Technical information
- Adware.Appsad.5.origin
- Android.Mobifun.32
- Android.RemoteCode.88.origin
- Android.Xiny.73.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) api.mob####.b####.com:80
- TCP(HTTP/1.1) api.ki####.com:80
- TCP(HTTP/1.1) mo.freeind####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) api.cloud####.net:80
- TCP(HTTP/1.1) api.bi####.com:80
- TCP(HTTP/1.1) pl####.mob####.b####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) 4####.33.0.176:80
- TCP(HTTP/1.1) www.cu####.com:80
- TCP(HTTP/1.1) www.zfr####.com:80
- TCP(HTTP/1.1) s####.adin####.com:80
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) a####.b####.qq.com:8011
- TCP(HTTP/1.1) amc.jiek####.com:80
- TCP(HTTP/1.1) s####.mob####.b####.com:80
- TCP(HTTP/1.1) u####.b####.com:80
- TCP(HTTP/1.1) www.koapk####.com:8081
- a####.b####.qq.com
- aexcep####.b####.qq.com
- amc.jiek####.com
- and####.b####.qq.com
- api.bi####.com
- api.cloud####.net
- api.ki####.com
- api.mob####.b####.com
- mo.freeind####.com
- pl####.mob####.b####.com
- s####.adin####.com
- s####.mob####.b####.com
- u####.b####.com
- www.cu####.com
- www.koapk####.com
- www.okyes####.com
- www.zfr####.com
- amc.jiek####.com/sdkcp/plugUpdate.php?uid=####&model=####&plugVersion=##...
- amc.jiek####.com/sdkcp/push_msgcp_new.php?uid=####&model=####&plugVersio...
- amc.jiek####.com/sdkcp/user_visit_appcp.php?uid=####&model=####&plugVers...
- api.bi####.com/sdkOffer?os=####&model=####&gaid=####&imei=####&androidId...
- api.cloud####.net/api/v3/template/get?slot_id=####&update_time=####&user...
- api.ki####.com/express?tid=####
- api.mob####.b####.com/strategy/api/v1/rule/get?p=####&hp=####&l=####&c=#...
- u####.b####.com/setting/grobal_strategy?p=####&hp=####&l=####&c=####&pro...
- www.cu####.com/20180103150757.gen521_BdJar_NgpDex_D827_0103.zip
- a####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- api.bi####.com/un
- mo.freeind####.com/detail/getOfferListNew?enc=####
- pl####.mob####.b####.com/ad_dex.php
- s####.adin####.com/track/ds?sdk_version=####&platform=####&app_version=#...
- s####.mob####.b####.com/cgi-bin-py/ad_sdk.cgi?ty=####&enc=####&bt=####
- www.koapk####.com:8081/sm/sr/rt/ry
- www.okyes####.com:8081/sdk/nsd.action?b=####
- www.zfr####.com/up.do
- <Package Folder>/.mbj/####/classes.zip
- <Package Folder>/cache/cc.jar
- <Package Folder>/databases/####/file__0.localstorage-journal
- <Package Folder>/databases/adblib.db-journal
- <Package Folder>/databases/bdownloaders.db-journal
- <Package Folder>/databases/bugly_db_legu-journal
- <Package Folder>/databases/mc_cache.db-journal
- <Package Folder>/databases/swith1014.db-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/databases/webviewCookiesChromium.db-journal
- <Package Folder>/files/201801161450.apk
- <Package Folder>/files/SW01.jar
- <Package Folder>/files/c201801161450.apk
- <Package Folder>/files/d.zip
- <Package Folder>/files/dtemp.apk
- <Package Folder>/files/google.db
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/native_record_lock
- <Package Folder>/files/ob2.zip
- <Package Folder>/files/security_info
- <Package Folder>/mix.dex
- <Package Folder>/shared_prefs/20160121.xml
- <Package Folder>/shared_prefs/<Package>;side_ct_default.xml
- <Package Folder>/shared_prefs/<Package>;watch_ct_default.xml
- <Package Folder>/shared_prefs/<Package>_ct_default.xml
- <Package Folder>/shared_prefs/AdsBusiness-data.xml
- <Package Folder>/shared_prefs/AdsBusiness-data.xml (deleted)
- <Package Folder>/shared_prefs/MobikokConfig_Type_1.xml
- <Package Folder>/shared_prefs/MobikokConfig_Type_1.xml.bak (deleted)
- <Package Folder>/shared_prefs/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- <Package Folder>/shared_prefs/SpZvShPrefs.xml
- <Package Folder>/shared_prefs/ag.xml
- <Package Folder>/shared_prefs/aps.xml
- <Package Folder>/shared_prefs/apsad.xml
- <Package Folder>/shared_prefs/apscomm.xml
- <Package Folder>/shared_prefs/cn_rs.xml
- <Package Folder>/shared_prefs/duspf6030945.xml
- <Package Folder>/shared_prefs/m_cfg.xml
- <Package Folder>/shared_prefs/m_cfg.xml (deleted)
- <Package Folder>/shared_prefs/ops_data.xml
- <Package Folder>/shared_prefs/t_ini.xml
- <Package Folder>/tx_shell/libnfix.so
- <Package Folder>/tx_shell/libshella-2.10.7.1.so
- <SD-Card>/.androidsystem/####/gads.db
- <SD-Card>/APPMarket/####/125183428.jpg.tmp
- <SD-Card>/baidu/####/journal.tmp
- <SD-Card>/baidu/.cuid
- <SD-Card>/test1510833296064
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- c201801161450.apk -p <Package> -c <Package>:side
- cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- chmod 6777 <Package Folder>/files/c201801161450.apk
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.10.7.1.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- logcat -d -v time
- ps
- sh
- Bugly
- com.down
- libnfix
- libshella-2.10.7.1
- libufix
- nfix
- ufix