Technical information
- 106901332942: rg|633|AhB3j.S11wiZPLfC4voMlAPLf5l4OMLO8Og5z74T385u5,kdh0b0NFYlvcKmXqhMUErMqB2o4loWlxtnhYTPcEl,chYXPw.,tZ8gJeLAdNE!
- Android.SmsSend.24778
- Android.Triada.248.origin
- Android.Triada.464.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.231.63.251:8004
- TCP(HTTP/1.1) 1####.159.180.48:8090
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) 1####.25.143.41:8010
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) 1####.159.103.205:8090
- TCP(HTTP/1.1) 1####.152.193.60:8008
- TCP(HTTP/1.1) 47.1####.5.162:9004
- TCP(HTTP/1.1) daliu####.c####.qini####.com:80
- TCP(HTTP/1.1) ot.grb.qin####.com:80
- TCP(HTTP/1.1) 1####.25.50.45:8001
- TCP(HTTP/1.1) 1####.78.31.198:8030
- TCP(HTTP/1.1) api.y####.com:8080
- TCP(HTTP/1.1) www.i####.top:80
- TCP(HTTP/1.1) 2####.64.16.83:8012
- TCP(HTTP/1.1) ga####.gamenew####.com:8080
- TCP(HTTP/1.1) 1####.25.95.88:8011
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
- TCP(HTTP/1.1) w####.cns####.com:9005
- TCP(HTTP/1.1) ji####.jieme####.com:8152
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) 1####.231.141.234:8002
- TCP(HTTP/1.1) 1####.25.144.78:8009
- TCP(HTTP/1.1) ot.prs.qin####.com:80
- TCP(HTTP/1.1) ifse####.mc####.com:29092
- TCP(HTTP/1.1) lp.lapia####.com:6099
- TCP(HTTP/1.1) fy.bigb####.com:6099
- TCP(HTTP/1.1) 1####.25.187.234:8013
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) api.qiazhiw####.cn:8888
- TCP(HTTP/1.1) 1####.25.191.62:8014
- TCP(HTTP/1.1) g####.mc####.com:9013
- TCP(HTTP/1.1) 1####.159.152.136:8090
- TCP(HTTP/1.1) www.palmfun####.cn:80
- TCP(HTTP/1.1) apc.wjm####.com:80
- TCP(HTTP/1.1) 1####.25.177.64:8003
- TCP(HTTP/1.1) a####.on####.club:80
- TCP(HTTP/1.1) 2####.111.8.140:8080
- a####.b####.qq.com
- a####.on####.club
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- apc.wjm####.com
- api.qiazhiw####.cn
- api.y####.com
- dd.bigb####.com
- fy.bigb####.com
- g####.mc####.com
- ga####.gamenew####.com
- hx.wjm####.com
- ifse####.mc####.com
- ji####.dl####.com
- ji####.jieme####.com
- l####.bigb####.com
- l.ace####.com
- lp.lapia####.com
- nfsjar####.funu####.com
- ot.cor.qin####.com
- ot.grb.qin####.com
- ot.m.qin####.com
- ot.prs.qin####.com
- pv.s####.com
- w####.cns####.com
- www.i####.top
- www.palmfun####.cn
- a####.on####.club/fileupload/247180c889c6a542.jar
- daliu####.c####.qini####.com/uploadToEnCode/1555915218447743.jar
- ga####.gamenew####.com:8080/pay/lianyun/zonghe_chenfeng.txt
- gd.a.s####.com/cityjson?ie=####
- a####.u####.com/app_logs
- aexcep####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- apc.wjm####.com/core/user/initPay
- apc.wjm####.com/fetchMobileService/fetchMobile
- apc.wjm####.com/inte/upSdkCrashLog
- apc.wjm####.com/inte/upSmsCollection
- api.qiazhiw####.cn:8888/v2/api/report?app_id=####&imei=####&imsi=####&ha...
- api.y####.com:8080/sdk/mobile-submit
- fy.bigb####.com:6099/aps/
- g####.mc####.com:9013/nfs/nf_s/g_s
- g####.mc####.com:9013/nfs/nf_s/s_l_i
- g####.mc####.com:9013/nfs/nf_s/u_j
- ifse####.mc####.com:29092/ifServer/gtmb
- ji####.jieme####.com:8152/ryf_webserver/payment/checkupdate.html
- lp.lapia####.com:6099/aps/
- ot.grb.qin####.com/JBVZVr/niyaei
- ot.grb.qin####.com/ei6VRb/ZJnAba
- ot.grb.qin####.com/zIFvYr/uaqmAn
- ot.prs.qin####.com/7ziimi/VJJfya
- ot.prs.qin####.com/7ziimi/ieuYzm
- ot.prs.qin####.com/JBVZVr/niyaei
- ot.prs.qin####.com/ei6VRb/ZJnAba
- w####.cns####.com:9005/csk/c_s/g_f.json
- w####.cns####.com:9005/csk/st_c/cn_i_sec.json
- w####.cns####.com:9005/csk/st_c/cn_sk_Order.json
- w####.cns####.com:9005/csk/st_c/cn_sk_login.json
- w####.cns####.com:9005/csk/st_c/cn_sk_specialVersion.json
- w####.cns####.com:9005/csk/st_c/cn_sk_tj.json
- w####.cns####.com:9005/csk/st_c/getst_tegy.json
- www.i####.top/vv/init
- www.i####.top/vv/initNew
- www.i####.top/vv/reg
- www.palmfun####.cn/fee/active
- www.palmfun####.cn/fee/code
- www.palmfun####.cn/fee/searchpc
- www.palmfun####.cn/fee/searchpcNew
- /data/com.sdhfje.erjtlk/####/15586959391555915218447743_.dex (deleted)
- /data/com.sdhfje.erjtlk/####/app_test.dex (deleted)
- /data/com.sdhfje.erjtlk/####/bugly_db_legu
- /data/com.sdhfje.erjtlk/####/hbi5pAYxWhVK1q-TVJElE8DK-UwwwOid_Q...pxEitf
- /data/com.sdhfje.erjtlk/####/jiepayplugin.dex
- /data/com.sdhfje.erjtlk/####/qs.db
- /data/com.sdhfje.erjtlk/####/tjfxa_f.dex
- /data/com.sdhfje.erjtlk/####/webview.db
- /data/com.sdhfje.erjtlk/mix.so
- /data/data/####/-r79hRLoClBMBZFhEshF-w==
- /data/data/####/.imprint
- /data/data/####/1558695938079
- /data/data/####/1558695938585
- /data/data/####/15586959391555915218447743_.dex (deleted)
- /data/data/####/15586959391555915218447743_.jar
- /data/data/####/1558695940218
- /data/data/####/1558695942554
- /data/data/####/1558695942555
- /data/data/####/1558695944224
- /data/data/####/1558695946066
- /data/data/####/1558695953963
- /data/data/####/1558695954100
- /data/data/####/1558695954191
- /data/data/####/1558695956395
- /data/data/####/1558695956868
- /data/data/####/1558695958412
- /data/data/####/1558695959990
- /data/data/####/1558695961933
- /data/data/####/1558695973912
- /data/data/####/1558695974065
- /data/data/####/1558695974101
- /data/data/####/1558695976078
- /data/data/####/1558695977256
- /data/data/####/1558695978461
- /data/data/####/1558695980600
- /data/data/####/1558695981968
- /data/data/####/1558695983884
- /data/data/####/1558695990551
- /data/data/####/1558695990636
- /data/data/####/1558695990779
- /data/data/####/1558695991611
- /data/data/####/1558695992339
- /data/data/####/1558695994373
- /data/data/####/1558695996826
- /data/data/####/1558695998673
- /data/data/####/1558695998756
- /data/data/####/1558696000286
- /data/data/####/1558696005268
- /data/data/####/1558696005312
- /data/data/####/1558696006445
- /data/data/####/1558696007639
- /data/data/####/1558696009424
- /data/data/####/1558696011808
- /data/data/####/1558696013002
- /data/data/####/1558696013840
- /data/data/####/A6njFJQcD-AXJavddMfg54RbIlA=.new
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/GIau0cGssqmg8I5FEWO3j4GszmA=.new
- /data/data/####/JbKFzQbwV3UjeVAYpdn2nw==.new
- /data/data/####/JiePay.xml
- /data/data/####/NorPay_SP.xml
- /data/data/####/Or_p9NVcmpiR1xgx.new
- /data/data/####/Q8wlRmTaQ6fvLeLb.dex
- /data/data/####/Q8wlRmTaQ6fvLeLb.zip
- /data/data/####/SF_C.xml
- /data/data/####/XinZF.xml
- /data/data/####/XinZF_conf.xml
- /data/data/####/XinZFsmspay.db
- /data/data/####/XinZFsmspay.db-journal
- /data/data/####/YccWTkl6rO1p-SHJuYR_GQ==
- /data/data/####/ZOBLbNiva37OVl5Y9oGx-w==.new
- /data/data/####/_fq_1.1.1_use.dex
- /data/data/####/_fq_1.1.1_use.jar
- /data/data/####/_kmYrrgge1VuGH2Dx-ecm2QAuiQ=.new
- /data/data/####/a_tmp
- /data/data/####/app_test.apk
- /data/data/####/bQALoRuyXLrQwGTdeeacFUXzR4w=.new
- /data/data/####/bZ9AIhVHH34JMvRgsYoV3CkCE5A=.new
- /data/data/####/brushs.xml
- /data/data/####/bugly_db_legu-journal
- /data/data/####/c8ef51bca7c6ca597d96a5924f5daec5.xml
- /data/data/####/c8ef51bca7c6ca597d96a5924f5daec5.xml.bak (deleted)
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cds.xml
- /data/data/####/com.sdhfje.erjtlk_preferences.xml
- /data/data/####/comsdhfjeerjtlk
- /data/data/####/config.xml
- /data/data/####/dmmoodd.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f004579380f3b7f2ef141f1b08f47b58.xml
- /data/data/####/fmoonStore.db
- /data/data/####/fmoonStore.db-journal
- /data/data/####/fplay_arthc
- /data/data/####/hbi5pAYxWhVK1q-TVJElE8DK-UwwwOid_QFn8j5XmUSpxEitf-journal
- /data/data/####/jiepay_config.xml
- /data/data/####/jiepayplugin.apk
- /data/data/####/jiepaysmspay.db
- /data/data/####/jiepaysmspay.db-journal
- /data/data/####/kvFZGyd_kyZJw3lG
- /data/data/####/lcNVrs5oYiy4bkeD1bOBtw==.new
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.9.1.2.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/loccalCache.xml
- /data/data/####/lpeg.dex
- /data/data/####/lpeg.jar
- /data/data/####/lzwQgF8aKMHcTFcqb5qKBXb-rRg=.new
- /data/data/####/mix.dex
- /data/data/####/native_record_lock
- /data/data/####/one.dex
- /data/data/####/onePayV3.xml
- /data/data/####/order_sp.xml
- /data/data/####/order_sp.xml.bak
- /data/data/####/pretw.xml
- /data/data/####/qs.db-journal
- /data/data/####/qs_LcCache.xml
- /data/data/####/rdata_comxveqzygb.new
- /data/data/####/runner_info.prop.new
- /data/data/####/security_info
- /data/data/####/sfp
- /data/data/####/sms_db
- /data/data/####/sms_db-journal
- /data/data/####/tFz135xUIKSrdExvcRJXy_7KOC-P7P6D.new
- /data/data/####/tjfxa_f.zip
- /data/data/####/tqGmHSdIMclTnNlRAuJJKg==.new
- /data/data/####/tw.dex
- /data/data/####/twc.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/ugmarssp.xml
- /data/data/####/uid.f
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/yapfq.db
- /data/data/####/yapfq.db-journal
- /data/data/####/ydutl.cf
- /data/data/####/yf.apk
- /data/data/####/yf.dex
- /data/data/####/yf.dex (deleted)
- /data/data/####/yunUid.f
- /data/data/####/zdbaj.dex
- /data/data/####/zdbaj.jar
- /data/media/####/.uunique.new
- /data/media/####/15586959391555915218447743.jar
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/WyyyCrashLog_20190524110542_2290.log
- /data/media/####/WyyyCrashLog_20190524110544_2290.log
- /data/media/####/WyyyCrashLog_20190524110546_2290.log
- /data/media/####/WyyyCrashLog_20190524110558_2730.log
- /data/media/####/WyyyCrashLog_20190524110559_2730.log
- /data/media/####/WyyyCrashLog_20190524110601_2730.log
- /data/media/####/WyyyCrashLog_20190524110603_2730.log
- /data/media/####/WyyyCrashLog_20190524110618_3134.log
- /data/media/####/WyyyCrashLog_20190524110620_3134.log
- /data/media/####/WyyyCrashLog_20190524110621_3134.log
- /data/media/####/WyyyCrashLog_20190524110623_3134.log
- /data/media/####/WyyyCrashLog_20190524110632_3564.log
- /data/media/####/WyyyCrashLog_20190524110634_3564.log
- /data/media/####/WyyyCrashLog_20190524110636_3564.log
- /data/media/####/WyyyCrashLog_20190524110638_3564.log
- /data/media/####/WyyyCrashLog_20190524110640_3564.log
- /data/media/####/WyyyCrashLog_20190524110647_4037.log
- /data/media/####/WyyyCrashLog_20190524110649_4037.log
- /data/media/####/WyyyCrashLog_20190524110651_4037.log
- /data/media/####/WyyyCrashLog_20190524110652_4037.log
- /data/media/####/WyyyCrashLog_20190524110653_4037.log
- /data/media/####/qshp_3001_2382.zip
- /data/media/####/tw
- /drw/cmds/10044.2290.eb590bce-a21a-3703-8fa2-6cef284f34ec.stdin.txt
- /drw/cmds/10044.2290.eb590bce-a21a-3703-8fa2-6cef284f34ec.stdout.txt
- ./fplay_arthc
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- cat /sys/block/mmcblk0/device/cid
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.1.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- chmod 777 <Package Folder>/comsdhfjeerjtlk
- chmod 777 <Package Folder>/files/fplay_arthc
- dd if <Package Folder>/files/fplay_arthc of <Package Folder>/comsdhfjeerjtlk
- dd if=<Package Folder>/files/fplay_arthc of=<Package Folder>/comsdhfjeerjtlk
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- getprop ro.yunos.version
- logcat -d -v threadtime
- sh
- sh ./fplay_arthc
- Bugly
- core
- engine
- fporpoise
- libnfix
- libshella-2.9.1.2
- libufix
- n67c5f
- nfix
- sewwww
- ufix
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES
- DES-CBC-PKCS5Padding