Technical information
- Android.BackDoor.985
- Android.Xiny.202.origin
- Android.Xiny.73.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 4####.79.77.161:80
- TCP(HTTP/1.1) 45.79.1####.241:80
- TCP(HTTP/1.1) 45.79.1####.161:80
- TCP(HTTP/1.1) 45.79.1####.160:80
- TCP(HTTP/1.1) 45.79.1####.48:80
- TCP(HTTP/1.1) ggg.koapk####.com:80
- TCP(HTTP/1.1) 4####.33.0.123:80
- TCP(HTTP/1.1) 45.33.1####.188:80
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) www.koapk####.com:8081
- TCP(TLS/1.0) 2####.58.212.206:443
- ggg.koapk####.com
- www.koapk####.com
- www.okyes####.com
- ggg.koapk####.com/pgm/sr/gm/gy
- www.koapk####.com:8081/sm/sr/rt/ry
- www.koapk####.com:8081/sm/sr/sp/py
- www.okyes####.com:8081/sdk/nsd.action?b=####
- /data/data/####/.m2.so
- /data/data/####/18751078.apk
- /data/data/####/18751078.dex
- /data/data/####/20160121.xml
- /data/data/####/20160121.xml.bak (deleted)
- /data/data/####/201806051950.apk
- /data/data/####/29061089.apk
- /data/data/####/29061089.dex
- /data/data/####/30909012.apk
- /data/data/####/30909012.dex
- /data/data/####/33821648.apk
- /data/data/####/33821648.dex
- /data/data/####/38533881.apk
- /data/data/####/38533881.dex
- /data/data/####/48024961.apk
- /data/data/####/48024961.dex
- /data/data/####/56816146.apk
- /data/data/####/56816146.dex
- /data/data/####/71811194.apk
- /data/data/####/71811194.dex
- /data/data/####/94091516.apk
- /data/data/####/94091516.dex
- /data/data/####/B201806041850.apk
- /data/data/####/N2026.data
- /data/data/####/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- /data/data/####/QURfUk9PVF9TREtfMjAxNzAyMDgxMA.xml
- /data/data/####/ag.xml
- /data/data/####/alarms.db-journal
- /data/data/####/bdownloaders.db-journal
- /data/data/####/c201806051950.apk
- /data/data/####/carrier_kqdw_radish
- /data/data/####/com.darshancomputing.BatteryIndicatorPro_preferences.xml
- /data/data/####/dc1
- /data/data/####/dc2
- /data/data/####/dcz
- /data/data/####/debuggerd_hulu
- /data/data/####/dk360.data
- /data/data/####/dk691.data
- /data/data/####/dk909.data
- /data/data/####/dk914.data
- /data/data/####/dk919.data
- /data/data/####/dk946.data
- /data/data/####/dk950.data
- /data/data/####/elfm
- /data/data/####/elfm1526455015613.zip
- /data/data/####/env201806041850.data
- /data/data/####/forever.sh
- /data/data/####/install-recovery.sh
- /data/data/####/kcol_ysy
- /data/data/####/krcfg.txt
- /data/data/####/krmain
- /data/data/####/krmain1526455016225.zip
- /data/data/####/krmain1526455022871.zip
- /data/data/####/krmain1526455045227.zip
- /data/data/####/krmain1526455053830.zip
- /data/data/####/krmain1526455064051.zip
- /data/data/####/krmain1526455074393.zip
- /data/data/####/krmain1526455083873.zip
- /data/data/####/krsdk.cert
- /data/data/####/loa.xml
- /data/data/####/logs.db-journal
- /data/data/####/predictor_sp_store.xml
- /data/data/####/rtr.db
- /data/data/####/rtr.db-journal
- /data/data/####/sp_store.xml
- /data/data/####/sp_store_main.xml
- /data/data/####/start_wkdq_hd
- /data/data/####/supolicy
- /data/data/####/swith1014.db-journal
- /data/data/####/toolbox
- /data/data/####/toolbox1526455015730.zip
- /data/media/####/.m2.so
- /data/media/####/B201806041850.apk
- /data/media/####/test1526455015658
- c201806051950.apk -c <Package>:love
- chmod -R 777 <Package Folder>/com.init.env/app_abz /storage/emulated/0/abz
- chmod 0755 <Package Folder>/com.init.env
- chmod 0777 <Package Folder>/com.init.env/files/elfm
- chmod 0777 <Package Folder>/com.init.env/files/forever.sh
- chmod 0777 <Package Folder>/com.init.env/files/toolbox
- chmod 0777 <Package Folder>/p.dk360/files/forever.sh
- chmod 0777 <Package Folder>/p.dk360/files/krmain
- chmod 0777 <Package Folder>/p.dk691/files/forever.sh
- chmod 0777 <Package Folder>/p.dk691/files/krmain
- chmod 0777 <Package Folder>/p.dk909/files/forever.sh
- chmod 0777 <Package Folder>/p.dk909/files/krmain
- chmod 0777 <Package Folder>/p.dk914/files/forever.sh
- chmod 0777 <Package Folder>/p.dk914/files/krmain
- chmod 0777 <Package Folder>/p.dk919/files/forever.sh
- chmod 0777 <Package Folder>/p.dk919/files/krmain
- chmod 0777 <Package Folder>/p.dk919/files/krsdk.cert
- chmod 0777 <Package Folder>/p.dk946/files/forever.sh
- chmod 0777 <Package Folder>/p.dk946/files/krmain
- chmod 0777 <Package Folder>/p.dk950/files/forever.sh
- chmod 0777 <Package Folder>/p.dk950/files/krmain
- chmod 6777 <Package Folder>/files/c201806051950.apk
- chmod 777 <Package Folder>/p.dk360/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk691/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk909/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk914/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk919/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk946/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk950/files/krcfg.txt
- dcz <Package Folder>/com.init.env/app_abz/dc1 <Package Folder>/com.init.env/app_abz/dc2
- id
- logcat -d -v time
- ls -l /system/bin/su
- ps
- sh
- sh /system/bin/start_wkdq_hd
- sh /system/bin/start_wkdq_hd -c id
- sh <Package Folder>/com.init.env/app_abz/dcz <Package Folder>/com.init.env/app_abz/dc1 <Package Folder>/com.init.env/app_abz/dc2
- start_wkdq_hd
- start_wkdq_hd -c id
- su
- su -c id
- libcom.forever.love
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding