Executes the following shell scripts:
- /system/bin/cat /proc/cpuinfo
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.dzpush.core.GtPushService 24497 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- date
- df
- getprop
- getprop ro.build.version.emui
- getprop ro.letv.release.version
- getprop ro.vivo.os.build.display.id
- id
- ip link
- ls /dev/socket
- ls /system/fonts
- mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
- mount
- ps
- service call iphonesubinfo 1
- sh
- sh -c cat /proc/meminfo
- sh -c cat /sys/class/net/eth0/address
- sh -c cd /proc/;cat cpuinfo
- sh -c cd /proc/net/ && cat arp
- sh -c cd /proc/self/;cat status
- sh -c echo MjVENTVBRDI4M0FBNDAwQUY0NjRDNzZENzEzQzA3QUQxMjM0NTY3OA== > <SD-Card>/../../../../../..<SD-Card>/.n_a
- sh -c echo MjVENTVBRDI4M0FBNDAwQUY0NjRDNzZENzEzQzA3QUQxMjM0NTY3OA== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_a
- sh -c echo NEE3RDFFRDQxNDQ3NEU0MDMzQUMyOUNDQjg2NTNEOUIwMDAw > <SD-Card>/../../../../../..<SD-Card>/.n_c
- sh -c echo NEE3RDFFRDQxNDQ3NEU0MDMzQUMyOUNDQjg2NTNEOUIwMDAw > <SD-Card>/../../../../../..<SD-Card>/.n_d
- sh -c echo NEE3RDFFRDQxNDQ3NEU0MDMzQUMyOUNDQjg2NTNEOUIwMDAw > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_c
- sh -c echo NEE3RDFFRDQxNDQ3NEU0MDMzQUMyOUNDQjg2NTNEOUIwMDAw > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_d
- sh -c echo QTQ1NDE4MDAxMEUyNjdDQUVEOEE0NjgzREMwRUIwQTEyMDE5MDgwMTAwMDE= > <SD-Card>/../../../../../..<SD-Card>/..ccvid
- sh -c echo QTQ1NDE4MDAxMEUyNjdDQUVEOEE0NjgzREMwRUIwQTEyMDE5MDgwMTAwMDE= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccvid
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/.o_a
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/o_a
- sh -c echo QzlDODU0MTRDMkY2NkVDNjNENkEyOTIyOEI3ODI3OUJGNTVBQUY6OEZDNTVBOjAwNTgwOA== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c echo QzlDODU0MTRDMkY2NkVDNjNENkEyOTIyOEI3ODI3OUJGNTVBQUY6OEZDNTVBOjAwNTgwOA== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- sh -c echo RDBCNTk5QjlGNDU2MkI4NTU3MUE3Qzk0NzRCMzE2NjN5QWdTdXM0c3pzQ1RqbWFmOThUc0Q1YWd1M25vRzBvdDNVdlhkT1RVM2pVa3d3L1UyakdqTGZtVFdIb0hzeFNBUGJKVG1GaS80bHBJZEk3aUdXc3hob0tkdnRScm5EbmM0SEFMOEhjNnA2VWJxUG1TamY4Y2xmWHAwak1vOVlNaHpBOUVkcU9mSkcyeEFOcVlnMWlDRXVFYmFvY3dIb0JPVk9wMWFaTStydlVzYk5ja0lnbnY4VmQycVpQbWVWVzE= > <SD-Card>/../../../../../..<SD-Card>/..ccdid
- sh -c echo RDBCNTk5QjlGNDU2MkI4NTU3MUE3Qzk0NzRCMzE2NjN5QWdTdXM0c3pzQ1RqbWFmOThUc0Q1YWd1M25vRzBvdDNVdlhkT1RVM2pVa3d3L1UyakdqTGZtVFdIb0hzeFNBUGJKVG1GaS80bHBJZEk3aUdXc3hob0tkdnRScm5EbmM0SEFMOEhjNnA2VWJxUG1TamY4Y2xmWHAwak1vOVlNaHpBOUVkcU9mSkcyeEFOcVlnMWlDRXVFYmFvY3dIb0JPVk9wMWFaTStydlVzYk5ja0lnbnY4VmQycVpQbWVWVzE= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccdid
- sh -c echo RDEyMzAyOTBEMDdFQThDMkU4ODFGMzgxRjdCMkU4QkRlZmYwYTc5YjkyZDc0ZWNkYTkyYmNmODY2YjdmNDhleAo= > <SD-Card>/../../../../../..<SD-Card>/.duid
- sh -c echo RDEyMzAyOTBEMDdFQThDMkU4ODFGMzgxRjdCMkU4QkRlZmYwYTc5YjkyZDc0ZWNkYTkyYmNmODY2YjdmNDhleAo= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/duid
- sh -c echo RTEwQURDMzk0OUJBNTlBQkJFNTZFMDU3RjIwRjg4M0UxMjM0NTY= > <SD-Card>/../../../../../..<SD-Card>/.n_b
- sh -c echo RTEwQURDMzk0OUJBNTlBQkJFNTZFMDU3RjIwRjg4M0UxMjM0NTY= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_b
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.dzpush.core.GtPushService 24497 300 0
Loads the following dynamic libraries:
- Bugly
- du
- getuiext3
- libjiagu-1712271711
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-OAEPPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- desede-CBC-NoPadding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.