Техническая информация
- Android.Backdoor.657.origin
- Android.Triada.222.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) reso####.msg.xi####.net:80
- TCP(HTTP/1.1) scs.opensp####.cn:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) api.xima####.com:80
- TCP(HTTP/1.1) d####.opensp####.cn:80
- TCP(HTTP/1.1) ga####.lotu####.com:80
- TCP(HTTP/1.1) 1####.213.69.195:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) h####.opensp####.cn:80
- TCP(HTTP/1.1) ope####.mob####.360.cn:80
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(HTTP/1.1) api.snail####.com:80
- TCP(HTTP/1.1) 1####.121.48.5:80
- TCP(HTTP/1.1) ga####.lotu####.com:88
- TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
- TCP(TLS/1.0) owe.joy-r####.com:9050
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP 4####.62.94.2:443
- a####.u####.com
- and####.b####.qq.com
- api.snail####.com
- api.xima####.com
- cdn.joy-r####.com
- d####.opensp####.cn
- ga####.lotu####.com
- h####.opensp####.cn
- log.u####.com
- on####.lotu####.com
- ope####.mob####.360.cn
- owe.joy-r####.com
- regi####.xm####.xi####.com
- reso####.msg.xi####.net
- s####.u####.com
- scs.opensp####.cn
- api.snail####.com/chipsguide/www/Api/Phone/getVersion?versionnumber=####...
- api.snail####.com/cloudmusic/api/getHasCoverAd?packagename=####&language...
- api.snail####.com/cloudmusic/api/getModuleState?client_sign=####&pk_name...
- api.snail####.com/cloudmusic/api/getSnailloveCoverAd?packagename=####&la...
- d####.c####.l####.####.com/243d5c3e-13b2-4811-9d68-48c6321da2e7bdco_60028
- h####.opensp####.cn/launchconfig?t=####&p=bmdkY####
- ope####.mob####.360.cn/index/upgrade?package=####&version=####&os=####&m...
- reso####.msg.xi####.net/gslb/?ver=####&type=####&conpt=####&uuid=####&li...
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- api.xima####.com/oauth2/access_token
- d####.opensp####.cn/index.php/clientrequest/clientcollect/isCollect
- ga####.lotu####.com/?st=####&sv=####&tm=####&sid=Ijc####&apn=####&ct=###...
- ga####.lotu####.com:88/?mid=####&st=####&sv=####&tm=####&sid=Ijc####&apn...
- scs.opensp####.cn/scs?cmd=####&logver=####&size=####
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_aqPVSg3/tMS866P3hcq
- <Package Folder>/app_bird_dex/bird_plugin.dex (deleted)
- <Package Folder>/app_bird_plugin/bird_plugin.dex
- <Package Folder>/app_bird_plugin/bird_plugin.jar
- <Package Folder>/app_bird_plugin/bird_plugin.jar.sig
- <Package Folder>/app_bird_plugin/bird_plugin.tmp
- <Package Folder>/app_bird_plugin/bird_plugin.tmp.sig
- <Package Folder>/app_bird_plugin/update_lc
- <Package Folder>/app_crashrecord/1002
- <Package Folder>/app_crashrecord/1004
- <Package Folder>/databases/alarms.db-journal
- <Package Folder>/databases/bugly_db_-journal
- <Package Folder>/databases/downloader.db-journal
- <Package Folder>/databases/geofencing.db
- <Package Folder>/databases/geofencing.db-journal
- <Package Folder>/databases/ilightDB-journal
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/####/1512539958727.log
- <Package Folder>/files/.imprint
- <Package Folder>/files/<Package>;pushservice
- <Package Folder>/files/H4O783l.apk
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/lotuseed.apps
- <Package Folder>/files/lotuseed.lock
- <Package Folder>/files/lotuseed.s
- <Package Folder>/files/lotuseed.task
- <Package Folder>/files/native_record_lock
- <Package Folder>/files/security_info
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/shared_prefs/<Package>.BETA_VALUES.xml
- <Package Folder>/shared_prefs/<Package>.BETA_VALUES.xml.bak
- <Package Folder>/shared_prefs/<Package>_preferences.xml
- <Package Folder>/shared_prefs/BUGLY_COMMON_VALUES.xml
- <Package Folder>/shared_prefs/CloudPreferences.cache.xml
- <Package Folder>/shared_prefs/XMPushServiceConfig.xml
- <Package Folder>/shared_prefs/com.iflytek.id.xml
- <Package Folder>/shared_prefs/com.iflytek.msc.xml
- <Package Folder>/shared_prefs/config.xml
- <Package Folder>/shared_prefs/crashrecord.xml
- <Package Folder>/shared_prefs/ifly_launch_lib.xml
- <Package Folder>/shared_prefs/iflytek_state_<Package>.xml
- <Package Folder>/shared_prefs/jg_so_upgrade_setting.xml
- <Package Folder>/shared_prefs/lotuseed_global.xml
- <Package Folder>/shared_prefs/lotuseed_main.xml
- <Package Folder>/shared_prefs/mipush.xml
- <Package Folder>/shared_prefs/mipush_account.xml
- <Package Folder>/shared_prefs/mipush_extra.xml
- <Package Folder>/shared_prefs/mobclick_agent_online_setting_<Package>.xml
- <Package Folder>/shared_prefs/multidex.version.xml
- <Package Folder>/shared_prefs/share_data_updatesdk.xml
- <Package Folder>/shared_prefs/ting_data.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <Package Folder>/shared_prefs/umeng_socialize.xml
- <SD-Card>/.system/lotuseed.devid
- <SD-Card>/Android/####/.nomedia
- <SD-Card>/Android/####/log.lock
- <SD-Card>/Android/####/log1.txt
- <SD-Card>/BIRDDOWNLOAD/####/Badinfo.xml
- <SD-Card>/BIRDDOWNLOAD/####/YvscMPs.xml
- <SD-Card>/BIRDDOWNLOAD/####/rinsWPVPycqVPSq38.db
- <SD-Card>/BIRDDOWNLOAD/####/rinsWPVPycqVPSq38.db-journal
- <SD-Card>/BIRDDOWNLOAD/####/webinfo.xml
- <SD-Card>/iflyworkdir_test
- <SD-Card>/msc/####/u.data
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/app_aqPVSg3/tMS866P3hcq -p <Package> -s com.birdads.out.BGService -t 600
- chmod 0755 <Package Folder>/app_aqPVSg3/tMS866P3hcq
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop
- ps
- sh <Package Folder>/app_aqPVSg3/tMS866P3hcq -p <Package> -s com.birdads.out.BGService -t 600
- Bugly
- bluetoothlibrary
- libjiagu
- msc
- realm-jni
- AES-CBC-NoPadding
- AES-GCM-NoPadding
- DES-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-NoPadding
- AES-GCM-NoPadding
- DES-ECB-NoPadding