Technical information
- Android.Backdoor.613.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) wap####.b####.com:80
- TCP(HTTP/1.1) wap.n.sh####.com:80
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(TLS/1.0) baif####.b####.com:443
- TCP(TLS/1.0) pass####.b####.com:443
- TCP(TLS/1.0) ti####.jom####.com:443
- TCP(TLS/1.0) wap.n.sh####.com:443
- TCP(TLS/1.0) box.jom####.com:443
- TCP(TLS/1.0) hpd.b####.com:443
- a####.xctr####.com
- and####.5####.com
- baif####.b####.com
- e.b####.com
- g####.bdst####.com
- hpd.b####.com
- i####.api.eji####.com
- m.b####.com
- mo.b####.com
- pass####.b####.com
- pv.s####.com
- re####.api.eji####.com
- s.bdst####.com
- sm.b####.com
- ss0.b####.com
- ss0.bdst####.com
- ss2.b####.com
- timg####.b####.com
- wap####.b####.com
- <Package Folder>/app_lib/lib18b1cf37.so
- <Package Folder>/app_payload_lib/done
- <Package Folder>/app_payload_lib/libcrypt_sign.so
- <Package Folder>/app_workbench10090/apk.zip
- <Package Folder>/app_workbench15616/apk.zip
- <Package Folder>/cache/####/data_0
- <Package Folder>/cache/####/data_1
- <Package Folder>/cache/####/data_2
- <Package Folder>/cache/####/data_3
- <Package Folder>/cache/####/f_000001
- <Package Folder>/cache/####/f_000002
- <Package Folder>/cache/####/index
- <Package Folder>/databases/Data_sync.db-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/databases/webviewCookiesChromium.db-journal
- <Package Folder>/files/cf1e9548ffc6bfa1c88c4c4e65369dd3.apk
- <Package Folder>/files/libabc
- <Package Folder>/shared_prefs/plugin_record_app_info.xml
- <Package Folder>/shared_prefs/pref_recomm.xml
- <Package Folder>/shared_prefs/zzconfig.xml
- <SD-Card>/Android/####/com.skymobi.pay.plugin.main.data
- <SD-Card>/Android/####/com.skymobi.pay.plugin.recordupload.data
- /system/bin/netcfg
- chmod 777 <Package Folder>/app_lib/lib18b1cf37.so
- lib18b1cf37
- libabc