Technical information
- Android.BackDoor.985
- Android.Xiny.164.origin
- Android.Xiny.202.origin
- Android.Xiny.73.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 45.33.1####.188:80
- TCP(HTTP/1.1) 45.79.1####.48:80
- TCP(HTTP/1.1) 4####.33.0.123:80
- TCP(HTTP/1.1) 45.79.1####.160:80
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) 45.79.2####.163:80
- TCP(HTTP/1.1) 4####.79.77.161:80
- TCP(HTTP/1.1) analy####.ray####.com:80
- TCP(HTTP/1.1) 45.79.1####.241:80
- TCP(HTTP/1.1) www.koapk####.com:8081
- TCP(HTTP/1.1) ggg.koapk####.com:80
- TCP(TLS/1.0) v####.ray####.com:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) at.al####.com:443
- TCP(TLS/1.0) tpc.googles####.com:443
- TCP(TLS/1.0) u####.com:443
- TCP(TLS/1.0) pag####.googles####.com:443
- TCP(TLS/1.0) disco####.amp.cloudf####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) s####.g.doublec####.net:443
- TCP(TLS/1.0) adser####.go####.nl:443
- TCP(TLS/1.0) amp.cloudf####.com:443
- TCP(TLS/1.0) f####.google####.com:443
- TCP(TLS/1.0) www.google-####.com:443
- TCP(TLS/1.0) r####.quick####.top:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) p####.quickg####.cc:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) net.ray####.com:443
- adser####.go####.com
- adser####.go####.nl
- amp.cloudf####.com
- analy####.ray####.com
- at.al####.com
- disco####.amp.cloudf####.com
- f####.google####.com
- f####.gst####.com
- ggg.koapk####.com
- googl####.g.doublec####.net
- im####.quickg####.cc
- net.ray####.com
- p####.quickg####.cc
- pag####.googles####.com
- r####.quick####.top
- s####.g.doublec####.net
- tpc.googles####.com
- u####.com
- v####.ray####.com
- www.go####.com
- www.go####.nl
- www.google-####.com
- www.koapk####.com
- www.okyes####.com
- analy####.ray####.com/?ts=####&key=####&browser=####&domain_url=####&ua=...
- ggg.koapk####.com/pgm/sr/gm/gy
- www.koapk####.com:8081/sm/sr/rt/ry
- www.koapk####.com:8081/sm/sr/sp/py
- www.okyes####.com:8081/sdk/nsd.action?b=####
- www.okyes####.com:8081/sdk/nsd.action?b=####&ci=####&ct=####&re=####&sd=...
- /data/data/####/.m2.so
- /data/data/####/07946104.apk
- /data/data/####/07946104.dex
- /data/data/####/15684413.apk
- /data/data/####/15684413.dex
- /data/data/####/19924381.apk
- /data/data/####/19924381.dex
- /data/data/####/20160121.xml
- /data/data/####/201804161450.apk
- /data/data/####/28347951.apk
- /data/data/####/28347951.dex
- /data/data/####/36777141.apk
- /data/data/####/36777141.dex
- /data/data/####/48341116.apk
- /data/data/####/48341116.dex
- /data/data/####/52934179.apk
- /data/data/####/52934179.dex
- /data/data/####/80253686.apk
- /data/data/####/80253686.dex
- /data/data/####/B201805072050.apk
- /data/data/####/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- /data/data/####/QURfUk9PVF9TREtfMjAxNzAyMDgxMA.xml
- /data/data/####/ZDExMDN6
- /data/data/####/ZDExMDN61527377429186.zip
- /data/data/####/ZGV4ZXoy
- /data/data/####/ZGV4ZXoy1527377428577.zip
- /data/data/####/ag.xml
- /data/data/####/alarms.db-journal
- /data/data/####/bdownloaders.db-journal
- /data/data/####/btnvtool_oygb_radish
- /data/data/####/c201804161450.apk
- /data/data/####/com.darshancomputing.BatteryIndicatorPro_preferences.xml
- /data/data/####/dc1
- /data/data/####/dc2
- /data/data/####/dcz
- /data/data/####/debuggerd_hulu
- /data/data/####/dk356.data
- /data/data/####/dk909.data
- /data/data/####/dk916.data
- /data/data/####/dk917.data
- /data/data/####/dk941.data
- /data/data/####/dk946.data
- /data/data/####/elfm
- /data/data/####/elfm1527377368577.zip
- /data/data/####/env201805072050.data
- /data/data/####/error
- /data/data/####/forever.sh
- /data/data/####/install-recovery.sh
- /data/data/####/kcol_ysy
- /data/data/####/krcfg.txt
- /data/data/####/krmain
- /data/data/####/krmain1527377369432.zip
- /data/data/####/krmain1527377389701.zip
- /data/data/####/krmain1527377400308.zip
- /data/data/####/krmain1527377410064.zip
- /data/data/####/krmain1527377417578.zip
- /data/data/####/krmain1527377438252.zip
- /data/data/####/krsdk.cert
- /data/data/####/loa.xml
- /data/data/####/logs.db-journal
- /data/data/####/p_dzpg48.data
- /data/data/####/predictor_sp_store.xml
- /data/data/####/rmdir_bogy_hd
- /data/data/####/rtr.db
- /data/data/####/rtr.db-journal
- /data/data/####/sp_store.xml
- /data/data/####/sp_store_main.xml
- /data/data/####/supolicy
- /data/data/####/swith1014.db-journal
- /data/data/####/toolbox
- /data/data/####/toolbox1527377368735.zip
- /data/media/####/.m2.so
- /data/media/####/076153442.jpeg.tmp
- /data/media/####/B201805072050.apk
- /data/media/####/test1527377367356
- /data/media/####/test1527377368655
- c201804161450.apk -c <Package>:away
- chmod -R 777 <Package Folder>/com.init.env/app_abz /storage/emulated/0/abz
- chmod 0755 <Package Folder>/com.init.env
- chmod 0777 <Package Folder>/com.init.env/files/elfm
- chmod 0777 <Package Folder>/com.init.env/files/forever.sh
- chmod 0777 <Package Folder>/com.init.env/files/toolbox
- chmod 0777 <Package Folder>/p.dk356/files/forever.sh
- chmod 0777 <Package Folder>/p.dk356/files/krmain
- chmod 0777 <Package Folder>/p.dk909/files/forever.sh
- chmod 0777 <Package Folder>/p.dk909/files/krmain
- chmod 0777 <Package Folder>/p.dk916/files/forever.sh
- chmod 0777 <Package Folder>/p.dk916/files/krmain
- chmod 0777 <Package Folder>/p.dk917/files/forever.sh
- chmod 0777 <Package Folder>/p.dk917/files/krmain
- chmod 0777 <Package Folder>/p.dk941/files/forever.sh
- chmod 0777 <Package Folder>/p.dk941/files/krmain
- chmod 0777 <Package Folder>/p.dk946/files/forever.sh
- chmod 0777 <Package Folder>/p.dk946/files/krmain
- chmod 0777 <Package Folder>/p.dk946/files/krsdk.cert
- chmod 0777 <Package Folder>/p.dzpg48/files/ZDExMDN6
- chmod 0777 <Package Folder>/p.dzpg48/files/ZGV4ZXoy
- chmod 0777 <Package Folder>/p.dzpg48/files/error
- chmod 6777 <Package Folder>/files/c201804161450.apk
- chmod 777 <Package Folder>/p.dk356/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk909/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk916/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk917/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk941/files/krcfg.txt
- chmod 777 <Package Folder>/p.dk946/files/krcfg.txt
- dcz <Package Folder>/com.init.env/app_abz/dc1 <Package Folder>/com.init.env/app_abz/dc2
- logcat -d -v time
- ls -l /system/bin/su
- ps
- rmdir_bogy_hd
- rmdir_bogy_hd -c id
- sh
- sh /system/bin/rmdir_bogy_hd
- sh /system/bin/rmdir_bogy_hd -c id
- sh <Package Folder>/com.init.env/app_abz/dcz <Package Folder>/com.init.env/app_abz/dc1 <Package Folder>/com.init.env/app_abz/dc2
- su
- su -c id
- libcom.walk.away
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding