IUWCL4Q1VD3DPVF6WYPZ1JUNAQARY.dex.flock (deleted)
  • /data/data/####/X2IUWCL4Q1VD3DPVF6WYPZ1JUNAQARY.zip
  • /data/data/####/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex
  • /data/data/####/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex.flock (deleted)
  • /data/data/####/com.android.launcher3.prefs.xml
  • /data/data/####/empty_classes.dex
  • /data/data/####/empty_classes.zip
  • /data/data/####/proc_auxv
  • /data/data/####/sealeh.bdc
  • /data/data/####/spUtils.xml
  • /data/data/####/working
Miscellaneous:
Executes the following shell scripts:
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/1QMM8G546XB1BLH7V2KQTRTNEV2QI7U.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/DMYUWSX4EPFPNT9VFI0QLFT36ZMMMNI.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/H5XZZ8JH0UWESOUE971G6GEDULL9ET7.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/M7BRT5A976GMCEUGWVPNA8UONSBR70N.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/MNBBDPY9ZIWUSYQGWJLFES24VGFVVON.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/OE1CYT6AO8VZ4UENHKXYL1DEDYO7L3Y.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/OL5DZZKJ5OE8Y88UELB9CM8IP6X11QD.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/SCK26JEKBTNPBJTX0UCVDN9K50KC54U.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/T314FLG1177YAJ9DMKV0PS0SXK9JMOY.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/TZ1OF54LDJNMQ3PD68RSTS88L8XNACE.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/X2IUWCL4Q1VD3DPVF6WYPZ1JUNAQARY.zip
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/6W6XBYU56SFC4VGD54364CK6IV5E9GKK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/6W6XBYU56SFC4VGD54364CK6IV5E9GKK.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex --oat-file=/data/user/0/<Package>/cache/<Package>/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/81JS8H98L5R07F0RSYYIAYF3BZRML6H3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/81JS8H98L5R07F0RSYYIAYF3BZRML6H3.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9KQZF4VXVGXPO0I5JV0C86FXGNEKQ3QS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9KQZF4VXVGXPO0I5JV0C86FXGNEKQ3QS.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex --oat-file=/data/user/0/<Package>/cache/<Package>/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex --oat-file=/data/user/0/<Package>/cache/<Package>/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex --oat-file=/data/user/0/<Package>/cache/<Package>/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex --oat-file=/data/user/0/<Package>/cache/<Package>/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex --compiler-filter=verify-none --instruction-set=x86
  • getprop ro.dalvik.vm.isa.arm
  • getprop ro.dalvik.vm.isa.arm64
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1EC95M2TUE0D8SL0P7FZNB8S8047Q7U8.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1MOPLAI52UG5OG585BFRBB484W0FQBM4.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2HVWOL8QWHEYLD3A8SPP5R4UX4RXVWF9.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2LJW8PS285AYP9VM00HD5F4QHCRLBG31.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5JE1GJZ8SZIJLEVSZHLZD9O3X17EUHYQ.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5LPQTZOM88A1NZNXGLT7VSIU5K7MW8JS.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/6W6XBYU56SFC4VGD54364CK6IV5E9GKK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/6W6XBYU56SFC4VGD54364CK6IV5E9GKK.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex --oat-file=/data/user/0/<Package>/cache/<Package>/71KBM5922DC1NG5QXRJ1BBMPFFHG074O.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/81JS8H98L5R07F0RSYYIAYF3BZRML6H3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/81JS8H98L5R07F0RSYYIAYF3BZRML6H3.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9KQZF4VXVGXPO0I5JV0C86FXGNEKQ3QS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9KQZF4VXVGXPO0I5JV0C86FXGNEKQ3QS.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AAM7US1Z1LBQ08CA5IQ4857VEDKRDDOH.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B3R4ZHQWUY0FXTDJ2NJD1IWSZALCIMHA.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BEILA6KD0HMTTFIK7MWZOMYKPJMARAB4.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BMU1QU058X2LP32CNQW7CMU0LFYIRE30.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BPNMGZF2NPST50D6I147TPLRNC2VU5LH.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BYGH9Y17L6J7IMKVD92MY45NULCUKP0U.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/E8VAP049LGJS2FSTSAQGIULO6UWV72FN.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FJZOVLECUYSZDXH7EF7L1IWW3MXWU296.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GEHWNEINFE1AGTAZAG4AK0NMCO2P9G1H.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GQ1KBME3VATA4H2RQK8IWWZQO8QXDSLL.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GY5WRIMZR2HAKPMV28WYK8NYWC2DP0PT.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GYKNHSSFG292IP237Y1OMMUSC5FKRU66.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex --oat-file=/data/user/0/<Package>/cache/<Package>/GZNYBRHALINYQ0N9CVDWLZNTM8R3SZ49.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/HLH6XV06882HRVJP4T5ZFSIQ18V24SRC.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex --oat-file=/data/user/0/<Package>/cache/<Package>/IEM32KPJ1LR6O04Y1YE8857NM5WN9145.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex --oat-file=/data/user/0/<Package>/cache/<Package>/IZ1MAZ3AJ7T2LHQDMCW40OT5PXP0J0BH.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MUUNYODJ1LJ6K48MDQ2G857RAH87LHW1.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex --oat-file=/data/user/0/<Package>/cache/<Package>/NL8BQ9DEE181BCX25JBPBJM1J3H4GBSG.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OSK94AZ9FBLCQEMOJ00E2FTHKN61RZ6Z.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P0GB4WMRE387ZTSALWE5YC4E7D8WXWTM.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P8SRKK23MJOZVXS21GYXMW0UN944H0LI.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex --oat-file=/data/user/0/<Package>/cache/<Package>/PFQHCFFWGB2JXIJG7PTBDLORDTNAEDAE.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QE2RQ4LJDLVU4C46TEYSW5VVI9ON1P8L.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex --oat-file=/data/user/0/<Package>/cache/<Package>/S7VIZF5I1UZQQGN58NDSDZN1AKBB4FKX.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SF7YFJLUPAFIM4NXORXKLZJHQGN343SD.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SNJEF71MXQVA2SNP4VXC9ZFXMCJB47K9.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/UTXOL5F07KPOSIXR6PFU39530E9XY9EN.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/W2TGB66B3ADAO5E7A08MKWNUGK2154DL.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Z5V6CN32N5KD14HEATSVTPLVROEZMLTD.dex --compiler-filter=verify-none --instruction-set=x86
Loads the following dynamic libraries:
  • libcovault-appsec
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about installed apps.
Intercepts notifications.
Requests the system alert window permission.

Рекомендации по лечению


Android

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке