Technical information
- Android.BankBot.563.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) ip####.com:80
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) raw.githubu####.com:443
- TCP(TLS/1.0) 1####.251.39.99:443
- TCP(TLS/1.0) rr5---s####.g####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) 1####.217.168.238:443
- TCP(TLS/1.2) 1####.251.39.99:443
- TCP(TLS/1.2) p####.google####.com:443
- UDP rr5---s####.g####.com:443
- UDP rr3---s####.g####.com:443
- UDP p####.google####.com:443
- and####.a####.go####.com
- and####.google####.com
- gmscomp####.google####.com
- ip####.com
- p####.google####.com
- raw.githubu####.com
- rr2---s####.g####.com
- rr3---s####.g####.com
- rr3---s####.g####.com
- rr5---s####.g####.com
- ip####.com/json
- raw.githubu####.com:443/hmellissan/tor-files/main/all_tor.zip
- /data/data/####/all_tor.zip
- /data/data/####/all_tor.zip (deleted)
- /data/data/####/bridges.txt
- /data/data/####/geoip
- /data/data/####/geoip6
- /data/data/####/obfs4proxy.so
- /data/data/####/obfs4proxy.so (deleted)
- /data/data/####/org.torproject.android_preferences.xml
- /data/data/####/pref_name_setting.xml
- /data/data/####/prefs30.xml
- /data/data/####/sQUa.dex
- /data/data/####/sQUa.dex.flock (deleted)
- /data/data/####/sQUa.json
- /data/data/####/tor.so
- /data/data/####/torrc
- /data/data/####/torrc.custom
- /data/misc/####/primary.prof
- /system/lib/arm/houdini <Package Folder>/files/tor_source/tor.so <Package Folder>/files/tor_source/tor.so DataDirectory <Package Folder>/app_data --defaults-torrc <Package Folder>/files/tor_source/torrc -f <Package Folder>/files/tor_source/torrc.custom --verify-config
- busybox kill -9 4427
- busybox killall -9 tor.so
- kill -9 4427
- toolbox kill -9 4427
- toolbox ps