My android phone has many queries to this domain:
z.moatads.com
Currently, since my pi-hole is on "steroids" (2,3M blocked domains from many blocklists)
it is on these three blocklists
[0]:https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts
[1]:http://sysctl.org/cameleon/hosts
[5]:https://hosts-file.net/ad_servers.txt
Problem is that these queries are of unkown origin to me. Is that malware, tracker?
The fact is that these queries are happening all the time my phone is not used but connected to Wi-Fi.
I have started tcpdump to my phone, I would like to know more about the traffic around these queries.
On the internet when i google motoadz there are informations about malware. So I am taking this issue very seriously.
Second part:
Do you guys have some sugestions about tracking this internaly in android OS. Without chance to have this overview we cannot say that android is secure. ...