Technical information
- Android.RemoteCode.32
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) www.vu####.com:80
- TCP(HTTP/1.1) zi####.b####.com:80
- TCP(HTTP/1.1) app.t####.com:80
- TCP(HTTP/1.1) www.tb####.com:80
- TCP(TLS/1.0) 74.1####.131.95:443
- TCP(TLS/1.0) 1####.194.222.95:443
- TCP(TLS/1.0) 1####.251.1.95:443
- TCP(TLS/1.2) 64.2####.161.100:443
- TCP(TLS/1.2) 1####.194.222.95:443
- TCP(TLS/1.2) 74.1####.131.100:443
- TCP(TLS/1.2) 74.1####.205.94:443
- UDP 1####.194.222.95:443
- app.t####.com
- int.d####.s####.####.cn
- pay.tp####.com
- www.tb####.com
- www.vu####.com
- app.t####.com/tools/haidian_hdus
- www.tb####.com/image/cr01.jpg
- www.tb####.com/image/cr02.jpg
- www.tb####.com/image/cr03.jpg
- www.tb####.com/image/cr04.jpg
- www.tb####.com/image/cr05.jpg
- www.tb####.com/image/cr06.jpg
- www.tb####.com/image/cr07.jpg
- www.tb####.com/image/cr08.jpg
- www.tb####.com/image/cr09.jpg
- www.tb####.com/image/cr10.jpg
- www.tb####.com/image/cr12.jpg
- www.tb####.com/image/cr13.jpg
- www.tb####.com/image/cr14.jpg
- www.tb####.com/image/cr15.jpg
- www.tb####.com/image/cr16.jpg
- www.tb####.com/image/cr17.jpg
- www.tb####.com/image/cr18.jpg
- www.tb####.com/image/cr19.jpg
- www.tb####.com/image/cr20.jpg
- www.tb####.com/image/cr21.jpg
- www.tb####.com/image/cr22.jpg
- www.tb####.com/image/cr23.jpg
- www.tb####.com/image/cr24.jpg
- www.tb####.com/image/cr25.jpg
- www.tb####.com/image/cr26.jpg
- www.tb####.com/image/cr27.jpg
- www.tb####.com/image/cr28.jpg
- www.tb####.com/image/cr29.jpg
- www.tb####.com/image/cr30.jpg
- www.tb####.com/image/cr31.jpg
- www.tb####.com/image/cr32.jpg
- www.tb####.com/image/cr33.jpg
- www.tb####.com/image/cr34.jpg
- www.tb####.com/image/cr35.jpg
- www.tb####.com/image/cr36.jpg
- www.tb####.com/image/cr37.jpg
- www.tb####.com/image/cr38.jpg
- www.tb####.com/image/cr39.jpg
- www.tb####.com/image/cr40.jpg
- www.tb####.com/image/cr41.jpg
- www.tb####.com/image/cr42.jpg
- www.tb####.com/image/cr43.jpg
- www.tb####.com/image/cr44.jpg
- www.tb####.com/image/cr45.jpg
- www.tb####.com/image/lb01.jpg
- www.tb####.com/image/lb02.jpg
- www.tb####.com/image/lb03.jpg
- www.tb####.com/image/lb04.jpg
- www.tb####.com/image/lb05.jpg
- www.tb####.com/image/lb06.jpg
- www.tb####.com/image/sk01.jpg
- www.tb####.com/image/sk02.jpg
- www.vu####.com/api/count.php?android_id=####&channelid=####&code=####
- www.vu####.com/api/payport.php?code=####
- www.vu####.com/api/uservip2.php?android_id=####&channelid=####
- zi####.b####.com/tmpay/initv2
- /data/data/####/EOZTzhVG.dex
- /data/data/####/EOZTzhVG.dex.flock (deleted)
- /data/data/####/EOZTzhVG.jar
- /data/data/####/MYYR.xml
- /data/data/####/libtm_pay.so
- /data/data/####/libus.lock
- /data/data/####/libus.so
- /data/data/####/proc_auxv
- /data/media/####/-1000680088.0.tmp
- /data/media/####/-1001603609.0.tmp
- /data/media/####/-1002527130.0.tmp
- /data/media/####/-1003450651.0.tmp
- /data/media/####/-1004374172.0.tmp
- /data/media/####/-1005297693.0.tmp
- /data/media/####/-1006221214.0.tmp
- /data/media/####/-1007144735.0.tmp
- /data/media/####/-1008068256.0.tmp
- /data/media/####/-1008991777.0.tmp
- /data/media/####/-1029309239.0.tmp
- /data/media/####/-1030232760.0
- /data/media/####/-1031156281.0.tmp
- /data/media/####/-1032079802.0
- /data/media/####/-1033003323.0.tmp
- /data/media/####/-1033926844.0
- /data/media/####/-1034850365.0.tmp
- /data/media/####/-1035773886.0
- /data/media/####/-1037620928.0
- /data/media/####/-1057938390.0.tmp
- /data/media/####/-1058861911.0
- /data/media/####/-1059785432.0
- /data/media/####/-1060708953.0.tmp
- /data/media/####/-1061632474.0.tmp
- /data/media/####/-1062555995.0.tmp
- /data/media/####/-1063479516.0.tmp
- /data/media/####/-1064403037.0
- /data/media/####/-1065326558.0
- /data/media/####/-1065326558.0.tmp
- /data/media/####/-866799924.0.tmp
- /data/media/####/-867723445.0
- /data/media/####/-867723445.0.tmp
- /data/media/####/-947115870.0.tmp
- /data/media/####/-948039391.0.tmp
- /data/media/####/-948962912.0.tmp
- /data/media/####/-949886433.0.tmp
- /data/media/####/-950809954.0.tmp
- /data/media/####/-951733475.0.tmp
- /data/media/####/-972050937.0.tmp
- /data/media/####/-972974458.0
- /data/media/####/-973897979.0.tmp
- /data/media/####/-974821500.0.tmp
- /data/media/####/-975745021.0.tmp
- /data/media/####/-976668542.0.tmp
- /data/media/####/-977592063.0
- /data/media/####/-978515584.0
- /data/media/####/-979439105.0
- /data/media/####/-980362626.0.tmp
- /data/media/####/.nomedia
- /data/media/####/journal
- libqaykd
- libtm_pay
- libus
- AES-ECB-PKCS5Padding
- RSA