Technical information
- Android.Backdoor.293.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) drm.cm####.com:80
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 64.2####.161.94:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) rr5---s####.g####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.2) p####.google####.com:443
- UDP rr18---####.g####.com:443
- UDP rr2---s####.g####.com:443
- UDP p####.google####.com:443
- UDP rr5---s####.g####.com:443
- and####.a####.go####.com
- and####.google####.com
- drm.cm####.com
- g####.g####.net
- g####.g####.net.####.8
- gmscomp####.google####.com
- m####.go####.com
- p####.google####.com
- pla####.google####.com
- rr18---####.g####.com
- rr2---s####.g####.com
- rr5---s####.g####.com
- rr9---s####.g####.com
- www.google####.com
- drm.cm####.com/egsb/authentication/getclientTel
- /data/data/####/MiguPay.Sdk20.Lib_26002_344EAA6187C551BFE03C528...A2.dat
- /data/data/####/appsdkmg0_.dex
- /data/data/####/appsdkmg0_.dex.flock (deleted)
- /data/data/####/appsdkmg0_.jar
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/jacruntime.dex
- /data/data/####/jacruntime.dex.flock (deleted)
- /data/data/####/libjiagu.so
- /data/data/####/libmiguED.so
- /data/data/####/mg20css.dat
- /data/data/####/mg20dss.dat
- /data/data/####/mg20irid.dat
- /data/data/####/proc_auxv
- /data/data/####/sdk_prefs
- /data/media/####/ShareData.txt
- /data/media/####/deviceId.txt
- /data/media/####/msgflag.txt
- /system/bin/sh
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- ls -l /sbin/su
- ls -l /sbin/su 2>&1
- ls -l /system/bin/su
- ls -l /system/sbin/su
- ls -l /system/xbin/su
- ls -l /vendor/bin/su
- libjiagu
- libmegjb
- libmg20p_03.08.01_01
- libmg20pbase
- libmiguED
- mg20pbase
- DES-ECB-PKCS5Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding