Executes next shell scripts:
- /system/bin/cat /proc/cpuinfo
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.common.push.GeTuiPushService 25730 300 0
- chmod 444/storage/emulated/0/.td-3
- chmod 444/storage/emulated/0/.tdck
- chmod 444/storage/emulated/0/Alarms/.tdck
- chmod 444/storage/emulated/0/Android/.td-3
- chmod 444/storage/emulated/0/Android/.tdck
- chmod 444/storage/emulated/0/DCIM/.td-3
- chmod 444/storage/emulated/0/DCIM/.tdck
- chmod 444/storage/emulated/0/Download/.td-3
- chmod 444/storage/emulated/0/Download/.tdck
- chmod 444/storage/emulated/0/Movies/.td-3
- chmod 444/storage/emulated/0/Movies/.tdck
- chmod 444/storage/emulated/0/Music/.td-3
- chmod 444/storage/emulated/0/Music/.tdck
- chmod 444/storage/emulated/0/Notifications/.td-3
- chmod 444/storage/emulated/0/Notifications/.tdck
- chmod 444/storage/emulated/0/Pictures/.td-3
- chmod 444/storage/emulated/0/Pictures/.tdck
- chmod 444/storage/emulated/0/Podcasts/.td-3
- chmod 444/storage/emulated/0/Podcasts/.tdck
- chmod 444/storage/emulated/0/Ringtones/.td-3
- chmod 444/storage/emulated/0/Ringtones/.tdck
- chmod 444/storage/emulated/0/libs/.tdck
- chmod 444/storage/emulated/0/system/.td-3
- chmod 444/storage/emulated/0/system/.tdck
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop
- getprop dalvik.vm.heapgrowthlimit
- getprop dalvik.vm.heapsize
- getprop dalvik.vm.heapstartsize
- getprop net.dns1
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.characteristics
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- ls -l /system/xbin/su
- ls /sys/class/thermal
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.common.push.GeTuiPushService 25730 300 0
Loads the following dynamic libraries:
- Bugly
- getuiext2
- libnfix
- libshella-2.9.0.2
- libufix
- nfix
- realm-jni
- tongdun
- ufix
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.
Gains access to information about incoming/outgoing calls.