Technical information
- Android.DownLoader.906.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 47.1####.222.149:996
- TCP(HTTP/1.1) 200####.i####.com:80
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) hy####.ray####.com:80
- TCP(HTTP/1.1) luna-im####.qq.com.####.com:80
- TCP(HTTP/1.1) z.c####.com:80
- TCP(HTTP/1.1) cdn-ad####.ray####.com:80
- TCP(HTTP/1.1) yq####.jn####.ltd:80
- TCP(HTTP/1.1) j####.o####.com:20193
- TCP(HTTP/1.1) php.sho####.com:80
- TCP(HTTP/1.1) a####.clou####.xyz:80
- TCP(HTTP/1.1) v.sho####.com:80
- TCP(TLS/1.0) z.c####.com:443
- TCP(TLS/1.0) analy####.ray####.com:443
- TCP(TLS/1.0) cdn.nvshenf####.com.####.com:443
- TCP(TLS/1.0) mi.s####.qq.com:443
- TCP(TLS/1.0) cdn-adn####.ray####.com:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) sf3-ttc####.ps####.com:443
- TCP(TLS/1.0) log.tracki####.com:443
- TCP(TLS/1.0) s####.e.qq.com:443
- TCP(TLS/1.0) t####.m.qq.com:443
- TCP(TLS/1.0) lhyysdk####.oss-cn-####.aliy####.com:443
- TCP(TLS/1.0) gm.mm####.com:443
- TCP(TLS/1.0) analy####.map.qq.com:443
- TCP(TLS/1.0) c.c####.com:443
- TCP(TLS/1.0) mi.g####.qq.com:443
- TCP(TLS/1.0) cdnqp####.tis####.com:443
- TCP(TLS/1.0) fk-old-####.ray####.com:443
- TCP(TLS/1.0) www.nvshenf####.com:443
- TCP(TLS/1.0) net.ray####.com:443
- TCP 1####.168.101.254:33779
- TCP 1####.168.101.254:54935
- TCP 1####.168.101.254:54300
- TCP 1####.168.101.254:43192
- TCP 1####.168.101.254:44009
- TCP 1####.168.101.254:47626
- TCP 1####.168.101.254:46271
- TCP 1####.168.101.254:43334
- 200####.i####.com
- 605.a####.top
- a####.clou####.xyz
- ad.fan####.cn
- analy####.map.qq.com
- analy####.ray####.com
- c####.mm####.com
- c.c####.com
- cdn-ad####.ray####.com
- cdn-adn####.ray####.com
- cdn.nvshenf####.com
- cdnqp####.tis####.com
- hy####.ray####.com
- imgc####.qq.com
- is.sn####.com
- j####.o####.com
- lhyysdk####.oss-cn-####.aliy####.com
- log.tracki####.com
- mi.g####.qq.com
- mi.s####.qq.com
- net.ray####.com
- php.sho####.com
- plb####.u####.com
- pv.s####.com
- s####.e.qq.com
- set####.ray####.com
- sf3-ttc####.ps####.com
- t####.m.qq.com
- u####.u####.com
- v.sho####.com
- v1.c####.com
- www.nvshenf####.com
- yq####.jn####.ltd
- z####.heyc####.net
- z12.c####.com
- z3.c####.com
- z6.c####.com
- z9.c####.com
- 200####.i####.com/
- cdn-ad####.ray####.com/cdn-adn/creativesync/19/07/24/11/40/5d37d339ee83f...
- cdn-ad####.ray####.com/cdn-adn/v2/image/jpeg/5e062e825c565.jpeg
- cdn-ad####.ray####.com/cdn-adn/vn/19/12/23/19/29/c51f41ec710cdb3696a5b68...
- gd.a.s####.com/cityjson
- hy####.ray####.com/rv-zip-2019/1127/mini-16af5baa8cf946a773ff5d49d1e1256...
- hy####.ray####.com/rv-zip-2020/0102/3like.v7-7be926a257c2e7c2f6d506ceb36...
- hy####.ray####.com/rv-zip-2020/0217/tpl4-7e254617d6c42a998849e176650d751...
- hy####.ray####.com/rv/endv4.html?mof=####&ec_id=####&rv_tid=####&tplgp=#...
- luna-im####.qq.com.####.com/qzone/biz/gdt/mod/android/AndroidAllInOne/pr...
- yq####.jn####.ltd/sy/fmnfs
- z.c####.com/stat.htm?id=####&cnzz_eid=####
- a####.clou####.xyz/index.php?r=####&uid=####&tm=####&model=####&density=...
- j####.o####.com:20193/h3wkt/
- php.sho####.com/index.php?r=####
- s####.e.qq.com/activate
- s####.e.qq.com/launch
- v.sho####.com/index.php?r=####
- /data/anr/traces.txt
- /data/data/####/-1127729055-1266689676
- /data/data/####/.imprint
- /data/data/####/.turing.dat
- /data/data/####/0.xml
- /data/data/####/1021689741840853517
- /data/data/####/1s.jar
- /data/data/####/2221.yaqcookie
- /data/data/####/2749.yaqcookie
- /data/data/####/3053.yaqcookie
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/MultiDex.lock
- /data/data/####/Reyun.db
- /data/data/####/Reyun.db-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/_p.xml
- /data/data/####/_sh.xml
- /data/data/####/_xsdk_.jar
- /data/data/####/com.fy.hpsm-1.apk.classes2.zip
- /data/data/####/com.qq.e.sdkconfig.xml
- /data/data/####/config
- /data/data/####/cow.xml
- /data/data/####/cv.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTIzMzE1;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTM1NTU2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTM2MzAx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTQ2OTY1;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTU5MzAz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTgyMzYzNTc1Njk3;
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/dfwwswds.data-journal
- /data/data/####/downloader.db-journal
- /data/data/####/dpi
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/fwswsedfrf.data-journal
- /data/data/####/fwwsf.xml
- /data/data/####/gdt_config.cfg
- /data/data/####/gdt_plugin.dex (deleted)
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_stat.db
- /data/data/####/gdt_stat.db-journal
- /data/data/####/gdt_suid
- /data/data/####/hxdata.xml
- /data/data/####/i==1.2.0&&1.0.3_1582363523337_envelope.log
- /data/data/####/i==1.2.0&&1.0.3_1582363535588_envelope.log
- /data/data/####/i==1.2.0&&1.0.3_1582363559330_envelope.log
- /data/data/####/i==1.2.0&&1.0.3_1582363575730_envelope.log
- /data/data/####/index
- /data/data/####/info.xml
- /data/data/####/kk_umeng_common_config.xml
- /data/data/####/libMMANDKSignature.076317a4.so
- /data/data/####/libMMANDKSignature.29a96205.so
- /data/data/####/libturingau.076317a4.so
- /data/data/####/libturingau.29a96205.so
- /data/data/####/libyaqbasic.076317a4.so
- /data/data/####/libyaqbasic.29a96205.so
- /data/data/####/libyaqpro.076317a4.so
- /data/data/####/libyaqpro.29a96205.so
- /data/data/####/mintegral.msdk.db-journal
- /data/data/####/mintegral.xml
- /data/data/####/mpdc_105498_1
- /data/data/####/multidex.version.xml
- /data/data/####/netflow.xml
- /data/data/####/sdfwsdswd3f.data-journal
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/share_date.xml
- /data/data/####/sp_push_time.xml
- /data/data/####/sp_reward_video_adslot.xml
- /data/data/####/t==8.1.1+G&&1.0.3_1582363524675_envelope.log
- /data/data/####/tmp-com.fy.hpsm-1.apk.classes-1499195986.zip
- /data/data/####/tmp-com.fy.hpsm-1.apk.classes333381958.zip
- /data/data/####/tracking_device_id_cache.xml
- /data/data/####/tracking_install.xml
- /data/data/####/tracking_interval.xml
- /data/data/####/tracking_pkgInfo.xml
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/tt_sdk_settings.xml.bak
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/turingfd_conf_105498_28_audienceMini.xml
- /data/data/####/turingfd_conf_105498_auMini.xml
- /data/data/####/turingfd_protect_105498_28_audienceMini.xml
- /data/data/####/turingfd_protect_105498_41_auMini.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/update_lc
- /data/data/####/userlist.xml
- /data/data/####/wRrsswsdef.xml
- /data/data/####/wRrsswsdef.xml.bak
- /data/data/####/wbwswswx.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/xbm.xml
- /data/data/####/yaq.076317a4.sec
- /data/data/####/yaq.29a96205.sec
- /data/data/####/yaq2.29a96205.sec
- /data/data/####/yaq3_0.29a96205.sec
- /data/data/####/yaqsdkcookie
- /data/media/####/-583766234
- /data/media/####/.a.dat
- /data/media/####/.adfwe.dat
- /data/media/####/.cca.dat
- /data/media/####/.nid
- /data/media/####/.nomedia
- /data/media/####/.turing.dat
- /data/media/####/.umm.dat
- /data/media/####/.yfzz
- /data/media/####/003.gif
- /data/media/####/082d28e84c34398d28bab8d2f06a33b2.zip
- /data/media/####/1051867569
- /data/media/####/2f1bb209f3d4cbc7a831b42b3b1aba46.zip
- /data/media/####/395b5500c6c7f195a029030c7ac15a45.zip
- /data/media/####/3ffb90c0156c7c065414c1c803b9225b.tmp
- /data/media/####/3like.v7.html
- /data/media/####/841bc5ca1085cf2c15336d2073e7065d.html
- /data/media/####/8945CFCC7D1347478D406FB92FD86B29.temp
- /data/media/####/EC_MOF.scss
- /data/media/####/EC_ORNAMENT_FESTIVAL.scss
- /data/media/####/EC_TUIA.scss
- /data/media/####/EC_TUIA_IFRAME.scss
- /data/media/####/_pn
- /data/media/####/_shn
- /data/media/####/b9856bab3add981eccc7a9b9ce2b83cd.tmp
- /data/media/####/b9867158b917722c7ec31cf360a52f08.zip
- /data/media/####/base.scss
- /data/media/####/btn_close.png
- /data/media/####/c1ef28421cca382bdf8753a2548a987a.html
- /data/media/####/circle.4ff7.png
- /data/media/####/circle.png
- /data/media/####/close_v2.png
- /data/media/####/common.min.js
- /data/media/####/e6c96905f4df7c0f736d609c76635207
- /data/media/####/endv4.js
- /data/media/####/endv4.scss
- /data/media/####/gift-love.gif
- /data/media/####/icon-mtg.7962.png
- /data/media/####/icon-mtg.png
- /data/media/####/icon_mtg.png
- /data/media/####/idcd.scss
- /data/media/####/loading.gif
- /data/media/####/logo-black.png
- /data/media/####/logo-gray.7b49.png
- /data/media/####/logo-gray.png
- /data/media/####/mini.html
- /data/media/####/om_js_content.txt
- /data/media/####/privacy-shadow.png
- /data/media/####/privacy.png
- /data/media/####/rv_bg_0.jpg
- /data/media/####/rv_bg_1.jpg
- /data/media/####/rv_bg_2.jpg
- /data/media/####/sound_off_v2.png
- /data/media/####/sound_open_v2.png
- /data/media/####/star-gray.bccb.png
- /data/media/####/star-gray.png
- /data/media/####/star-yellow.070f.png
- /data/media/####/star-yellow.png
- /data/media/####/star.png
- /data/media/####/star1.png
- /data/media/####/subscripts.0971.png
- /data/media/####/subscripts.png
- /data/media/####/sysid.dat
- /data/media/####/tpl4.html
- /data/media/####/tpl4.js
- /data/media/####/user-gray.072c.png
- /data/media/####/user-gray.png
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/df
- /system/bin/getprop
- /system/bin/sh
- cat /sys/class/android_usb/android0/idProduct
- cat /sys/class/android_usb/android0/idVendor
- cat /sys/class/net/wlan0/address
- getprop
- getprop ro.build.version.emui
- getprop ro.letv.release.version
- getprop ro.vivo.os.build.display.id
- ls -l /dev
- ls -l /dev/block
- ls -l /dev/block/vold
- ls -l /dev/bus
- ls -l /dev/bus/usb
- ls -l /dev/bus/usb/001
- ls -l /dev/com.android.settings.daemon
- ls -l /dev/cpuctl
- ls -l /dev/cpuctl/apps
- ls -l /dev/cpuctl/apps/bg_non_interactive
- ls -l /dev/graphics
- ls -l /dev/input
- ls -l /dev/log
- ls -l /dev/pts
- ls -l /dev/snd
- ls -l /dev/socket
- ls /
- ls /proc/2221
- ls /sys/class/thermal
- ps
- cocos2djs
- libMMANDKSignature.076317a4
- libMMANDKSignature.29a96205
- libturingau.076317a4
- libturingau.29a96205
- libyaqbasic.076317a4
- libyaqbasic.29a96205
- libyaqpro.076317a4
- libyaqpro.29a96205
- nms
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-None-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- DES
- RSA-ECB-PKCS1Padding
- RSA-None-PKCS1Padding