Technical information
- Android.Backdoor.627.origin
- Android.Click.272.origin
- Android.Triada.110
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) rr16---####.g####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 1####.217.23.99:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 1####.217.23.99:443
- and####.a####.go####.com
- and####.b####.qq.com
- and####.google####.com
- bcd.lk####.com
- gmscomp####.google####.com
- p####.google####.com
- pla####.google####.com
- rr16---####.g####.com
- www.google####.com
- and####.b####.qq.com/rqd/async?aid=####
- /data/data/####/0.xml
- /data/data/####/1004
- /data/data/####/1022016403.dex
- /data/data/####/1022016403.dex.flock (deleted)
- /data/data/####/1022016403.jar
- /data/data/####/1525248626431
- /data/data/####/217571125.dex
- /data/data/####/217571125.dex.flock (deleted)
- /data/data/####/217571125.jar
- /data/data/####/34465809.dex
- /data/data/####/34465809.dex.flock (deleted)
- /data/data/####/34465809.jar
- /data/data/####/492663497.apk
- /data/data/####/492663497.dex
- /data/data/####/492663497.dex.flock (deleted)
- /data/data/####/50235029.dex
- /data/data/####/50235029.dex.flock (deleted)
- /data/data/####/50235029.jar
- /data/data/####/669636817.dex
- /data/data/####/669636817.dex.flock (deleted)
- /data/data/####/669636817.jar
- /data/data/####/702969806.dex
- /data/data/####/702969806.dex.flock (deleted)
- /data/data/####/702969806.jar
- /data/data/####/XNJ.xml
- /data/data/####/base.so
- /data/data/####/bugly_db_-journal
- /data/data/####/crashrecord.xml
- /data/data/####/global.xml
- /data/data/####/hotpatch.data
- /data/data/####/libva-native.so
- /data/data/####/libzuma.so
- /data/data/####/libzuma2.so
- /data/data/####/libzuma2.so.0.so
- /data/data/####/libzumadata.so
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/logRecord
- /data/data/####/mouse
- /data/data/####/proc_auxv
- /data/data/####/security_info
- /data/data/####/test.dex
- /data/data/####/userlist.xml
- /data/media/####/1c072118d5311d5ad9eec2812aff3a38.xml
- /data/media/####/1c072118d5311d5ad9eec2812aff3a38.xml.bak
- /data/media/####/3c43ed0a071df85904c49ded7e644916.xml
- /data/media/####/3c43ed0a071df85904c49ded7e644916.xml.bak
- /data/media/####/42f6acb2029626386be083159cf97fbb.xml
- /data/media/####/439a8870f6e94cf9b9b80fb0db422a02.xml
- /data/media/####/439a8870f6e94cf9b9b80fb0db422a02.xml.bak
- /data/media/####/5c2c15d6ef6a961c570787a051029119.xml
- /data/media/####/5c2c15d6ef6a961c570787a051029119.xml.bak
- /data/media/####/bbc58a575b5bd0863b3c4b71bc01bb0b.xml
- /data/misc/####/primary.prof
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- getprop
- base
- libva-native
- libzuma
- libzuma2.so.0
- AES-GCM-NoPadding
- Des-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-GCM-NoPadding
- DES-ECB-NoPadding
- Des-ECB-NoPadding