Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sd####.cm####.com:80
- TCP(HTTP/1.1) 1####.199.251.172:80
- TCP(HTTP/1.1) g####.g####.net:8080
- TCP(HTTP/1.1) ga####.lotu####.com:80
- TCP(HTTP/1.1) sw####.j####.com.cn:8080
- TCP(HTTP/1.1) drm.cm####.com:80
- TCP(HTTP/1.1) 2####.111.8.140:8080
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(text/html ) 1####.230.22.208:8080
- TCP(text/html ) sw####.j####.com.cn:8080
- adser####.go####.com
- and####.cli####.go####.com
- drm.cm####.com
- g####.g####.net
- ga####.lotu####.com
- on####.lotu####.com
- sd####.cm####.com
- ssl.gst####.com
- sw####.j####.com.cn
- wap.cm####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- 1####.230.22.208:8080/WebTest/gameNofity HTTP/1.1 Host: switch.jssg.com....
- drm.cm####.com/egsb/game/getclientProvince?tel=####&iccid=####&imsi=####
- drm.cm####.com/egsb/startup/queryConfiguration?channelId=####&contentId=...
- drm.cm####.com/egsb/verification/checkSDKModuleUpdate?sdkVersion=####&co...
- sw####.j####.com.cn:8080/WebTest/Query?gid=####&vid=####&ch=####&iccid=#...
- drm.cm####.com/egsb/dataPlan/privateSwith
- drm.cm####.com/egsb/discount/getPreQueryResult
- drm.cm####.com/egsb/game/getPaymentCapability
- drm.cm####.com/egsb/gshare/switches
- drm.cm####.com/egsb/message/queryPushMessages
- drm.cm####.com/egsb/otherPay/querySMSInterceptorConf
- drm.cm####.com/egsb/thirdPay/queryThirdPayInfo
- g####.g####.net:8080/migusdk/tl/tcttl
- g####.g####.net:8080/migusdk/verification/checkSdkUpdate
- ga####.lotu####.com/?st=####&sv=####&tm=####&sid=Jzc####&apn=####&ct=###...
- sd####.cm####.com/behaviorLogging/eventLogging/accept?
- sw####.j####.com.cn:8080/WebTest/DataSubmit
- /data/data/####/2289.dex
- /data/data/####/2289.dex (deleted)
- /data/data/####/2405.dex
- /data/data/####/2405.dex (deleted)
- /data/data/####/2583.dex
- /data/data/####/2583.dex (deleted)
- /data/data/####/2719.dex
- /data/data/####/ED.ini
- /data/data/####/MiguPay.Sdk30.Lib_12003047_430e4ccea95331954c0e...02.cod
- /data/data/####/MiguPay.Sdk30.Lib_12003047_430e4ccea95331954c0e...02.dat
- /data/data/####/action.lst
- /data/data/####/libmgRun_05.22.09_00.so
- /data/data/####/libmiguED.so
- /data/data/####/lotuseed.apps
- /data/data/####/lotuseed.lock
- /data/data/####/lotuseed.s
- /data/data/####/lotuseed_global.xml
- /data/data/####/lotuseed_main.xml
- /data/data/####/mgAS.dat
- /data/data/####/mgSS.dat
- /data/data/####/miguGameBillingRequestMonitor.xml
- /data/data/####/sdk_prefs
- /data/data/####/sg.dex
- /data/data/####/sg.dex (deleted)
- /data/data/####/sg_game.dex
- /data/data/####/sg_game.dex (deleted)
- /data/media/####/ShareData.txt
- /data/media/####/deviceId
- /data/media/####/lotuseed.devid
- /data/media/####/pushDB.txt
- /data/media/####/pushTime.txt
- /data/media/####/pushTotal.txt
- /data/media/####/sdk_prefs.txt
- df
- ps
- gdx
- libmiguED
- megjb
- sg
- AES-CBC-PKCS5Padding
- DES-ECB-PKCS5Padding
- AES-CBC-PKCS5Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding