Technical information
- Android.Spy.2442
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) gl####.w.kunl####.####.com:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) d####.d####.mob.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) 1####.254.116.117:80
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) l####.cc:80
- TCP(HTTP/1.1) api.shu####.cn:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) 2####.205.128.130:80
- TCP(TLS/1.0) s####.we####.com:443
- TCP(TLS/1.0) dcc.shu####.cn:443
- TCP(TLS/1.0) api.shu####.cn:443
- TCP(TLS/1.0) sa.dreams####.cn:443
- TCP(TLS/1.0) ab.dreams####.cn:443
- TCP(TLS/1.0) dai.shu####.cn:443
- TCP(TLS/1.0) opera####.dreams####.cn:443
- TCP(TLS/1.0) daa.shu####.cn:443
- TCP t####.qq.com:80
- a####.exc.mob.com
- a####.u####.com
- ab.dreams####.cn
- acc####.dreams####.cn
- ad.dreams####.cn
- and####.b####.qq.com
- api.s####.mob.com
- api.shu####.cn
- c####.dreams####.cn
- c.d####.mob.com
- d####.d####.mob.com
- d####.dreams####.cn
- daa.shu####.cn
- dai.shu####.cn
- dcc.shu####.cn
- f2.dreams####.cn
- l####.cc
- l####.tbs.qq.com
- m.d####.mob.com
- opera####.dreams####.cn
- p1.dreams####.cn
- pay.dreams####.cn
- pi####.qq.com
- s####.we####.com
- sa.dreams####.cn
- t####.dreams####.cn
- t####.qq.com
- ugc.dreams####.cn
- gl####.w.kunl####.####.com/xm/image/180801/hcDwSKUU0.webp-c.w190
- gl####.w.kunl####.####.com/xm/image/180820/la7Mat6Kw.webp-c.w190
- gl####.w.kunl####.####.com/xm/image/180821/BFkktkQJO.webp-c.w190
- gl####.w.kunl####.####.com/xm/image/181103/NIdSqjKCK.webp-c.w190
- gl####.w.kunl####.####.com/xm/image/181106/irfqe1SJc.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/181221/efe4AuM5I.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190107/dzeX9JxcG.webp-c.w190
- gl####.w.kunl####.####.com/xm/image/190114/JKtgFPyt5.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190124/NUqka7QVu.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190305/6i5pBqJlc.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190305/BDvIklxD6.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190305/Dd2xgG1qr.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190305/TIdenLBY8.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190325/HNZQqtRW1.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/190605/rwHZPuaOI.webp-c.w640
- gl####.w.kunl####.####.com/xm/image/c337087/191104/E1e9Q4Cy2.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/IuZYYl5NH.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/Soxmfn0Ul.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/avEFPiQ65.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/fEPqRBGri.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/jRb32hlZl.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/kDP5utNaS.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/lS0a99oBF.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/vSlkbkrrD.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/vY0cXs7x5.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/c337087/191104/xg6GRvSHo.webp-cw.w64...
- gl####.w.kunl####.####.com/xm/image/dump/180617/zw85gzm7w.webp-c.w190
- l####.cc/i/sdk/is_gal?imei_md5=####&os=####&p_chklst_version=####&retry_...
- m.d####.mob.com/v3/cconf?appkey=####&plat=####&apppkg=####&appver=####&n...
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/log4
- api.s####.mob.com/snsconf
- api.shu####.cn/report?v=####&c=####&e=####
- d####.d####.mob.com/dinfo
- d####.d####.mob.com/dsign
- l####.cc/i/sdk/install
- l####.cc/i/sdk/open
- l####.tbs.qq.com/ajax?c=####&k=####
- m.d####.mob.com/v3/cdata
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/.tpns.service.xml.xml
- /data/data/####/.tpns.settings.xml.xml
- /data/data/####/.tpush_mta.xml
- /data/data/####/1004
- /data/data/####/LKME_Server_Request_Queue.xml
- /data/data/####/MultiDex.lock
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/bugly_db_-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.infinitemarket.comic-journal
- /data/data/####/com.infinitemarket.comic_dna.xml
- /data/data/####/com.infinitemarket.comic_preferences.xml
- /data/data/####/com.infinitemarket.comic_prefs.xml
- /data/data/####/com.infinitemarket.comic_prefs.xml.bak
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDataAPI.xml
- /data/data/####/com_kuaikan_comic_android.xml
- /data/data/####/com_kuaikan_comic_config_android.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/device_id.xml
- /data/data/####/dso_deps
- /data/data/####/dso_lock
- /data/data/####/dso_manifest
- /data/data/####/dso_state
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/kkxm.db-journal
- /data/data/####/libjiagu-733565256.so
- /data/data/####/linkedme_referral_shared_pref.xml
- /data/data/####/linkedme_referral_shared_pref.xml.bak
- /data/data/####/linkedme_referral_shared_pref.xml.bak (deleted)
- /data/data/####/local_crash_lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/security_info
- /data/data/####/sensorsdata.xml
- /data/data/####/share_sdk_1
- /data/data/####/sharesdk.db-journal
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/media/####/..ccvid
- /data/media/####/._android.dat
- /data/media/####/._driver.dat
- /data/media/####/._system.dat
- /data/media/####/.acc.dat
- /data/media/####/.aio.dat
- /data/media/####/.ccvid
- /data/media/####/.dh-journal
- /data/media/####/.dhlock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.lm_device_id
- /data/media/####/.mps
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.rcTag
- /data/media/####/.rc_lock
- /data/media/####/0qkSQLyzcp2m4kgHsF4sQoVB7AE.-895311222.tmp
- /data/media/####/37JOjL9S8lLWFFiU-IfHKxEzvkk.-1825344849.tmp
- /data/media/####/6lfpuXTziJUbt_sZyGcPgqWmHHE.481522732.tmp
- /data/media/####/7ppOu8UKapiQdQA6Rr30SB0ZAwQ.1980961112.tmp
- /data/media/####/8nPgOtOZ8YtI7bYlxTPkhySLERI.-351310248.tmp
- /data/media/####/AD_DATA
- /data/media/####/AqTi4QCkW2DyrT7Mn2uRMwDuPZw.-1406831228.tmp
- /data/media/####/CXYI4oWIQZM0OVoMC--BL-a15e4.1962035563.tmp
- /data/media/####/HOME_DATA
- /data/media/####/Kc3-QaGEotcx90Pb-DUqiA5_MMI.586120656.tmp
- /data/media/####/ONr5yEQFXVvxX44InAyBmrU50CI.-1836576015.tmp
- /data/media/####/SzYLRV8kc3dwXsVHPWzTNWRY_nU.-445501167.tmp
- /data/media/####/TNaj9XsUKBaOqfi8vK8Y_p1bW0E.-540298104.tmp
- /data/media/####/UqAZQ7wsL3W2PgocRXKgH8s93XE.-749686164.tmp
- /data/media/####/VDHDQO5Jzpd5OfCwWkhjbh1KIkA.1383980820.tmp
- /data/media/####/WrAYx8LIB0rHxIs1EuAZ8VAGS2E.916895231.tmp
- /data/media/####/XPdOJXPxklpeOB19ma6mwA_Uf1c.-1223736659.tmp
- /data/media/####/ZFUmZYh3_8S78DxpX5nu9vULifA.-916396392.tmp
- /data/media/####/ZFgAlj6dbFVQumfn8xvaSUePbqE.573279881.tmp
- /data/media/####/_android.dat
- /data/media/####/_driver.dat
- /data/media/####/_system.dat
- /data/media/####/acc.dat
- /data/media/####/aio.dat
- /data/media/####/fKxbHhqYxu9GFtBa89TICVkxJC4.8831476.tmp
- /data/media/####/i2_-V5xIgbD4l0GHyXdYi0lQXEY.1459870860.tmp
- /data/media/####/iPTHD4QvqUcXc2454qXrnw2gook.1992867701.tmp
- /data/media/####/id2cqoayBNM56fy3dsFiJYxwBIA.-1705654375.tmp
- /data/media/####/irGHLNByJ2VOBLoZtQBW7a_306c.-927603111.tmp
- /data/media/####/jMtRZDP9Y4Al1RZyKbya9SXC36E.-1819016392.tmp
- /data/media/####/tX1piRVIl_N0-lnm7qptQApgBAI.-988787817.tmp
- /data/media/####/tbslog.txt
- /data/media/####/wk2MrSSK59-d9nd3BIT_zJPyZic.-128074377.tmp
- /data/media/####/xZwRiSgtrTyYZxRxCbb6v8PAa3U.538468538.tmp
- /data/media/####/yn4YCJ09Y6vZYTNEzE_Cn_iuC_8.533472342.tmp
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/lib/libxguardian.so <Package>,2100307961; 55426 203.205.128.130 [{"idx":0,"ts":%d,"et":2000,"si":0,"ui":"<IMEI>","ky":"Axg%lu","mid":"0","ev":{"ov":"18","sr":"600*752","md":"<System Property>","lg":"en","sv":"3.26","mf":"unknown","apn":"%s"}}] 0 18
- cat /sys/class/net/wlan0/address
- date
- df
- getprop
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- id
- ls /dev/socket
- mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
- ps
- service call iphonesubinfo 1
- sh
- sh -c cat
- sh -c cat /proc/meminfo
- sh -c cat /proc/sys/kernel/osrelease
- sh -c cat /proc/sys/kernel/random/boot_id
- sh -c cat /proc/sys/kernel/random/uuid
- sh -c cat /proc/uptime
- sh -c cat /sys/block/mmcblk0/device/cid
- sh -c cat /sys/class/net/eth0/address
- sh -c cat /sys/class/net/eth1/address
- sh -c cat /sys/class/net/eth2/address
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/..ccdid
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/..ccvid
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/._driver.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/.acc.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/.aio.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccdid
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccvid
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_driver.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/acc.dat
- sh -c cat <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/aio.dat
- sh -c cd /proc/;cat cpuinfo
- sh -c cd /proc/net/ && cat arp
- sh -c cd /proc/self/;cat status
- sh -c cd /sys/class/net/eth0/ && cat address
- sh -c cd /sys/class/net/wlan0/ && cat address
- sh -c echo MERGMjgzNjc0OEUyMkI4MjE1MzU4RTdCRjUwQjUxRUI1RTQ4QUI6NzhERjU5OkQ5MERGRA== > <SD-Card>/../../../../../..<SD-Card>/._driver.dat
- sh -c echo MERGMjgzNjc0OEUyMkI4MjE1MzU4RTdCRjUwQjUxRUI1RTQ4QUI6NzhERjU5OkQ5MERGRA== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_driver.dat
- sh -c echo MjRDNjhCRjJGRTcwRDZBMjdBMzM2RjUwMjIwRjNFRTRjOGZ2NXhDVjUrMllMaEtrSGRjWjQ2NGp3aGlwbGFNMTV4R3gydjFBVUIxUXMzVUNHMGN5OC9qNFJUK3E5N0xkbGYxdkF6WE5udSsxTDV0MnF6dSt5QnphWHRvODdJUmNxTjAvenE2bDBMeWpza3Zva0Z1UnFxMTdOMW9iWWFSZlArVkZJOE5oS0MvUmcvaWVtYkFyVG1jQlRJZWlJSGlJb3NNaDhZNFNRdFlVUGhBM2pFb3V4TEpJeHozSDdPN25wdEhrRTNqYXVMS1NndFlWY3Y4NXljSzE4YU5IaS9zSHBvWnF4S2FEMWgxVXRjd01wSmlFWlZRaHcvcnM5bmp4SUQvNEpCekE2SHJPS0syK2ljQXBpejJwUWc5Y09Pd3ovWWk2YXFoY3Q4NnJwb0g3Tk4vbTZqYjQzcTZvZ3pzK1lPQ2JRY1ZQRkd4NG1EdGZTKzJVbDYwTzRURl
- sh -c echo NjgxNEMxMUQ0RTg5QzZGMjFBQkQ4NTk4NDlGQTBENzcxNTcyOTI0ODk1 > <SD-Card>/../../../../../..<SD-Card>/.acc.dat
- sh -c echo NjgxNEMxMUQ0RTg5QzZGMjFBQkQ4NTk4NDlGQTBENzcxNTcyOTI0ODk1 > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/acc.dat
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/..ccvid
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccvid
- sh -c echo OThBRjQ0QzQ5NkMyQTJBMkU0MTZBRDRDNTFENTA2MjkxNTcyOTI0ODkx > <SD-Card>/../../../../../..<SD-Card>/.aio.dat
- sh -c echo OThBRjQ0QzQ5NkMyQTJBMkU0MTZBRDRDNTFENTA2MjkxNTcyOTI0ODkx > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/aio.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c echo QzlDODU0MTRDMkY2NkVDNjNENkEyOTIyOEI3ODI3OUJGNTVBQUY6OEZDNTVBOjAwNTgwOA== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c echo QzlDODU0MTRDMkY2NkVDNjNENkEyOTIyOEI3ODI3OUJGNTVBQUY6OEZDNTVBOjAwNTgwOA== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- sh <Package Folder>/lib/libxguardian.so <Package>,2100307961; 55426 203.205.128.130 [{ idx :0, ts :%d, et :2000, si :0, ui : <IMEI> , ky : Axg%lu , mid : 0 , ev :{ ov : 18 , sr : 600*752 , md : <System Property> , lg : en , sv : 3.26 , mf : unknown , apn : %s }}] 0 18
- Bugly
- du
- libimagepipeline
- libjiagu-733565256
- neh
- tpnsSecurity
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-GCM-NoPadding
- DES-ECB-PKCS5Padding
- desede-CBC-NoPadding