Technical information
- Android.SmsSpy.135.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) api-s####.mob.com:80
- TCP(HTTP/1.1) ap####.yk####.com:80
- TCP(HTTP/1.1) ap####.hia####.com:80
- TCP(HTTP/1.1) i####.lan####.cc:80
- TCP(HTTP/1.1) m.mpl.du####.com:80
- TCP(HTTP/1.1) a####.du####.com:80
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) co####.j####.cn:443
- TCP(TLS/1.0) ce3e####.j####.cn:443
- TCP(TLS/1.0) errne####.u####.com.####.com:443
- TCP(TLS/1.0) aip.baid####.com:443
- TCP(TLS/1.0) s####.cl####.com:443
- TCP(TLS/1.0) smartop####.jig####.cn:443
- TCP(TLS/1.0) i####.lan####.cc:443
- TCP(TLS/1.0) msh####.b####.com:443
- TCP(TLS/1.0) tbsreco####.i####.qq.com:443
- TCP(TLS/1.0) new-####.u####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) sdk.yol####.hk:443
- TCP(TLS/1.0) s####.cn.ron####.com:443
- TCP(TLS/1.0) sy.c####.cn:443
- TCP(TLS/1.0) bj####.j####.cn:443
- TCP(TLS/1.0) u####.u####.com.####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) 2####.239.36.223:443
- TCP(TLS/1.0) iot.sino####.com:443
- TCP(TLS/1.2) 74.1####.205.94:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 1####.177.14.147:443
- TCP 27.44.2####.188:21001
- UDP 1####.251.1.102:443
- TCP schedul####.yo####.com:443
- UDP s.j####.cn:19000
- TCP 1.94.1####.136:7002
- a####.du####.com
- a####.du####.com
- a####.hia####.com
- a####.hia####.com
- abroad-####.du####.com
- abroad-####.hia####.com
- aip.baid####.com
- android####.go####.com
- ap####.du####.com
- ap####.du####.com
- ap####.hia####.com
- ap####.hia####.com
- ap####.mob####.com
- ap####.mob####.com
- ap####.mob####.com
- ap####.mob####.com
- ap####.mob####.com
- ap####.yk####.com
- ap####.yk####.com
- ap####.yk####.com
- ap####.yk####.com
- ap####.yk####.com
- api####.du####.com
- api####.hia####.com
- api-s####.mob.com
- api-ve####.du####.com
- api-ve####.hia####.com
- api.map.b####.com
- bj####.j####.cn
- cache-v####.du####.com
- cache-v####.hia####.com
- cdn-api####.du####.com
- cdn-api####.hia####.com
- ce3e####.j####.cn
- co####.j####.cn
- devs-####.du####.com
- devs-####.hia####.com
- errne####.u####.com
- f####.gst####.com
- g-a####.du####.com
- g-a####.hia####.com
- gmscomp####.google####.com
- i####.lan####.cc
- i####.me
- iot.sino####.com
- log-ve####.du####.com
- log-ve####.hia####.com
- m####.hia####.com
- m-a####.du####.com
- m-a####.hia####.com
- m.lan####.cc
- m.mpl.du####.com
- msh####.b####.com
- o####.youza####.com
- s####.cl####.com
- s####.cn.ron####.com
- s.j####.cn
- sdk-####.du####.com
- sdk-####.hia####.com
- sdk.yol####.hk
- sis-####.j####.cn
- sis.j####.io
- smartop####.jig####.cn
- status-####.j####.cn
- sy.c####.cn
- tbsreco####.i####.qq.com
- u####.u####.com
- ut####.u####.com
- www.google####.com
- a####.du####.com/privacy/policy/authorization/status?networktype=####&is...
- ap####.yk####.com/dm?appkey=####
- ap####.yk####.com/v6/gcf?networktype=####&ts=####&isAgreePp=####&v6=####...
- i####.lan####.cc/aboutusprivacy_apple?city_id_change=####&uid=####&key=#...
- msh####.b####.com:443/p/1/rs/250/985050722/1729936777/6fccf1c03aadd75da4...
- aip.baid####.com:443/public/2.0/license/face-api/app/querydevicelicense
- ap####.hia####.com/getDuidBlacklist
- api-s####.mob.com/conf5
- api-s####.mob.com/conn
- api-s####.mob.com/snsconf
- api.map.b####.com:443/sdkcs/verify
- ce3e####.j####.cn:443/wi/plp8j0k
- co####.j####.cn:443/v1/status
- errne####.u####.com.####.com:443/apm_cc
- i####.lan####.cc:443/2/users_action_statistics
- iot.sino####.com:443/api/sino-deviceaccess/sdk/authentication
- m.mpl.du####.com/tcp/config/init
- msh####.b####.com:443/c/11/z/250/985050722/1729936776/3f73b6af40271c4717...
- msh####.b####.com:443/c/11/z/250/985050722/1729936782/be7498221158a7c4fa...
- msh####.b####.com:443/c/11/z/250/985050722/1729936787/4187d598af50469b28...
- msh####.b####.com:443/f/2/jc/250/985050722/1729936776/3f73b6af40271c4717...
- msh####.b####.com:443/p/1/auh/250/985050001/1729936770/b35a68933157bc492...
- msh####.b####.com:443/p/1/r/250/985050722/1729936779/efecc2fff91965a18ce...
- msh####.b####.com:443/p/1/r/250/985050722/1729936780/abea672dbc7a1dd464f...
- msh####.b####.com:443/s/3/gd/250/985050722/1729936775/c16fd2b98075085385...
- msh####.b####.com:443/s/5/aio/250/985050722/1729936772/6f4b6f5d3c58452ab...
- new-####.u####.com:443/api/postZdata/v4
- s####.cl####.com:443//log/fdr/v3
- s####.cn.ron####.com:443/active.json
- sdk.yol####.hk:443//open_api/sdk/init
- smartop####.jig####.cn:443/v1/visual-bury-sdk-api/smartop/1/getEvent
- sy.c####.cn:443/flash/thin/accountInit/v3
- tbsreco####.i####.qq.com:443/getconfig
- u####.u####.com.####.com:443/unify_logs
- u####.u####.com.####.com:443/zcfg
- /data/anr/traces.txt
- /data/data/####/.cl_lock
- /data/data/####/.dex2oatlock
- /data/data/####/.dh
- /data/data/####/.dh-journal
- /data/data/####/.dhlock
- /data/data/####/.dk
- /data/data/####/.duid
- /data/data/####/.gcf_lock
- /data/data/####/.imprint
- /data/data/####/.lock
- /data/data/####/.mp_lockcn_sharesdk_weibodb_QQ_2
- /data/data/####/.mp_lockcn_sharesdk_weibodb_SinaWeibo_1
- /data/data/####/.mp_lockcn_sharesdk_weibodb_WechatMoments_1
- /data/data/####/.mp_lockcn_sharesdk_weibodb_Wechat_1
- /data/data/####/.mp_lockgu_0
- /data/data/####/.mp_lockmob_commons_1
- /data/data/####/.mp_lockmob_dh_1
- /data/data/####/.mp_lockshare_sdk_1
- /data/data/####/.mrecord
- /data/data/####/.mrecord (deleted)
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/.updateIV.dat
- /data/data/####/.updateIV.dat_0
- /data/data/####/.updateIV.dat_1
- /data/data/####/.updateIV.dat_2
- /data/data/####/.updateIV.dat_3
- /data/data/####/.updateIV.dat_4
- /data/data/####/.updateIV.dat_5
- /data/data/####/0000000lllll_0.dex
- /data/data/####/0000000lllll_1.dex
- /data/data/####/0000000lllll_2.dex
- /data/data/####/0000000lllll_3.dex
- /data/data/####/0000000lllll_4.dex
- /data/data/####/0000000lllll_5.dex
- /data/data/####/000O00ll111l_0.dex
- /data/data/####/000O00ll111l_1.dex
- /data/data/####/000O00ll111l_2.dex
- /data/data/####/000O00ll111l_3.dex
- /data/data/####/000O00ll111l_4.dex
- /data/data/####/000O00ll111l_5.dex
- /data/data/####/00O000ll111l_0.dex
- /data/data/####/00O000ll111l_0.dex (deleted)
- /data/data/####/00O000ll111l_0.dex.flock
- /data/data/####/00O000ll111l_0.dex.flock (deleted)
- /data/data/####/00O000ll111l_1.dex
- /data/data/####/00O000ll111l_1.dex (deleted)
- /data/data/####/00O000ll111l_1.dex.flock
- /data/data/####/00O000ll111l_1.dex.flock (deleted)
- /data/data/####/00O000ll111l_2.dex
- /data/data/####/00O000ll111l_2.dex (deleted)
- /data/data/####/00O000ll111l_2.dex.flock
- /data/data/####/00O000ll111l_2.dex.flock (deleted)
- /data/data/####/00O000ll111l_3.dex
- /data/data/####/00O000ll111l_3.dex (deleted)
- /data/data/####/00O000ll111l_3.dex.flock
- /data/data/####/00O000ll111l_3.dex.flock (deleted)
- /data/data/####/00O000ll111l_4.dex
- /data/data/####/00O000ll111l_4.dex (deleted)
- /data/data/####/00O000ll111l_4.dex.flock
- /data/data/####/00O000ll111l_4.dex.flock (deleted)
- /data/data/####/00O000ll111l_5.dex
- /data/data/####/00O000ll111l_5.dex (deleted)
- /data/data/####/00O000ll111l_5.dex.flock
- /data/data/####/00O000ll111l_5.dex.flock (deleted)
- /data/data/####/0OO00l111l1l
- /data/data/####/0OO00l111l1l.lock
- /data/data/####/0a395752-5f2b-4e42-bdb1-c0093d79c6ae
- /data/data/####/23cd2bbe4f0af219_0
- /data/data/####/424fd016946f2e45_0 (deleted)
- /data/data/####/52aa66ab7822235c_0
- /data/data/####/52aa66ab7822235c_1
- /data/data/####/74741f984705377b_0
- /data/data/####/9851350d1c934156_0
- /data/data/####/COUNTLY_STORE.xml
- /data/data/####/Cookies-journal
- /data/data/####/FwLog.xml
- /data/data/####/IpInfos.xml
- /data/data/####/Map_Privacy.xml
- /data/data/####/Push_Page_Config.xml
- /data/data/####/Statistics.xml
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/Y29uZmlnXzU2NzhmY2FlZTBmNTVhNDdmMTAwMjdmMw.sp
- /data/data/####/Y29uZmlnXzU2NzhmY2FlZTBmNTVhNDdmMTAwMjdmMw.sp.bak
- /data/data/####/ZzxCache.xml
- /data/data/####/_nohttp_cache_db.db
- /data/data/####/_nohttp_cache_db.db-journal
- /data/data/####/_nohttp_cookies_db.db
- /data/data/####/_nohttp_cookies_db.db-journal
- /data/data/####/ad_auth.xml
- /data/data/####/app_LANCAREWEB-FACE-ANDROID_3
- /data/data/####/app_idl-license.face-android
- /data/data/####/bac.catch
- /data/data/####/bwc.catch
- /data/data/####/cn.jiguang.common.xml
- /data/data/####/cn.jiguang.joperate.jcore_config.xml
- /data/data/####/cn.jiguang.prefs.xml
- /data/data/####/cn.jiguang.sdk.address.xml
- /data/data/####/cn.jiguang.sdk.address.xml.bak (deleted)
- /data/data/####/cn.jiguang.sdk.device.xml
- /data/data/####/cn.jiguang.sdk.user.profile.xml
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.android.user.profile.xml.bak
- /data/data/####/cn.jpush.config.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/cn_sharesdk_weibodb_QQ_2
- /data/data/####/cn_sharesdk_weibodb_SinaWeibo_1
- /data/data/####/cn_sharesdk_weibodb_WechatMoments_1
- /data/data/####/cn_sharesdk_weibodb_Wechat_1
- /data/data/####/com.china.lancareweb_preferences.xml
- /data/data/####/crs.catch
- /data/data/####/ct_account_api_sdk.xml
- /data/data/####/delayed_transmission_flag_new.xml
- /data/data/####/e492e5e1-614d-45dd-ba65-fd034cbc3bda
- /data/data/####/ef0e52ed-1c35-47ed-a027-b36a87ff84b7
- /data/data/####/efs_launch.xml
- /data/data/####/efs_launch.xml.bak
- /data/data/####/efsid
- /data/data/####/elp_msg.db
- /data/data/####/elp_msg.db-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f04277d4f8f504f2_0
- /data/data/####/gu_0
- /data/data/####/i==1.2.0&&3.8.05.31_1729936757679_dW5pZnlfbG9ncw==;.log
- /data/data/####/index
- /data/data/####/internal_debug.xml
- /data/data/####/itconfig.sp
- /data/data/####/itconfig.sp.bak
- /data/data/####/lancare.xml
- /data/data/####/leroadcfg.xml
- /data/data/####/leroadmshieldcfg.xml
- /data/data/####/libcuid_v3.so
- /data/data/####/libshellx-super.com.china.lancareweb.so
- /data/data/####/locale.config.xml
- /data/data/####/login_sdk_235.db
- /data/data/####/login_sdk_235.db-journal
- /data/data/####/map_pref.xml
- /data/data/####/metrics_guid
- /data/data/####/mmap_block
- /data/data/####/mob_commons_1
- /data/data/####/mob_dh_1
- /data/data/####/msfffppcfg.xml
- /data/data/####/msfffppcfg.xml.bak
- /data/data/####/msgzpfc.xml
- /data/data/####/msgzpfc.xml.bak
- /data/data/####/msre.db-journal
- /data/data/####/msre_po_rt.xml
- /data/data/####/msre_po_rt.xml.bak
- /data/data/####/msre_po_rt.xml.bak (deleted)
- /data/data/####/msvolcano.db-journal
- /data/data/####/netmt.catch.
- /data/data/####/o0oooOO0ooOo.dat
- /data/data/####/old_app_active_cache.l
- /data/data/####/old_report_cache.l
- /data/data/####/old_report_cache.l (deleted)
- /data/data/####/paconfig.sp
- /data/data/####/paconfig.sp.bak
- /data/data/####/placeholder_00001729936751712001.dirty.xcrash
- /data/data/####/placeholder_00001729936751843002.clean.xcrash
- /data/data/####/placeholder_00001729936751843003.dirty.xcrash
- /data/data/####/placeholder_00001729936751849004.clean.xcrash
- /data/data/####/placeholder_00001729936751849005.dirty.xcrash
- /data/data/####/placeholder_00001729936751879006.clean.xcrash
- /data/data/####/prefs.lock
- /data/data/####/proc_auxv
- /data/data/####/push_stat_cache.json
- /data/data/####/qn_sdk_config.xml
- /data/data/####/r_key_info
- /data/data/####/report_cache.l
- /data/data/####/reserved_events_cache.l
- /data/data/####/rlogs.db-journal
- /data/data/####/rlogs.db-journal (deleted)
- /data/data/####/sai.xml
- /data/data/####/sdk.txt
- /data/data/####/sec_gd_config_mshield.xml
- /data/data/####/sec_gd_config_mshield.xml.bak
- /data/data/####/secure_rc_encryption_info.xml
- /data/data/####/sendlock
- /data/data/####/shanyan_share_data.xml
- /data/data/####/shanyan_share_data.xml.bak
- /data/data/####/share_sdk_1
- /data/data/####/sino_minute_sdk_sp.xml
- /data/data/####/sp_replace_flag.sp
- /data/data/####/sp_replace_flag.sp.bak
- /data/data/####/ssoconfigs.xml
- /data/data/####/ssoconfigs.xml.bak
- /data/data/####/t==9.5.2&&3.8.05.31_1729936753787_dW5pZnlfbG9ncw==;.log
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_emergence.xml
- /data/data/####/tbs_preloadx5_check_cfg_file.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/the-real-index
- /data/data/####/tosversion
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/uifa.xml
- /data/data/####/um_policy_grant.xml
- /data/data/####/um_session_id.xml
- /data/data/####/um_umcrash.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_policy_result_flag
- /data/data/####/umeng_sp_oaid.xml
- /data/data/####/umeng_zcfg_flag
- /data/data/####/umeng_zero_cache.db
- /data/data/####/umeng_zero_cache.db-journal
- /data/data/####/umzid_general_config.xml
- /data/data/####/unique
- /data/data/####/user_properties_cache.l
- /data/data/####/ver
- /data/data/####/z==1.2.0&&3.8.05.31_1729936747222_emNmZw==;.log
- /data/misc/####/primary.prof
- /data/user_de/####/move_to_de_records.xml
- /data/user_de/####/push_client_self_info.xml
- /system/bin/netcfg
- cat /proc/5430/mounts
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.build.version.security_patch
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- ls -l /system/bin/su
- ls /
- ls /sys/class/thermal
- sh -c type su
- libBaiduMapSDK_base_v7_5_5
- libRongIMLib
- libbd_unifylicense
- libbdface_sdk
- libcrashsdk
- libgnustl_shared
- libpl_droidsonroids_gif
- librongcloud_xcrash
- librtslog
- libshellx-super.com.china.lancareweb
- libsqlite
- libtiny_magic
- libumeng-spy
- libvcom_mediasdk
- libylpacker
- libyolanda_calc
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS7Padding
- DES
- DES-CBC-PKCS5Padding
- RC4
- RSA-ECB-PKCS1Padding
- RSA-None-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- DES
- RSA-ECB-PKCS1Padding