Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.55.28.235:80
- TCP(HTTP/1.1) 47.97.2####.214:80
- TCP(HTTP/1.1) a.e####.cn:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) 47.1####.40.225:80
- TCP(HTTP/1.1) api.e####.cn:80
- TCP(HTTP/1.1) dynamic####.sn####.com.####.com:80
- TCP(HTTP/1.1) 47.1####.44.93:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(HTTP/1.1) 1####.31.213.162:80
- TCP(HTTP/1.1) luna-im####.qq.com.####.com:80
- TCP(TLS/1.0) is.sn####.com:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) dynamic####.sn####.com.####.com:443
- TCP(TLS/1.0) s####.e.qq.com:443
- a.e####.cn
- api.e####.cn
- i.sn####.com
- imgc####.qq.com
- is.sn####.com
- mi.g####.qq.com
- p####.ugd####.com
- pic.ange####.cn
- plb####.u####.com
- s####.e.qq.com
- a.e####.cn/public/getClickUrlPoList.shtml?os=####&model=####&ts=####&ven...
- a.e####.cn/public/rab.shtml?id=####&network=####&machine=####
- a.e####.cn/public/showUrlVisit.shtml?os=####&osversion=####&appversion=#...
- api.e####.cn/public/getSecondaryHomeData.shtml?machine=####&version=####...
- dynamic####.sn####.com.####.com/web/258794635.jpg
- dynamic####.sn####.com.####.com/web/263076170.jpg!m720
- dynamic####.sn####.com.####.com/web/263756921.jpg!m720
- dynamic####.sn####.com.####.com/web/264287396.jpg!m3
- dynamic####.sn####.com.####.com/web/264309767.jpg!m720
- dynamic####.sn####.com.####.com/web/264405170.jpg!s4
- dynamic####.sn####.com.####.com/web/264683119.jpg!m720
- luna-im####.qq.com.####.com/gdt/0/EAA4xlsAQ4AeAAAAi8FBfI_gyBNaaOHhm.jpg/...
- luna-im####.qq.com.####.com/gdt/0/EAA6_ZPAQ4AeAAAAiwRBe_1lkBruvnDjJ.jpg/...
- luna-im####.qq.com.####.com/qzone/biz/gdt/mod/android/AndroidAllInOne/pr...
- mi.g####.qq.com/gdt_mview.fcg?actual_width=####&count=####&r=####&templa...
- mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
- s####.e.qq.com/activate
- s####.e.qq.com/msg
- /data/data/####/.jg.ic
- /data/data/####/2072e00339abc70f322341f8dd8def29.temp
- /data/data/####/2181.yaqcookie
- /data/data/####/AdloadStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/ContextData.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/Ji.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/ce0c1715d44bd2e72828acad3dd4764d.xml
- /data/data/####/cn.ecook.xml
- /data/data/####/collectiondatabase
- /data/data/####/collectiondatabase-journal
- /data/data/####/com.ciba.data.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTk2NDUxMjkxMzUx;
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/dexMethod.36117467.dat
- /data/data/####/downloader.db-journal
- /data/data/####/ecookdatabase
- /data/data/####/ecookdatabase-journal
- /data/data/####/f1fd1a57d2f07ed6100f9deb4229e42e.temp
- /data/data/####/gdt_config.cfg
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_stat.db
- /data/data/####/gdt_stat.db-journal
- /data/data/####/gdt_suid
- /data/data/####/index
- /data/data/####/info.xml
- /data/data/####/libjiagu-1465347486.so
- /data/data/####/libyaqbasic.36117467.so
- /data/data/####/libyaqpro.36117467.so
- /data/data/####/multidex.version.xml
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/update_lc
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/yaqsdkcookie
- /data/media/####/.nomedia
- /data/media/####/1xa4b8d6vjcfodb55fmees0n1.tmp
- /data/media/####/365r3pv53hfyxvrt45pi4vvky.tmp
- /data/media/####/3no0z7punu34dn62oyiq4spla.tmp
- /data/media/####/3np7vi4zwnuvfsibw098mdiwa.tmp
- /data/media/####/3oz4f3mgi0oa3thml9c5b0nt3.tmp
- /data/media/####/3sguz0wq29dxp02a99l5ugu3i.tmp
- /data/media/####/65505s7kmx5rb8f1aq5xbm6f8.tmp
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- cat /sys/class/net/wlan0/address
- getprop ro.build.version.emui
- getprop ro.letv.release.version
- getprop ro.vivo.os.build.display.id
- ls /
- ls /sys/class/thermal
- libjiagu-1465347486
- libyaqbasic.36117467
- libyaqpro.36117467
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding