Technical information
- Android.BankBot.748.origin
- UDP(DNS) <Google DNS>
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 2####.109.148.129:443
- TCP(TLS/1.0) 1####.251.67.240:443
- TCP(TLS/1.0) d####.qupe####.cn:443
- TCP(TLS/1.0) ch####.qupe####.com:443
- TCP(TLS/1.0) 1####.166.182.25:443
- TCP(TLS/1.0) 2####.119.169.43:443
- TCP(TLS/1.0) 47.2####.133.25:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) 2####.109.148.139:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 1####.177.14.95:443
- TCP(TLS/1.2) 74.1####.205.95:443
- TCP p####.google####.com:443
- TCP 64.2####.164.95:443
- UDP 1####.250.69.195:443
- TCP 1####.250.187.238:443
- TCP 1####.250.69.195:443
- UDP 1####.251.211.238:443
- TCP 1####.217.169.10:443
- UDP <Google DNS>
- TCP 1####.85.67.12:443
- UDP 8####.8.4.4:53
- TCP www.google####.com:443
- TCP 1####.251.33.67:443
- TCP 1####.177.14.106:443
- ch####.qupe####.com
- d####.qupe####.cn
- g####.face####.com
- p####.google####.com
- rr2---s####.g####.com
- www.google####.com
- ch####.qupe####.com:443/basic/getBasicUserAttributes?timestamp=####&uid=...
- ch####.qupe####.com:443/basic/getConfig?uid=####×tamp=####&sign=###...
- d####.qupe####.cn:443/config/Android.conf
- ch####.qupe####.com:443/user/guestLogin
- ch####.qupe####.com:443/user/isAllowGuestLogin
- d####.qupe####.cn:443/sa?project=####
- /data/data/####/.dmpvedpogjhejs.cfg
- /data/data/####/.hptc_kache_ishowedu.aitalk
- /data/data/####/.imprint
- /data/data/####/0e75b26e6650d75fbafd800051befffc7d5781071d3d3ad...b4c5.0
- /data/data/####/1730942254
- /data/data/####/1ee041b0bf75c44aefc7b8c66ee6e8e1
- /data/data/####/1f57781c3eaf292b267fbf81d11d74c0eca359846f24d73...d778.0
- /data/data/####/20002427@bd_tea_agent.db-journal
- /data/data/####/2e15114b7d279a626c7ee8a75aeefc35d779201edf6d964...90a0.0
- /data/data/####/376cb710f1597a40017b7de1c1c23cd10c8e57bcec1f5e8...2ed8.0
- /data/data/####/3fb3aa13bce57236296a5b5749e33399a0885b3a39da2f0...a9be.0
- /data/data/####/49ad4335c53f26b0271de530ee77265db266896a6bdfc37....0.tmp
- /data/data/####/55ae53e80ae716c036006d0cc5276b036aaaf19e06627d0...c243.0
- /data/data/####/562f55eddd4386ab6552d2313fcf3527
- /data/data/####/7394fb053d12d891003f4351ced981ee626ccccf859f1a3...f9cf.0
- /data/data/####/AppEventsLogger.persistedevents
- /data/data/####/Cookies-journal
- /data/data/####/SP_AROUTER_CACHE.xml
- /data/data/####/SP_AROUTER_CACHE.xml.bak
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/Y29uZmlnXzY1MGU4NGU4YjJmNmZhMDBiYTU4MzhiNA.sp
- /data/data/####/Y29uZmlnXzY1MGU4NGU4YjJmNmZhMDBiYTU4MzhiNA.sp.bak
- /data/data/####/_global_cache.xml
- /data/data/####/a8aa28cb0015abf4299b1f38c8cf01fb
- /data/data/####/androidx.work.workdb-journal (deleted)
- /data/data/####/applog_stats.xml
- /data/data/####/bdtracker_dr_migrate_detector.xml
- /data/data/####/c4c2e1a0fa369bcb1377083dd85613f969a4f53cc85884c...5ab3.0
- /data/data/####/c797c475d85542510eca8e60d6c47cce4bedd769042ef1f...04e9.0
- /data/data/####/cacd074d4120d269ac1b41cddf9e44c37e61ea120f4614c....0.tmp
- /data/data/####/ccg_sp_config_file.xml
- /data/data/####/com.facebook.sdk.USER_SETTINGS.xml
- /data/data/####/com.facebook.sdk.appEventPreferences.xml
- /data/data/####/com.ishowedu.aitalk_preferences.xml
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDa...ml.bak
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDataAPI.xml
- /data/data/####/d4c956c43e2d44ac18abf33e182ce7bcc5a29438694a998...9d69.0
- /data/data/####/d76c8a3866fa0c4e88e258eb0a67e61547d653369049656....0.tmp
- /data/data/####/d92a4f84733095a30c0f49348f797486a666195a2fcaf24...f8bf.0
- /data/data/####/delayed_transmission_flag_new.xml
- /data/data/####/e5b627c2c064faac97d70d8993f02b12fcc9be14e2ae61a...0068.0
- /data/data/####/ecb161b893edd4355afb672b24032e0a
- /data/data/####/ede2ea9316d9e0b4cbdf5c2ffe7c5e45f684810d9db8359....0.tmp
- /data/data/####/efs_launch.xml
- /data/data/####/efs_launch.xml.bak
- /data/data/####/efsid
- /data/data/####/efsid5030
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/file_home_data.xml
- /data/data/####/file_setting.xml
- /data/data/####/gc_plugin.xml
- /data/data/####/gc_plugin.xml.bak (deleted)
- /data/data/####/grp.prop
- /data/data/####/header_custom.xml
- /data/data/####/header_custom.xml.bak
- /data/data/####/hihonor_gcjointsdk_20005301.apk
- /data/data/####/hihonor_gcjointsdk_20005301.apk_temp
- /data/data/####/i==1.2.0&&4.15.2_1730942282068_dW5pZnlfbG9ncw==;.log
- /data/data/####/image_opt_table.xml
- /data/data/####/itconfig.sp
- /data/data/####/itconfig.sp.bak
- /data/data/####/journal
- /data/data/####/last_sp_session.xml
- /data/data/####/last_sp_session.xml.bak
- /data/data/####/logan.mmap2
- /data/data/####/master.db-journal
- /data/data/####/paconfig.sp
- /data/data/####/paconfig.sp.bak
- /data/data/####/proc_auxv
- /data/data/####/sendlock
- /data/data/####/sensorsdata-journal
- /data/data/####/sensorsdata.xml
- /data/data/####/snssdk_openudid.xml
- /data/data/####/sp_name_bd_convert_click_id.xml
- /data/data/####/ss_app_config.xml
- /data/data/####/stub.dex
- /data/data/####/stub.odex
- /data/data/####/stub.odex.flock (deleted)
- /data/data/####/t==9.6.5&&4.15.2_1730942277895_dW5pZnlfbG9ncw==;.log
- /data/data/####/ttnet_tnc_config.xml
- /data/data/####/ttnet_tnc_config.xml.bak
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/ug_install_settings_pref.xml
- /data/data/####/um_policy_grant.xml
- /data/data/####/um_session_id.xml
- /data/data/####/um_umcrash.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_policy_result_flag
- /data/data/####/umeng_sp_oaid.xml
- /data/data/####/umeng_zcfg_flag
- /data/data/####/umeng_zero_cache.db
- /data/data/####/umeng_zero_cache.db-journal
- /data/data/####/umzid_general_config.xml
- /data/data/####/umzid_general_config.xml.bak
- /data/data/####/unique
- /data/data/####/ver
- /data/data/####/version
- /data/data/####/z==1.2.0&&4.15.2_1730942270636_emNmZw==;.log
- /data/media/####/1730926800000
- /data/media/####/448926930
- /data/media/####/com.ishowedu.aitalk.cert.pem
- /data/media/####/com.ishowedu.aitalk.cert.pem_temp
- /data/media/####/mmkv.default
- /data/media/####/mmkv.default.crc
- /data/media/####/uuid.txt
- /data/misc/####/primary.prof
- /data/user_de/####/move_to_de_records.xml
- getprop ro.build.version.emui
- getprop ro.letv.release.version
- getprop ro.product.brand
- getprop ro.product.model
- getprop ro.system.build.id
- getprop ro.vivo.os.build.display.id
- ls -l /system/bin/su
- ls /
- ls /sys/class/thermal
- sh -c type su
- libEncryptorP
- libcrashsdk
- libflutter
- liblogan
- libmmkv
- libmsaoaidsec
- libnesec-x86
- libqcloud_asr_realtime
- libspeechengine
- libsscronet
- libumeng-spy
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7PADDING
- AES-CBC-PKCS7Padding