Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) poll-di####.cooteks####.com:80
- TCP(HTTP/1.1) un####.wos####.cn:8061
- TCP(TLS/1.0) 1####.217.17.110:443
- poll-di####.cooteks####.com
- se####.wos####.cn
- sw####.j####.com.cn
- un####.wos####.cn
- unipa####.wos####.cn
- poll-di####.cooteks####.com/dualsim/appkey_dsi?appkey=####&host=####&man...
- un####.wos####.cn:8061/logserver/wostore/logCrash
- /data/anr/traces.txt
- /data/data/####/4.6.0L2111B1010_resource_400.apk
- /data/data/####/app_crash_c7b46f2d12e68c313804eb19fc549cfb.txt
- /data/data/####/local.jar
- /data/data/####/login
- /data/data/####/msg_store.xml
- /data/data/####/sdk_load_info.xml
- /data/data/####/sdkclasses.dex
- /data/data/####/sdkclasses.dve
- /data/data/####/sdkclasses.jar
- /data/data/####/sg.dex
- /data/data/####/sg.dex (deleted)
- /data/data/####/unicom_cl.xml
- /data/media/####/data0.dat
- /data/media/####/data1.dat
- /data/media/####/data111.dat
- /data/media/####/dualsim.dat
- netstat -apn
- gdxbase
- me_unipay
- DESede-CBC-NoPadding
- DESede-CBC-NoPadding
- RSA-ECB-PKCS1Padding