Technical information
- Android.Backdoor.478.origin
- Android.SmsBot.620.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) t.e####.com:80
- TCP(HTTP/1.1) t.pk####.com:80
- TCP(HTTP/1.1) 1####.26.6.37:443
- TCP(HTTP/1.1) ip####.io:80
- TCP(HTTP/1.1) g.i####.com:80
- TCP(HTTP/1.1) t.wq####.com:80
- TCP(HTTP/1.1) t.pl####.com:80
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) 1####.251.36.42:443
- TCP(TLS/1.0) 1####.26.6.37:443
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) 1####.217.17.46:443
- TCP(TLS/1.2) 1####.251.36.3:443
- TCP(TLS/1.2) 1####.217.17.46:443
- UDP 1####.217.168.202:443
- android####.go####.com
- api.zkwt####.com
- api.zkwt####.com.####.8
- g.i####.com
- ip####.io
- md####.google####.com
- t.e####.com
- t.pk####.com
- t.pl####.com
- t.wq####.com
- www.hugedom####.com
- ip####.io/json
- 1####.26.6.37:443/domain_profile.cfm?d=####&e=####
- g.i####.com/pilot/api/300102
- t.e####.com/ggview/rsddateindex
- t.pk####.com/ggview/rsddateindex
- t.pl####.com/ggview/rsddateindex
- t.wq####.com/ggview/rsddateindex
- /data/data/####/BOOST.xml
- /data/data/####/i.apk
- /data/data/####/i.dex
- /data/data/####/i.dex.flock (deleted)
- /data/data/####/mobclick_agent_state_wld.tcf.snl.xml
- /data/data/####/name.apk
- /data/data/####/name.dex
- /data/data/####/name.dex.flock (deleted)
- /data/data/####/wld.tcf.snl_preferences.xml
- chmod 755 /data/user/0/<Package>/files/i.apk
- AES-CBC-NoPadding