Technical information
- Adware.Egame.1
- Android.Triada.2018
- Android.Triada.464.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sd####.cm####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) 2####.86.5.167:14840
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) app####.m####.cn:8080
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) s####.cdn.cmv####.cn:8080
- TCP(HTTP/1.1) s####.cdn.cmv####.cn:80
- TCP(HTTP/1.1) drm.cm####.com:80
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- app####.m####.cn
- drm.cm####.com
- int.d####.s####.####.cn
- l.ace####.com
- s####.cmv####.cn
- sd####.cm####.com
- sdk.cm####.com
- wap.cm####.com
- drm.cm####.com/egsb/game/getclientProvince?tel=####&iccid=####&imsi=####
- drm.cm####.com/egsb/startup/queryConfiguration?channelId=####&contentId=...
- drm.cm####.com/egsb/verification/checkSDKModuleUpdate?sdkVersion=####&co...
- s####.cdn.cmv####.cn/download//moduleVersion/marketing_1132_201808011642...
- s####.cdn.cmv####.cn:8080/MiguPay.SO30.Lib_012226_137D848DA99F7B12A8FBD7...
- s####.cdn.cmv####.cn:8080/MiguPay.Sdk30.Lib_12003072_D59587AB4958B47F2C8...
- a####.u####.com/app_logs
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- app####.m####.cn:8080/migusdk/tl/tcttl
- app####.m####.cn:8080/migusdk/verification/checkSdkUpdate
- drm.cm####.com/egsb/dataPlan/privateSwith
- drm.cm####.com/egsb/desktopShortcut/queryAll
- drm.cm####.com/egsb/discount/getPreQueryResult
- drm.cm####.com/egsb/game/getPaymentCapability
- drm.cm####.com/egsb/gshare/switches
- drm.cm####.com/egsb/message/queryPushMessages
- drm.cm####.com/egsb/otherPay/querySMSInterceptorConf
- drm.cm####.com/egsb/recommendGame/getAdvertisementList
- drm.cm####.com/egsb/thirdPay/queryThirdPayInfo
- sd####.cm####.com/behaviorLogging/eventLogging/accept?
- /data/data/####/-TmXM8IrdUymVHC1jLAwsA==.new
- /data/data/####/.DS_Store
- /data/data/####/.imprint
- /data/data/####/1ivwPaRIgqPNABbYvtbIi9ZxQL_2aOpK.new
- /data/data/####/2319.dex
- /data/data/####/3YaoIaGtEOefjdG6.new
- /data/data/####/4Ixs0DyVP1voMtY1wfDAC48T6As=.new
- /data/data/####/5QShh3CJ5OrF-4xf-vo1vuYlHfo=
- /data/data/####/6WN4hXw8aISZE2gR6yzsGg_yk4xHqduE.new
- /data/data/####/Alvin2.xml
- /data/data/####/Bn0UhMwbHChoImeryCdZDyh4ZMR-NMRbJO-EPnrFsDQ=.new
- /data/data/####/CitiGame.ini.xml
- /data/data/####/ContextData.xml
- /data/data/####/ED.ini
- /data/data/####/FLFAAKa4Rg6A-XredgZyVg9kIfHUtE5b.new
- /data/data/####/FnMmbQQSDWZBKgL8ZaURXqaf2OQUUkYlfX5EztJDWEc=.new
- /data/data/####/J5-kpwbpv9p10KjC1f2N-E3Ba1s=.new
- /data/data/####/MiguPay.Sdk30.Lib_12003049_2b7f4055276371c21c62...02.cod
- /data/data/####/MiguPay.Sdk30.Lib_12003049_2b7f4055276371c21c62...02.dat
- /data/data/####/MiguPay.Sdk30.Lib_12003072_f7cf98fb679eaa6b0d77...02.cod
- /data/data/####/MiguPay.Sdk30.Lib_12003072_f7cf98fb679eaa6b0d77...02.dat
- /data/data/####/MiguPay.Sdk30.Res_00026014_3C3B3538E3D2C3DFD6BD...02.zip
- /data/data/####/NWMkQ8pvnN-R7iHRmE8LdPKI5ZPrMmUCoF3CNg==.new
- /data/data/####/QCm9JaQyK1VbmsgzSHkZu4Sb3tXBwK41F84eUxSH7qc=.new
- /data/data/####/SWdqsmfMksvcNh98N0T7dFxz3TGBYcQq.new
- /data/data/####/TfjQpjuNwc4laAgs
- /data/data/####/WZ05i-4MgQdd7gcWVtcnpoiQfAmtjhydPt2-Cw==.new
- /data/data/####/X5fPZlKd5I1u-pjwP-goCqe1F2o=.new
- /data/data/####/YCGklSVabuIDZ76JMspCK_TuPnAztYBj.new
- /data/data/####/YX1DWSNpl8cQpgNLzpxtJecZ1tg=.new
- /data/data/####/an6doBZgdJGk-kGG86XVuFb26Ik=.new
- /data/data/####/bIzqZJTZdpZ0z14UlwodrrSq115iQguonYx5KGsXVOs=.new
- /data/data/####/bugly_db_legu-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/duD71fp7gerDdv-X5ydU_g==
- /data/data/####/eDnZrCLb-ei6wH49xQUj5w==.new
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fylHzTm-qQqAeuzGlUiyc6w-cxPM1z9E.new
- /data/data/####/game_arrow_big.png
- /data/data/####/game_arrow_little.png
- /data/data/####/game_arrow_text.png
- /data/data/####/game_businesscard.png
- /data/data/####/game_check_success.png
- /data/data/####/game_checkbox_mark.png
- /data/data/####/game_contacts.png
- /data/data/####/game_failure.png
- /data/data/####/game_grey_logo.png
- /data/data/####/game_loading.png
- /data/data/####/game_logo.png
- /data/data/####/game_network.png
- /data/data/####/game_people.png
- /data/data/####/game_piccode_refresh_touched.png
- /data/data/####/game_save.png
- /data/data/####/game_show_pwd.png
- /data/data/####/game_start_logo.png
- /data/data/####/game_success.png
- /data/data/####/gamedata.xml
- /data/data/####/gevaxa_f.zip
- /data/data/####/gray.png
- /data/data/####/iGTX5fp6EchkpA7yOj46Y6GtHwLt6gpc.new
- /data/data/####/icon_about.png
- /data/data/####/icon_annoucement_close.png
- /data/data/####/icon_back.png
- /data/data/####/icon_bind_email.png
- /data/data/####/icon_bind_tel.png
- /data/data/####/icon_businesscard.png
- /data/data/####/icon_center_about.png
- /data/data/####/icon_center_arrow.png
- /data/data/####/icon_center_look.png
- /data/data/####/icon_center_save.png
- /data/data/####/icon_check_failure.png
- /data/data/####/icon_checkbox.png
- /data/data/####/icon_close.png
- /data/data/####/icon_common_problem.png
- /data/data/####/icon_compact_close.png
- /data/data/####/icon_discount_icon.png
- /data/data/####/icon_edit_del.png
- /data/data/####/icon_email_icon.png
- /data/data/####/icon_extend.png
- /data/data/####/icon_firends_circle.png
- /data/data/####/icon_full_arrow_down.png
- /data/data/####/icon_full_arrow_up.png
- /data/data/####/icon_grey_contacts.png
- /data/data/####/icon_head.png
- /data/data/####/icon_hide_pwd.png
- /data/data/####/icon_magnet_draghide.png
- /data/data/####/icon_magnet_gameshare.png
- /data/data/####/icon_magnet_help.png
- /data/data/####/icon_magnet_onlineservice.png
- /data/data/####/icon_magnet_startlogin.png
- /data/data/####/icon_magnet_welfare.png
- /data/data/####/icon_notification.png
- /data/data/####/icon_online_service.png
- /data/data/####/icon_people.png
- /data/data/####/icon_personal_bg.png
- /data/data/####/icon_personal_bg_l.png
- /data/data/####/icon_piccode.png
- /data/data/####/icon_piccode_refresh.png
- /data/data/####/icon_qq.png
- /data/data/####/icon_recommend_flow_one.png
- /data/data/####/icon_recommend_flow_third.png
- /data/data/####/icon_recommend_flow_two.png
- /data/data/####/icon_recommend_hall.png
- /data/data/####/icon_rightextend.png
- /data/data/####/icon_security_setting.png
- /data/data/####/icon_service_tel.png
- /data/data/####/icon_share_game.png
- /data/data/####/icon_shrink.png
- /data/data/####/icon_sina.png
- /data/data/####/icon_sms.png
- /data/data/####/icon_tel.png
- /data/data/####/icon_transaction_detail.png
- /data/data/####/icon_upgrade_pass.png
- /data/data/####/icon_wechat.png
- /data/data/####/icon_window.png
- /data/data/####/jcyuL2Med9Xs_1EOVUnez4kmcAUZE-qTmsr_bg==_Y61CsA...ournal
- /data/data/####/jcyuL2Med9Xs_1EOVUnez4kmcAUZE-qTmsr_bg==_cGdCSQ...ournal
- /data/data/####/jcyuL2Med9Xs_1EOVUnez4kmcAUZE-qTmsr_bg==_cGdCSQ3FV3gJKug7
- /data/data/####/jcyuL2Med9Xs_1EOVUnez4kmcAUZE-qTmsr_bg==_hEaMrz...Jqlg==
- /data/data/####/jcyuL2Med9Xs_1EOVUnez4kmcAUZE-qTmsr_bg==_hEaMrz...ournal
- /data/data/####/libmgRun_01.22.26_01.so
- /data/data/####/libmgRun_05.22.09_01.so
- /data/data/####/libmiguED.so
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.8.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/mgAS.dat
- /data/data/####/mgSS.dat
- /data/data/####/mgid.dat
- /data/data/####/miguGameBillingRequestMonitor.xml
- /data/data/####/migu_slider_target.png
- /data/data/####/migu_slider_thumb_nor.png
- /data/data/####/migu_slider_thumb_prs.png
- /data/data/####/migu_slider_thumb_suc.png
- /data/data/####/mix.dex
- /data/data/####/mzPlCKp3VSS40dLeaz2GmcINH9zIPM17CvS3YQ==.new
- /data/data/####/native_record_lock
- /data/data/####/p.l
- /data/data/####/pay_icon_0.png
- /data/data/####/pay_icon_1.png
- /data/data/####/pay_icon_2.png
- /data/data/####/pay_icon_3.png
- /data/data/####/pay_icon_4.png
- /data/data/####/pay_icon_5.png
- /data/data/####/pay_icon_payment.png
- /data/data/####/pay_icon_phonenumber.png
- /data/data/####/pay_icon_telpoint.png
- /data/data/####/plus_businesscard.png
- /data/data/####/plus_check_success.png
- /data/data/####/plus_checkbox_mark.png
- /data/data/####/plus_contacts.png
- /data/data/####/plus_failure.png
- /data/data/####/plus_grey_logo.png
- /data/data/####/plus_loading.png
- /data/data/####/plus_logo.png
- /data/data/####/plus_network.png
- /data/data/####/plus_people.png
- /data/data/####/plus_piccode_refesh_touched.png
- /data/data/####/plus_save.png
- /data/data/####/plus_show_pwd.png
- /data/data/####/plus_start_logo.png
- /data/data/####/plus_success.png
- /data/data/####/q8AZpK1kKGgtNU_tr0rn5w==
- /data/data/####/rdata_comzsfzqmfyldmz.new
- /data/data/####/rj_wybgJdefSwxmE.zip
- /data/data/####/runner_info.prop.new
- /data/data/####/rz3Et3sGkHZAeC9wuZMgrtBlr2a2eHx9.new
- /data/data/####/sdk_prefs
- /data/data/####/security_info
- /data/data/####/shortcut_desktop_icon.png
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/xvqR-NtMqmJvYHrjrn9-hA==.new
- /data/data/####/xxl_about.png
- /data/data/####/xxl_arraw_left.png
- /data/data/####/xxl_billing_failure.png
- /data/data/####/xxl_billing_success.png
- /data/data/####/xxl_close.png
- /data/data/####/xxl_logo.png
- /data/data/####/xxl_pic_refresh.png
- /data/data/####/xxl_right_arraw.png
- /data/data/####/xxl_sale.png
- /data/data/####/zmplane
- /data/media/####/.uunique.new
- /data/media/####/607416063000userInfo.txt
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M
- /data/media/####/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M.lk
- /data/media/####/MiguPay.SO30.Lib_012226_137D848DA99F7B12A8FBD7...02.zip
- /data/media/####/MiguPay.Sdk30.Lib_12003072_D59587AB4958B47F2C8...02.zip
- /data/media/####/MiguPay.Sdk30.Lib_12003072_f7cf98fb679eaa6b0d7...02.cod
- /data/media/####/MiguPay.Sdk30.Lib_12003072_f7cf98fb679eaa6b0d7...02.dat
- /data/media/####/MiguPay.Sdk30.Res_00026014_3C3B3538E3D2C3DFD6B...02.zip
- /data/media/####/ShareData.txt
- /data/media/####/app_info.txt
- /data/media/####/deviceId
- /data/media/####/libmgRun_01.22.26_01.so
- /data/media/####/marketing_1132.jar
- /data/media/####/pushDB.txt
- /data/media/####/pushTime.txt
- /data/media/####/pushTotal.txt
- /data/media/####/sdk_prefs.txt
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.8.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- getprop ro.yunos.version
- logcat -d -v threadtime
- Bugly
- libmiguED
- libnfix
- libshella-2.8
- libufix
- megjb
- nfix
- ufix
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-GCM-NoPadding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding