Technical information
- 106575206321505460: dyl#null,<IMEI>,6000200-1-1-a92556007-0
- 10691009: @8DYL#null,<IMEI>,6000200-1-1-a92556007-0
- Android.Backdoor.613.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sms.yy####.com:80
- TCP(HTTP/1.1) www.huangda####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) col####.yy####.com:80
- a####.u####.com
- and####.b####.qq.com
- bus####.yy####.com
- c####.api.zhifa####.net
- col####.yy####.com
- ga####.lotu####.com
- i####.api.zhifa####.net
- i####.api.zhifa####.net
- on####.lotu####.com
- p1.i####.cc
- pv.s####.com
- re####.api.zhifa####.net
- sms.yy####.com
- v####.api.eeric####.com
- www.huangda####.com
- www.huangda####.com/payres!getResource.action?resTypes=####&appid=####&c...
- and####.b####.qq.com/rqd/async
- <Package Folder>/app_Wyzf_plg/5.0.9.jar
- <Package Folder>/app_wyzf_plg/pay_plg.jar
- <Package Folder>/databases/.fb
- <Package Folder>/databases/.fb-journal
- <Package Folder>/databases/347781996620052-journal
- <Package Folder>/databases/bugly_db_legu-journal
- <Package Folder>/databases/cc.db
- <Package Folder>/databases/cc.db-journal
- <Package Folder>/databases/sms_db
- <Package Folder>/databases/sms_db-journal
- <Package Folder>/databases/smspay20647207.db
- <Package Folder>/databases/smspay20647207.db-journal
- <Package Folder>/databases/sy_pay_record-journal
- <Package Folder>/databases/ua.db
- <Package Folder>/databases/ua.db-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/exid.dat
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/lotuseed.apps
- <Package Folder>/files/lotuseed.lock
- <Package Folder>/files/lotuseed.s
- <Package Folder>/files/lotuseed.task
- <Package Folder>/files/native_record_lock
- <Package Folder>/files/pay
- <Package Folder>/files/pay.jar
- <Package Folder>/files/security_info
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/files/yf.apk
- <Package Folder>/mix.dex
- <Package Folder>/shared_prefs/<Package>.xml
- <Package Folder>/shared_prefs/Alvin2.xml
- <Package Folder>/shared_prefs/ContextData.xml
- <Package Folder>/shared_prefs/SP_REPLACE_CLASSLOADER_CLASS_NAME.xml
- <Package Folder>/shared_prefs/config50083.xml
- <Package Folder>/shared_prefs/lotuseed_global.xml
- <Package Folder>/shared_prefs/lotuseed_main.xml
- <Package Folder>/shared_prefs/pretw.xml
- <Package Folder>/shared_prefs/t2B5C0b0q2f6q6g9D9j1p8r7r7s4t3.xml
- <Package Folder>/shared_prefs/t2B5C0b0q2f6q6g9D9j1p8r7r7s4t3.xml.bak
- <Package Folder>/shared_prefs/twc.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml.bak (deleted)
- <Package Folder>/shared_prefs/wpspay.xml
- <Package Folder>/shared_prefs/wyzf_config20647207.xml
- <Package Folder>/tx_shell/libnfix.so
- <Package Folder>/tx_shell/libshella-2.10.6.0.so
- <Package Folder>/tx_shell/libufix.so
- <SD-Card>/.DataStorage/ContextData.xml
- <SD-Card>/.UTSystemConfig/####/Alvin2.xml
- <SD-Card>/.system/lotuseed.devid
- <SD-Card>/.twservice/####/tw
- <SD-Card>/.twservice/qshp_3001_2284.zip
- <SD-Card>/pay/<Package>_<IMSI>_20171205234944_pay.log
- <SD-Card>/pay/<Package>_<IMSI>_20171205_pay.log
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- cat /proc/version
- cat /sys/block/mmcblk0/device/cid
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.10.6.0.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.yunos.version
- logcat -d -v threadtime
- ps
- Bugly
- cocos2dcpp
- libnfix
- libshella-2.10.6.0
- libufix
- nfix
- ufix