Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) poll-di####.cooteks####.com:80
- UDP(NTP) 1.cn.p####.####.org:123
- 1.cn.p####.####.org
- i####.cn
- pg.x####.com
- poll-di####.cooteks####.com
- se####.wos####.cn
- un####.wos####.cn
- unipa####.wos####.cn
- poll-di####.cooteks####.com/dualsim/appkey_dsi?appkey=####&host=####&man...
- /data/data/####/4.8.0M2111B0715_resource_400.apk
- /data/data/####/TD_app_pefercen_profile.xml
- /data/data/####/TDpref_longtime.xml
- /data/data/####/TDpref_shorttime.xml
- /data/data/####/TDtcagent.db
- /data/data/####/TDtcagent.db-journal
- /data/data/####/app_crash_11cec77f6d335b6c354514841f8ace60.txt
- /data/data/####/app_crash_1d824494aa5d311449c3b81ddc3eea96.txt
- /data/data/####/app_crash_5334943d7ca2edab52526e1a66d61c46.txt
- /data/data/####/app_crash_714fadbe5fb56f1813f0346ec1d271a6.txt
- /data/data/####/app_crash_7bdfaba1ccf081b04068e2b690852fcf.txt
- /data/data/####/app_crash_8730c15cfd81af379f1152d18d7c2e9b.txt
- /data/data/####/app_crash_8e87a76aaa14476b09d9c5a89065af39.txt
- /data/data/####/app_crash_a1b6ef3693e239bb87892c3cb8c3e25e.txt
- /data/data/####/app_crash_ac3f5156da050aeb7083019a09d4c58d.txt
- /data/data/####/app_crash_c49653df91f18439a5dd827cb65479a4.txt
- /data/data/####/app_crash_e1da0309b335766217563f9ed29e5141.txt
- /data/data/####/libjiagu-1022106304.so
- /data/data/####/libonlywechat_plugin.so
- /data/data/####/local.jar
- /data/data/####/login
- /data/data/####/msg_store.xml
- /data/data/####/oppo_game_service_232.apk_temp
- /data/data/####/plugin_framework.xml
- /data/data/####/plugin_framework.xml.bak
- /data/data/####/sdk_load_info.xml
- /data/data/####/talkingdata_app.db-journal
- /data/data/####/talkingdata_app_process_preferences_file
- /data/data/####/talkingdata_app_version_preferences_file
- /data/data/####/td.lock
- /data/data/####/tdid.xml
- /data/data/####/unicom_cl.xml
- /data/data/####/wwoclasses.dex
- /data/data/####/wwoclasses.dve
- /data/data/####/wwoclasses.jar
- /data/media/####/.tcookieid
- /data/media/####/data0.dat
- /data/media/####/data1.dat
- /data/media/####/data111.dat
- /data/media/####/dualsim.dat
- chmod 755 <Package Folder>/.jiagu/libjiagu-1022106304.so
- netstat -apn
- libjiagu-1022106304
- me_unipay
- megjb
- AES-CBC-PKCS7Padding
- DESede-CBC-NoPadding
- AES-CBC-PKCS7Padding
- DESede-CBC-NoPadding
- RSA-ECB-PKCS1Padding