Technical information
- Android.BankBot.Ermac.6.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) os####.pro:80
- TCP(TLS/1.0) content####.google####.com:443
- TCP(TLS/1.0) acco####.go####.com:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) acco####.you####.com:443
- TCP(TLS/1.0) p####.go####.com:443
- TCP(TLS/1.0) up####.google####.com:443
- TCP(TLS/1.0) dl.go####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) clients####.google####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- UDP www.gst####.com:443
- UDP acco####.go####.com:443
- acco####.go####.com
- acco####.you####.com
- as####.pro
- clients####.google####.com
- content####.google####.com
- dl.go####.com
- ed####.me.g####.com
- f####.gst####.com
- it####.live
- md####.live
- nd####.live
- os####.pro
- p####.go####.com
- up####.google####.com
- www.go####.com
- www.gst####.com
- os####.pro/socket.io/?EIO=####&transport=####
- os####.pro/socket.io/?EIO=####&transport=####&sid=####
- os####.pro/php/0.php/
- os####.pro/php/26tr6l7qi769241.php/
- os####.pro/php/2twwrsq38vaad1z6f.php/
- os####.pro/php/3d64qkylmvfc0z18mh4.php/
- os####.pro/php/3jzr1d68zl66vrj0jx.php/
- os####.pro/php/3pga3cv2hv28vos.php/
- os####.pro/php/49f9cjjevlyj04fl24.php/
- os####.pro/php/4tvj.php/
- os####.pro/php/4w209dl21lhq261k.php/
- os####.pro/php/4wp07ojqry2wvj.php/
- os####.pro/php/5nilojoka46u0h2ii74r.php/
- os####.pro/php/5zml64l.php/
- os####.pro/php/60xrsbc9gdyeyz4.php/
- os####.pro/php/686bar7.php/
- os####.pro/php/69ugys.php/
- os####.pro/php/6gry.php/
- os####.pro/php/706wf6.php/
- os####.pro/php/7pt5.php/
- os####.pro/php/9ba5xzf5f4sf6byh.php/
- os####.pro/php/bfu6lfb.php/
- os####.pro/php/c39kc123u7.php/
- os####.pro/php/cy510umoses6.php/
- os####.pro/php/d33r4wd4.php/
- os####.pro/php/d379lqc.php/
- os####.pro/php/dak.php/
- os####.pro/php/dja9xybyifmlea.php/
- os####.pro/php/e.php/
- os####.pro/php/fv6oa3wxkjpt9sdi.php/
- os####.pro/php/g8sexza.php/
- os####.pro/php/i.php/
- os####.pro/php/j16bxkr117.php/
- os####.pro/php/jby1cmji5jxadu.php/
- os####.pro/php/ko0nq0tdsvx68wy6a5.php/
- os####.pro/php/kz8ysi4az.php/
- os####.pro/php/lda.php/
- os####.pro/php/lqfesdc0m.php/
- os####.pro/php/lrpouaa40emz8vkb7.php/
- os####.pro/php/m9gpob5mln4o76.php/
- os####.pro/php/me33c1ij7kmuh.php/
- os####.pro/php/n.php/
- os####.pro/php/nade.php/
- os####.pro/php/o4upk56w8n5kbmzh.php/
- os####.pro/php/oct2ipf4uu7z90rildr.php/
- os####.pro/php/p.php/
- os####.pro/php/p502nhuik.php/
- os####.pro/php/pjal.php/
- os####.pro/php/qmun0lbdedh8mm8ggy.php/
- os####.pro/php/r.php/
- os####.pro/php/rmxrbb98cuc9n.php/
- os####.pro/php/rpla4.php/
- os####.pro/php/sibuko.php/
- os####.pro/php/tqf50rzm.php/
- os####.pro/php/u82.php/
- os####.pro/php/v14tn8f.php/
- os####.pro/php/ves4mhkrpq.php/
- os####.pro/php/vyzecovv6vie24u6.php/
- os####.pro/php/y8.php/
- os####.pro/php/za6joqxk42y.php/
- os####.pro/socket.io/?EIO=####&transport=####&sid=####
- /com.wefinimapoxivopo.dafozoha/app_webview/####/000003.log
- /com.wefinimapoxivopo.dafozoha/app_webview/####/Cookies
- /com.wefinimapoxivopo.dafozoha/app_webview/####/LOCK
- /com.wefinimapoxivopo.dafozoha/app_webview/####/LOG
- /com.wefinimapoxivopo.dafozoha/app_webview/####/MANIFEST-000001
- /com.wefinimapoxivopo.dafozoha/app_webview/####/QuotaManager
- /com.wefinimapoxivopo.dafozoha/app_webview/####/QuotaManager-journal
- /com.wefinimapoxivopo.dafozoha/app_webview/####/Web Data
- /com.wefinimapoxivopo.dafozoha/app_webview/####/Web Data-journal
- /com.wefinimapoxivopo.dafozoha/app_webview/webview_data.lock
- /com.wefinimapoxivopo.dafozoha/no_backup/androidx.work.workdb
- /com.wefinimapoxivopo.dafozoha/no_backup/androidx.work.workdb-shm
- /com.wefinimapoxivopo.dafozoha/no_backup/androidx.work.workdb-wal
- /data/user/####/.org.chromium.Chromium.FSK2ue
- /data/user/####/.org.chromium.Chromium.eg7NqF (deleted)
- /data/user/####/000001.dbtmp
- /data/user/####/000003.log
- /data/user/####/01548f75bb1acd74_0
- /data/user/####/0c8be5d6ce15dfe6_0
- /data/user/####/1363a834602cc3b7_0
- /data/user/####/1e3c3ca648cc5554_0
- /data/user/####/24ea366b394af28f_0
- /data/user/####/32bf6f7ed0fdcfad_0
- /data/user/####/33166b95042feb2d_0
- /data/user/####/39a9d184d7e8b6b2_0
- /data/user/####/3b6062ae12595dd2_0
- /data/user/####/3ce188ca72f500b4_0
- /data/user/####/50b62a63d7947399_0
- /data/user/####/72803fca62d701fa_0
- /data/user/####/75897134d21a378a_0
- /data/user/####/8e10f629c9990b58_0
- /data/user/####/8fb53405f0c3f399_0
- /data/user/####/BrowserMetrics-spare.pma
- /data/user/####/Cookies-journal
- /data/user/####/DJCAb.json
- /data/user/####/DJCAb.json.cur.prof
- /data/user/####/LOCK
- /data/user/####/LOG
- /data/user/####/MANIFEST-000001
- /data/user/####/WebViewChromiumPrefs.xml
- /data/user/####/a09364c3a9a1cf2f_0
- /data/user/####/a8c98f08e10b3af6_0
- /data/user/####/androidx.work.workdb-journal (deleted)
- /data/user/####/androidx.work.workdb-wal
- /data/user/####/b59536648277bb7a_0
- /data/user/####/c4520543b240d7b9_0
- /data/user/####/cbb9b1e8818da640_0
- /data/user/####/db78dbe738ea880d_0
- /data/user/####/ec22a0fa7539355c_0
- /data/user/####/f39aa141b0d65cb9_0
- /data/user/####/f536d18bbc6028a2_0
- /data/user/####/fc110faf4a561f16_0
- /data/user/####/fc78fa54d3420b50_0
- /data/user/####/font_unique_name_table.pb
- /data/user/####/index
- /data/user/####/settings.dat
- /data/user/####/settings.xml
- /data/user/####/settings.xml.bak
- /data/user/####/temp-index
- /data/user/####/todelete_39ba66cfa7866675_0_1 (deleted)
- /data/user/####/todelete_7e5271d65b027836_0_1 (deleted)
- /data/user/####/todelete_be7668478d4b909b_0_1 (deleted)
- /data/user/####/todelete_c802dee663c2a7b8_0_1 (deleted)
- /data/user/####/todelete_e27a0f8caf7b2921_0_1 (deleted)
- /data/user/####/todelete_ead9e48e1d6c6a56_0_1 (deleted)
- /data/user/####/todelete_f2347facc1e193e7_0_1 (deleted)
- /data/user/####/variations_seed_new
- /data/user/####/variations_stamp
- /system/bin/su