Technical information
- Android.Backdoor.371.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP) aos.w####.y####.net:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) aos.w####.y####.net:80
- TCP(HTTP/1.1) s####.gw.y####.net:80
- TCP(HTTP/1.1) au.y####.net:80
- TCP(HTTP/1.1) down####.c####.189.cn:80
- TCP(HTTP/1.1) vdown####.c####.189.cn:80
- TCP(HTTP/1.1) pan.b####.com:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) pan.b####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) 1####.217.20.78:443
- 0.oklasnf####.d####.com
- 1.lka####.d####.com
- a####.u####.com
- adser####.go####.com
- aos.w####.y####.net
- au.y####.net
- down####.c####.189.cn
- oc.gw.y####.net
- pan.b####.com
- s####.gw.y####.net
- ssl.gst####.com
- vdown####.c####.189.cn
- www.go####.com
- www.gst####.com
- aos.w####.y####.net/v3/conf?app=####
- aos.w####.y####.net/v3/get?s=####
- au.y####.net/offer/aos/offers.manifest
- au.y####.net/offer/aos/slient.html?type=####&model=####
- au.y####.net/offer/dist/aos/global/2.0.1/global.js
- au.y####.net/offer/dist/aos/img/blank.gif
- au.y####.net/offer/dist/aos/img/sprite-face.png
- au.y####.net/offer/dist/aos/img/sprite-icons.png
- au.y####.net/offer/dist/aos/lists/2.0.1/detail.js
- au.y####.net/offer/dist/aos/lists/2.0.1/lists.css
- au.y####.net/offer/dist/aos/lists/2.0.1/lists.js
- au.y####.net/offer/dist/aos/slient/2.0.1/slient.js
- down####.c####.189.cn/favicon.ico
- down####.c####.189.cn/v5/downloadFile.action?downloadRequest=####
- pan.b####.com/s/18E2tH
- s####.gw.y####.net/v3/init?s=####
- vdown####.c####.189.cn/favicon.ico
- a####.u####.com/app_logs
- /data/data/####/.jg.ic
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/Superuser.apk
- /data/data/####/Superuser.apk_jiemi
- /data/data/####/Superuser.apk_jiemi (deleted)
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/aa
- /data/data/####/busybox
- /data/data/####/busybox1
- /data/data/####/busybox1_jiemi
- /data/data/####/busybox_jiemi
- /data/data/####/busybox_jiemi (deleted)
- /data/data/####/com.lovewanqing.root_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/getroot
- /data/data/####/index
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/libjiagu1277303816.so
- /data/data/####/mobclick_agent_header_com.lovewanqing.root.xml
- /data/data/####/mobclick_agent_state_com.lovewanqing.root.xml
- /data/data/####/root
- /data/data/####/root.sh
- /data/data/####/root1
- /data/data/####/root1_jiemi
- /data/data/####/root_jiemi
- /data/data/####/root_jiemi (deleted)
- /data/data/####/su
- /data/data/####/su_jiemi
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/media/####/.nomedia
- /system/bin/sh
- /system/bin/sh <Package Folder>/files/getroot
- /system/bin/sh <Package Folder>/files/root /system/bin/sh <Package Folder>/files/root.sh
- chmod 755 <Package Folder>/.jiagu/libjiagu1277303816.so
- chmod 777 <Package Folder>/files/getroot
- chmod 777 <Package Folder>/files/root
- chmod 777 <Package Folder>/files/root.sh
- chmod 777 <Package Folder>/files/root1
- sh
- su
- eroot
- libjiagu1277303816
- PBEWITHMD5andDES
- AES-ECB-PKCS5Padding