Technical information
- Android.Backdoor.613.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) gd.a.s####.com:80
- c####.api.zhifa####.net
- i####.api.zhifa####.net
- i####.api.zhifa####.net
- pv.s####.com
- sdk.api.zhifa####.net
- v####.api.eeric####.com
- /data/anr/traces.txt
- <Package Folder>/app_wyzf_plg/pay_plg.jar
- <Package Folder>/files/####/onib_clz.jar
- <Package Folder>/files/new_md.jar
- <Package Folder>/shared_prefs/<Package>.xml
- <Package Folder>/shared_prefs/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml
- <Package Folder>/shared_prefs/config50240.xml
- <SD-Card>/pay/<Package>_<IMSI>_20171215_pay.log