Technical information
- Android.Backdoor.564.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.b####.qq.com:8012
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) ga####.lotu####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) a####.b####.qq.com:8011
- TCP(HTTP/1.1) ga####.lotu####.com:88
- a####.b####.qq.com
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- ga####.lotu####.com
- on####.lotu####.com
- a####.b####.qq.com:8011/rqd/async?aid=####
- a####.b####.qq.com:8012/rqd/async?aid=####
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- ga####.lotu####.com/?st=####&sv=####&tm=####&sid=fTY####&apn=####&ct=###...
- ga####.lotu####.com:88/?mid=####&st=####&sv=####&tm=####&sid=fTY####&apn...
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_crashrecord/1002
- <Package Folder>/app_crashrecord/1004
- <Package Folder>/code_cache/####/MultiDex.lock
- <Package Folder>/databases/bugly_db_-journal
- <Package Folder>/databases/cc.db
- <Package Folder>/databases/cc.db-journal
- <Package Folder>/databases/geofencing.db
- <Package Folder>/databases/geofencing.db-journal
- <Package Folder>/databases/ua.db
- <Package Folder>/databases/ua.db-journal
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/.imprint
- <Package Folder>/files/exid.dat
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/lotuseed.apps
- <Package Folder>/files/lotuseed.lock
- <Package Folder>/files/lotuseed.s
- <Package Folder>/files/lotuseed.task
- <Package Folder>/files/security_info
- <Package Folder>/files/tiny_data.data
- <Package Folder>/files/tiny_data.lock
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/shared_prefs/.tpns.settings.xml.xml
- <Package Folder>/shared_prefs/4.2.0.xml
- <Package Folder>/shared_prefs/<Package>.BETA_VALUES.xml
- <Package Folder>/shared_prefs/Alvin2.xml
- <Package Folder>/shared_prefs/BUGLY_COMMON_VALUES.xml
- <Package Folder>/shared_prefs/ContextData.xml
- <Package Folder>/shared_prefs/appall.xml
- <Package Folder>/shared_prefs/common.xml
- <Package Folder>/shared_prefs/crashrecord.xml
- <Package Folder>/shared_prefs/jg_so_upgrade_setting.xml
- <Package Folder>/shared_prefs/lotuseed_global.xml
- <Package Folder>/shared_prefs/lotuseed_main.xml
- <Package Folder>/shared_prefs/mipush.xml
- <Package Folder>/shared_prefs/mipush_extra.xml
- <Package Folder>/shared_prefs/multidex.version.xml
- <Package Folder>/shared_prefs/pref.xml
- <Package Folder>/shared_prefs/qihoo_jiagu_crash_report.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <SD-Card>/.DataStorage/ContextData.xml
- <SD-Card>/.UTSystemConfig/####/Alvin2.xml
- <SD-Card>/.system/lotuseed.devid
- <SD-Card>/.youchong.info
- <SD-Card>/Android/####/.nomedia
- <SD-Card>/Android/####/420share_logo.jpg
- <SD-Card>/Android/####/420third_share_weibo_icon.jpg
- <SD-Card>/Android/####/sysid.dat
- <SD-Card>/yclog/YourPet-_2017-11-16_2022.log
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- df
- getprop
- logcat -d -v threadtime
- ps
- Bugly
- libjiagu
- libtpnsSecurity
- tpnsSecurity
- yourpetsign