Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) adalli####.zmen####.com:80
- TCP(HTTP/1.1) 1####.31.213.162:80
- TCP(HTTP/1.1) 47.97.2####.214:80
- TCP(HTTP/1.1) as.lie####.cn:80
- TCP(HTTP/1.1) s6.ps####.com.####.com:80
- TCP(HTTP/1.1) c####.360.cn:80
- TCP(HTTP/1.1) 1####.26.247.23:80
- TCP(HTTP/1.1) a.e####.cn:80
- TCP(HTTP/1.1) api.map.b####.com:80
- TCP(HTTP/1.1) ap####.adi####.com:80
- TCP(HTTP/1.1) d.ix####.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(HTTP/1.1) sf1-ttc####.ps####.com:80
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
- TCP(TLS/1.0) api.e####.cn:443
- TCP(TLS/1.0) lf.sn####.com:443
- TCP(TLS/1.0) s####.fas####.net:443
- TCP(TLS/1.0) d.ix####.com:443
- a.e####.cn
- adalli####.zmen####.com
- ap####.adi####.com
- api.e####.cn
- api.map.b####.com
- as.lie####.cn
- c####.360.cn
- c.appj####.com
- d.ix####.com
- lf.sn####.com
- plb####.u####.com
- s####.fas####.net
- s.ix####.com
- s.l.fas####.net
- s6.ps####.com
- sf1-ttc####.ps####.com
- u####.u####.com
- wn.pos.b####.com
- a.e####.cn/public/getClickUrlPoList.shtml?lng=####&sd=####&screenheight=...
- a.e####.cn/public/getCommonStartUpAd.shtml?height=####&width=####&lng=##...
- a.e####.cn/public/isDebugAd.shtml?ts=####&appid=####&sign=####
- a.e####.cn/public/rab.shtml?id=####&network=####&machine=####
- a.e####.cn/public/showUrlVisit.shtml?os=####&osversion=####&appversion=#...
- adalli####.zmen####.com/zmtmobads/v1/impl.do?param=####
- ap####.adi####.com/tj?key=####&rd=####&req=####&token=####
- as.lie####.cn/v2/forward/click/ch/25?version=####&sspaid=####&sid=####&g...
- as.lie####.cn/v2/forward/imp/ch/25?version=####&sspaid=####&sid=####&gui...
- d.ix####.com/ocDaB/
- s6.ps####.com.####.com/package/apk/video_article/VideoArticle_video_duan...
- sf1-ttc####.ps####.com/img/ad.union.api/144e609a6755bac6eebed359b39962b4...
- wn.pos.b####.com/adx.php?c=####&ext=####
- api.map.b####.com/location/ip?ak=####&coor=####
- c####.360.cn/stra_packet
- c.appj####.com/ad/splash/stats.html
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgrpa.xml
- /data/data/####/.log.lock
- /data/data/####/.log.rpa
- /data/data/####/3d4a28966bfece8e25721e9da7a7d103.0.tmp
- /data/data/####/3d4a28966bfece8e25721e9da7a7d103.1.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/a==7.3.1&&3.35.32_1529780129251_envelope.log
- /data/data/####/ad_show_time.xml
- /data/data/####/b074efaa5e3f6ef05f73fec50c47f1c7.0.tmp
- /data/data/####/b074efaa5e3f6ef05f73fec50c47f1c7.1.tmp
- /data/data/####/cn.ecook.xml
- /data/data/####/d==7.3.1&&3.35.32_1529780129327_envelope.log
- /data/data/####/d==7.3.1&&3.35.32_1529780180212_envelope.log
- /data/data/####/d==7.3.1&&3.35.32_1529780184647_envelope.log
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/index
- /data/data/####/info.xml
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/journal.tmp
- /data/data/####/libjiagu649597836.so
- /data/data/####/log.android.library.xml
- /data/data/####/multidex.version.xml
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/1529780184156.apk
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- chmod 755 <Package Folder>/.jiagu/libjiagu649597836.so
- ls /
- ls /sys/class/thermal
- libjiagu649597836
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- RSA
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding