Technical information
- 106901332942: rg|460|AhB3j.S11wiZPLfC4voMlAPLf5l4OMLO8Og5z74T385u5,kdh0b0NFYlvcKmXqhMZUTh.GPFSku4y80Wpe72OxxkLK6k0m9Bdyo7R3cRjb4!
- Android.SmsSend.24778
- Android.Triada.248.origin
- Android.Triada.464.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.159.180.48:8090
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) 1####.159.103.205:8090
- TCP(HTTP/1.1) api.y####.com:8080
- TCP(HTTP/1.1) daliu####.c####.qini####.com:80
- TCP(HTTP/1.1) 1####.78.31.198:8030
- TCP(HTTP/1.1) 47.1####.5.162:9004
- TCP(HTTP/1.1) www.i####.top:80
- TCP(HTTP/1.1) fy.bigb####.com:6099
- TCP(HTTP/1.1) q####.a####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
- TCP(HTTP/1.1) w####.cns####.com:9005
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) ot.prs.qin####.com:80
- TCP(HTTP/1.1) ifse####.mc####.com:29092
- TCP(HTTP/1.1) lp.lapia####.com:6099
- TCP(HTTP/1.1) ga####.gamenew####.com:8080
- TCP(HTTP/1.1) ji####.jieme####.com:8152
- TCP(HTTP/1.1) api.qiazhiw####.cn:8888
- TCP(HTTP/1.1) g####.mc####.com:9013
- TCP(HTTP/1.1) 1####.159.152.136:8090
- TCP(HTTP/1.1) www.palmfun####.cn:80
- TCP(HTTP/1.1) apc.wjm####.com:80
- TCP(HTTP/1.1) ot.grb.qin####.com:80
- TCP(HTTP/1.1) a####.on####.club:80
- TCP(TLS/1.0) 1####.217.17.78:443
- a####.b####.qq.com
- a####.on####.club
- aexcep####.b####.qq.com
- and####.b####.qq.com
- apc.wjm####.com
- api.qiazhiw####.cn
- api.y####.com
- dd.bigb####.com
- fy.bigb####.com
- g####.mc####.com
- ga####.gamenew####.com
- hx.wjm####.com
- ifse####.mc####.com
- ji####.dl####.com
- ji####.jieme####.com
- l####.bigb####.com
- l.ace####.com
- lp.lapia####.com
- mt####.go####.com
- nfsjar####.funu####.com
- ot.cor.qin####.com
- ot.grb.qin####.com
- ot.m.qin####.com
- ot.prs.qin####.com
- pv.s####.com
- w####.cns####.com
- www.i####.top
- www.palmfun####.cn
- a####.on####.club/fileupload/247180c889c6a542.jar
- daliu####.c####.qini####.com/uploadToEnCode/1555915218447743.jar
- ga####.gamenew####.com:8080/pay/lianyun/zonghe_chenfeng.txt
- gd.a.s####.com/cityjson?ie=####
- q####.a####.com/jieplginf/djmdeta29x
- aexcep####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- apc.wjm####.com/core/user/initPay
- apc.wjm####.com/fetchMobileService/fetchMobile
- apc.wjm####.com/inte/upSdkCrashLog
- apc.wjm####.com/inte/upSmsCollection
- api.qiazhiw####.cn:8888/v2/api/report?app_id=####&imei=####&imsi=####&ha...
- api.y####.com:8080/sdk/mobile-submit
- fy.bigb####.com:6099/aps/
- g####.mc####.com:9013/nfs/nf_s/g_s
- g####.mc####.com:9013/nfs/nf_s/s_l_i
- g####.mc####.com:9013/nfs/nf_s/u_j
- ifse####.mc####.com:29092/ifServer/gtmb
- ji####.jieme####.com:8152/ryf_webserver/payment/checkupdate.html
- lp.lapia####.com:6099/aps/
- ot.grb.qin####.com/JBVZVr/niyaei
- ot.grb.qin####.com/ei6VRb/ZJnAba
- ot.grb.qin####.com/zIFvYr/uaqmAn
- ot.prs.qin####.com/7ziimi/QriUva
- ot.prs.qin####.com/7ziimi/ieuYzm
- ot.prs.qin####.com/JBVZVr/niyaei
- ot.prs.qin####.com/ei6VRb/ZJnAba
- w####.cns####.com:9005/csk/c_s/g_f.json
- w####.cns####.com:9005/csk/st_c/cn_i_sec.json
- w####.cns####.com:9005/csk/st_c/cn_sk_Order.json
- w####.cns####.com:9005/csk/st_c/cn_sk_login.json
- w####.cns####.com:9005/csk/st_c/cn_sk_specialVersion.json
- w####.cns####.com:9005/csk/st_c/cn_sk_tj.json
- w####.cns####.com:9005/csk/st_c/getst_tegy.json
- www.i####.top/vv/init
- www.i####.top/vv/initNew
- www.i####.top/vv/reg
- www.palmfun####.cn/fee/active
- www.palmfun####.cn/fee/searchpc
- www.palmfun####.cn/fee/searchpcNew
- /data/anr/traces.txt
- /data/data/####/-K8YkAAwHI0hJq4T.dex
- /data/data/####/-K8YkAAwHI0hJq4T.zip
- /data/data/####/-cdGnkJZIvXiF5gqlieRhY6htTs=.new
- /data/data/####/1558477384787
- /data/data/####/1558477385162
- /data/data/####/15584773861555915218447743_.dex (deleted)
- /data/data/####/15584773861555915218447743_.jar
- /data/data/####/1558477387285
- /data/data/####/1558477388959
- /data/data/####/1558477390971
- /data/data/####/1558477400574
- /data/data/####/1558477400688
- /data/data/####/1558477400881
- /data/data/####/1558477401420
- /data/data/####/1558477403086
- /data/data/####/1558477404339
- /data/data/####/1558477406316
- /data/data/####/1558477408352
- /data/data/####/1558477410319
- /data/data/####/1558477416630
- /data/data/####/1558477416788
- /data/data/####/1558477416836
- /data/data/####/1558477417921
- /data/data/####/1558477418574
- /data/data/####/1558477420587
- /data/data/####/1558477422578
- /data/data/####/1558477424603
- /data/data/####/1558477426562
- /data/data/####/1558477431214
- /data/data/####/1558477433097
- /data/data/####/1558477433494
- /data/data/####/1558477433601
- /data/data/####/1558477435115
- /data/data/####/1558477437138
- /data/data/####/1558477439110
- /data/data/####/1558477440175
- /data/data/####/1558477448956
- /data/data/####/1558477450781
- /data/data/####/1558477451327
- /data/data/####/1558477452115
- /data/data/####/1558477453047
- /data/data/####/1558477453400
- /data/data/####/1558477454870
- /data/data/####/1558477456862
- /data/data/####/1558477462760
- /data/data/####/1558477464728
- /data/data/####/1558477465053
- /data/data/####/1558477465706
- /data/data/####/1558477466558
- /data/data/####/1558477466923
- /data/data/####/1558477468746
- /data/data/####/1558477470761
- /data/data/####/17mSmlc-dz_ha-OEmxKw7g==
- /data/data/####/1T_kagn07xvPIjieL80Fig==
- /data/data/####/5oixufUpcWDgdllWi9enxQ==.new
- /data/data/####/63UTwYUYbuSiwdrf.new
- /data/data/####/CxTr1TcOrtjjSP47UyRLsZE2sDw=.new
- /data/data/####/D0h30w8kk_nhP8aj
- /data/data/####/FOxFL5s7-RF6oGfdTmi0h_X1E3Q=.new
- /data/data/####/JiePay.xml
- /data/data/####/L4itcP_j9tGTJz79gK8UkA==.new
- /data/data/####/L9zzYtaEIfFgLevvqDPjpQ==.new
- /data/data/####/Ls8gLzq4p9iD5jna2gvYM1E-rYkCDd9c_c3ocYl4BZVnqPPiX
- /data/data/####/Ls8gLzq4p9iD5jna2gvYM1E-rYkCDd9c_c3ocYl4BZVnqPPiX-journal
- /data/data/####/NorPay_SP.xml
- /data/data/####/OkCcxgsCKUIjapGD5IEXxFeNhZY=.new
- /data/data/####/SF_C.xml
- /data/data/####/SuNeQT2CVCNXEA3tdTB739CpQWU=.new
- /data/data/####/XinZF.xml
- /data/data/####/XinZF_conf.xml
- /data/data/####/XinZFsmspay.db
- /data/data/####/XinZFsmspay.db-journal
- /data/data/####/ZNW9G67Fl1lOxmMuE4PJN-7AxQM=.new
- /data/data/####/_fq_1.1.1_use.dex
- /data/data/####/_fq_1.1.1_use.jar
- /data/data/####/a_tmp
- /data/data/####/app_test.apk
- /data/data/####/app_test.dex (deleted)
- /data/data/####/brushs.xml
- /data/data/####/bugly_db_legu
- /data/data/####/bugly_db_legu-journal
- /data/data/####/c8ef51bca7c6ca597d96a5924f5daec5.xml
- /data/data/####/c8ef51bca7c6ca597d96a5924f5daec5.xml.bak
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cds.xml
- /data/data/####/com.sdjfd.ergjtlk_preferences.xml
- /data/data/####/comsdjfdergjtlk
- /data/data/####/config.xml
- /data/data/####/dmmoodd.xml
- /data/data/####/eKbEq260v7x15F5HY06f0g==.new
- /data/data/####/f004579380f3b7f2ef141f1b08f47b58.xml
- /data/data/####/fmoonStore.db
- /data/data/####/fmoonStore.db-journal
- /data/data/####/fplay_arthc
- /data/data/####/jiepay_config.xml
- /data/data/####/jiepayplugin.apk
- /data/data/####/jiepayplugin.apkdata
- /data/data/####/jiepayplugin.dex
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.9.1.2.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/loccalCache.xml
- /data/data/####/lpeg.dex
- /data/data/####/lpeg.jar
- /data/data/####/mix.dex
- /data/data/####/mix.so
- /data/data/####/native_record_lock
- /data/data/####/one.dex
- /data/data/####/onePayV3.xml
- /data/data/####/order_sp.xml
- /data/data/####/order_sp.xml.bak (deleted)
- /data/data/####/p7Hw2rG1t7FQG8xRRC5oWAWfuF-ATcwI.new
- /data/data/####/pretw.xml
- /data/data/####/qs_LcCache.xml
- /data/data/####/rdata_comxveqzygb.new
- /data/data/####/runner_info.prop.new
- /data/data/####/security_info
- /data/data/####/sfp
- /data/data/####/sms_db
- /data/data/####/sms_db-journal
- /data/data/####/tjfxa_f.dex
- /data/data/####/tjfxa_f.zip
- /data/data/####/tw.dex
- /data/data/####/twc.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/ugmarssp.xml
- /data/data/####/uid.f
- /data/data/####/umeng_general_config.xml
- /data/data/####/webview.db
- /data/data/####/webview.db-journal
- /data/data/####/yapfq.db
- /data/data/####/yapfq.db-journal
- /data/data/####/ydutl.cf
- /data/data/####/yf.apk
- /data/data/####/yf.dex
- /data/data/####/yf.dex (deleted)
- /data/data/####/yunUid.f
- /data/data/####/zdbaj.dex
- /data/data/####/zdbaj.jar
- /data/media/####/.uunique.new
- /data/media/####/15584773861555915218447743.jar
- /data/media/####/WyyyCrashLog_20190521222323_2599.log
- /data/media/####/WyyyCrashLog_20190521222324_2599.log
- /data/media/####/WyyyCrashLog_20190521222326_2599.log
- /data/media/####/WyyyCrashLog_20190521222328_2599.log
- /data/media/####/WyyyCrashLog_20190521222330_2599.log
- /data/media/####/WyyyCrashLog_20190521222338_2990.log
- /data/media/####/WyyyCrashLog_20190521222340_2990.log
- /data/media/####/WyyyCrashLog_20190521222342_2990.log
- /data/media/####/WyyyCrashLog_20190521222344_2990.log
- /data/media/####/WyyyCrashLog_20190521222346_2990.log
- /data/media/####/WyyyCrashLog_20190521222400_3340.log
- /data/media/####/WyyyCrashLog_20190521222413_3642.log
- /data/media/####/WyyyCrashLog_20190521222414_3642.log
- /data/media/####/WyyyCrashLog_20190521222416_3642.log
- /data/media/####/WyyyCrashLog_20190521222426_3987.log
- /data/media/####/WyyyCrashLog_20190521222428_3987.log
- /data/media/####/WyyyCrashLog_20190521222430_3987.log
- /data/media/####/qshp_3001_2382.zip
- /data/media/####/tw
- ./fplay_arthc
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- cat /sys/block/mmcblk0/device/cid
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.1.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- chmod 777 <Package Folder>/comsdjfdergjtlk
- chmod 777 <Package Folder>/files/fplay_arthc
- dd if <Package Folder>/files/fplay_arthc of <Package Folder>/comsdjfdergjtlk
- dd if=<Package Folder>/files/fplay_arthc of=<Package Folder>/comsdjfdergjtlk
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- getprop ro.yunos.version
- logcat -d -v threadtime
- sh
- sh ./fplay_arthc
- Bugly
- cocos2dcpp
- core
- engine
- fporpoise
- libnfix
- libshella-2.9.1.2
- libufix
- n67c5f
- nfix
- ufix
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES
- DES-CBC-PKCS5Padding