Technical information
- Android.CoinSteal.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) bea####.gcp.g####.com:443
- TCP(TLS/1.0) 64.2####.163.94:443
- TCP(TLS/1.0) f####.l####.net:443
- TCP(TLS/1.2) 64.2####.163.94:443
- TCP(TLS/1.2) 1####.177.14.103:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 64.2####.164.139:443
- UDP bea####.gcp.g####.com:443
- UDP 74.1####.205.101:443
- and####.b####.qq.com
- and####.google####.com
- android####.go####.com
- bea####.gcp.g####.com
- f####.l####.net
- gmscomp####.google####.com
- p####.google####.com
- rr2---s####.g####.com
- www.gst####.com
- and####.b####.qq.com/rqd/async?aid=####
- /data/data/####/1
- /data/data/####/1004
- /data/data/####/2
- /data/data/####/3
- /data/data/####/4
- /data/data/####/75ad21e28b1d7c47_0 (deleted)
- /data/data/####/Cookies-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/bugly_db_-journal
- /data/data/####/crashrecord.xml
- /data/data/####/fcjcic.gjcbcd_preferences.xml
- /data/data/####/index
- /data/data/####/keepAliveSpFileMulti.xml
- /data/data/####/littleproxy-mitm.p12
- /data/data/####/littleproxy-mitm.pem
- /data/data/####/local_crash_lock
- /data/data/####/metrics_guid
- /data/data/####/saveData.xml
- /data/data/####/security_info
- /data/data/####/temp-index
- /data/data/####/the-real-index
- /data/media/####/fcjcicgjcbcd_main.js
- /data/misc/####/primary.prof
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- getprop
- 1
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- 1
- AES-CBC-PKCS5Padding
- AES-GCM-NoPadding