Technical information
- Android.BackDoor.985
- Android.Triada.467.origin
- Android.Xiny.287.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.200.16.77:80
- TCP(HTTP/1.1) api.bi####.com:80
- TCP(HTTP/1.1) 1####.250.131.130:80
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) api.f####.com:80
- TCP(HTTP/1.1) www.koapk####.com:8081
- TCP(TLS/1.0) and####.cli####.go####.com:443
- and####.cli####.go####.com
- api.bi####.com
- api.f####.com
- www.koapk####.com
- www.okyes####.com
- api.f####.com/co?u=####&s=####&gaid=####&imei=####&androidId=####&at=###...
- api.bi####.com/un
- www.koapk####.com:8081/sm/sr/rt/ry
- www.okyes####.com:8081/sdk/nsd.action?b=####
- /data/data/####/20160121.xml
- /data/data/####/20160121.xml.bak (deleted)
- /data/data/####/201908261150.apk
- /data/data/####/201908261150.dex
- /data/data/####/3243cbfb-a123-494c-a7e1-246f94cdf0f4.jar
- /data/data/####/3e2beafa-e71d-4d0b-aa1f-f98e3a428b81.dex (deleted)
- /data/data/####/3e2beafa-e71d-4d0b-aa1f-f98e3a428b81.jar
- /data/data/####/69636505.apk
- /data/data/####/69636505.dex
- /data/data/####/MobikokCommonConfig.xml
- /data/data/####/MobikokCommonConfig.xml.bak (deleted)
- /data/data/####/MobikokDeviceConfig.xml
- /data/data/####/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- /data/data/####/ag.xml
- /data/data/####/ba7cb514-4a99-4d9a-abb1-bbeda6d0ecae.jar
- /data/data/####/bdownloaders.db
- /data/data/####/bdownloaders.db-journal
- /data/data/####/c201908261150.apk
- /data/data/####/ja201908091350.data
- /data/data/####/libAlterHeader.so
- /data/data/####/swith1014.db
- /data/data/####/swith1014.db-journal
- /data/data/####/webview.db
- /data/data/####/webview.db-journal
- /data/media/####/Config.txt
- app_process /system/bin com.android.commands.pm.Pm path <Package>
- awk {print $9}
- grep 2146
- grep 2863
- logcat -d -v time
- ps
- sh
- com.poweralert
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding