Technical information
- Android.Backdoor.481.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.171.131.73:80
- TCP(HTTP/1.1) 1####.171.131.72:80
- TCP(HTTP/1.1) s.nin####.cn:80
- TCP(HTTP/1.1) a####.u####.com.####.com:80
- TCP(HTTP/1.1) img.nin####.cn:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.2) 1####.217.168.202:443
- TCP(TLS/1.2) 1####.250.179.202:443
- TCP(TLS/1.2) 2####.58.208.99:443
- TCP(TLS/1.2) 1####.250.179.174:443
- a####.u####.com
- and####.google####.com
- android####.go####.com
- b.nin####.cn
- c.nin####.cn
- img.nin####.cn
- instant####.google####.com
- loc.map.b####.com
- md####.google####.com
- p.nin####.cn
- s.nin####.cn
- www.gst####.com
- img.nin####.cn/dat/b/1.0.5/12.dat
- img.nin####.cn/dat/p/2.1.6/12.dat
- a####.u####.com.####.com/app_logs
- loc.map.b####.com/sdk.php
- s.nin####.cn/admin/bcp.action?requestId=####
- s.nin####.cn/admin/nbad.action
- s.nin####.cn/admin/sc.action?requestId=####
- s.nin####.cn/admin/scs.action?requestId=####
- /data/data/####/.imprint
- /data/data/####/1.dex
- /data/data/####/1.dex.flock (deleted)
- /data/data/####/1.jar
- /data/data/####/13.dex
- /data/data/####/13.dex.flock (deleted)
- /data/data/####/13.jar
- /data/data/####/14.dex
- /data/data/####/14.dex.flock (deleted)
- /data/data/####/14.jar
- /data/data/####/15.dex
- /data/data/####/15.dex.flock (deleted)
- /data/data/####/15.jar
- /data/data/####/2.dex
- /data/data/####/2.dex.flock (deleted)
- /data/data/####/2.jar
- /data/data/####/9j_recommend.xml
- /data/data/####/Alvin2.xml
- /data/data/####/AppStore.xml
- /data/data/####/ContextData.xml
- /data/data/####/UMENG_RUNTIME_CACHE.xml
- /data/data/####/UTMCBase.xml
- /data/data/####/agoo.pid
- /data/data/####/bigPoins.xml
- /data/data/####/box_cp_states.xml
- /data/data/####/boxcpdownloads
- /data/data/####/boxcpdownloads-journal
- /data/data/####/cachetimesha_sidebar.xml
- /data/data/####/dim.xml
- /data/data/####/down.db
- /data/data/####/down.db-journal
- /data/data/####/mid.xml
- /data/data/####/mobclick_agent_online_setting_com.ubtdwican.app...em.xml
- /data/data/####/proc_auxv
- /data/data/####/rs.xml
- /data/data/####/running_app_name.xml
- /data/data/####/s_update.xml
- /data/data/####/type.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/xy.xml
- /data/media/####/.cuid
- /data/media/####/1.dat
- /data/media/####/12.dat
- /data/media/####/783280468.tmp (deleted)
- /data/media/####/783280469.tmp (deleted)
- /data/media/####/783280470.tmp (deleted)
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/MID.DAT
- /data/media/####/conlts.dat
- /data/media/####/d.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/names.dat
- /data/media/####/packgename.txt
- /data/media/####/share.dat
- /data/misc/####/primary.prof
- AES-CBC-PKCS5Padding
- DES
- AES-CBC-PKCS5Padding
- DES