Technical information
- Android.BackDoor.985
- Android.Xiny.202.origin
- Android.Xiny.73.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 45.33.1####.188:80
- TCP(HTTP/1.1) of.okyes####.com:80
- TCP(HTTP/1.1) go####.nl:80
- TCP(HTTP/1.1) 45.79.1####.48:80
- TCP(HTTP/1.1) ssl.gst####.com:80
- TCP(HTTP/1.1) www.go####.com:80
- TCP(HTTP/1.1) t####.cloud####.com:80
- TCP(HTTP/1.1) 45.79.1####.142:80
- TCP(HTTP/1.1) 4####.33.0.123:80
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) www.okyes####.com:8080
- TCP(HTTP/1.1) 45.79.1####.161:80
- TCP(HTTP/1.1) 45.79.1####.230:80
- TCP(HTTP/1.1) s2s.go2af####.com:80
- TCP(HTTP/1.1) www.koapk####.com:8081
- TCP(HTTP/1.1) 45.79.1####.241:80
- TCP(HTTP/1.1) y####.to:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) r.lead####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.nl:443
- TCP(TLS/1.0) go####.nl:443
- TCP(TLS/1.0) adser####.go####.com:443
- adser####.go####.com
- adser####.go####.nl
- go####.nl
- of.okyes####.com
- r.lead####.com
- s2s.go2af####.com
- ssl.gst####.com
- t####.cloud####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- www.koapk####.com
- www.okyes####.com
- y####.to
- go####.nl/
- go####.nl/gen_204?atyp=####&ct=####&cad=####&ogsr=####&id=####&ic=####&o...
- go####.nl/gen_204?atyp=####&ct=####&cad=####&tt=####&ei=####&zx=####
- go####.nl/gen_204?atyp=####&ei=####&s=####&imc=####&imn=####&imp=####&ad...
- go####.nl/gen_204?s=####&atyp=####&ei=####&rt=####
- go####.nl/images/branding/googlelogo/2x/googlelogo_color_160x56dp.png
- go####.nl/images/hpp/Chrome_Owned_96x96.png
- go####.nl/images/nav_logo242.png
- go####.nl/xjs/_/js/k=xjs.qs.nl.6xRxEFvvD70.O/m=RMhBfe/am=gEWyAggJBBhTxAJ...
- go####.nl/xjs/_/js/k=xjs.qs.nl.6xRxEFvvD70.O/m=sb_wiz,aa,abd,async,dvl,f...
- go####.nl/xjs/_/js/k=xjs.qs.nl.OKtyjaIYpLo.O/m=sx,bct,cdos,elog,hsm,jsa,...
- of.okyes####.com/redirect?uid=####&sourceid=####&clickid=####
- s2s.go2af####.com/click?pid=####&offer_id=####&sub1=####
- ssl.gst####.com/gb/images/qi1_36e7b564.png
- t####.cloud####.com/go.php?p=####
- www.go####.com/complete/search?hl=####&client=####&q=####
- y####.to/s/9B6?pubref=####&affpubid=####
- go####.nl/gen_204?script=####&error=####&line=####&jsr=####&ei=####
- www.koapk####.com:8081/sm/sr/rt/ry
- www.koapk####.com:8081/sm/sr/sp/py
- www.okyes####.com:8080/sdk/cb.action
- www.okyes####.com:8080/sdk/td.action
- www.okyes####.com:8081/sdk/nsd.action?b=####
- www.okyes####.com:8081/sdk/nsd.action?b=####&ci=####&ct=####&re=####&sd=...
- /data/data/####/07515628.apk
- /data/data/####/07515628.dex
- /data/data/####/08614010.apk
- /data/data/####/08614010.dex
- /data/data/####/20160121.xml
- /data/data/####/201804231550.apk
- /data/data/####/22281367.apk
- /data/data/####/22281367.dex
- /data/data/####/28034195.apk
- /data/data/####/28034195.dex
- /data/data/####/40740094.apk
- /data/data/####/40740094.dex
- /data/data/####/62738967.apk
- /data/data/####/62738967.dex
- /data/data/####/70765176.apk
- /data/data/####/70765176.dex
- /data/data/####/86828218.apk
- /data/data/####/86828218.dex
- /data/data/####/91698632.apk
- /data/data/####/91698632.dex
- /data/data/####/95841873.apk
- /data/data/####/95841873.dex
- /data/data/####/AD_ID_SPINFO.xml
- /data/data/####/N2026.data
- /data/data/####/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- /data/data/####/QURfUk9PVF9TREtfMjAxNzAyMDgxMA.xml
- /data/data/####/ag.xml
- /data/data/####/alarms.db
- /data/data/####/alarms.db-journal
- /data/data/####/bdownloaders.db-journal
- /data/data/####/c201804231550.apk
- /data/data/####/com.darshancomputing.BatteryIndicatorPro_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/debuggerd_hulu
- /data/data/####/dk363.data
- /data/data/####/dk437.data
- /data/data/####/dk840.data
- /data/data/####/dk909.data
- /data/data/####/dk910.data
- /data/data/####/dk926.data
- /data/data/####/dk940.data
- /data/data/####/dk942.data
- /data/data/####/elfm
- /data/data/####/elfm1524557680668.zip
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/forever.sh
- /data/data/####/index
- /data/data/####/install-recovery.sh
- /data/data/####/ja201801152050.data
- /data/data/####/kcol_ysy
- /data/data/####/krcfg.txt
- /data/data/####/krmain
- /data/data/####/krmain1524557681231.zip
- /data/data/####/krmain1524557704475.zip
- /data/data/####/krmain1524557713862.zip
- /data/data/####/krmain1524557720991.zip
- /data/data/####/krmain1524557730816.zip
- /data/data/####/krmain1524557741905.zip
- /data/data/####/krmain1524557749234.zip
- /data/data/####/krsdk.cert
- /data/data/####/load_jpoo_hd
- /data/data/####/logs.db-journal
- /data/data/####/oatdump_pooj_radish
- /data/data/####/predictor_sp_store.xml
- /data/data/####/rtr.db
- /data/data/####/rtr.db-journal
- /data/data/####/sp_store.xml
- /data/data/####/sp_store_main.xml
- /data/data/####/supolicy
- /data/data/####/swith1014.db-journal
- /data/data/####/toolbox
- /data/data/####/toolbox1524557680767.zip
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/204102004.jpg.tmp
- /data/media/####/test1524557679300
- c201804231550.apk -c <Package>:ships
- chmod 0755 <Package Folder>/com.init.env
- chmod 0777 <Package Folder>/com.init.env/files/elfm
- chmod 0777 <Package Folder>/com.init.env/files/forever.sh
- chmod 0777 <Package Folder>/com.init.env/files/toolbox
- chmod 0777 <Package Folder>/p.dk363/files/forever.sh
- chmod 0777 <Package Folder>/p.dk363/files/krmain
- chmod 0777 <Package Folder>/p.dk437/files/forever.sh
- chmod 0777 <Package Folder>/p.dk437/files/krmain
- chmod 0777 <Package Folder>/p.dk840/files/forever.sh
- chmod 0777 <Package Folder>/p.dk909/files/forever.sh
- chmod 0777 <Package Folder>/p.dk909/files/krmain
- chmod 0777 <Package Folder>/p.dk910/files/forever.sh
- chmod 0777 <Package Folder>/p.dk910/files/krmain
- chmod 0777 <Package Folder>/p.dk926/files/forever.sh
- chmod 0777 <Package Folder>/p.dk926/files/krmain
- chmod 0777 <Package Folder>/p.dk926/files/krsdk.cert
- chmod 0777 <Package Folder>/p.dk940/files/forever.sh
- chmod 0777 <Package Folder>/p.dk940/files/krmain
- chmod 0777 <Package Folder>/p.dk942/files/forever.sh
- chmod 0777 <Package Folder>/p.dk942/files/krmain
- chmod 6777 <Package Folder>/files/c201804231550.apk
- chmod 777 <Package Folder>/p.dk363/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk437/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk840/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk909/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk910/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk926/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk940/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk942/files/krcfg.txt
- load_jpoo_hd
- load_jpoo_hd -c id
- logcat -d -v time
- ls -l /system/bin/su
- ps
- sh
- sh /system/bin/load_jpoo_hd
- sh /system/bin/load_jpoo_hd -c id
- su
- su -c id
- libcom.friend.ships
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding