Technical information
- Android.BankBot.563.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) rr3---s####.g####.com:443
- TCP(TLS/1.0) rr5---s####.g####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) 51.2####.96.208:9001
- TCP(TLS/1.0) raw.githubu####.com:443
- TCP(TLS/1.0) 1####.70.43.76:9001
- TCP(TLS/1.0) 8####.7.14.253:443
- TCP(TLS/1.2) 1####.251.36.46:443
- TCP(TLS/1.2) 1####.217.168.238:443
- TCP(TLS/1.2) 1####.217.168.195:443
- TCP(TLS/1.2) www.google####.com:443
- UDP rr5---s####.g####.com:443
- UDP rr3---s####.g####.com:443
- UDP www.google####.com:443
- and####.google####.com
- gmscomp####.google####.com
- newdb7v####.o####.8.####.8
- newdb7v####.onion
- p####.google####.com
- raw.githubu####.com
- rr3---s####.g####.com
- rr3---s####.g####.com
- rr5---s####.g####.com
- www.google####.com
- raw.githubu####.com:443/dyd1y/tor-files/main/all_tor.zip
- /data/data/####/all_tor.zip
- /data/data/####/bridges.txt
- /data/data/####/control.txt
- /data/data/####/control.txt.tmp
- /data/data/####/control_auth_cookie
- /data/data/####/control_auth_cookie.tmp
- /data/data/####/geoip
- /data/data/####/geoip6
- /data/data/####/lock
- /data/data/####/obfs4proxy.so
- /data/data/####/org.torproject.android_preferences.xml
- /data/data/####/pref_name_setting.xml
- /data/data/####/prefs30.xml
- /data/data/####/qtAD.dex
- /data/data/####/qtAD.dex.flock (deleted)
- /data/data/####/qtAD.json
- /data/data/####/state.tmp
- /data/data/####/tor.so
- /data/data/####/torrc
- /data/data/####/torrc.custom
- /system/lib/arm/houdini <Package Folder>/files/tor_source/tor.so <Package Folder>/files/tor_source/tor.so DataDirectory <Package Folder>/app_data --defaults-torrc <Package Folder>/files/tor_source/torrc -f <Package Folder>/files/tor_source/torrc.custom
- /system/lib/arm/houdini <Package Folder>/files/tor_source/tor.so <Package Folder>/files/tor_source/tor.so DataDirectory <Package Folder>/app_data --defaults-torrc <Package Folder>/files/tor_source/torrc -f <Package Folder>/files/tor_source/torrc.custom --verify-config
- busybox kill -9 4058
- busybox killall -9 tor.so
- kill -9 4058
- toolbox kill -9 4058
- toolbox ps