Technical information
- Android.Backdoor.613.origin
- Android.Xiny.1513
- Android.Xiny.240.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.api.qiazhiw####.cn:10002
- TCP(HTTP/1.1) sdk.api.qiazhiw####.cn:10201
- TCP(HTTP/1.1) 1####.159.103.205:8090
- TCP(HTTP/1.1) wn.qiazhiw####.cn.####.net:80
- TCP(HTTP/1.1) www.be####.com:8080
- TCP(HTTP/1.1) 2####.73.211.68:5292
- TCP(HTTP/1.1) q####.a####.com:80
- TCP(HTTP/1.1) 1####.55.93.104:9004
- TCP(HTTP/1.1) pa.yunj####.cn:8002
- TCP(HTTP/1.1) ji####.jieme####.com:8152
- TCP(HTTP/1.1) xz####.zhan####.com:10011
- TCP(HTTP/1.1) b.yunj####.cn:5284
- TCP(HTTP/1.1) 1####.159.131.193:10201
- TCP(HTTP/1.1) p1.i####.cc:80
- TCP(HTTP/1.1) 1####.129.132.111:8001
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) 1####.159.152.136:8090
- TCP(HTTP/1.1) v####.api.eeric####.com:80
- TCP(HTTP/1.1) sdk.api.qiazhiw####.cn:10001
- TCP(HTTP/1.1) 1####.159.131.193:10002
- TCP(HTTP/1.1) i####.api.qiazhiw####.cn:10001
- TCP(HTTP/1.1) a####.peiz####.cn.####.com:5285
- TCP(HTTP/1.1) cnmon####.com:8080
- TCP(HTTP/1.1) i####.api.qiazhiw####.cn:10002
- TCP 1####.196.192.72:9920
- a####.peiz####.cn
- a####.u####.com
- b.yunj####.cn
- cnmon####.com
- i####.api.qiazhiw####.cn
- ji####.dl####.com
- ji####.jieme####.com
- p1.i####.cc
- pa.yunj####.cn
- re####.api.qiazhiw####.cn
- sdk.api.qiazhiw####.cn
- v####.api.eeric####.com
- wn.qiazhiw####.cn
- www.be####.com
- x####.bj####.cn
- xz####.zhan####.com
- a####.peiz####.cn.####.com:5285/AppDownLoad/apk/downloadAPK?appId=####
- cnmon####.com:8080/console/client/app/check/data.do?pModel=####&netType=...
- cnmon####.com:8080/console/client/spApi/init/data.do?productNo=####&pMod...
- cnmon####.com:8080/console/upload/control/control.jar
- cnmon####.com:8080/console/upload/sdk/208caa2f-2f31-4777-a79e-ac17251dd4...
- q####.a####.com/jieplginf/wchzfdat25
- wn.qiazhiw####.cn.####.net/update/pay06057081
- a####.u####.com/app_logs
- b.yunj####.cn:5284/android.frontserver/pcsvc
- cnmon####.com:8080/console/client/spApi/reportError/data.do
- i####.api.qiazhiw####.cn:10001/v2/update/check?app_id=####&t=####
- i####.api.qiazhiw####.cn:10002/v2/sdk/init?app_id=####&t=####
- ji####.jieme####.com:8152/ryf_webserver/payment/checkupdate.html
- p1.i####.cc/index.php/MC/HB
- pa.yunj####.cn:8002/pps
- sdk.api.qiazhiw####.cn:10001/v2/update/check?app_id=####&t=####
- sdk.api.qiazhiw####.cn:10002/v2/log/add?app_id=####&t=####
- sdk.api.qiazhiw####.cn:10002/v2/sdk/init?app_id=####&t=####
- sdk.api.qiazhiw####.cn:10201/v2/sdk/report?app_id=####&t=####
- v####.api.eeric####.com/api/payment/mobileInit.html
- www.be####.com:8080/game/paycontrolv2
- xz####.zhan####.com:10011/zxhypay/action/update.do
- /data/data/####/.fb
- /data/data/####/.fb-journal
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/347781996620052
- /data/data/####/347781996620052-journal
- /data/data/####/6056a0e434260e3514af030d9cf24078.jar
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/F85C58A2196623557E8A00D8A4680702
- /data/data/####/JiePay.xml
- /data/data/####/buntutu.dex
- /data/data/####/buntutu_data_s.xml
- /data/data/####/c868f2190c3d2c142468a94de06b03e9.dat (deleted)
- /data/data/####/c868f2190c3d2c142468a94de06b03e9.dex
- /data/data/####/c868f2190c3d2c142468a94de06b03e9.jar
- /data/data/####/cached.pref.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.nwe.fewio.ewb.xml
- /data/data/####/com.nwe.fewio.ewb_preferences.xml
- /data/data/####/com_android_command_buntutu_v.xml
- /data/data/####/config.xml
- /data/data/####/config.xml.bak (deleted)
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/game_n.xml
- /data/data/####/i2q590C0p266c6A9y9c198l7d7p4o3.xml
- /data/data/####/initRoot.xml
- /data/data/####/installTime.xml
- /data/data/####/jiepay_config.xml
- /data/data/####/jiepayplugin.apk
- /data/data/####/jiepayplugin.apkdata
- /data/data/####/jiepayplugin.dex (deleted)
- /data/data/####/kb_idle.ini
- /data/data/####/libjiagu920077311.so
- /data/data/####/mm_nw_app.xml
- /data/data/####/native_1536691337227.so
- /data/data/####/onib_clz.dex
- /data/data/####/onib_clz.jar
- /data/data/####/pay06057081
- /data/data/####/pay06057081.jar
- /data/data/####/shunpay_config
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db
- /data/data/####/webview.db-journal
- /data/data/####/{2BD4537D-12B79B36}.P1
- /data/data/####/{2BD4537D-12B79B36}.P3
- /data/data/####/{6109AB2B-769CFABF}_{2BD4537D-12B79B36}.P2
- /data/media/####/0C3E1782C1F853AF.jar.i
- /data/media/####/0C3E1782C1F853AFwh.jar
- /data/media/####/1B3A2967E5FD862EFD957606C65C8122
- /data/media/####/2887A00B589C85A5FF5607D7EB45E7C8
- /data/media/####/30592A6B8B0C769E3F7FDE6E1A033DF5
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/D99494BB10D048C393648C204AF8AA38
- /data/media/####/buntutu.jar.tmp.i
- /data/media/####/buntutu.jar.tmp.i (deleted)
- /data/media/####/buntutu.jaru
- /data/media/####/cash_2018-09-11_log.txt
- /data/media/####/kb_idle.ini
- /data/media/####/pConifg.ini
- /data/media/####/{BE2355DB-D785E335}.PC1
- /system/bin/cat /proc/cpuinfo
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- cat /sys/block/mmcblk0/device/cid
- chmod 755 <Package Folder>/.jiagu/libjiagu920077311.so
- getprop ro.product.cpu.abi
- libjiagu920077311
- native_1536691337227
- shunpay
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding
- DES
- DES-CBC-PKCS5Padding