Technical information
- Android.Mixi.16.origin
- Android.Xiny.184.origin
- Android.Loki.15.origin
- Android.Backdoor.336.origin
- Android.MulDrop.84.origin
- Android.DownLoader.304.origin
- Android.Backdoor.336.origin
- s####.####.com
- t####.####.com
- g####.####.com
- ip####.io
- d####.####.com
- e####.####.com
- and####.####.com
- m####.####.com
- a####.####.com
- s####.####.com/rtf/4303e8e0c1feae973da3a9e9f6774365.slze
- s####.####.com/cr/sdk/dynV17041701D/des_onlydyV17041701Dj1so32.zip
- g####.####.com/cr/sv/getRecord?eids=####&appKey=####&flag=####
- s####.####.com/rtf/6115c9af6b1c30917b41f5c378956f40.slze
- s####.####.com/rtf/617d41e9630fe337ac7a57c083c1c068.slze
- s####.####.com/rtf/408c223fa967dc4d9933c57041b7f49f.slze
- s####.####.com/rtf/180562885f3e4c613c5e9844caef22755.slze
- g####.####.com/cr/sv/getRltNew?eid=####&estatus=####&appkey=####&pid=###...
- d####.####.com/thinking/group/rtt0421_662.apk
- s####.####.com/cr/sdk/170417/goplaysdk_statistics_all_1704171.dat
- a####.####.com/pull/top_offer?gaid=####&id=####
- ip####.io/json
- s####.####.com/rtf/806a6b70c891c315e00b5dfd26af42ed.slze
- g####.####.com/cr/sv/getGoFile?name=####
- e####.####.com/thinking/group/exp
- s####.####.com/rtf/421d8d61ecc491beaa0499837e702272.slze
- s####.####.com/rtf/6106c835e4d5906917109492ee4c4578.slze
- s####.####.com/rtf/6408c259f823e8db8ced83ef353a06b4.slze
- g####.####.com/cr/sv/getEPList
- a####.####.com/oversea_adjust_and_download_write_redis/notify/download/app
- a####.####.com/subscribe/api/1110
- and####.####.com/rqd/async
- t####.####.com/ggview/rsddateindex
- g####.####.com/pilot/api/300102
- m####.####.com/errorview/api/601
- a####.####.com/app_logs
- /data/data/####/databases/cc.db-journal
- /data/data/####/files/1493729027707_onlydyV17041701Dj1so32.so
- /data/data/####/databases/cc.db
- /data/data/####/files/.snow/b.png
- /data/data/####/files/.S1CH1S/611E9A41717CEEE048E4AE210100CA33
- /data/data/####/files/wifi_configuration2DB8520H4/5wifi_configuration2DB8520H46
- /data/data/####/databases/webviewCookiesChromium.db-journal
- /data/data/####/files/.S1CH1S/B9715B7918D2D279EFCC5D0D892DFA3A
- /data/data/####/shared_prefs/umeng_general_config.xml
- /data/data/####/files/408.jar
- /data/data/####/files/.umeng/exchangeIdentity.json
- /data/data/####/files/.S1CH1S/1C6146ECCF85DE5D6A343ABE109AC76D
- /data/data/####/databases/ua.db.mirror
- /data/data/####/files/611.jar
- /data/data/####/files/806.jar
- /data/data/####/files/.snow/.zip/rt8
- /data/data/####/files/exid.dat
- /data/data/####/files/hello.apk
- /data/data/####/databases/webview.db-journal
- /data/data/####/files/source.apk
- /data/data/####/files/awsrabf/libLDyARNDidKiYcqzxdynamicloader.so
- /data/data/####/files/430.jar
- /data/data/####/shared_prefs/share_data.xml
- /data/data/####/files/.snow/.dico.apk
- /data/data/####/files/na1l2t/ntmp21342190
- /data/data/####/files/hftJcw46N.jar
- /data/data/####/files/.snow/.service
- /sdcard/.windy/508e8558f784e3a21d3368e4763e2693.dat
- /data/data/####/files/.snow/myshell
- /data/data/####/files/.snow/.ir
- /data/data/####/files/.snow/checkFile0
- /data/data/####/shared_prefs/googlesdk.xml.bak
- /data/data/####/databases/webviewCookiesChromium.db.mirror
- /data/data/####/files/.S1CH1S/4BE0DCBCE845EDA30A4A7CBC6A2E86C4
- /data/data/####/files/awsrabf/libbcVPHHDpaVhsxLGUlala.so
- /data/data/####/files/.snow/.center.tapk
- /data/data/####/files/.snow/exp
- /data/data/####/files/.snow/.dlme.apk
- /data/data/####/files/.S1CH1S/301B743A25916CB9DA3C6199B2E0506E
- /data/data/####/files/umeng_it.cache
- /data/data/####/files/.snow/.catr.apk
- /data/data/####/files/security_info
- /data/data/####/files/.snow/.ukd
- /data/data/####/databases/bugly_db_legu.mirror
- /data/data/####/files/.work/postroot.sh
- /data/data/####/files/local_crash_lock
- /data/data/####/files/native_record_lock
- /data/data/####/files/95d3861ebbd38c2dc8795952cc6c4d37.data
- /sdcard/.windy/508e8558f784e3a21d3368e4763e2693.tmp
- /data/data/####/files/.snow/.uks
- /data/data/####/files/.snow/.dg
- /data/data/####/files/awsrabf/libqBikvXzxORCegosEzxc.so
- /data/data/####/shared_prefs/googlesdk.xml
- /data/data/####/databases/ua.db
- /data/data/####/files/.snow/.dlsb.apk
- /data/data/####/files/617.jar
- /data/data/####/files/640.jar
- /data/data/####/files/.default/95d3861ebbd38c2dc8795952cc6c4d37.data.temp
- /data/data/####/files/awsrabf/libUniUxqsTCxkMnvngbt.so
- /data/data/####/files/.play/test
- /data/data/####/files/.S1CH1S/C32F925E36EF6D6723BA863618B860E6
- /data/data/####/shared_prefs/internal.xml
- /data/data/####/files/.play/.md
- /data/data/####/files/1805.jar
- /data/data/####/shared_prefs/####_preferences.xml
- /data/data/####/files/.snow/.zip/rsh
- /data/data/####/databases/webview.db.mirror
- /data/data/####/files/421.jar
- /data/data/####/files/libhjdSsDMxuUQaCVMDbootstrap.so
- /data/data/####/shared_prefs/umeng_general_config.xml.bak
- /data/data/####/files/23DB8520H32/####12x862
- /data/data/####/files/.snow/supolicy
- /data/data/####/tx_shell/libufix.so
- /data/data/####/files/.snow/busybox
- /data/data/####/mix.dex
- /data/data/####/files/.snow/.zip/r4
- /data/data/####/files/.snow/.zip/r1
- /data/data/####/files/.snow/.zip/r3
- /data/data/####/files/.snow/.zip/r2
- /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s
- /data/data/####/files/tzcar.apk
- /data/data/####/databases/ua.db-journal
- /data/data/####/tx_shell/libnfix.so
- /data/data/####/files/.snow/.client
- /data/data/####/files/.S1CH1S/77C88DAB96A79BD7EA89098DEBA88F21
- /data/data/####/files/.imprint
- /data/data/####/files/.snow/checkFile13
- /data/data/####/files/.snow/.zip/mkdevsh
- /data/data/####/files/610.jar
- /data/data/####/files/.gepd/gpdu
- /data/data/####/tx_shell/libshella-2.10.2.3.so
- /data/data/####/shared_prefs/####_preferences.xml.bak
- /data/data/####/files/.snow/a.xml
- /data/data/####/databases/bugly_db_legu-journal
- /data/data/####/files/.snow/.uok
- /data/data/####/files/.S1CH1S/DAE162B8F5BD577ECEBC6108599F20CC
- /data/data/####/files/.S1CH1S/92A3CECF3802288A78D870D83988D064
- /data/data/####/files/LDyARNDidKiYcqzxdynamicloader.jar
- /data/data/####/files/Android-x86112.jar
- /data/data/####/databases/cc.db.mirror
- /data/data/####/files/.snow/.catr.apk
- /data/data/####/files/.work/postroot.sh
- /data/data/####/files/.snow/.ir
- /data/data/####/files/.snow/.zip/rsh
- /data/data/####/files/.snow/busybox
- /data/data/####/files/.snow/.zip/mkdevsh
- /data/data/####/files/.snow/b.png
- /data/data/####/tx_shell/libshella-2.10.2.3.so
- sh -c rm /data/data/####/files/hftJcw46N.jar > /dev/null 2>&1
- chown 0.0 /system/bin/.author
- mount -wo remount rw /system
- app_process /system/bin com.android.commands.pm.Pm disable org.app.info.grate
- mount -o remount ro /system
- /system/bin/sh -c getprop ro.meizu.product.model
- chown 0.0 /system/xbin/.rainin
- mount -o remount,ro /system
- chmod 700 /data/data/####/tx_shell/libufix.so
- getprop ro.gn.gnromvernumber
- /system/bin/dexopt --dex 27 57 40 30568 /data/data/####/files/LDyARNDidKiYcqzxdynamicloader.jar 1251703873 325286116 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system
- getenforce
- sh /data/data/####/files/.snow/exp /data/data/####/files/.snow /data/data/####/files/.work
- app_process /system/bin com.android.commands.pm.Pm disable com.setting.dysdtool
- /system/bin/sh -c getprop ro.miui.ui.version.name
- chcon u:object_r:system_file:s0 /system/bin/debuggerd
- getprop ro.build.nubia.rom.name
- chown 0.0 /system/app/Banner.apk
- sh -c rm -f /data/data/####/files/hftJcw46N.jar > /dev/null 2>&1
- chown 0:0 /system/app/oneshs.apk
- chmod 777 /data/data/####/files/.snow/.zip/r4
- /data/data/####/files/.snow/exp /data/data/####/files/.snow /data/data/####/files/.work
- chmod 777 /data/data/####/files/.snow/.zip/r1
- getprop ro.build.version.opporom
- chmod 777 /data/data/####/files/.snow/.zip/r2
- sh -c rm -f /data/data/####/files/hftJcw46N.dex > /dev/null 2>&1
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- mount -o remount,rw /system
- chmod 777 /data/data/####/files/.snow/.zip/mkdevsh
- chmod 777 /data/data/####/files/.snow/busybox
- chmod 777 /data/data/####/files/.work/postroot.sh
- chown 0:0 /system/app/Dingps.apk
- mount -ro remount,ro /system
- chcon u:object_r:system_file:s0 /system/xbin/.ci.pm
- chcon u:object_r:system_file:s0 /system/xbin/supolicy
- app_process /system/bin com.android.commands.pm.Pm disable com.fly.me.ssp.be
- chmod 777 /data/data/####/files/.snow/myshell
- getprop ro.lewa.version
- chown 0:0 /system/xbin/.cp
- chown 0.0 /system/app/Lowerp.apk
- chown 0.0 /system/app/Dingps.apk
- app_process /system/bin com.android.commands.pm.Pm enable com.setting.dysdtool
- chcon u:object_r:system_file:s0 /system/bin/.author
- app_process /system/bin com.android.commands.pm.Pm enable com.android.tools.receiver
- /system/bin/sh -c getprop ro.aa.romver
- mount -ro remount ro /system
- /system/bin/dexopt --dex 27 65 40 23552 /data/data/####/files/hftJcw46N.jar 1251050865 -405892272 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar
- rm /data/data/####/files/hftJcw46N.dex
- sh -c /system/usr/toolbox rm -f /data/data/####/files/hftJcw46N.jar > /dev/null 2>&1
- app_process /system/bin com.android.commands.pm.Pm disable com.android.upon.hash
- chown 0:0 /system/xbin/.ci.pm
- rm -f /data/data/####/files/hftJcw46N.dex
- chmod 777 /data/data/####/files/.snow/.ukd
- chmod 777 /data/data/####/files/.snow/.client
- chown 0.0 /data/local/tmp/busybox
- /system/bin/sh -c getprop ro.lewa.version
- chmod 777 /data/data/####/files/.snow/.uks
- chmod 777 /data/data/####/files/.snow/a.xml
- chown 0.0 /system/app/Treese.apk
- app_process /system/bin com.android.commands.pm.Pm enable org.app.info.grate
- chmod 700 /data/data/####/tx_shell/libnfix.so
- getprop ro.miui.ui.version.name
- /system/bin/dexopt --dex 27 51 40 10544 /data/data/####/files/hello.apk 1251708389 1311588194 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /sys
- chown 0:0 /system/app/Treese.apk
- /system/bin/sh -c getprop ro.build.version.emui
- rm -f /data/data/####/files/hftJcw46N.jar
- rm -f /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s
- chown 0:0 /system/bin/.author
- /data/data/####/files/.play/test /data/data/####/files/.play/ 22a66d1676604160b855343cd9b269fe
- /system/bin/sh -c getprop ro.build.fingerprint
- app_process /system/bin com.android.commands.pm.Pm enable com.android.upon.hash
- chmod 777 /data/data/####/files/.snow/.dg
- chcon u:object_r:system_file:s0 /system/xbin/.rainin
- chown 0:0 /data/local/tmp/busybox
- chown 0:0 /system/lib/libsoon.so
- chown 0.0 /system/xbin/supolicy
- getprop ro.build.rom.id
- getprop ro.yunos.version
- /system/bin/dexopt --dex 27 65 40 234420 /data/data/####/files/tzcar.apk 1247969587 301827261 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /sys
- /system/bin/sh -c getprop ro.board.platform
- chown 0:0 /system/app/Lowerp.apk
- chown 0.0 /system/bin/debuggerd
- chmod 777 /data/data/####/files/.snow/.uok
- /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s -h 22a66d1676604160b855343cd9b269fe /data/data/####/.syslib-
- getprop ro.build.fingerprint
- chmod 777 /data/data/####/files/.snow/b.png
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- sh -c rm /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s > /dev/null 2>&1
- sh /data/data/####/files/.play/test /data/data/####/files/.play/ 22a66d1676604160b855343cd9b269fe
- chown 0.0 /system/app/oneshs.apk
- getprop ro.board.platform
- rm /data/data/####/files/hftJcw46N.jar
- chown 0.0 /system/xbin/.cp
- df /system
- rm /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s
- chown 0:0 /system/xbin/.rainin
- /system/bin/sh -c getprop ro.lenovo.series
- chmod 777 /data/data/####/files/.snow/.catr.apk
- chmod 777 /data/data/####/files/.snow/supolicy
- chmod 777 /data/data/####/files/.snow/.zip/rsh
- sh -c /system/usr/toolbox rm -f /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s > /dev/null 2>&1
- chmod 777 /data/data/####/files/.snow/exp
- chown 0.0 /system/xbin/.ci.pm
- chmod 777 /data/data/####/files/.snow/.zip/rt8
- getprop ro.build.version.emui
- chown 0:0 /system/bin/debuggerd
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.opporom
- chcon u:object_r:system_file:s0 /system/xbin/.cp
- chcon u:object_r:system_file:s0 /system/lib/libsoon.so
- /system/bin/dexopt --dex 27 67 40 2504384 /data/data/####/files/.default/.p.apk 1251299633 -1585053023 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext
- app_process /system/bin com.android.commands.pm.Pm enable com.fly.me.ssp.be
- rm /system/bin/debuggerd
- chmod 777 /data/data/####/files/.snow/.service
- /system/bin/sh -c getprop ro.build.rom.id
- sh -c rm -f /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s > /dev/null 2>&1
- /system/bin/dexopt --dex 27 81 40 66944 /data/data/####/files/Android-x86112.jar 1251052727 1662001824 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext
- chmod 770 /data/data/####/files/.play/test
- getprop ro.aa.romver
- /data/data/####/app_bin/daemon -p #### -s com.dzlp.we.c.a -t 180
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/dexopt --dex 27 52 40 1859444 /data/data/####/files/source.apk 1251708388 -1359275103 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar
- /system/bin/sh -c type su
- /system/bin/dexopt --dex 27 51 40 292 /data/data/####/mix.dex 1493729024 -49011495 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framewo
- app_process /system/bin com.android.commands.pm.Pm disable com.android.tools.receiver
- chown 0.0 /data/local/tmp/.catr.apk
- chown 0:0 /system/xbin/supolicy
- chmod 0771 /data/data/####/.syslib-
- getprop ro.lenovo.series
- chown 0:0 /data/local/tmp/.catr.apk
- sh /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s -h 22a66d1676604160b855343cd9b269fe /data/data/####/.syslib-
- logcat -d -v threadtime
- getprop ro.build.tyd.kbstyle_version
- getprop ro.meizu.product.model
- chmod 777 /data/data/####/files/.snow/.zip/r3
- mount -wo remount,rw /system
- getprop ro.vivo.os.build.display.id
- mount -o remount rw /system
- chmod 700 /data/data/####/tx_shell/libshella-2.10.2.3.so
- chown 0.0 /system/lib/libsoon.so
- sh
- sh -c /system/usr/toolbox rm -f /data/data/####/files/hftJcw46N.dex > /dev/null 2>&1
- sh -c rm /data/data/####/files/hftJcw46N.dex > /dev/null 2>&1
- /system/bin/sh ./mkdevsh
- chmod 777 /data/data/####/files/.snow/.zip/
- chown 0:0 /system/app/Banner.apk