Technical information
- 12114516410: YIPAY#5437fb779904e44be936730151ff4b83#<IMSI>
- Android.Backdoor.613.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) pay####.oss-cn-####.aliy####.com:80
- TCP(HTTP/1.1) 1####.159.180.48:8090
- TCP(HTTP/1.1) x####.d####.top:20006
- TCP(HTTP/1.1) sdk.api.zhifa####.net:10201
- TCP(HTTP/1.1) 1####.75.56.106:10201
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) 1####.224.212.152:80
- TCP(HTTP/1.1) sm####.hej####.com:80
- TCP(HTTP/1.1) cid.r####.cn:80
- TCP(HTTP/1.1) 1####.159.152.136:8090
- TCP(HTTP/1.1) i####.api.zhifa####.net:10001
- TCP(HTTP/1.1) wn.zhifa####.net.####.net:80
- TCP(HTTP/1.1) p1.i####.cc:80
- TCP(HTTP/1.1) v####.api.eeric####.com:80
- TCP(HTTP/1.1) i####.api.zhifa####.net:10002
- TCP(HTTP/1.1) c####.api.zhifa####.net:10101
- TCP(HTTP/1.1) 1####.199.9.227:80
- TCP(HTTP/1.1) 1####.129.132.111:8001
- TCP(HTTP/1.1) i####.api.zhifa####.net:10003
- 766c3b6####.d####.top
- c####.api.zhifa####.net
- cid.r####.cn
- i####.api.zhifa####.net
- i####.api.zhifa####.net
- p1.i####.cc
- pay####.oss-cn-####.aliy####.com
- pv.s####.com
- re####.api.zhifa####.net
- sdk.api.zhifa####.net
- sm####.hej####.com
- v####.api.eeric####.com
- wn.zhifa####.net
- www.huangda####.com
- x####.d####.top
- gd.a.s####.com/cityjson?ie=####
- pay####.oss-cn-####.aliy####.com/sdk/jar/e00e23acc8724bca841961181e1ea70...
- sm####.hej####.com/getAd.php?apiKey=####&imsi=####&mobile=####&apiKey=##...
- sm####.hej####.com/getMobile.php?apiKey=####&imsi=####&n####&n####
- wn.zhifa####.net.####.net/update/up010363_66
- x####.d####.top:20006/SmsPayServer/sdkUpdate/index?
- c####.api.zhifa####.net:10101/v2/splog/config?app_id=####&t=####
- cid.r####.cn/api3
- i####.api.zhifa####.net:10001/v2/adconfig/get?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/bag/monitor?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/sdk/init?app_id=####&t=####
- i####.api.zhifa####.net:10001/v2/update/check?app_id=####&t=####
- i####.api.zhifa####.net:10002/v2/callback/message?app_id=####&t=####
- i####.api.zhifa####.net:10003/v2/chis
- p1.i####.cc/index.php/MC/HB
- sdk.api.zhifa####.net:10201/v2/sdk/report?app_id=####&t=####
- v####.api.eeric####.com/api/payment/mobileInit.html
- v####.api.eeric####.com/api/payment/updateinit_v2
- x####.d####.top:20006/SmsPayServer/sms/initMobile/province?
- <Package Folder>/app_wyzf_plg/pay_plg.jar
- <Package Folder>/databases/.fb
- <Package Folder>/databases/.fb-journal
- <Package Folder>/databases/347781996620052-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/files/####/onib_clz.jar
- <Package Folder>/files/new_md.jar
- <Package Folder>/files/up010363_66
- <Package Folder>/files/up010363_66.jar
- <Package Folder>/shared_prefs/<Package>.xml
- <Package Folder>/shared_prefs/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml
- <Package Folder>/shared_prefs/config50240.xml
- <Package Folder>/shared_prefs/i2w5g0d0i2h656n9h9i1y8p7n724t3.xml
- <Package Folder>/shared_prefs/i2w5g0d0i2h656n9h9i1y8p7n724t3.xml.bak
- <Package Folder>/shared_prefs/jy_hot_sdk_config.xml
- <Package Folder>/shared_prefs/jy_sdk_pe_info.xml
- <Package Folder>/shared_prefs/pretw.xml
- <Package Folder>/shared_prefs/pz_sharedpre_cmreaderlogininfo.xml
- <SD-Card>/.twservice/####/tw
- <SD-Card>/.twservice/qshp_3003_2296.zip
- <SD-Card>/JYMM/####/jypaysdk.apk
- <SD-Card>/pay/<Package>_<IMSI>_20171116_pay.log
- cat /sys/block/mmcblk0/device/cid
- getprop apps.customerservice.device
- cocos2dcpp