Technical information
- Android.Backdoor.657.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) reso####.msg.xi####.net:80
- TCP(TLS/1.0) api.e####.cn:443
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP 47.74.1####.157:5222
- TCP 1####.13.142.2:5222
- api.e####.cn
- regi####.xm####.xi####.com
- reso####.msg.xi####.net
- reso####.msg.xi####.net/gslb/?ver=####&type=####&conpt=####&uuid=####&li...
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/UserAgent.xml
- /data/data/####/XMPushServiceConfig.xml
- /data/data/####/cn.ecook.xml
- /data/data/####/cn.ecook;pushservice
- /data/data/####/cn.ecook_preferences.xml
- /data/data/####/geofencing.db
- /data/data/####/geofencing.db-journal
- /data/data/####/libjiagu.so
- /data/data/####/mipush.xml
- /data/data/####/mipush_account.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/multidex.version.xml
- /data/data/####/pref_registered_pkg_names.xml
- /data/data/####/webview.db-journal
- /data/media/####/.nomedia
- /data/media/####/log.lock
- /data/media/####/log1.txt
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- libjiagu
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding