Technical information
- Android.Backdoor.564.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) nav.cn.ron####.com:80
- TCP(TLS/1.0) s####.cn.ron####.com:443
- TCP 1####.46.25.202:7007
- TCP 1####.92.22.206:8618
- UDP s.j####.cn:19000
- TCP 4####.90.84.229:7003
- ga####.lotu####.com
- nav.cn.ron####.com
- s####.cn.ron####.com
- s####.j####.cn
- s.j####.cn
- www.tha####.me
- nav.cn.ron####.com/navipush.json
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_lib/####/push_daemon
- <Package Folder>/cache/####/journal.tmp
- <Package Folder>/databases/jpush_local_notification.db
- <Package Folder>/databases/jpush_local_notification.db-journal
- <Package Folder>/databases/jpush_statistics.db
- <Package Folder>/databases/jpush_statistics.db-journal
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/INSTALLATION
- <Package Folder>/files/appPackageNames
- <Package Folder>/files/lotuseed.apps
- <Package Folder>/files/lotuseed.lock
- <Package Folder>/files/lotuseed.s
- <Package Folder>/files/lotuseed.task
- <Package Folder>/shared_prefs/COUNTLY_STORE.xml
- <Package Folder>/shared_prefs/RongPush.xml
- <Package Folder>/shared_prefs/Statistics.xml
- <Package Folder>/shared_prefs/cn.jpush.android.user.profile.xml
- <Package Folder>/shared_prefs/cn.jpush.preferences.v2.xml
- <Package Folder>/shared_prefs/config.xml
- <Package Folder>/shared_prefs/jpush_device_info.xml
- <Package Folder>/shared_prefs/lotuseed_global.xml
- <Package Folder>/shared_prefs/lotuseed_main.xml
- <Package Folder>/shared_prefs/multidex.version.xml
- <SD-Card>/.system/lotuseed.devid
- <SD-Card>/Android/####/10-24.txt
- <SD-Card>/Android/####/RongLog.log
- <SD-Card>/data/.push_deviceid
- /system/bin/chmod 777 <Package Folder>/app_lib/x86/push_daemon
- <Package Folder>/app_lib/x86/push_daemon <Package> io.rong.push.PushService /storage/emulated/0/.rongLock
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- ps
- RongIMLib
- jcore100
- libjiagu
- push