Техническая информация
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) cp.ads.8l####.com:80
- TCP(HTTP/1.1) 1####.55.28.235:80
- TCP(HTTP/1.1) c####.360.cn:80
- TCP(HTTP/1.1) 1####.26.247.23:80
- TCP(HTTP/1.1) t####.zhiz####.com:80
- TCP(HTTP/1.1) log.yex.yo####.com:80
- TCP(HTTP/1.1) cm.adi####.com:80
- TCP(HTTP/1.1) s####.tc.qq.com:80
- TCP(HTTP/1.1) dl.lian####.com:80
- TCP(HTTP/1.1) ap####.adi####.com:80
- TCP(HTTP/1.1) p####.tc.qq.com:80
- TCP(HTTP/1.1) a.e####.cn:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) api.mo####.com:80
- TCP(HTTP/1.1) na61-####.wagbr####.adverti####.####.com:80
- TCP(HTTP/1.1) ad-sh-s####.wagbr####.t####.####.com:80
- TCP(HTTP/1.1) adalli####.zmen####.com:80
- TCP(HTTP/1.1) u####.bfsspad####.8l####.com:80
- TCP(HTTP/1.1) dsp.zhiz####.com:80
- TCP(HTTP/1.1) rcv.a####.com:80
- TCP(HTTP/1.1) t####.cor####.com:80
- TCP(HTTP/1.1) dsp.tou####.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(HTTP/1.1) 1####.31.213.162:80
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) api.jo####.com:80
- TCP(HTTP/1.1) 47.97.2####.214:80
- TCP(HTTP/1.1) api.map.b####.com:80
- TCP(HTTP/1.1) s####.zt####.com:80
- TCP(HTTP/1.1) app.mijia####.com:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(HTTP/1.1) o####.ad####.cn:80
- TCP(HTTP/1.1) t####.r####.com:80
- TCP(TLS/1.0) 1####.t####.com:443
- TCP(TLS/1.0) dsp.tou####.com:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) s####.e.qq.com:443
- 1####.t####.com
- a.e####.cn
- adalli####.zmen####.com
- ap####.adi####.com
- api.e####.cn
- api.jo####.com
- api.map.b####.com
- api.mo####.com
- app.mijia####.com
- c####.360.cn
- c####.t####.com
- c.appj####.com
- cm.adi####.com
- cp.ads.8l####.com
- dl.lian####.com
- dsp.tou####.com
- dsp.zhiz####.com
- ef-dong####.t####.com
- imgc####.qq.com
- log.yex.yo####.com
- mi.g####.qq.com
- o####.ad####.cn
- p####.ugd####.com
- plb####.u####.com
- rcv.a####.com
- rd####.t####.com
- s####.e.qq.com
- s####.zt####.com
- ssl.google-####.com
- t####.cor####.com
- t####.r####.com
- t####.zhiz####.com
- u####.bfsspad####.8l####.com
- u####.u####.com
- wn.pos.b####.com
- a.e####.cn/public/getClickUrlPoList.shtml?lng=####&sd=####&screenheight=...
- a.e####.cn/public/isDebugAd.shtml?ts=####&appid=####&sign=####
- a.e####.cn/public/rab.shtml?id=####&network=####&machine=####
- a.e####.cn/public/showUrlVisit.shtml?os=####&osversion=####&appversion=#...
- ad-sh-s####.wagbr####.t####.####.com/cm?e=####&k=####
- adalli####.zmen####.com/zmtmobads/v1/impl.do?param=####
- ap####.adi####.com/tj?key=####&rd=####&req=####&token=####
- ap####.adi####.com/tj?key=####&rd=####&req=YWR####&token=####
- api.jo####.com/phone/notify.php?act=####&log=dsp####&uniplayid=####&rid=...
- api.mo####.com/stat?advertiser_ad_size=####&advertiser_id=####&log_event...
- app.mijia####.com/ad/show?adtype=####&uid=####&adid=####&adclass=####&os...
- cm.adi####.com/?t=####&d=####&k=####&rd=####&c=####&code=####&pcode=####...
- cp.ads.8l####.com/adShow?v=####&b=####&i=####&r=####&bid=####&p=####&l=#...
- dl.lian####.com/download/ad/jrtt-zhixiao20.apk
- dsp.tou####.com/api/ruangao/ads/click?extra=Z####
- dsp.tou####.com/api/ruangao/ads/show?extra=####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=8####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=9####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=C####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=H####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=I####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=K####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=Q####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=T####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=U####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=c####&price=####
- dsp.tou####.com/api/ruangao/ads/show?extra=r####&price=####
- dsp.zhiz####.com/track/pixel?op=####&ct=####&price=####&ext=####
- log.yex.yo####.com/it?yexi=####&yexcb=####&yext=####&yexv=####&iid=####&...
- log.yex.yo####.com/it?yexi=####&yexv=####&yexcb=####&sid=####
- mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
- na61-####.wagbr####.adverti####.####.com/tf?e=tZdSapAwqNwHcrC6nH2QVnuIYO...
- na61-####.wagbr####.adverti####.####.com/trd?f=####&k=####&p=####&pvid=#...
- o####.ad####.cn/agent/openDisplay.do?st=####&uuidEncType=####&sv=####&sr...
- p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
- rcv.a####.com/show?CAAQFw.####
- s####.tc.qq.com/gdt/0/DAAVUSmAKAAPAABgBbh5RfCsdVt9OO.jpg/0?ck=####
- s####.zt####.com/s.gif?adx=####&s=####&plat_id=####&b=djNfd####&mprice=#...
- t####.cor####.com//tj?bid=####&id=####&ua=####&ip=####&m=####&n=####&clk...
- t####.cor####.com/tj?bid=####&id=####&ua=####&ip=####&m=####&imp=####
- t####.cor####.com/tj?bid=####&id=####&ua=####&ip=####&m=####&n=####&imp=...
- t####.r####.com/trace/cm?et=####&e=H4sIA####
- t####.zhiz####.com/mad.do?zzat=####&siteid=####&zzid=####&pr=####&adx=##...
- u####.bfsspad####.8l####.com/adClick?v=####&b=####&st=####&p=####&g=####...
- u####.bfsspad####.8l####.com/adShow?v=####&b=####&i=####&r=####&bid=####...
- u####.bfsspad####.8l####.com/dplClick?v=####&b=####&st=####&p=####&g=###...
- wn.pos.b####.com/adx.php?c=####
- wn.pos.b####.com/adx.php?c=####&ext=####
- api.map.b####.com/location/ip?ak=####&coor=####
- c####.360.cn/stra_packet
- c.appj####.com/ad/splash/stats.html
- s####.e.qq.com/activate
- s####.e.qq.com/launch
- s####.e.qq.com/msg
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgrpa.xml
- /data/data/####/.log.lock
- /data/data/####/.log.rpa
- /data/data/####/27af684a04c1f71bc8b08e0c8d2f6215.xml
- /data/data/####/2944.yaqcookie
- /data/data/####/3057.yaqcookie
- /data/data/####/3187.yaqcookie
- /data/data/####/3311.yaqcookie
- /data/data/####/3458.yaqcookie
- /data/data/####/3559.yaqcookie
- /data/data/####/3660.yaqcookie
- /data/data/####/3812.yaqcookie
- /data/data/####/3912.yaqcookie
- /data/data/####/4011.yaqcookie
- /data/data/####/4158.yaqcookie
- /data/data/####/4259.yaqcookie
- /data/data/####/4348.yaqcookie
- /data/data/####/4480.yaqcookie
- /data/data/####/475397accde5ab46da3b89f2a5e6e964.temp
- /data/data/####/AdloadStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/ContextData.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/Ji.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/ad_show_time.xml
- /data/data/####/cn.ecook.xml
- /data/data/####/collectiondatabase
- /data/data/####/collectiondatabase-journal
- /data/data/####/com.google.android.gms.analytics.prefs.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNTg5MTA0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNTk1MjM5;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNTk2MjMx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNTkwNDEw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNTkxNTYz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjA3NzQ3;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjAwNjc5;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjE0NTc2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjEyMTUx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjI0MDUz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjI3MTU0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjI5Mzcz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjIwNjI0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjM0Nzg5;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjM3MTYz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjMyNzYx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjQ1MDIw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjQ4MjMz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjQwNjU1;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxODMwNjQyOTAx;
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/dexMethod.82894129.dat
- /data/data/####/ecookdatabase
- /data/data/####/ecookdatabase-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000002 (deleted)
- /data/data/####/gaClientId
- /data/data/####/gdt_config.cfg
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_stat.db
- /data/data/####/gdt_stat.db-journal
- /data/data/####/gdt_suid
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/i==1.2.0&&4.31.50_1541830589146_envelope.log
- /data/data/####/i==1.2.0&&4.31.50_1541830620622_envelope.log
- /data/data/####/i==1.2.0&&4.31.50_1541830649335_envelope.log
- /data/data/####/index
- /data/data/####/info.xml
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/libjiagu2063946030.so
- /data/data/####/libyaqbasic.82894129.so
- /data/data/####/libyaqpro.82894129.so
- /data/data/####/log.android.library.xml
- /data/data/####/lonLat.xml
- /data/data/####/multidex.version.xml
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/update_lc
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/yaqsdkcookie
- /data/media/####/.a.dat
- /data/media/####/.adfwe.dat
- /data/media/####/.cca.dat
- /data/media/####/.nomedia
- /data/media/####/.umm.dat
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/sysid.dat
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- cat /sys/class/net/wlan0/address
- ls /sys/class/thermal
- libjiagu2063946030
- libyaqbasic.82894129
- libyaqpro.82894129
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding