Technical information
- Android.SmsSpy.677.origin
- Android.SmsSpy.677.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.qi1####.com:80
- TCP(HTTP/1.1) 1####.55.16.91:8080
- TCP(HTTP/1.1) q####.qi1####.com:14302
- TCP(HTTP/1.1) 1####.55.17.147:8080
- TCP(HTTP/1.1) q####.qi1####.com:15302
- TCP(HTTP/1.1) zxc####.wann####.com:8200
- TCP(HTTP/1.1) z####.wann####.com:9500
- TCP(HTTP/1.1) hangzho####.oss-cn-####.aliy####.com:80
- TCP(HTTP/1.1) qyc####.qi1####.com:8200
- TCP(HTTP/1.1) p####.nj####.com.####.com:8080
- TCP(HTTP/1.1) z####.wann####.com:9600
- a####.u####.com
- hangzho####.oss-cn-####.aliy####.com
- p####.nj####.com
- q####.qi1####.com
- qyc####.qi1####.com
- sdk.qi1####.com
- z####.wann####.com
- zxc####.wann####.com
- hangzho####.oss-cn-####.aliy####.com/qiyi/client/sdk/so/libzxvps.so
- p####.nj####.com.####.com:8080/sdk/spaycoredex_so_2020.jar
- qyc####.qi1####.com:8200/sdk/file?6dejdTO####
- qyc####.qi1####.com:8200/sdk/file?aK4I5Iu####
- sdk.qi1####.com/qiyi/client/sdk/PaySDK-1.2.16.8-UR_yx.jar
- q####.qi1####.com:14302/sdk_login?t=####
- q####.qi1####.com:15302/sdk_login?t=####
- z####.wann####.com:9500/
- z####.wann####.com:9600/
- zxc####.wann####.com:8200/qy/acceptSdkFileReq
- zxc####.wann####.com:8200/qy/getOnlineLoginHttpReq
- <Package Folder>/PaySDK-1.2.16.8-UR_yx.jar
- <Package Folder>/app_dex/PaySDK-1.2.16.8-UR_yx.dex
- <Package Folder>/app_osdk/FrameCore.dex
- <Package Folder>/app_payload_odex/<Package>.dex
- <Package Folder>/app_payload_odex/<Package>.dex (deleted)
- <Package Folder>/app_payload_odex/<Package>.jar
- <Package Folder>/app_payload_res/####/._logo_img_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_0_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_0_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_0_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_0_3.jpg
- <Package Folder>/app_payload_res/####/._mm_show_1_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_1_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_1_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_1_3.jpg
- <Package Folder>/app_payload_res/####/._mm_show_2_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_2_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_2_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_2_3.jpg
- <Package Folder>/app_payload_res/####/._mm_show_3_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_3_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_3_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_4_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_4_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_4_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_5_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_5_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_5_2.jpg
- <Package Folder>/app_payload_res/####/._mm_show_6_0.jpg
- <Package Folder>/app_payload_res/####/._mm_show_6_1.jpg
- <Package Folder>/app_payload_res/####/._mm_show_6_2.jpg
- <Package Folder>/app_payload_res/####/._pg_1.png
- <Package Folder>/app_payload_res/####/._pg_2.png
- <Package Folder>/app_payload_res/####/._pg_3.png
- <Package Folder>/app_payload_res/####/._pic_bg.png
- <Package Folder>/app_payload_res/####/._pic_mm_0.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_1.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_2.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_3.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_4.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_5.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_6.jpg
- <Package Folder>/app_payload_res/####/._pic_mm_7.jpg
- <Package Folder>/app_payload_res/####/._price1.jpg
- <Package Folder>/app_payload_res/####/._price3.png
- <Package Folder>/app_payload_res/logo_img_0.jpg
- <Package Folder>/app_payload_res/maan.so
- <Package Folder>/app_payload_res/mm_show_0_0.jpg
- <Package Folder>/app_payload_res/mm_show_0_1.jpg
- <Package Folder>/app_payload_res/mm_show_0_2.jpg
- <Package Folder>/app_payload_res/mm_show_0_3.jpg
- <Package Folder>/app_payload_res/mm_show_1_0.jpg
- <Package Folder>/app_payload_res/mm_show_1_1.jpg
- <Package Folder>/app_payload_res/mm_show_1_2.jpg
- <Package Folder>/app_payload_res/mm_show_1_3.jpg
- <Package Folder>/app_payload_res/mm_show_2_0.jpg
- <Package Folder>/app_payload_res/mm_show_2_1.jpg
- <Package Folder>/app_payload_res/mm_show_2_2.jpg
- <Package Folder>/app_payload_res/mm_show_2_3.jpg
- <Package Folder>/app_payload_res/mm_show_3_0.jpg
- <Package Folder>/app_payload_res/mm_show_3_1.jpg
- <Package Folder>/app_payload_res/mm_show_3_2.jpg
- <Package Folder>/app_payload_res/mm_show_4_0.jpg
- <Package Folder>/app_payload_res/mm_show_4_1.jpg
- <Package Folder>/app_payload_res/mm_show_4_2.jpg
- <Package Folder>/app_payload_res/mm_show_5_0.jpg
- <Package Folder>/app_payload_res/mm_show_5_1.jpg
- <Package Folder>/app_payload_res/mm_show_5_2.jpg
- <Package Folder>/app_payload_res/mm_show_6_0.jpg
- <Package Folder>/app_payload_res/mm_show_6_1.jpg
- <Package Folder>/app_payload_res/mm_show_6_2.jpg
- <Package Folder>/app_payload_res/pg_1.png
- <Package Folder>/app_payload_res/pg_2.png
- <Package Folder>/app_payload_res/pg_3.png
- <Package Folder>/app_payload_res/pic_bg.png
- <Package Folder>/app_payload_res/pic_mm_0.jpg
- <Package Folder>/app_payload_res/pic_mm_1.jpg
- <Package Folder>/app_payload_res/pic_mm_2.jpg
- <Package Folder>/app_payload_res/pic_mm_3.jpg
- <Package Folder>/app_payload_res/pic_mm_4.jpg
- <Package Folder>/app_payload_res/pic_mm_5.jpg
- <Package Folder>/app_payload_res/pic_mm_6.jpg
- <Package Folder>/app_payload_res/pic_mm_7.jpg
- <Package Folder>/app_payload_res/price1.jpg
- <Package Folder>/app_payload_res/price3.png
- <Package Folder>/app_payload_res/story_btn_read.png
- <Package Folder>/app_payload_res/tab1_0.png
- <Package Folder>/app_payload_res/tab1_1.png
- <Package Folder>/app_payload_res/tab2_0.png
- <Package Folder>/app_payload_res/tab2_1.png
- <Package Folder>/app_process_lock/1122136439072.54
- <Package Folder>/app_process_lock/1122136439072.54 (deleted)
- <Package Folder>/app_process_lock/2965421312405.01
- <Package Folder>/app_process_lock/2965421312405.01 (deleted)
- <Package Folder>/databases/a.db
- <Package Folder>/databases/a.db-journal
- <Package Folder>/databases/cc.db
- <Package Folder>/databases/cc.db-journal
- <Package Folder>/databases/qy_db_pay
- <Package Folder>/databases/qy_db_pay-journal
- <Package Folder>/databases/ua.db
- <Package Folder>/databases/ua.db-journal
- <Package Folder>/databases/xUtils_http_cache.db
- <Package Folder>/databases/xUtils_http_cache.db-journal
- <Package Folder>/databases/xUtils_http_cache.db-shm
- <Package Folder>/databases/xUtils_http_cache.db-shm (deleted)
- <Package Folder>/databases/xUtils_http_cache.db-wal
- <Package Folder>/databases/xUtils_http_cookie.db
- <Package Folder>/databases/xUtils_http_cookie.db-journal
- <Package Folder>/databases/xUtils_http_cookie.db-shm
- <Package Folder>/databases/xUtils_http_cookie.db-shm (deleted)
- <Package Folder>/databases/xUtils_http_cookie.db-wal
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/exid.dat
- <Package Folder>/files/getprop
- <Package Folder>/files/pid
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/libzxvps/####/libzxvps.so
- <Package Folder>/libzxvps/####/tmp_so
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <Package Folder>/shared_prefs/unknown.xml
- <Package Folder>/tmp_jar
- <SD-Card>/.Systemp/.cfg
- <SD-Card>/.Systemp/device
- <SD-Card>/Android/####/9e0009b1dfb183d3ff94e3211a0a3de3
- <SD-Card>/updateApkDemo/FrameCore.jar
- app_process /system/bin com.android.commands.am.Am startservice --user 0 -n <Package>/com.google.android.gms.analytics.CampaignTrackingService
- cat /sys/block/mmcblk0/device/cid
- chmod 777 <Package Folder>/lib/helper
- dd if=<Package Folder>/lib/libhelper.so of=<Package Folder>/lib/helper
- df
- getprop
- ls -l /system/bin/su
- ps | grep <Package>
- sh
- libhelper
- libsmsmanager
- libzxvps
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- DES-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- DES-ECB-NoPadding