Technical information
- Android.Banker.5138
- Android.Banker.630.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 64.2####.162.94:80
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) sqs.ap-nort####.amazo####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 74.1####.205.101:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) 64.2####.162.94:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.2) 64.2####.162.106:443
- UDP www.gst####.com:443
- UDP www.google####.com:443
- UDP rr18---####.g####.com:443
- and####.a####.go####.com
- and####.google####.com
- gmscomp####.google####.com
- m####.go####.com
- p####.google####.com
- rr18---####.g####.com
- rr2---s####.g####.com
- rr9---s####.g####.com
- sqs.ap-nort####.amazo####.com
- www.go####.com
- www.google####.com
- www.gst####.com
- sqs.ap-nort####.amazo####.com:443/664144478517/report_queue_svc
- /data/data/####/.com_offer_rewards.meta
- /data/data/####/150035
- /data/data/####/19
- /data/data/####/2024-01-12AM103520.rt
- /data/data/####/2024-01-12AM103520.str
- /data/data/####/2024-01-12AM103529.so.rt
- /data/data/####/2024-01-12AM103539.so.rt
- /data/data/####/2024-01-12AM103545.so.rt
- /data/data/####/2024-01-12AM103551.so.rt
- /data/data/####/2024-01-12AM103557.so.rt
- /data/data/####/2024-01-12AM103604.so.rt
- /data/data/####/2024-01-12AM103611.so.rt
- /data/data/####/2024-01-12AM103617.so.rt
- /data/data/####/2024-01-12AM103624.so.rt
- /data/data/####/2024-01-12AM103632.so.rt
- /data/data/####/2024-01-12AM103649.rt
- /data/data/####/2024-01-12AM103649.str
- /data/data/####/250035
- /data/data/####/29
- /data/data/####/40OYUVU03D7X371XSMC7PV54DSS4TWQ.zip
- /data/data/####/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.dex (deleted)
- /data/data/####/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.dex.flock (deleted)
- /data/data/####/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.zip
- /data/data/####/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.dex (deleted)
- /data/data/####/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.dex.flock (deleted)
- /data/data/####/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.zip
- /data/data/####/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex
- /data/data/####/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex.flock (deleted)
- /data/data/####/AppKey.xml
- /data/data/####/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.dex
- /data/data/####/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.dex (deleted)
- /data/data/####/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.dex.flock (deleted)
- /data/data/####/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.zip
- /data/data/####/FU49XA17T2376U0J952YU8TBMH06WHSU.dex
- /data/data/####/FU49XA17T2376U0J952YU8TBMH06WHSU.dex.flock (deleted)
- /data/data/####/H2UQK4HKM9BL3DPZFUCQ531JYJAYUVM.dex (deleted)
- /data/data/####/H2UQK4HKM9BL3DPZFUCQ531JYJAYUVM.dex.flock (deleted)
- /data/data/####/H2UQK4HKM9BL3DPZFUCQ531JYJAYUVM.zip
- /data/data/####/HTXB3OF94IKQW02E9N1KYSYL615PA57.dex (deleted)
- /data/data/####/HTXB3OF94IKQW02E9N1KYSYL615PA57.dex.flock (deleted)
- /data/data/####/HTXB3OF94IKQW02E9N1KYSYL615PA57.zip
- /data/data/####/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.dex
- /data/data/####/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.dex (deleted)
- /data/data/####/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.dex.flock (deleted)
- /data/data/####/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.zip
- /data/data/####/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex
- /data/data/####/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex.flock (deleted)
- /data/data/####/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.dex (deleted)
- /data/data/####/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.dex.flock (deleted)
- /data/data/####/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.zip
- /data/data/####/OOGQI3USVP35VFDXC6CZ1V5C9OW0D8Y.dex (deleted)
- /data/data/####/OOGQI3USVP35VFDXC6CZ1V5C9OW0D8Y.dex.flock (deleted)
- /data/data/####/OOGQI3USVP35VFDXC6CZ1V5C9OW0D8Y.zip
- /data/data/####/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex
- /data/data/####/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex.flock (deleted)
- /data/data/####/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.dex (deleted)
- /data/data/####/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.dex.flock (deleted)
- /data/data/####/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.zip
- /data/data/####/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.dex (deleted)
- /data/data/####/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.dex.flock (deleted)
- /data/data/####/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.zip
- /data/data/####/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.dex (deleted)
- /data/data/####/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.dex.flock (deleted)
- /data/data/####/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.zip
- /data/data/####/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex
- /data/data/####/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex.flock (deleted)
- /data/data/####/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex
- /data/data/####/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex.flock (deleted)
- /data/data/####/com.offer.rewards_preferences.xml
- /data/data/####/empty_classes.dex
- /data/data/####/empty_classes.zip
- /data/data/####/lastReportSendTimeFile
- /data/data/####/proc_auxv
- /data/data/####/sealed1.obk
- /data/data/####/sealed2.obk
- /data/data/####/sealed3.obk
- /data/data/####/sealed4.obk
- /data/data/####/sealed5.obk
- /data/data/####/sealeh.bdc
- /data/data/####/stat1
- /data/data/####/stat2
- /data/data/####/stat3
- /data/data/####/stat4
- /data/data/####/stat5
- /data/data/####/working
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/HTXB3OF94IKQW02E9N1KYSYL615PA57.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/OOGQI3USVP35VFDXC6CZ1V5C9OW0D8Y.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/7BZTLIP7I8EGQYCWBLNM8MONSV7RC3P.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/804EU7UORDZHJB1X4Q43PNPGP4OG5WA.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DHDNBSFPKACUWKEYLZ1KU8U5EPXXMXB.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/HTXB3OF94IKQW02E9N1KYSYL615PA57.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/HTXB3OF94IKQW02E9N1KYSYL615PA57.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/II2WSDKQDN5RPTBF2SY1FTZU3A6E3YS.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/LH9N7WF1WUWEO8EETR1CQSIT2X9LUHF.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/OOGQI3USVP35VFDXC6CZ1V5C9OW0D8Y.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/RCS8223A8BL7DJRPXSEK3T7TWHGW8T4.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/S6D061MUKOVZGEIN1OXU5DXU5UCJ1R6.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/T7697AR7P1WCX3VOMTMFA6I7IJ54M8N.vdex
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex --compiler-filter=verify-none --instruction-set=x86
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FU49XA17T2376U0J952YU8TBMH06WHSU.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FU49XA17T2376U0J952YU8TBMH06WHSU.dex --compiler-filter=verify-none --instruction-set=x86
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex --compiler-filter=verify-none --instruction-set=x86
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex --oat-file=/data/user/0/<Package>/cache/<Package>/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex --compiler-filter=verify-none --instruction-set=x86
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex --oat-file=/data/user/0/<Package>/cache/<Package>/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex --compiler-filter=verify-none --instruction-set=x86
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex --compiler-filter=verify-none --instruction-set=x86
- getprop ro.dalvik.vm.isa.arm
- getprop ro.dalvik.vm.isa.arm64
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9HPMTR4IO0M97NVLW1DVJSM6503YK8BC.dex --compiler-filter=verify-none --instruction-set=x86
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FU49XA17T2376U0J952YU8TBMH06WHSU.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FU49XA17T2376U0J952YU8TBMH06WHSU.dex --compiler-filter=verify-none --instruction-set=x86
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/KE0JHK8BCU1UIDQBNULCA2YKC1BWFUEA.dex --compiler-filter=verify-none --instruction-set=x86
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex --oat-file=/data/user/0/<Package>/cache/<Package>/PQZNF5O2RW4SNWDK31O6HJCH0TFN2L2C.dex --compiler-filter=verify-none --instruction-set=x86
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex --oat-file=/data/user/0/<Package>/cache/<Package>/UJ5AYRR6V7D6XLM12C08OGPXPLHCJKBP.dex --compiler-filter=verify-none --instruction-set=x86
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XS4XWSCWF4B28Q9K691FKNKZCIREE7LR.dex --compiler-filter=verify-none --instruction-set=x86
- libcovault-appsec