Technical information
- Adware.Iflytek.1
- UDP(DNS) <Google DNS>
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) y####.b0.a####.com:80
- TCP(HTTP/1.1) ap####.w####.cn.####.com:80
- TCP(HTTP/1.1) na61-####.wagbr####.ali####.####.com:80
- TCP(HTTP/1.1) ada####.m.ta####.com:80
- TCP(HTTP/1.1) up####.sdk.jig####.cn:80
- TCP(HTTP/1.1) hk.wagbr####.non####.####.com:80
- TCP(HTTP/1.1) zb-cent####.m.ta####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) t####.dmp.y####.net:80
- TCP(HTTP/1.1) app.w####.cn:80
- TCP(HTTP/1.1) s.y####.net:80
- TCP(TLS/1.0) 1####.217.19.206:443
- TCP(TLS/1.0) nbsdk-b####.al####.com:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) 1####.217.17.74:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) s####.j####.cn:443
- TCP(TLS/1.2) 1####.217.17.74:443
- TCP(TLS/1.2) and####.google####.com:443
- UDP s.j####.cn:19000
- UDP 2####.0.0.1:9998
- TCP 1####.202.138.25:7000
- 7####.nd####.y####.com
- acs4bai####.m.ta####.com
- ad####.m.ta####.com
- ada####.m.ta####.com
- and####.b####.qq.com
- and####.google####.com
- aos.w####.y####.net
- ap####.w####.cn
- app.w####.cn
- au.y####.net
- instant####.google####.com
- log.u####.com
- m####.go####.com
- nbsdk-b####.al####.com
- plb####.u####.com
- s####.gw.y####.net
- s####.j####.cn
- s.j####.cn
- s.y####.net
- sdk.st####.y####.com
- t####.dmp.y####.net
- u####.u####.com
- up####.sdk.jig####.cn
- wb.110.ta####.com
- y####.al####.com
- ap####.w####.cn.####.com/appfile/b_pkg3.0.9_4.png
- app.w####.cn/t.jsp?app_id=####&channel=####
- s.y####.net/aos/v3/initf?s=####
- s.y####.net/stat/aos/v3/pkc?s=####
- s.y####.net/stat/aos/v3/pku?s=####
- s.y####.net/stat/v3/udt2?appid=####&s=####
- s.y####.net/v3/get?s=####
- s.y####.net/v3/zip_upd?s=####
- y####.b0.a####.com/offer/dist/aos/pkg/3.3.1/offers_3.3.1.zip
- zb-cent####.m.ta####.com/gw-open/mtop.taobao.tbk.sdk.config/1.0/?data=####
- ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
- and####.b####.qq.com/rqd/async?aid=####
- hk.wagbr####.non####.####.com/saveWb.json
- na61-####.wagbr####.ali####.####.com/api/update.do
- t####.dmp.y####.net/v2/android/pkgtime?rt=####&sign=####
- up####.sdk.jig####.cn/v1/push/sdk/postlist
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1004
- /data/data/####/135a920b7a91504b.lock
- /data/data/####/1d77ea041509fe06.lock
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/3509847f4cbd90566d5d8a85f723df90-journal
- /data/data/####/4f381e4a18db964acd607fbc01c91ab6
- /data/data/####/4f381e4a18db964acd607fbc01c91ab6.ymtf
- /data/data/####/617fbec2da0311bcbd379d9595e74c95.zip
- /data/data/####/725a9ca2b85bc222.lock
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/AlibcLinkPartner.xml
- /data/data/####/Alvin2.xml
- /data/data/####/AppSettings.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml.bak
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml.bak
- /data/data/####/ContextData.xml
- /data/data/####/Cookies
- /data/data/####/Cookies-journal
- /data/data/####/JPushSA_Config.xml
- /data/data/####/JPushSA_Config.xml.bak
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/OxgHkj2lz09F
- /data/data/####/OxgHkj2lz09F-journal
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/SGMANAGER_DATA2
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/UTCommon.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/ab914f43b8296c2c.lock
- /data/data/####/aliTradeConfigSP.xml
- /data/data/####/ap.Lock
- /data/data/####/appPackageNames_v2
- /data/data/####/arrow-left-pink.png
- /data/data/####/arrow-left.png
- /data/data/####/arrow-right-pink.png
- /data/data/####/arrow-right.png
- /data/data/####/auth_sdk_device.xml
- /data/data/####/blank.gif
- /data/data/####/bugly_db_-journal
- /data/data/####/c295d36b3e9e4d4199e6d5fe05d96ad5
- /data/data/####/c295d36b3e9e4d4199e6d5fe05d96ad5-journal
- /data/data/####/classes.dex
- /data/data/####/classes2.dex
- /data/data/####/classes3.dex
- /data/data/####/close-icon.png
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml.bak (deleted)
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/crashrecord.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyODg2NDg5;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyODkzMDc2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTE1ODg4;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTI3NjAx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTIyMzY3;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTM2NTQ0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTQzMTE0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTcwMjkyOTYyMzY5;
- /data/data/####/default.png
- /data/data/####/detail-wx-miniprogram.html
- /data/data/####/detail-wx-miniprogram.js
- /data/data/####/detail-wx.html
- /data/data/####/detail-wx.js
- /data/data/####/detail.html
- /data/data/####/detail.js
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/feedback.html
- /data/data/####/feedback.js
- /data/data/####/form.css
- /data/data/####/global.js
- /data/data/####/i42d45df023jnkdd93la483f9xGFKXI
- /data/data/####/i==1.2.0&&1.3.2_1570292886684_envelope.log
- /data/data/####/i==1.2.0&&1.3.2_1570292915839_envelope.log
- /data/data/####/i==1.2.0&&1.3.2_1570292922423_envelope.log
- /data/data/####/i==1.2.0&&1.3.2_1570292962377_envelope.log
- /data/data/####/info.xml
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_local_notification.db-wal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/jpush_statistics.db-shm (deleted)
- /data/data/####/jpush_statistics.db-wal
- /data/data/####/jpush_uncaughtexception_file
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/libjiagu.so
- /data/data/####/libsgmain_312757200000.dex
- /data/data/####/libsgmain_312757200000.dex.flock (deleted)
- /data/data/####/libsgmainso-5.1.81.so.tmp
- /data/data/####/lists.css
- /data/data/####/lists.html
- /data/data/####/lists.js
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/lock.lock
- /data/data/####/md5.js
- /data/data/####/nointernet.png
- /data/data/####/pic_friend_step1.jpg
- /data/data/####/pic_friend_step2.jpg
- /data/data/####/pic_friend_step3.jpg
- /data/data/####/pic_friend_step4.jpg
- /data/data/####/pic_friend_step5.jpg
- /data/data/####/pic_m.png
- /data/data/####/pic_tips_01.png
- /data/data/####/pic_tips_02.png
- /data/data/####/pic_xiaochengxu_kefu_step1.png
- /data/data/####/pic_xiaochengxu_kefu_step2.png
- /data/data/####/pic_xiaochengxu_kefu_step3.png
- /data/data/####/pic_xiaochengxu_kefu_step4.png
- /data/data/####/pic_xiaochengxu_kefu_step5.png
- /data/data/####/pic_xiaochengxu_kefu_step6.png
- /data/data/####/pic_xiaochengxu_step1.png
- /data/data/####/pic_xiaochengxu_step2.png
- /data/data/####/pic_xiaochengxu_step3.png
- /data/data/####/pic_xiaochengxu_step4.png
- /data/data/####/pic_xiaochengxu_step5.png
- /data/data/####/proc_auxv
- /data/data/####/result.png
- /data/data/####/rule.html
- /data/data/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
- /data/data/####/sdetail.html
- /data/data/####/security_info
- /data/data/####/share.css
- /data/data/####/share.db-journal
- /data/data/####/share.html
- /data/data/####/share.js
- /data/data/####/sp.lock
- /data/data/####/sprite-face.png
- /data/data/####/sprite-icons.png
- /data/data/####/sprite-icons2.png
- /data/data/####/timestamp
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_config.xml.bak
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/wakeup_cache.json
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/data/####/wx-qr-step1.jpg
- /data/data/####/wx-qr-step2.jpg
- /data/data/####/wx-qr-step3.jpg
- /data/data/####/wx-qr-step4.jpg
- /data/data/####/wx-qr-step5.jpg
- /data/data/####/wx-step1.jpg
- /data/data/####/wx-step2.jpg
- /data/data/####/wx-step3.jpg
- /data/data/####/wx-step4.jpg
- /data/data/####/wx-step5.jpg
- /data/data/####/wx-wifi-step1.jpg
- /data/data/####/wx-wifi-step2.jpg
- /data/data/####/wx-wifi-step3.jpg
- /data/data/####/wx-wifi-step4.jpg
- /data/data/####/wx-wifi-step5.jpg
- /data/data/####/ymdex.dex
- /data/data/####/ymdex.dex.flock (deleted)
- /data/data/####/ymdex.jar
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/cat /sys/devices/system/cpu/kernel_max
- /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes2.dex --dex-file=<Package Folder>/.jiagu/classes3.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_SGLib/libsgmain_312757200000.zip --oat-fd=51 --oat-location=/data/user/0/<Package>/app_SGLib/libsgmain_312757200000.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_libs/ymdex.jar --oat-fd=68 --oat-location=/data/user/0/<Package>/app_libs/ymdex.dex --compiler-filter=speed
- /system/bin/sh -c type su
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop
- logcat -d -v threadtime
- ls /sys/class/thermal
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- PBEWITHMD5andDES
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- PBEWITHMD5andDES