Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) adalli####.zmen####.com:80
- TCP(HTTP/1.1) m.cuda####.com:80
- TCP(HTTP/1.1) 1####.55.28.235:80
- TCP(HTTP/1.1) 47.97.2####.214:80
- TCP(HTTP/1.1) c####.360.cn:80
- TCP(HTTP/1.1) at.al####.com:80
- TCP(HTTP/1.1) 1####.26.247.23:80
- TCP(HTTP/1.1) a.e####.cn:80
- TCP(HTTP/1.1) api.map.b####.com:80
- TCP(HTTP/1.1) ap####.adi####.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) 1####.31.213.162:80
- TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
- TCP(TLS/1.0) bu####.bianxia####.com:443
- TCP(TLS/1.0) s####.fas####.net:443
- TCP(TLS/1.0) l####.bianxia####.com:443
- TCP(TLS/1.0) buy.bianxia####.com:443
- TCP(TLS/1.0) s.l.fas####.net:443
- a.e####.cn
- adalli####.zmen####.com
- ap####.adi####.com
- api.map.b####.com
- at.al####.com
- bu####.bianxia####.com
- buy.bianxia####.com
- c####.360.cn
- c.appj####.com
- l####.bianxia####.com
- l.fas####.net
- m.cuda####.com
- plb####.u####.com
- s####.fas####.net
- s.l.fas####.net
- wn.pos.b####.com
- a.e####.cn/public/getClickUrlPoList.shtml?lng=####&sd=####&screenheight=...
- a.e####.cn/public/getCommonStartUpAd.shtml?height=####&width=####&lng=##...
- a.e####.cn/public/isDebugAd.shtml?ts=####&appid=####&sign=####
- a.e####.cn/public/rab.shtml?id=####&network=####&machine=####
- a.e####.cn/public/showUrlVisit.shtml?os=####&osversion=####&appversion=#...
- adalli####.zmen####.com/zmtmobads/v1/impl.do?param=####
- ap####.adi####.com/tj?key=####&rd=####&req=####&token=####
- at.al####.com/t/font_1wwdhj84a38fr.ttf
- at.al####.com/t/font_wsni5ytblm78pvi.ttf
- m.cuda####.com/?appKey=####&appType=####&appEntrance=####&business=####&...
- m.cuda####.com/dist/ACTIVITY/activity/2018/03/26/bc2d523c-f944-4e8f-82eb...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/0377061b-7db6-427a-812f...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/1197527f-6537-4997-805a...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/8d6ff6e4-5804-439b-b329...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/a6f70386-bc56-42f8-b15f...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/bba8d057-7b23-41bf-9225...
- m.cuda####.com/dist/ACTIVITY/activity/2018/04/20/f74ba2dc-d827-46a5-b6ad...
- m.cuda####.com/dist/ACTIVITY/prize/2017/11/01/8fefa22f-a5ce-43e1-a393-0c...
- m.cuda####.com/dist/ACTIVITY/prize/2018/04/20/47040945-47cd-4b73-bda8-84...
- m.cuda####.com/dist/ACTIVITY/prize/2018/04/20/8d458ea1-dac8-46a9-9ad8-8d...
- m.cuda####.com/dist/ACTIVITY/prize/2018/04/20/be9513d4-67dd-412a-b04d-fe...
- m.cuda####.com/dist/ACTIVITY/prize/2018/04/20/c78d3197-861d-45cc-a963-44...
- m.cuda####.com/dist/ACTIVITY/prize/2018/04/20/dba005a9-a0b4-4d51-82ba-6b...
- m.cuda####.com/dist/bxm_base/css/pops.css
- m.cuda####.com/dist/bxm_base/js/clipboard.min.js
- m.cuda####.com/dist/bxm_base/js/polyfill.min.js
- m.cuda####.com/dist/bxm_base/js/vue.min.js
- m.cuda####.com/dist/bxm_base/js/zepto.js
- m.cuda####.com/dist/newwheel/show/css/Popup.css
- m.cuda####.com/dist/newwheel/show/css/loading.css
- m.cuda####.com/dist/newwheel/show/css/style.css
- m.cuda####.com/dist/newwheel/show/images/border-quan.png
- m.cuda####.com/dist/newwheel/show/images/gongxi.png
- m.cuda####.com/dist/newwheel/show/images/sunshine-bottom.png
- m.cuda####.com/dist/newwheel/show/img/banner.png
- m.cuda####.com/dist/newwheel/show/img/bg.png
- m.cuda####.com/dist/newwheel/show/img/button1.png
- m.cuda####.com/dist/newwheel/show/img/frequency.png
- m.cuda####.com/dist/newwheel/show/img/turntable.png
- m.cuda####.com/dist/newwheel/show/img/turntable_bg.png
- m.cuda####.com/dist/newwheel/show/js/newWheel.min.20180620.js
- m.cuda####.com/dist/welfareAT/public/common.js
- m.cuda####.com/dist/welfareAT/public/extend.css
- m.cuda####.com/dist/welfareAT02/public/lib/conf/actConf.js
- m.cuda####.com/dist/wheelModel/images/cry@2x.png
- m.cuda####.com/dist/wheelModel/images/top.png
- m.cuda####.com/dist/wheelModel/js/awardRotate.js
- m.cuda####.com/distt/newwheel/show/img/coin.png
- m.cuda####.com/distt/newwheel/show/img/hb-down.png
- m.cuda####.com/distt/newwheel/show/img/hb-up.png
- m.cuda####.com/distt/newwheel/show/wheel13174.html?business=####&appkey=...
- wn.pos.b####.com/adx.php?c=####&ext=####
- api.map.b####.com/location/ip?ak=####&coor=####
- c####.360.cn/stra_packet
- c.appj####.com/ad/splash/stats.html
- /data/data/####/.jg.ic
- /data/data/####/.jgrpa.xml
- /data/data/####/.log.lock
- /data/data/####/.log.rpa
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/ad_show_time.xml
- /data/data/####/b074efaa5e3f6ef05f73fec50c47f1c7.0.tmp
- /data/data/####/b074efaa5e3f6ef05f73fec50c47f1c7.1.tmp
- /data/data/####/cn.ecook.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/index
- /data/data/####/info.xml
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/journal.tmp
- /data/data/####/libjiagu1894981982.so
- /data/data/####/log.android.library.xml
- /data/data/####/lonLat.xml
- /data/data/####/multidex.version.xml
- /data/data/####/um_pri.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- chmod 755 <Package Folder>/.jiagu/libjiagu1894981982.so
- ls /
- ls /sys/class/thermal
- libjiagu1894981982
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- RSA
- RSA-ECB-PKCS1Padding
- AES-ECB-PKCS5Padding