Technical information
- Android.DownLoader.1051.origin
- Android.Mobifun.11.origin
- Android.Mobifun.30.origin
- Android.Mobifun.33.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) p####.pay####.com:80
- TCP(HTTP/1.1) s2.humanhu####.space:80
- TCP(TLS/1.0) 1####.250.150.95:443
- TCP(TLS/1.0) 5.ah####.com:443
- TCP(TLS/1.0) s####.y####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) c####.d####.net:443
- TCP(TLS/1.0) c####.pay####.com:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 1####.250.150.95:443
- TCP(TLS/1.2) 1####.251.1.138:443
- UDP 1####.250.150.95:443
- UDP p####.google####.com:443
- UDP rr5---s####.g####.com:443
- UDP rr3---s####.g####.com:443
- 5.ah####.com
- and####.google####.com
- c####.d####.net
- c####.pay####.com
- m####.go####.com
- p####.google####.com
- p####.pay####.com
- rr3---s####.g####.com
- rr3---s####.g####.com
- rr5---s####.g####.com
- s####.y####.com
- s2.humanhu####.space
- safebro####.google####.com
- 5.ah####.com:443/thirdsdk/flowcashpack/82/MF-1.19a-202104301548d
- c####.pay####.com:443/policy/content
- p####.pay####.com/s-r/332/60063a81055a8
- s2.humanhu####.space/op?p=####&v=####&uuid=####
- c####.d####.net:443/1/policy?g=####&a=####&d=####
- c####.pay####.com:443/1/j?a=####
- s####.y####.com:443/v1/init?id=####
- s####.y####.com:443/v1/mr?id=####
- /data/data/####/.dex2oatlock
- /data/data/####/.m
- /data/data/####/.t
- /data/data/####/.updateIV.dat
- /data/data/####/0000000lllll_0.dex
- /data/data/####/000O00ll111l_0.dex
- /data/data/####/00O000ll111l_0.dex
- /data/data/####/00O000ll111l_0.dex (deleted)
- /data/data/####/00O000ll111l_0.dex.flock
- /data/data/####/00O000ll111l_0.dex.flock (deleted)
- /data/data/####/011134986548f3458aa3e7e2a7fceb8d
- /data/data/####/0OO00l111l1l
- /data/data/####/0OO00l111l1l.lock
- /data/data/####/1.dex
- /data/data/####/1.dex.flock (deleted)
- /data/data/####/1.jar
- /data/data/####/120821.dex
- /data/data/####/120821.dex.flock
- /data/data/####/120821.jar
- /data/data/####/120950.dex
- /data/data/####/120950.dex.flock (deleted)
- /data/data/####/120950.jar
- /data/data/####/4D34D9B160360DA6A68215411E9CDC14.xml
- /data/data/####/4D34D9B160360DA6A68215411E9CDC14.xml.bak
- /data/data/####/5049d4c87ff811eb8cdbb8599f4fd9e038e17b0e57b6ecc...leted)
- /data/data/####/5049d4c87ff811eb8cdbb8599f4fd9e038e17b0e57b6ecc...rcache
- /data/data/####/5049d4c87ff811eb8cdbb8599f4fd9e0ac67091e-b5cc-4...8b48db
- /data/data/####/5049d4c87ff811eb8cdbb8599f4fd9e0ac67091e-b5cc-4...db.dex
- /data/data/####/5049d4c87ff811eb8cdbb8599f4fd9e0ac67091e-b5cc-4...leted)
- /data/data/####/53415CB2A1BBEA4D3E9D6738F960C652.xml
- /data/data/####/853b3a8845333ea69ed5d9ea48f85535
- /data/data/####/C5EF8FD8D339CB6F1FC6CF3C18F8897C.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/base.apk
- /data/data/####/base.dex
- /data/data/####/base.dex.flock (deleted)
- /data/data/####/c1556101d6e64c38a0a306fb8c55f580
- /data/data/####/com.terrible.remarks.disease_preferences.xml
- /data/data/####/db73c13bfde39908882da460473d174c.xml
- /data/data/####/libshellx-super.2019.so
- /data/data/####/metrics_guid
- /data/data/####/nrnun.dex
- /data/data/####/nrnun.dex.flock (deleted)
- /data/data/####/nrnun.jar
- /data/data/####/o0oooOO0ooOo.dat
- /data/data/####/proc_auxv
- /data/data/####/rkkdio
- /data/data/####/tosversion
- /data/data/####/userData.xml
- /data/data/####/xfksgku
- /data/media/####/2582715C_DC28E968.txt
- cat /proc/cpuinfo
- getprop gsm.version.baseband
- getprop net.dns1
- getprop persist.sys.timezone
- getprop ro.com.google.gmsversion
- getprop ro.product.cpu.abi
- ps
- libshellx-super.2019
- xfksgku
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- RSA-ECB-PKCS1Padding