Technical information
- 106904006189121: myqxt<IMSI>
- Android.DownLoader.441.origin
- Android.SmsSend.21305
- Android.SmsSend.23889
- Android.Spy.398.origin
- Android.Triada.235.origin
- Android.Triada.236.origin
- Android.Triada.243
- Android.Triada.248.origin
- Android.Triada.351.origin
- Android.Triada.373.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) pay.lik####.com:7820
- TCP(HTTP/1.1) dws.you####.com.####.com:8080
- TCP(HTTP/1.1) jx.ha####.com:80
- TCP(HTTP/1.1) a####.xctr####.com:12580
- TCP(HTTP/1.1) x####.ha####.com:80
- TCP(HTTP/1.1) 1####.27.154.102:1234
- TCP(HTTP/1.1) pay.lik####.com:7830
- TCP(HTTP/1.1) pus####.to####.net:80
- TCP(HTTP/1.1) pay.lik####.com:7840
- TCP(HTTP/1.1) s####.ha####.com:9999
- TCP(HTTP/1.1) wap.n.sh####.com:80
- TCP(HTTP/1.1) jx####.ha####.com:9999
- TCP(TLS/1.0) dow####.b####.com:443
- TCP(TLS/1.0) b.bdst####.com:443
- TCP(TLS/1.0) box.jom####.com:443
- TCP(TLS/1.0) mbd.n.sh####.com:443
- TCP(TLS/1.0) mbd.b####.com:443
- TCP(TLS/1.0) ti####.jom####.com:443
- TCP(TLS/1.0) mb####.n.sh####.com:443
- TCP(TLS/1.0) hpd.b####.com:443
- TCP(TLS/1.0) www.a.sh####.com:443
- TCP(TLS/1.0) ss0.b####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) t####.jom####.com:443
- TCP(TLS/1.0) down####.b####.com:443
- TCP(TLS/1.0) h####.b####.com:443
- TCP(TLS/1.0) g####.bdst####.com:443
- TCP(TLS/1.0) wap.n.sh####.com:443
- TCP(TLS/1.0) na0.bdst####.com.####.com:443
- a####.xctr####.com
- api.lik####.com
- b.bdst####.com
- do####.abc####.info
- dow####.b####.com
- down####.b####.com
- dws.you####.com
- e####.bdst####.com
- ext.b####.com
- f####.b####.com
- g####.bdst####.com
- h####.b####.com
- hm.b####.com
- hpd.b####.com
- jx####.ha####.com
- jx.ha####.com
- m.b####.com
- mbd.b####.com
- mo.b####.com
- na0.bdst####.com
- pay.lik####.com
- pus####.to####.net
- pus####.tou####.cn
- s####.ha####.com
- s.bdst####.com
- ss0.b####.com
- ss1.b####.com
- ss2.b####.com
- sv.bdst####.com
- ti####.b####.com
- timg####.b####.com
- up####.abc####.info
- www.b####.com
- x####.ha####.com
- a####.xctr####.com:12580/log2?c=####
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.damai_p2018041...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.miwan_p2018041...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.myadv_p2017052...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.mysdk_p2018032...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.qipa_p20180419...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.shangan_p20180...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.taiku_p2017120...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.utadv_p2017081...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.yufeng_p201711...
- dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.zhongzhi_p2018...
- jx####.ha####.com:9999/main/checkAppInfo.do?IMSI=####&V=####&mobile=####...
- jx####.ha####.com:9999/main/uploadDeviceInfo.do?IMSI=####&V=####&mobile=...
- jx####.ha####.com:9999/page/getPageContent.do?IMSI=####&V=####&imei=####...
- jx####.ha####.com:9999/sms/submit.do?imsi=####&feechanid=####&sms=####&f...
- jx.ha####.com/SdkNotity.aspx?i=####&v=####&c=####&av=####&dm=####&t=####...
- pay.lik####.com:7820/?igtcmd=####&gameid=####
- pay.lik####.com:7830/openplg?appid=####&channelid=####
- pay.lik####.com:7840/gselfc?iccid=####&price=####&imsi=####&imei=####&ap...
- pay.lik####.com:7840/gselfpi?appid=####&channel=####
- pus####.to####.net/czfiles/plugindp
- s####.ha####.com:9999/log/stat.do?i=####&v=####&c=####&av=####&dm=####&t...
- wap.n.sh####.com/
- x####.ha####.com/getconfig.aspx
- x####.ha####.com/getjar.aspx?pno=####
- x####.ha####.com/versioncheck.aspx
- pay.lik####.com:7820/
- /data/data/####/04c7c02b-bb2f-4547-b183-3d9c692e62ad.zip
- /data/data/####/57CSXG4AkRf8mBYZ.zip
- /data/data/####/5c0d58e4-66ee-448b-9bdc-acfee31ae7a6.zip
- /data/data/####/6623bdf78746d87e7c6c2888a5c70c9f.apk
- /data/data/####/67FrdcF4gl2hImERCnpAug==.new
- /data/data/####/DATA_DB-journal
- /data/data/####/KooVrmclnZxDD3BodBEzDw==.new
- /data/data/####/LGXEUljdGWi27Y-ctaxaHg==
- /data/data/####/Signature_0.key
- /data/data/####/a0c175d0.apk
- /data/data/####/appStatus.xml
- /data/data/####/base-1.apk
- /data/data/####/base-1.dex
- /data/data/####/base-1.dex (deleted)
- /data/data/####/c2f3051e-6412-4077-a649-ed06d97de7ed.zip
- /data/data/####/config.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dbinfo.xml
- /data/data/####/done
- /data/data/####/dp.apk
- /data/data/####/eOaNAKS7ZFL-EL5m7K1DVQ==
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/heajva_f.zip
- /data/data/####/index
- /data/data/####/libcocos2dcpp.so
- /data/data/####/libcrypt_sign.so
- /data/data/####/libgoldcoast.so
- /data/data/####/libkjOnlinePay.so
- /data/data/####/n2-lXTPq9At8Dxrw
- /data/data/####/net.tt.plugin.damai (deleted)
- /data/data/####/net.tt.plugin.damai.apk
- /data/data/####/net.tt.plugin.miwan (deleted)
- /data/data/####/net.tt.plugin.miwan.apk
- /data/data/####/net.tt.plugin.myadv (deleted)
- /data/data/####/net.tt.plugin.myadv.apk
- /data/data/####/net.tt.plugin.mysdk (deleted)
- /data/data/####/net.tt.plugin.mysdk.apk
- /data/data/####/net.tt.plugin.qipa (deleted)
- /data/data/####/net.tt.plugin.qipa.apk
- /data/data/####/net.tt.plugin.shangan (deleted)
- /data/data/####/net.tt.plugin.shangan.apk
- /data/data/####/net.tt.plugin.taiku (deleted)
- /data/data/####/net.tt.plugin.taiku.apk
- /data/data/####/net.tt.plugin.utadv (deleted)
- /data/data/####/net.tt.plugin.utadv.apk
- /data/data/####/net.tt.plugin.yufeng (deleted)
- /data/data/####/net.tt.plugin.yufeng.apk
- /data/data/####/net.tt.plugin.zhongzhi (deleted)
- /data/data/####/net.tt.plugin.zhongzhi.apk
- /data/data/####/plugin.jar
- /data/data/####/rdata_comwjkziukz.new
- /data/data/####/runtimeConfig.xml
- /data/data/####/smsJx_v4_2.xml
- /data/data/####/tmp.AL2082
- /data/data/####/tmp.aL2082
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/wochi_v4.db-journal
- /data/media/####/.config
- /system/bin/netcfg
- chmod -R 755 <Package Folder>/Plugin
- ls -l /system/bin/su
- esodkiap
- eyudgijw
- DES-ECB-NoPadding
- AES-CBC-PKCS5Padding
- DESede