Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sd####.cm####.com:80
- TCP(HTTP/1.1) 1####.199.251.172:80
- TCP(HTTP/1.1) 1####.159.18.80:8000
- TCP(HTTP/1.1) ga####.lotu####.com:80
- TCP(HTTP/1.1) wap.cm####.com:7758
- TCP(HTTP/1.1) app####.m####.cn:8080
- TCP(HTTP/1.1) 1####.159.18.80:8001
- TCP(HTTP/1.1) sw####.j####.com.cn:8080
- TCP(HTTP/1.1) drm.cm####.com:80
- TCP(HTTP/1.1) 2####.111.8.140:8080
- TCP(HTTP/1.1) ga####.lotu####.com:88
- TCP(HTTP/1.1 Host: switch.jssg.com.cn Content-Type: text/html ) sw####.j####.com.cn:8080
- TCP(HTTP/1.1 Host: switch.jssg.com.cn Content-Type: text/html ) 1####.230.22.208:8080
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP 1####.62.78.26:19999
- Aser####.1####.cn
- adser####.go####.com
- api.miguv####.com
- app####.m####.cn
- drm.cm####.com
- edu.1####.cn
- g####.g####.net
- ga####.lotu####.com
- mt####.go####.com
- on####.lotu####.com
- sd####.cm####.com
- ssl.gst####.com
- sw####.j####.com.cn
- wap.cm####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- 1####.230.22.208:8080/WebTest/gameNofity
- drm.cm####.com/egsb/game/getclientProvince?tel=####&iccid=####&imsi=####
- drm.cm####.com/egsb/startup/queryConfiguration?channelId=####&contentId=...
- drm.cm####.com/egsb/verification/checkSDKModuleUpdate?sdkVersion=####&co...
- sw####.j####.com.cn:8080/WebTest/Query?gid=####&vid=####&ch=####&iccid=#...
- app####.m####.cn:8080/migusdk/tl/tcttl
- app####.m####.cn:8080/migusdk/verification/checkSdkUpdate
- drm.cm####.com/egsb/dataPlan/privateSwith
- drm.cm####.com/egsb/discount/getPreQueryResult
- drm.cm####.com/egsb/game/getPaymentCapability
- drm.cm####.com/egsb/gshare/switches
- drm.cm####.com/egsb/message/queryPushMessages
- drm.cm####.com/egsb/otherPay/querySMSInterceptorConf
- drm.cm####.com/egsb/thirdPay/queryThirdPayInfo
- ga####.lotu####.com/?st=####&sv=####&tm=####&sid=Jzc####&apn=####&ct=###...
- ga####.lotu####.com:88/?mid=####&st=####&sv=####&tm=####&sid=Jzc####&apn...
- sd####.cm####.com/behaviorLogging/eventLogging/accept?
- sw####.j####.com.cn:8080/WebTest/DataSubmit
- wap.cm####.com:7758/normandie/QueryConfigPolicy
- /data/data/####/0CDJ
- /data/data/####/0CDJ.dex
- /data/data/####/0CDJ.jar
- /data/data/####/2071.dex
- /data/data/####/2071.dex (deleted)
- /data/data/####/2174.dex
- /data/data/####/ED.ini
- /data/data/####/MiguPay.Sdk30.Lib_12003049_2b7f4055276371c21c62...02.cod
- /data/data/####/MiguPay.Sdk30.Lib_12003049_2b7f4055276371c21c62...02.dat
- /data/data/####/abc.dex
- /data/data/####/abc.jar
- /data/data/####/abc.jar.temp
- /data/data/####/abc.jpg
- /data/data/####/abc.jpg.temp
- /data/data/####/abc.jpg.temp (deleted)
- /data/data/####/action.lst
- /data/data/####/libmgRun_05.22.09_01.so
- /data/data/####/libmiguED.so
- /data/data/####/lotuseed.apps
- /data/data/####/lotuseed.lock
- /data/data/####/lotuseed.s
- /data/data/####/lotuseed_global.xml
- /data/data/####/lotuseed_main.xml
- /data/data/####/mgAS.dat
- /data/data/####/mgSS.dat
- /data/data/####/mgid.dat
- /data/data/####/miguGameBillingRequestMonitor.xml
- /data/data/####/sdk_prefs
- /data/data/####/sg.dex
- /data/data/####/sg.dex (deleted)
- /data/data/####/sg_game.dex
- /data/data/####/sg_game.dex (deleted)
- /data/data/####/xcngame.xml
- /data/media/####/ShareData.txt
- /data/media/####/deviceId
- /data/media/####/lotuseed.devid
- /data/media/####/pushDB.txt
- /data/media/####/pushTime.txt
- /data/media/####/pushTotal.txt
- /data/media/####/sdk_prefs.txt
- chmod 777 <Package Folder>/files/abc.jar
- ps
- gdx
- libmiguED
- megjb
- sg
- AES-CBC-PKCS5Padding
- DES-ECB-PKCS5Padding
- AES-CBC-PKCS5Padding
- DES-CBC-PKCS5Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding