Technical information
- Adware.MyFolder.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c.d####.mob.com:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) i####.sms.mob.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) pin####.qq.com:80
- TCP(HTTP/1.1) zhongre####.cc:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) d####.d####.mob.com:80
- TCP(HTTP/1.1) thi####.q####.cn:80
- TCP(HTTP/1.1) c####.jianz####.com:80
- TCP(TLS/1.0) loc.map.b####.com:443
- TCP(TLS/1.0) c####.jianz####.com:443
- TCP(TLS/1.0) statson####.pu####.b####.com:443
- TCP(TLS/1.0) api.w####.com:443
- TCP(TLS/1.0) q.q####.cn:443
- TCP(TLS/1.0) api.tui####.b####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) h####.b####.com:443
- TCP sa.tui####.b####.com:5287
- a####.b####.qq.com
- a####.exc.mob.com
- a####.tui####.b####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- api.map.b####.com
- api.s####.mob.com
- api.tui####.b####.com
- api.w####.com
- c####.jianz####.com
- c.d####.mob.com
- d####.d####.mob.com
- h####.b####.com
- i####.sms.mob.com
- l####.tbs.qq.com
- loc.map.b####.com
- m.d####.mob.com
- mt####.go####.com
- pi####.qq.com
- pin####.qq.com
- q.q####.cn
- sa.tui####.b####.com
- sa0.tui####.b####.com
- statson####.pu####.b####.com
- thi####.q####.cn
- www.b####.com
- zhongre####.cc
- c####.jianz####.com/C/headimg/201706/thumb_e1c4a49b-ea35-4640-aec2-efc99...
- c####.jianz####.com/C/headimg/201806/thumb_98ea6d87-4712-41ad-b80d-f2067...
- c####.jianz####.com/C/headimg/201807/thumb_5503ceee-6c96-4de9-a6a6-13194...
- c####.jianz####.com/C/headimg/201807/thumb_d392b7d3-1ebb-41e3-ad0a-14ea7...
- c####.jianz####.com/C/headimg/201809/thumb_93cb0b24-d956-4ff7-af4b-c71e5...
- c####.jianz####.com/C/headimg/201810/thumb_ba3f9c0e-b542-4237-b296-7fe3a...
- c####.jianz####.com/C/headimg/201811/thumb_38067d38-64b6-4884-a25a-4d36d...
- c####.jianz####.com/C/headimg/201811/thumb_d2a0d6ff-e457-42fe-92ef-ba8f8...
- c####.jianz####.com/C/headimg/201811/thumb_ee529109-dde3-4bcf-ab18-f68fb...
- c####.jianz####.com/C/headimg/201812/thumb_373143c2-111f-47b6-a9dd-02568...
- c####.jianz####.com/C/headimg/201812/thumb_3a834c3c-59de-4d99-a6bf-a48f6...
- c####.jianz####.com/C/headimg/201812/thumb_4764ffa9-d52f-4bb9-bf0e-9fd65...
- c####.jianz####.com/C/headimg/201812/thumb_7f3cab68-f575-4d66-8bab-59d53...
- c####.jianz####.com/C/headimg/201812/thumb_80ba5e8a-45ba-4448-b8f2-2d820...
- c####.jianz####.com/C/headimg/201812/thumb_85eeea28-cc34-4ffc-9b16-f1ea6...
- c####.jianz####.com/C/headimg/201812/thumb_cc2462eb-9b54-4122-b56a-465b8...
- c####.jianz####.com/C/headimg/201812/thumb_d513306d-5ba2-44ce-8f52-d9068...
- c####.jianz####.com/C/headimg/201901/thumb_5acfd65c-83a1-4635-b23b-4c0d3...
- c####.jianz####.com/C/img/icons/no_picture.png
- m.d####.mob.com/v4/cconf?appkey=####&plat=####&apppkg=####&appver=####&n...
- thi####.q####.cn/mmopen/vi_32/DtfUiaYkxDhQAiaVOqBomanpe704W5tamX7Ribhyrd...
- a####.exc.mob.com/errconf
- aexcep####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- and####.b####.qq.com/rqd/async?aid=####
- api.s####.mob.com/conn
- api.s####.mob.com/snsconf
- c.d####.mob.com/v3/cdata
- d####.d####.mob.com/dinfo
- d####.d####.mob.com/dsign
- i####.sms.mob.com/v3/sdk/init
- l####.tbs.qq.com/ajax?c=####&k=####
- pi####.qq.com/mstat/report/?index=####
- pin####.qq.com/request
- zhongre####.cc/api/Other/GetNews
- zhongre####.cc/api/earnuser/EarnList
- zhongre####.cc/api/earnuser/EarnRecommend
- zhongre####.cc/api/other/BidList
- zhongre####.cc/api/user/AppAndUserInfo
- zhongre####.cc/api/user/MobileAdprojectVersion
- zhongre####.cc/api/user/SMSFreeOrPay
- /data/data/####/.cb
- /data/data/####/.duid
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/.vpl_lock
- /data/data/####/1004
- /data/data/####/120ed6022a2ac606e7dfa32ffc598537b64a37a51382610....0.tmp
- /data/data/####/1370003342ebd95af171877890b80df7c513165bb475567....0.tmp
- /data/data/####/16826628829084b24401b7116e094796f09fcff82977d35....0.tmp
- /data/data/####/2ee2870b0c2ebdbb3098dc51d8a77dae415abe32999422a....0.tmp
- /data/data/####/2f4a364bcd8232e0f290c9db15878e1539115ed1669c0ff....0.tmp
- /data/data/####/4167c316087892e97a33184bf7aacbdf3bc911e4c32e8f4....0.tmp
- /data/data/####/53771c6dae9e3f800d64b627ba9a7549a69d4b935b0f02a....0.tmp
- /data/data/####/66bf76c00a894b5ea20bf9ec0b4bafd8c3b53634f9788aa....0.tmp
- /data/data/####/773f3102314cc7861dbbea12f49530f958bb9216916337b....0.tmp
- /data/data/####/7cf29feaead5dc8b715fe51f4ec42b9b31fb3cdaa003f82....0.tmp
- /data/data/####/826ede2123dc5dc07f5243267a65af653fe6d3103af53ef....0.tmp
- /data/data/####/83f13521cddbe22ba1dc24309e4e99b211579ee76a62ac4....0.tmp
- /data/data/####/88b7058a1afee7316cec48a3c4c817384932a60cdf7e660....0.tmp
- /data/data/####/935091ac8d8cf7505f95e9823bfcf9ed4c2edf442084369....0.tmp
- /data/data/####/ChatDB-journal
- /data/data/####/EarnUser
- /data/data/####/EarnUser-journal
- /data/data/####/FindoutDB
- /data/data/####/FindoutDB-journal
- /data/data/####/HistoryJobList-journal
- /data/data/####/MultiDex.lock
- /data/data/####/QALConfigStore.dat
- /data/data/####/SMSSDK_2
- /data/data/####/TLS_DEVICE_INFO.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/TuijianDB-journal
- /data/data/####/WLOGIN_DEVICE_INFO.xml
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1546535809711
- /data/data/####/ads.xml
- /data/data/####/authStatus_com.jianzhiku.zhongrenbang;remote.xml
- /data/data/####/ba43e7b82e20f3bbec7fd993476e676b150d06a0eda2a12....0.tmp
- /data/data/####/baidu_mtj_sdk_record.xml
- /data/data/####/be4094245868b33809b4fb04e8743849ecd011b622d0d24....0.tmp
- /data/data/####/beb3fbc152de1fb491c266512030ceb76dd15ae26ffee78....0.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/bugly_db_legu-journal
- /data/data/####/c492da092872662680f734c1e159ac8dd5336ae483f0cf3....0.tmp
- /data/data/####/ccdb5fb88366718fa9b549657941b9c5c1acb846ec9367b....0.tmp
- /data/data/####/com.baidu.pushservice.BIND_CACHE.xml
- /data/data/####/com.jianzhiku.zhongrenbang.mid.world.ro.xml
- /data/data/####/com.jianzhiku.zhongrenbang.push_sync.xml
- /data/data/####/com.jianzhiku.zhongrenbang.self_push_sync.xml
- /data/data/####/com.jianzhiku.zhongrenbang_preferences.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/df0e469b192e0e544e212c0b8952e31fa7df457af37f99d...e4ba.0
- /data/data/####/e0e5bf77e1ff55eec6ca5f3ac9860acbc5f2de5631646db....0.tmp
- /data/data/####/e8a48d01dfdfd7288539bb171bbe39b5a3f810d0e45305d....0.tmp
- /data/data/####/eb94562326ff03da1a05c75e91728fcd7730d1560d32057....0.tmp
- /data/data/####/fed2897ae3dc9cc55b6d3293892f0a5fb5b7f288528d803....0.tmp
- /data/data/####/firll.dat
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/journal.tmp
- /data/data/####/legu_tencent_analysis.db_com.jianzhiku.zhongren...ournal
- /data/data/####/libcuid.so
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.9.0.2.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/pri_legu_tencent_analysis.db_com.jianzhiku.zhon...ournal
- /data/data/####/pst.xml
- /data/data/####/pst.xml (deleted)
- /data/data/####/pst.xml.bak
- /data/data/####/pushclient.xml
- /data/data/####/pushinfo.db
- /data/data/####/pushinfo.db-journal
- /data/data/####/pushstat_5.6.0.db
- /data/data/####/pushstat_5.6.0.db-journal
- /data/data/####/qalimid_v2
- /data/data/####/report_v5.msgstore-journal
- /data/data/####/security_info
- /data/data/####/share_sdk_1
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tls_device.dat
- /data/data/####/weibo_sdk_aid1
- /data/data/####/wlogin_device.dat
- /data/media/####/.al
- /data/media/####/.artc_lock
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid2
- /data/media/####/.dh-journal
- /data/media/####/.dhlock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.digap
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.info
- /data/media/####/.lecd
- /data/media/####/.lesd_lock
- /data/media/####/.mcli
- /data/media/####/.mid.txt
- /data/media/####/.mid.txt1000001
- /data/media/####/.mn_-1464060969
- /data/media/####/.nomedia
- /data/media/####/.nulal
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.plst
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.timestamp
- /data/media/####/app.19.01.03.17.log
- /data/media/####/sdk.19.01.03.17.log
- /data/media/####/yoh.dat
- /data/media/####/yol.dat
- /data/media/####/yom.dat
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- app_process /system/bin com.android.commands.pm.Pm list packages
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.display.id
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- getprop ro.yunos.version
- grep -E -v root|shell|system
- logcat -d -v threadtime
- netstat -ant
- pm list packages
- sh
- top -d 0 -n 1
- Bugly
- MtaNativeCrash
- _imcore_group_ext_gyp
- _imcore_jni_gyp
- _imcore_msg_ext_gyp
- _imcore_sns_ext_gyp
- _imcore_ugc_ext_gyp
- bdpush_V2_7
- crash_analysis
- gnustl_shared
- libnfix
- libshella-2.9.0.2
- libufix
- libwtcrypto
- locSDK7b
- nfix
- qalcodecwrapper
- qalmsfboot
- ufix
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-PKCS1PADDING
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- AES-ECB-NoPadding
- AES-GCM-NoPadding