Техническая информация
- Android.RemoteCode.88.origin
- Android.Xiny.197
- Android.Xiny.244.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.cu####.com:80
- TCP(HTTP/1.1) www.zfr####.com:80
- www.cu####.com
- www.zfr####.com
- www.cu####.com/20180530155843.BdJar521Dex_05301557.zip
- www.zfr####.com/up.do
- /data/data/####/backw
- /data/data/####/cn_rs.xml
- /data/data/####/com.ort.kp_preferences.xml
- /data/data/####/d.zip
- /data/data/####/dtemp.apk
- /data/data/####/lib_v19n.dat
- /data/data/####/m_cfg.xml
- /data/data/####/mesosphere_v19n.jar
- /data/data/####/ob3.zip
- /data/data/####/t_ini.xml
- /data/media/####/pid
- /data/media/####/sp
- app_process /system/bin com.android.commands.am.Am startservice --user 0 -n <Package>/com.zon.qoo.MS
- chmod 777 <Package Folder>/backw
- dd if=<Package Folder>/lib/libbackw.so of=<Package Folder>/backw
- sh
- backw
- AES-ECB-PKCS5Padding
- AES
- AES-ECB-PKCS5Padding