Technical information
- Android.Banker.5141
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 64.2####.161.94:80
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) 64.2####.161.94:443
- TCP(TLS/1.0) rr18---####.g####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) sqs.ap-nort####.amazo####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.2) 64.2####.161.94:443
- TCP(TLS/1.2) www.go####.com:443
- TCP(TLS/1.2) and####.google####.com:443
- UDP and####.google####.com:443
- and####.a####.go####.com
- and####.google####.com
- m####.go####.com
- p####.google####.com
- pla####.google####.com
- rr18---####.g####.com
- rr2---s####.g####.com
- rr9---s####.g####.com
- sqs.ap-nort####.amazo####.com
- www.go####.com
- sqs.ap-nort####.amazo####.com:443/664144478517/report_queue_svc
- /data/data/####/.com_phdf_fileman.meta
- /data/data/####/150035
- /data/data/####/19
- /data/data/####/2024-01-07AM011734.rt
- /data/data/####/2024-01-07AM011734.str
- /data/data/####/2024-01-07AM011743.so.rt
- /data/data/####/2024-01-07AM011751.so.rt
- /data/data/####/2024-01-07AM011756.so.rt
- /data/data/####/2024-01-07AM011803.so.rt
- /data/data/####/2024-01-07AM011809.so.rt
- /data/data/####/2024-01-07AM011814.so.rt
- /data/data/####/2024-01-07AM011819.so.rt
- /data/data/####/2024-01-07AM011826.so.rt
- /data/data/####/2024-01-07AM011832.so.rt
- /data/data/####/2024-01-07AM011839.so.rt
- /data/data/####/2024-01-07AM011846.so.rt
- /data/data/####/2024-01-07AM011852.so.rt
- /data/data/####/226K4PWILR9F1PRVQWEP3H7ER6MARI8.dex (deleted)
- /data/data/####/226K4PWILR9F1PRVQWEP3H7ER6MARI8.dex.flock (deleted)
- /data/data/####/226K4PWILR9F1PRVQWEP3H7ER6MARI8.zip
- /data/data/####/250035
- /data/data/####/29
- /data/data/####/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.dex (deleted)
- /data/data/####/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.dex.flock (deleted)
- /data/data/####/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.zip
- /data/data/####/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.dex (deleted)
- /data/data/####/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.dex.flock (deleted)
- /data/data/####/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.zip
- /data/data/####/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex
- /data/data/####/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex.flock (deleted)
- /data/data/####/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.dex (deleted)
- /data/data/####/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.dex.flock (deleted)
- /data/data/####/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.zip
- /data/data/####/AppKey.xml
- /data/data/####/AppKey.xml.bak
- /data/data/####/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.dex (deleted)
- /data/data/####/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.dex.flock (deleted)
- /data/data/####/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.zip
- /data/data/####/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.dex (deleted)
- /data/data/####/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.dex.flock (deleted)
- /data/data/####/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.zip
- /data/data/####/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.dex (deleted)
- /data/data/####/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.dex.flock (deleted)
- /data/data/####/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.zip
- /data/data/####/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.dex (deleted)
- /data/data/####/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.dex.flock (deleted)
- /data/data/####/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.zip
- /data/data/####/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.dex (deleted)
- /data/data/####/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.dex.flock (deleted)
- /data/data/####/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.zip
- /data/data/####/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.dex (deleted)
- /data/data/####/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.dex.flock (deleted)
- /data/data/####/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.zip
- /data/data/####/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.dex (deleted)
- /data/data/####/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.dex.flock (deleted)
- /data/data/####/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.zip
- /data/data/####/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.dex (deleted)
- /data/data/####/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.dex.flock (deleted)
- /data/data/####/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.zip
- /data/data/####/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.dex (deleted)
- /data/data/####/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.dex.flock (deleted)
- /data/data/####/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.zip
- /data/data/####/com.phdf.fileman_preferences.xml
- /data/data/####/empty_classes.dex
- /data/data/####/empty_classes.zip
- /data/data/####/lastReportSendTimeFile
- /data/data/####/proc_auxv
- /data/data/####/sealed1.obk
- /data/data/####/sealeh.bdc
- /data/data/####/stat1
- /data/data/####/working
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/226K4PWILR9F1PRVQWEP3H7ER6MARI8.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/226K4PWILR9F1PRVQWEP3H7ER6MARI8.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/226K4PWILR9F1PRVQWEP3H7ER6MARI8.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/2OYD0QHYIS4BRSAA314DYP1LYHUK71N.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/2WBIOZOSIE9LUW0LBAZSFZFORWEXB5S.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/6UA8W5W25ZHBLLFVUKUPR1BUJIU2VQO.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/BLC3TSTL3NE6ZX92CNW1CK4LCXRQCIH.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/CKO2MV6KN1FPR7HDOY8NDNHCPCK850A.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/J4C8QUNMSVTFL7R5T4QGJXZ5KT0OS58.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/L1DBJSRT4YKM0KUUHVX0Y0QTQTPHY1V.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/PNX4RP8T5NRAYBLDMGFODK80L45R2W6.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/QIMK0DWUXVDZDTRVY4UHJ1V2FEEYF2C.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/RXKR5KTTBB2Y7PX2SJW9K0KDGHNES6T.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/TFM9R2331H4OL3N4IDAFUMQNQFT4I47.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/U7JFTLA1JEOMSEY4W75B682C3GRBROJ.vdex
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex --oat-file=/data/user/0/<Package>/cache/<Package>/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex --compiler-filter=verify-none --instruction-set=x86
- getprop ro.dalvik.vm.isa.arm
- getprop ro.dalvik.vm.isa.arm64
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex --oat-file=/data/user/0/<Package>/cache/<Package>/3L32SVZQ3TGLDOLM61OZHD577CIR255P.dex --compiler-filter=verify-none --instruction-set=x86
- libcovault-appsec