Technical information
- Android.Backdoor.613.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.am####.com.####.net:80
- TCP(HTTP/1.1) v####.a####.eeric####.com:80
- TCP(HTTP/1.1) 1####.206.227.63:80
- TCP(HTTP/1.1) i####.api.zhifa####.net:10001
- TCP(HTTP/1.1) 1####.159.103.205:8090
- TCP(HTTP/1.1) c####.api.zhifa####.net:10101
- TCP(HTTP/1.1) int.d####.s####.####.cn:80
- TCP(HTTP/1.1) gdv.a.s####.com:80
- TCP(HTTP/1.1) i####.api.zhifa####.net:10003
- TCP(HTTP/1.1) i####.api.zhifa####.net:10002
- TCP(HTTP/1.1) sdk.api.zhifa####.net:10201
- TCP(HTTP/1.1) sdk.hzzr####.com:80
- TCP(HTTP/1.1) s####.hzzr####.com:80
- TCP(HTTP/1.1) x####.d####.top:20006
- TCP(HTTP/1.1) 1####.75.56.106:10201
- TCP(HTTP/1.1) 1####.129.132.111:8001
- TCP(HTTP/1.1) pay####.oss-cn-####.aliy####.com:80
- TCP(HTTP/1.1) sm####.hej####.com:80
- TCP(HTTP/1.1) 1####.159.152.136:8090
- TCP(HTTP/1.1) v####.api.eeric####.com:80
- TCP(HTTP/1.1) wn.zhifa####.net.####.net:80
- TCP(SSL/3.0) userm####.k####.net:443
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) u####.o####.net:443
- TCP(TLS/1.0) i####.de####.net:443
- TCP(TLS/1.0) www.am####.com.####.net:443
- TCP(TLS/1.0) d####.a####.com:443
- TCP(TLS/1.0) ph####.go####.com:443
- TCP(TLS/1.0) t####.blu####.com.####.net:443
- TCP(TLS/1.0) s####.1rx.io:443
- TCP(TLS/1.0) t####.rubicon####.com:443
- TCP(TLS/1.0) ads.twi####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) bh.contex####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) x.bidsw####.net:443
- TCP(TLS/1.0) s####.ipredic####.com:443
- TCP(TLS/1.0) s.amazon-####.com:443
- TCP(TLS/1.0) trc.tab####.com:443
- TCP(TLS/1.0) aa.a####.com:443
- TCP(TLS/1.0) www.face####.com:443
- TCP(TLS/1.0) ssum####.casalem####.com.####.net:443
- TCP(TLS/1.0) odr.moo####.com:443
- TCP(TLS/1.0) cm.g.doublec####.net:443
- TCP(TLS/1.0) m.media-a####.com:443
- TCP(TLS/1.0) im####.pubm####.com.####.net:443
- TCP(TLS/1.0) userm####.k####.net:443
- TCP(TLS/1.0) gat####.p####.us-ea####.####.com:443
- TCP(TLS/1.0) ads.y####.com:443
- TCP(TLS/1.0) log-ec-####.a####.tv.####.net:443
- TCP(TLS/1.0) aax-us-####.amazon-####.com:443
- TCP(TLS/1.0) p####.adverti####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) s####.search####.spotxch####.####.net:443
- TCP(TLS/1.0) g.geo####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- aa.a####.com
- aax-us-####.amazon-####.com
- ads.y####.com
- adser####.go####.com
- analy####.twi####.com
- bh.contex####.com
- c####.api.zhifa####.net
- cm.g.doublec####.net
- d.a####.com
- dpm.de####.net
- fl####.am####.com
- googl####.g.doublec####.net
- i####.api.zhifa####.net
- i####.api.zhifa####.net
- ib.a####.com
- im####.pubm####.com
- image####.ssl-ima####.com
- int.d####.s####.####.cn
- m.media-a####.com
- odr.moo####.com
- p####.adverti####.com
- pay####.oss-cn-####.aliy####.com
- ph####.go####.com
- pv.s####.com
- re####.api.zhifa####.net
- s####.1rx.io
- s####.ad####.adverti####.com
- s####.blu####.com
- s####.hzzr####.com
- s####.ipredic####.com
- s####.se####.spotxch####.com
- s.amazon-####.com
- sdk.api.zhifa####.net
- sdk.hzzr####.com
- sm####.hej####.com
- ssl.gst####.com
- ssum####.casalem####.com
- t####.blu####.com
- t####.rubicon####.com
- trc.tab####.com
- u####.o####.net
- userm####.k####.net
- v####.a####.eeric####.com
- v####.api.eeric####.com
- wn.zhifa####.net
- www.am####.com
- www.face####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- www.huangda####.com
- x####.d####.top
- x.bidsw####.net
- gdv.a.s####.com/cityjson?ie=####
- int.d####.s####.####.cn/iplookup/iplookup.php?format=####&ip=####
- pay####.oss-cn-####.aliy####.com/sdk/jar/e00e23acc8724bca841961181e1ea70...
- s####.hzzr####.com/SdkNotity.aspx?i=####&v=####&c=####&av=####&dm=####&t...
- sdk.hzzr####.com/getconfig.aspx
- sdk.hzzr####.com/getjar.aspx?pno=####
- sdk.hzzr####.com/versioncheck.aspx
- sm####.hej####.com/getAd.php?apiKey=####&imsi=####&mobile=####&apiKey=##...
- sm####.hej####.com/getError.php?echoName=####&error=####&hKey=####&OS=##...
- sm####.hej####.com/getMobile.php?apiKey=####&imsi=####&n####&n####
- sm####.hej####.com/getSP135.php?echoName=####&appName=####&productName=#...
- v####.a####.eeric####.com/fileupload/e00ac1690539a0b6.jar
- wn.zhifa####.net.####.net/update/up010363_66
- www.am####.com.####.net/
- x####.d####.top:20006/SmsPayServer/sdkUpdate/index?
- c####.api.zhifa####.net:10101/v2/order/get?app_id=####&t=####
- c####.api.zhifa####.net:10101/v2/splog/config?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/adconfig/get?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/bag/monitor?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/sdk/init?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/update/check?app_id=####&t=####
- i####.api.zhifa####.net:10002/v2/callback/message?app_id=####&t=####
- i####.api.zhifa####.net:10003/v2/chis
- sdk.api.zhifa####.net:10201/v2/sdk/report?app_id=####&t=####
- v####.api.eeric####.com/api/payment/mobileInit.html
- v####.api.eeric####.com/api/payment/payDynamic.html
- v####.api.eeric####.com/api/payment/updateinit_v2
- /data/data/####/.fb
- /data/data/####/.fb-journal
- /data/data/####/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml
- /data/data/####/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml.bak
- /data/data/####/config50240.xml
- /data/data/####/config50240.xml.bak
- /data/data/####/jy_hot_sdk_config.xml
- /data/data/####/new_md.jar
- /data/data/####/onib_clz.jar
- /data/data/####/pay_plg.dex (deleted)
- /data/data/####/pay_plg.jar
- /data/data/####/pretw.xml
- /data/data/####/pz_sharedpre_cmreaderlogininfo.xml
- /data/data/####/scpj.gbcsgkj671.wlm179.com.pay.db.DBHelper_smsp...ournal
- /data/data/####/scpj.gbcsgkj671.wlm179.xml
- /data/data/####/up010363_66
- /data/data/####/up010363_66.jar
- /data/data/####/up010363_66.jar (deleted)
- /data/data/####/webview.db-journal
- /data/data/####/wochi_v4.db-journal
- /data/media/####/jypaysdk.apk
- /data/media/####/qshp_3003_2296.zip
- /data/media/####/scpj.gbcsgkj671.wlm179_250026699187743_20180415_pay.log
- /data/media/####/tw
- cat /sys/block/mmcblk0/device/cid
- cocos2dcpp
- AES-CBC-PKCS5PADDING
- DES-CBC-PKCS5Padding
- AES
- AES-CBC-PKCS5PADDING
- AES-CBC-PKCS5Padding
- DES
- DES-CBC-PKCS5Padding