Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
- TCP(HTTP/1.1) pin####.qq.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) gt####.al####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) h####.b####.com:443
- TCP(TLS/1.0) 1####.217.19.206:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) app.uun####.com:443
- a####.b####.qq.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- app.uun####.com
- gt####.al####.com
- h####.b####.com
- localh####
- log.u####.com
- pi####.qq.com
- pin####.qq.com
- plb####.u####.com
- s####.u####.com
- sdk.o####.p####.####.com
- u####.u####.com
- gt####.al####.com/tps/i3/TB1mdsiMpXXXXXpXXXXNw4JIXXX-640-4.png
- aexcep####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- pi####.qq.com/mstat/report/?index=####
- pin####.qq.com/request
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.imprint
- /data/data/####/0107ba731a2eeaf0cd03942e6ae6e494a832068533cd13e....0.tmp
- /data/data/####/0d66d7aca5af92e9e3826bf84f1959f25fe25f82f5126c0....0.tmp
- /data/data/####/0de0d0153cc4e20979caf9ad49d6f1b612cc969eb16c7a1....0.tmp
- /data/data/####/14eca91ee7d90d6bcdefed4589b28819765f99eed79dfd3....0.tmp
- /data/data/####/1557922378579.log
- /data/data/####/1e35b44a4ed702e83358e3be64056fb606fddfbb71df7e2....0.tmp
- /data/data/####/1ffc244a825178243520e90aa4556420a07485c65b69224....0.tmp
- /data/data/####/275a9c9831ffd6b7ccd21c81f69a77543070c194ee9d9f7....0.tmp
- /data/data/####/29b1c876155f461c669558e0b94a3874d88fdd2cd5be302....0.tmp
- /data/data/####/29bbae0a64b4ec8647fd561147d619b1288247a2ee9ae96....0.tmp
- /data/data/####/2c842c663532dad5fdba3fd99225697d6be6912918e3863....0.tmp
- /data/data/####/2dd376fd90667e019ceea1123a90e7556f3bc84d2af44d5....0.tmp
- /data/data/####/334b0488f5b52c7a0344b0354dca5403a97764b0b694bef....0.tmp
- /data/data/####/368f9f570a641302443c9d1a867c8b69af86f85c92aff39....0.tmp
- /data/data/####/369bfc4ab2678d2bcaafc95e6705b7ebe146be4f6f8e34d....0.tmp
- /data/data/####/369bfc4ab2678d2bcaafc95e6705b7ebe146be4f6f8e34d...471e.0
- /data/data/####/37734f9bac793b47591370835ba1171a368c00a5b03a16a....0.tmp
- /data/data/####/377442d29ed0f09d35687a5c4b5c534666bc9ffb6c12f7f....0.tmp
- /data/data/####/44c5a27fada2bb054530fd13c9b9d3c4b0141e91ad5ee69....0.tmp
- /data/data/####/48510fdb932ccc6796b90bfa87470fe5599e99a596bf30f....0.tmp
- /data/data/####/55d38ea07f937d1a2fe8c3dbebdec1000bce20ac70e7087....0.tmp
- /data/data/####/55f2b3f65b65b84772120ed224736b8b73154998608599f....0.tmp
- /data/data/####/56d1c8ca2257703ea604d19a8abae98e9a7bc34602dbbe0....0.tmp
- /data/data/####/576f49df76e0a9298cc773a67ef9787ba4095526a03802d....0.tmp
- /data/data/####/59a344ad2b3b81869540628bda8c013b02d36959c4b8e61....0.tmp
- /data/data/####/5f185f08904e5fa19cdff51bb530800f68fb9b790332544....0.tmp
- /data/data/####/6389c7d3287db8b1c3b5f38c46c98d128ac15e46976fe10....0.tmp
- /data/data/####/6f1232426e5688f25e363db341e70c949812870c0e2feb4....0.tmp
- /data/data/####/70fa58c9daa82e0128b5959314b80ba66e6d058f02fbcde....0.tmp
- /data/data/####/7432dd45dacba6cc3bd54004edb88736baa1370d446f11f....0.tmp
- /data/data/####/78bc4eba6ec766314510ccbc620dc7034b8e9766e0abe83....0.tmp
- /data/data/####/7b11eef74bc1f82c462850055cd697f484c3c0244d84d8d....0.tmp
- /data/data/####/82814a65b9467d0a2092f06be8a608e1a7a8c1ce4971dfe....0.tmp
- /data/data/####/8a1462d559e9ac90df61f00ef6699c715f3380ec0927de9....0.tmp
- /data/data/####/8a4319c54940d2b2586ab9e914ed7beef4d737d59ae2094....0.tmp
- /data/data/####/94e2887e5a824b0b80a8ea90a04f9a9cfa8020f182e85ad....0.tmp
- /data/data/####/957ecf9293391484e0dbb523b6da6f6e4d7a418b08bc6c9....0.tmp
- /data/data/####/9b656a5887f38ed16a06aafba4c8e7fde507ff9833d3306....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/BMWEEXOPEN_JS_SP.xml
- /data/data/####/BMWEEXOPEN_NATIVE_SP.xml
- /data/data/####/ContextData.xml
- /data/data/####/CookiePrefsFile.xml
- /data/data/####/MultiDex.lock
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1557922349870
- /data/data/####/__send_data_1557922385278
- /data/data/####/__send_data_1557922404828
- /data/data/####/a339d7e891da05a0a6f9ce5ad62f09268b1c4d90c90e432....0.tmp
- /data/data/####/a68720a09882777cd982d4e434c04550ac23572585f393a....0.tmp
- /data/data/####/aef2741aa6c6483237741d990987fbfe9ec19381f6b7466....0.tmp
- /data/data/####/baidu_mtj_sdk_record.xml
- /data/data/####/be802c8847f17c798ae48218eecfb2d9376eb92ed21f75f....0.tmp
- /data/data/####/bugly_db_legu
- /data/data/####/bugly_db_legu-journal
- /data/data/####/c325d41a75f12f224140949bde9707af9ea91e47754da96....0.tmp
- /data/data/####/c3a23ff4d33d1d26980f79ade7205d67b19b9a75ca08749...2a32.0
- /data/data/####/c5a04543faa6151f131b7ddc268a0cbb86db826d2567f99....0.tmp
- /data/data/####/com.shixi.uucard.mid.world.ro.xml
- /data/data/####/com.shixi.uucard_preferences.xml
- /data/data/####/d44251d1f17336b99a793c752039622cc7fd7efaa21630a....0.tmp
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTU3OTIyMzc3ODcw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTU3OTIyMzk2MTcy;
- /data/data/####/e11a5b351d1b5bebb30d266e94699224662816cc744f508....0.tmp
- /data/data/####/e3b44e74e04fd08c953ccaa948a438160e5f8063f8043ef....0.tmp
- /data/data/####/eda955add67abede534f9c182521a90cdb3facd72e10ddd....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f265c336fb0faf324c992fd0dd2ed04903b03691990d445....0.tmp
- /data/data/####/f5d0932f8af1252f06223c14b8a8cb5936a55069393300c....0.tmp
- /data/data/####/fd5f7b9201d09c88c9cf7bbc7e7818ea5fd534bfb5589d1....0.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/i==1.2.0&&2.1.0_1557922377949_envelope.log
- /data/data/####/info.xml
- /data/data/####/init_c1.pid
- /data/data/####/init_er.pid
- /data/data/####/journal.tmp
- /data/data/####/jsserver_crash_info.log
- /data/data/####/legu_tencent_analysis.db_com.shixi.uucard-journal
- /data/data/####/libcuid.so
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.9.0.2.so
- /data/data/####/libufix.so
- /data/data/####/libweexjsb.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/mix.so
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/pri_legu_tencent_analysis.db_com.shixi.uucard-journal
- /data/data/####/security_info
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/media/####/+.png
- /data/media/####/.a.dat
- /data/media/####/.adfwe.dat
- /data/media/####/.cca.dat
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.mid.txt
- /data/media/####/.mid.txt1000001
- /data/media/####/.timestamp
- /data/media/####/.umm.dat
- /data/media/####/Alvin2.xml
- /data/media/####/Artwork.png
- /data/media/####/Botton-WQ.png
- /data/media/####/Botton-YQ.png
- /data/media/####/ContextData.xml
- /data/media/####/Q-bg.png
- /data/media/####/aboutUs.js
- /data/media/####/activate_.png
- /data/media/####/addCard.js
- /data/media/####/apn.png
- /data/media/####/applyMember.js
- /data/media/####/auth.js
- /data/media/####/background-team.png
- /data/media/####/background.png
- /data/media/####/ban_vitality_bg.png
- /data/media/####/bankList.js
- /data/media/####/banner.png
- /data/media/####/bind.js
- /data/media/####/bundle.zip
- /data/media/####/cardInfo.js
- /data/media/####/chaxun.png
- /data/media/####/close.png
- /data/media/####/comboCart.js
- /data/media/####/comboSelect.js
- /data/media/####/comboUpdate.js
- /data/media/####/ddk.png
- /data/media/####/diejiabao-benyue.png
- /data/media/####/diejiabao-ciyue.png
- /data/media/####/drawCash.js
- /data/media/####/drawCashBindAccount.js
- /data/media/####/drawCashRecord.js
- /data/media/####/dsh.png
- /data/media/####/dzf.png
- /data/media/####/extenCenter.js
- /data/media/####/extenShare.js
- /data/media/####/fan.png
- /data/media/####/fanhui.png
- /data/media/####/fanm.png
- /data/media/####/gold.png
- /data/media/####/goodsDetail.js
- /data/media/####/goodsSearch.js
- /data/media/####/goodsShare.js
- /data/media/####/guide.js
- /data/media/####/guide1.png
- /data/media/####/guide2.png
- /data/media/####/guide3.png
- /data/media/####/hd.png
- /data/media/####/hh-cx.png
- /data/media/####/hh-fh.png
- /data/media/####/hh-fx.png
- /data/media/####/hh-fz.png
- /data/media/####/hh-qq.png
- /data/media/####/hh-quan.png
- /data/media/####/hh-sc.png
- /data/media/####/hh-wq.png
- /data/media/####/hh-wx.png
- /data/media/####/hq.png
- /data/media/####/ic-gold.png
- /data/media/####/ico_UUcard_blue.png
- /data/media/####/ico_UUcard_gray.png
- /data/media/####/ico_UUcen_blue.png
- /data/media/####/ico_UUcen_gray.png
- /data/media/####/ico_UUgd_blue.png
- /data/media/####/ico_UUgd_gray.png
- /data/media/####/ico_UUtask_blue.png
- /data/media/####/ico_UUtask_gray.png
- /data/media/####/ico_center_phone.png
- /data/media/####/ico_center_signin.png
- /data/media/####/ico_center_vitality.png
- /data/media/####/ico_home_alter.png
- /data/media/####/ico_popup_close.png
- /data/media/####/ico_return.png
- /data/media/####/ico_share.png
- /data/media/####/ico_vitality_little_vitality.png
- /data/media/####/ico_vitality_rule.png
- /data/media/####/ico_vitality_vitality.png
- /data/media/####/icon-fx.png
- /data/media/####/icon-ll.png
- /data/media/####/icon-ll2.png
- /data/media/####/icon-yq.png
- /data/media/####/iconfont.ttf
- /data/media/####/iconfont_doctor.ttf
- /data/media/####/index.js
- /data/media/####/infoEdit.js
- /data/media/####/jiantou-shang.png
- /data/media/####/jiaofei.png
- /data/media/####/jt-g.png
- /data/media/####/jt-sh.png
- /data/media/####/jt-xh.png
- /data/media/####/jyk.png
- /data/media/####/kthy.png
- /data/media/####/lifeInfo.js
- /data/media/####/lifeTrade.js
- /data/media/####/login.js
- /data/media/####/logo.png
- /data/media/####/md5.json
- /data/media/####/member-g.png
- /data/media/####/member-o.png
- /data/media/####/messageDetail.js
- /data/media/####/messageList.js
- /data/media/####/mr.png
- /data/media/####/myTeam.js
- /data/media/####/news.png
- /data/media/####/orderList.js
- /data/media/####/partner-g.png
- /data/media/####/partner-o.png
- /data/media/####/payRecord.js
- /data/media/####/place_holder.png
- /data/media/####/popList.js
- /data/media/####/qq.png
- /data/media/####/questionDetail.js
- /data/media/####/questionList.js
- /data/media/####/reward.js
- /data/media/####/s+.png
- /data/media/####/s-.png
- /data/media/####/save-photo.png
- /data/media/####/sc.png
- /data/media/####/schi.png
- /data/media/####/searchResult.js
- /data/media/####/set.png
- /data/media/####/setting.js
- /data/media/####/sfbs.png
- /data/media/####/shimingrenzheng.png
- /data/media/####/signIn.js
- /data/media/####/sjhhr.png
- /data/media/####/ssk.png
- /data/media/####/sxh.png
- /data/media/####/tg.png
- /data/media/####/tianjiaxinka.png
- /data/media/####/tu1.png
- /data/media/####/tu3.png
- /data/media/####/txk.png
- /data/media/####/user-g.png
- /data/media/####/user-o.png
- /data/media/####/uu-dd.png
- /data/media/####/uu-fh.png
- /data/media/####/uu-fk.png
- /data/media/####/uu-guan.png
- /data/media/####/uu-hhr.png
- /data/media/####/uu-hy.png
- /data/media/####/uu-hyuan.png
- /data/media/####/uu-jl.png
- /data/media/####/uu-jt.png
- /data/media/####/uu-kai.png
- /data/media/####/uu-qb.png
- /data/media/####/uu-sx.png
- /data/media/####/uu-t.png
- /data/media/####/uu-td.png
- /data/media/####/uu-tg.png
- /data/media/####/uu-wc.png
- /data/media/####/uu-wt.png
- /data/media/####/uu-wx.png
- /data/media/####/uu-x.png
- /data/media/####/uu-xgb.png
- /data/media/####/uu-yh.png
- /data/media/####/uu-yuan.png
- /data/media/####/uu-zfb.png
- /data/media/####/uuCoin.js
- /data/media/####/uuCoinDetail.js
- /data/media/####/uuCoinPending.js
- /data/media/####/uub.png
- /data/media/####/uuhaohuo-blue.png
- /data/media/####/uuhaohuo-gray.png
- /data/media/####/uuka-blue.png
- /data/media/####/uuka-gray.png
- /data/media/####/uuzhongxin-blue.png
- /data/media/####/uuzhongxin-gray.png
- /data/media/####/v-bs.png
- /data/media/####/v-fu.png
- /data/media/####/v-kt.png
- /data/media/####/v-sj.png
- /data/media/####/v-tg.png
- /data/media/####/w-gray.png
- /data/media/####/webView.js
- /data/media/####/wechat.png
- /data/media/####/weirz.png
- /data/media/####/weixinzhifu.png
- /data/media/####/wk.png
- /data/media/####/wq.png
- /data/media/####/wt.png
- /data/media/####/wx.png
- /data/media/####/wxz.png
- /data/media/####/x.png
- /data/media/####/xdf.png
- /data/media/####/xiala.png
- /data/media/####/xx.png
- /data/media/####/xxk.png
- /data/media/####/xz.png
- /data/media/####/yuan1.png
- /data/media/####/yuan2.png
- /data/media/####/z-green.png
- /data/media/####/z.png
- /data/media/####/zhifubaozhifu.png
- /data/media/####/zm.png
- /data/app-lib/<Package>-1/libweexjsb.so 52 0
- /data/app-lib/<Package>-1/libweexjsb.so 57 0
- /data/app-lib/<Package>-1/libweexjsb.so 58 0
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.display.id
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.smartisan.version
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- getprop ro.yunos.version
- logcat -d -v threadtime
- ls /sys/class/thermal
- Bugly
- MtaNativeCrash
- Patcher
- getuiext2
- libnfix
- libshella-2.9.0.2
- libufix
- nfix
- ufix
- weexjsc
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-PKCS1PADDING
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-GCM-NoPadding