Technical information
- Android.Backdoor.333.origin
- Android.Rootkit.5.origin
- Android.Triada.74.origin
- Android.Xiny.10.origin
- Android.Backdoor.336.origin
- Android.Backdoor.336.origin
- s####.####.com
- p####.####.com:8080
- g####.####.com
- hostwe####.com
- hostwe####.com:8080
- p####.####.com
- q####.####.com:8092
- al####.####.com
- l####.####.net
- d####.####.com
- inter####.####.com
- k####.####.com
- m####.####.COM
- r####.####.com
- a####.####.com
- d####.####.com/thinking/group/rtt0421_662.apk
- k####.####.com/download/opacore/xcore7_1.0.2.md
- al####.####.com/Ag21
- g####.####.com/atmp/ad.png
- al####.####.com/ym_jar
- inter####.####.com/newservice/newgetApks.action
- p####.####.com:8080/OpaService/OpaStrategy
- a####.####.com/oversea_adjust_and_download_write_redis/notify/download/app
- m####.####.COM/gcview/api/910
- p####.####.com:8080/OpaService/OpaQHCode
- p####.####.com/OpaService/OpaMagicCode
- m####.####.COM/pmsg/api/20
- r####.####.com/rqd/sync
- l####.####.net/gkview/info/601
- inter####.####.com/newservice/newopenOrSale.action
- hostwe####.com:8080/dispatcher.php
- q####.####.com:8092/active.do?ie=####&ch=####&svs=####&system=####&ua=##...
- m####.####.COM/errorview/api/601
- a####.####.com/app_logs
- hostwe####.com/dispatcher.php
- p####.####.com/OpaService/OpaReport
- p####.####.com/OpaService/OpaStrategy
- s####.####.com/ggview/rsddateindex
- /sdcard/cpf/cpf.txt
- /data/data/####/files/.snow/.dico.apk
- /data/data/####/shared_prefs/Oveead.xml
- /data/data/####/files/.snow/.dg
- /data/data/####/shared_prefs/bugly_data.xml
- /data/data/####/files/Agcr.tmp
- /data/data/####/shared_prefs/config.xml
- /data/data/####/files/.snow/.center.tapk
- /data/data/####/files/.snow/busybox
- /data/data/####/shared_prefs/####_preferences.xml
- /data/data/####/files/.snow/.ukd
- /data/data/####/files/bcjyxp.dat
- /data/data/####/files/.snow/.zip/r4
- /data/data/####/files/.snow/.dlsb.apk
- /data/data/####/files/.snow/.zip/r1
- /data/data/####/files/.snow/.service
- /data/data/####/files/.snow/.zip/r3
- /data/data/####/files/.snow/.zip/r2
- /data/data/####/files/.snow/b.png
- /data/data/####/shared_prefs/bugly_data.xml.bak
- /data/data/####/tx_shell/libshella-0.0.4.so
- /data/data/####/shared_prefs/gfprf.xml.bak
- /data/data/####/databases/webviewCookiesChromium.db-journal
- /data/data/####/files/bcjyxp.jar
- /data/data/####/files/.snow/myshell
- /data/data/####/shared_prefs/gpac.xml
- /data/data/####/shared_prefs/OverseaSDK.xml
- /data/data/####/files/mySdk.jar
- /data/data/####/shared_prefs/gfprf.xml
- /data/data/####/files/.snow/checkFile0
- /data/data/####/shared_prefs/mobclick_agent_state_####.xml
- /data/data/####/files/mda.ico
- /data/data/####/files/miuk.db
- /data/data/####/shared_prefs/xapcinfo.xml
- /data/data/####/files/.androidod/ac.jar
- /data/data/####/shared_prefs/moertry.xml
- /data/data/####/databases/gpab.db-journal
- /data/data/####/app_sgdex/dos.jar
- /data/data/####/files/wddex.jar
- /data/data/####/files/.snow/.catr.apk
- /data/data/####/mix.dex
- /data/data/####/files/.snow/.zip/rt8
- /data/data/####/files/cpf/cpf.txt
- /data/data/####/files/.snow/.dlme.apk
- /data/data/####/databases/webview.db-journal
- /data/data/####/shared_prefs/OverseaSDK.xml.bak
- /data/data/####/files/.snow/.zip/rsh
- /data/data/####/shared_prefs/mobclick_agent_state_####.xml.bak
- /data/data/####/databases/StaticDataC.dataBase-journal
- /data/data/####/files/sss.pdb
- /data/data/####/databases/gpab.db
- /data/data/####/shared_prefs/config.xml.bak
- /data/data/####/files/.snow/.ir
- /data/data/####/files/.snow/a.xml
- /data/data/####/files/bcjyxp.md
- /data/data/####/files/.snow/.uok
- /data/data/####/files/.Ag/Agcr
- /data/data/####/files/mylala/95d3861ebbd38c2dc8795952cc6c4d37.data.temp
- /data/data/####/shared_prefs/mobclick_agent_header_####.xml
- /data/data/####/files/.snow/.client
- /data/data/####/files/.snow/.zip/mkdevsh
- /data/data/####/files/95d3861ebbd38c2dc8795952cc6c4d37.data
- /data/data/####/databases/bugly_db_lejiagu-journal
- /data/data/####/files/.snow/supolicy
- /data/data/####/files/.snow/.uks
- /data/data/####/files/.snow/.catr.apk
- /data/data/####/files/.snow/.ir
- /data/data/####/files/.Ag/Agcr
- /data/data/####/files/.snow/.zip/rt8
- /data/data/####/files/.snow/busybox
- /data/data/####/files/.snow/.zip/r4
- /data/data/####/files/.snow/.zip/rsh
- /data/data/####/files/.snow/.zip/r1
- /data/data/####/files/.snow/.zip/r3
- /data/data/####/files/.snow/.zip/r2
- /data/data/####/files/.snow/.zip/mkdevsh
- /data/data/####/files/.snow/b.png
- configopb ebf05813c1
- chown 0.0 /system/bin/.author
- app_process /system/bin com.android.commands.pm.Pm disable org.app.info.grate
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.meizu.product.model
- getprop ro.gn.gnromvernumber
- /system/bin/dexopt --dex 27 55 40 13876 /data/data/####/app_sgdex/dos.jar 1200312071 1108093956 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framewor
- chmod 0777 /data/data/####/files/.rtt/chattr
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- chown 0.0 /system/xbin/.cp
- /system/bin/sh -c getprop ro.miui.ui.version.name
- chmod 0777 /data/data/####/files/su
- /data/data/####/files/.rtt/r1 /data/data/####/files/psneuter.js
- /system/bin/sh -c getprop ro.board.platform
- getprop ro.build.nubia.rom.name
- chown 0.0 /system/app/Banner.apk
- /data/data/####/files/.rtt/r2 -c /data/data/####/files/psneuter.js
- chmod 777 /data/data/####/files/.snow/.zip/r4
- chmod 777 /data/data/####/files/.snow/.zip/r1
- getprop ro.build.version.opporom
- chmod 777 /data/data/####/files/.snow/.zip/r2
- /system/bin/dexopt --dex 27 114 40 38812 /data/data/####/files/bcjyxp.jar 1223856443 62427497 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.
- mount -o remount,rw /system
- chmod 0777 /data/data/####/files/.rtt/nis
- chmod 777 /data/data/####/files/.snow/busybox
- chown 0:0 /system/app/Dingps.apk
- chcon u:object_r:system_file:s0 /system/xbin/.ci.pm
- chcon u:object_r:system_file:s0 /system/xbin/supolicy
- app_process /system/bin com.android.commands.pm.Pm disable com.fly.me.ssp.be
- chmod 777 /data/data/####/files/.snow/myshell
- /data/data/####/files/.rtt/r4 -c /data/data/####/files/psneuter.js
- getprop ro.lewa.version
- ls /data/data
- /system/bin/dexopt --dex 27 55 40 127996 /data/data/####/files/.androidod/ac.jar 1195937496 -1605482392 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/
- chown 0.0 /system/app/Dingps.apk
- /system/bin/dexopt --dex 27 94 40 13992 /data/data/####/files/mySdk.jar 1223010873 -889945778 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.
- sh /data/data/####/files/suc f0h5zguZ9aJXbCZExMaN2kDhh6V0Uw== /system/bin/sh /data/data/####/files/psneuter.js
- chcon u:object_r:system_file:s0 /system/bin/.author
- app_process /system/bin com.android.commands.pm.Pm disable com.android.tools.receiver
- /system/bin/sh -c getprop ro.aa.romver
- logcat -d -v threadtime
- mount -wo remount rw /system
- chmod 777 /data/data/####/files/.Ag/Agcr
- chmod 777 /data/data/####/app_outdex
- chown 0:0 /system/xbin/.ci.pm
- /system/bin/dexopt --dex 27 83 40 2504384 /data/data/####/files/mylala/.p.apk 1251299633 -1585053023 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/fra
- chmod 777 /data/data/####/files/.snow/.ukd
- chmod 777 /data/data/####/files/.snow/.client
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/dexopt --dex 27 52 40 292 /data/data/####/mix.dex 1493729294 -49011495 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.jar /system
- conbb od2gf04pd9
- chmod 777 /data/data/####/files/.snow/.uks
- sh /data/data/####/files/suc HygZRm2IHTKWpp7Hll/sS0uY66xdcw== /system/bin/sh /data/data/####/files/psneuter.js
- chmod 777 /data/data/####/files/.snow/a.xml
- <error:2>
- chown 0.0 /system/app/Treese.apk
- getprop ro.meizu.product.model
- app_process /system/bin com.android.commands.pm.Pm enable org.app.info.grate
- getprop ro.miui.ui.version.name
- chown 0:0 /system/app/Treese.apk
- /system/bin/sh -c getprop ro.build.version.emui
- /data/data/####/files/suc HygZRm2IHTKWpp7Hll/sS0uY66xdcw== /system/bin/sh /data/data/####/files/psneuter.js
- /system/bin/sh -c getprop ro.build.fingerprint
- chmod 0777 /data/data/####/files/busybox
- /system/bin/dexopt --dex 27 87 40 38812 /data/data/####/files/bcjyxp.jar 1223856443 62427497 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.j
- sh /data/data/####/files/.rtt/r3 -c /data/data/####/files/psneuter.js
- chmod 777 /data/data/####/files/.snow/.dg
- getprop ro.build.version.sdk
- cat /proc/cpuinfo
- chown 0.0 /system/xbin/supolicy
- getprop ro.build.rom.id
- getprop ro.yunos.version
- chmod 777 /data/data/####/files/.snow/.uok
- getprop ro.build.fingerprint
- chmod 777 /data/data/####/files/.snow/b.png
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- getprop ro.board.platform
- chown 0:0 /system/xbin/.cp
- df /system
- chmod 0777 /data/data/####/files/suc
- /data/data/####/files/suc f0h5zguZ9aJXbCZExMaN2kDhh6V0Uw== /system/bin/sh /data/data/####/files/psneuter.js
- /system/bin/sh -c getprop ro.lenovo.series
- chmod 777 /data/data/####/files/.snow/.catr.apk
- chmod 777 /data/data/####/files/.snow/supolicy
- chmod 0777 /data/data/####/files/psneuter.js
- chmod 777 /data/data/####/files/.snow/.zip/rsh
- chown 0:0 /system/bin/.author
- chmod 777 /data/data/####/files/.snow/.zip/mkdevsh
- /system/bin/dexopt --dex 27 55 40 47924 /data/data/####/files/wsh.jar 1244093369 1005593515 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.ja
- chown 0.0 /system/xbin/.ci.pm
- getprop ro.build.version.release
- chmod 777 /data/data/####/files/.snow/.zip/rt8
- getprop ro.build.version.emui
- getprop
- /system/bin/dexopt --dex 27 102 40 38812 /data/data/####/files/bcjyxp.jar 1223856443 62427497 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.
- /system/bin/sh -c getprop ro.build.version.opporom
- chcon u:object_r:system_file:s0 /system/xbin/.cp
- app_process /system/bin com.android.commands.pm.Pm enable com.fly.me.ssp.be
- chmod 777 /data/data/####/files/.snow/.service
- /system/bin/sh -c getprop ro.build.rom.id
- chmod 0777 /data/data/####/files/.rtt/r4
- sh /data/data/####/files/.rtt/r1 /data/data/####/files/psneuter.js
- getprop ro.aa.romver
- chmod 0777 /data/data/####/files/.rtt/r1
- chmod 0777 /data/data/####/files/.rtt/r3
- chmod 0777 /data/data/####/files/.rtt/r2
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- cat /proc/version
- app_process /system/bin com.android.commands.pm.Pm enable com.android.tools.receiver
- chmod 777 /data/data/####/files/.Ag
- chmod 700 /data/data/####/tx_shell/libshella-0.0.4.so
- chown 0:0 /system/xbin/supolicy
- getprop ro.lenovo.series
- getprop ro.build.tyd.kbstyle_version
- chmod 777 /data/data/####/files/wsh.jar
- chmod 777 /data/data/####/files/.snow/.zip/r3
- mount -wo remount,rw /system
- getprop ro.vivo.os.build.display.id
- mount -o remount rw /system
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- sh
- /data/data/####/files/.rtt/r3 -c /data/data/####/files/psneuter.js
- /data/data/####/files/suc al1s7jBFNtn9faBmC0Jb9A9Ns1GZSg== /system/bin/sh /data/data/####/files/psneuter.js
- /system/bin/sh ./mkdevsh
- chmod 777 /data/data/####/files/.snow/.zip/
- chown 0:0 /system/app/Banner.apk