Technical information
- Android.RemoteCode.127.origin
- TCP(DNS) <Google DNS>
- TCP(DNS) 8####.8.4.4:53
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) up####.sdk.jig####.cn:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(TLS/1.0) adt.x####.com:443
- TCP(TLS/1.0) 1####.217.19.202:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 1####.217.17.106:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) na61-####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) c####.im.ta####.com:443
- TCP(TLS/1.0) app.gomefin####.com.cn:443
- TCP(TLS/1.2) 1####.250.179.206:443
- TCP(TLS/1.2) 1####.217.19.202:443
- TCP(TLS/1.2) 1####.250.179.163:443
- UDP sis.j####.io:19000
- UDP easytom####.com:19000
- TCP 1####.202.138.23:7005
- UDP 1####.31.17.108:19000
- UDP s.j####.cn:19000
- 1####.3.188.193
- 1####.9.135.156
- 1####.9.138.15
- a####.exc.mob.com
- adt.x####.com
- api.s####.com
- api.s####.mob.com
- app.gomefin####.com.cn
- c####.im.ta####.com
- easytom####.com
- i####.j####.cn
- i####.ww.ta####.com
- i.t####.com
- instant####.google####.com
- m.d####.mob.com
- md####.google####.com
- p####.google####.com
- s####.j####.cn
- s.j####.cn
- sis.j####.io
- up####.sdk.jig####.cn
- api.s####.mob.com/date
- m.d####.mob.com/v4/cconf?appkey=####&plat=####&apppkg=####&appver=####&n...
- a####.exc.mob.com/errconf
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/log4
- api.s####.mob.com/snsconf
- up####.sdk.jig####.cn/v1/push/sdk/postlist
- /data/anr/traces.txt
- /data/data/####/.artc_lock
- /data/data/####/.dic_lock
- /data/data/####/.duid
- /data/data/####/.globalLock
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mps
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.pkg_lock
- /data/data/####/.slw
- /data/data/####/.statistics
- /data/data/####/1622467238834_3370
- /data/data/####/1622467238860_3370
- /data/data/####/1622467238934_3370
- /data/data/####/1622467247071_3526
- /data/data/####/1622467247311_3526
- /data/data/####/1622467253222_3526
- /data/data/####/1622467268050_3526
- /data/data/####/1622467268100_3526
- /data/data/####/1622467268873_3526
- /data/data/####/1622467269053_3526
- /data/data/####/1622467276493_3774
- /data/data/####/1622467276591_3774
- /data/data/####/1622467276667_3774
- /data/data/####/1622467282496_3774
- /data/data/####/1622467304583_3526
- /data/data/####/1622467307543_3526
- /data/data/####/1622467308210_3526
- /data/data/####/1622467308721_3774
- /data/data/####/AZURE2d.png
- /data/data/####/BLUE2d.png
- /data/data/####/CYAN2d.png
- /data/data/####/GREEN2d.png
- /data/data/####/JPushSA_Config.xml
- /data/data/####/JPushSA_Config.xml.bak
- /data/data/####/MAGENTAV2d.png
- /data/data/####/ORANGE2d.png
- /data/data/####/RED2d.png
- /data/data/####/ROSE2d.png
- /data/data/####/SECURE.xml
- /data/data/####/SECURE.xml.bak
- /data/data/####/TD_app_pefercen_profile.xml
- /data/data/####/TD_app_pefercen_profile.xml.bak
- /data/data/####/TD_app_pefercen_profile.xml.bak (deleted)
- /data/data/####/TDpref_longtime.xml
- /data/data/####/TDpref_longtime.xml.bak
- /data/data/####/TDpref_longtime1.xml
- /data/data/####/TDpref_shorttime.xml
- /data/data/####/TDpref_shorttime.xml (deleted)
- /data/data/####/TDpref_shorttime.xml.bak
- /data/data/####/TDpref_shorttime.xml.bak (deleted)
- /data/data/####/TDpref_shorttime1.xml
- /data/data/####/TDtcagent.db
- /data/data/####/TDtcagent.db-journal
- /data/data/####/ThrowalbeLog.db
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/VIOLET2d.png
- /data/data/####/YELLOW2d.png
- /data/data/####/aa600fe984a90d1d76d80996c2a3b284.0.tmp
- /data/data/####/aa600fe984a90d1d76d80996c2a3b284.1
- /data/data/####/aa600fe984a90d1d76d80996c2a3b284.1.tmp
- /data/data/####/android-logo-mask.png
- /data/data/####/android-logo-shine.png
- /data/data/####/android-weberror.png
- /data/data/####/ap12d.data
- /data/data/####/ap2d.data
- /data/data/####/bad6278e4b21def3f54e69b01899b916.0
- /data/data/####/bad6278e4b21def3f54e69b01899b916.0.tmp
- /data/data/####/bad6278e4b21def3f54e69b01899b916.1
- /data/data/####/bad6278e4b21def3f54e69b01899b916.1.tmp
- /data/data/####/classes.dex
- /data/data/####/classes2.dex
- /data/data/####/classes3.dex
- /data/data/####/classes4.dex
- /data/data/####/clock_font.png
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.android.user.profile.xml.bak
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/cn.jpush.preferences.v2.xml.bak
- /data/data/####/com.gomemyc.mylc.android_preferences.xml
- /data/data/####/dso_deps
- /data/data/####/dso_lock
- /data/data/####/dso_manifest
- /data/data/####/dso_state
- /data/data/####/faae69ab8c81c6642dd4ef9c21230f94.0.tmp
- /data/data/####/faae69ab8c81c6642dd4ef9c21230f94.1
- /data/data/####/faae69ab8c81c6642dd4ef9c21230f94.1.tmp
- /data/data/####/financial-account-10-10-6.dex
- /data/data/####/financial-account-10-10-6.dex.flock (deleted)
- /data/data/####/financial-account-10-10-6.jar
- /data/data/####/fund_config.xml
- /data/data/####/fund_config.xml.bak
- /data/data/####/infowindow_bg2d.9.png
- /data/data/####/journal.tmp
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/lbs-10-10-3.dex
- /data/data/####/lbs-10-10-3.dex.flock (deleted)
- /data/data/####/lbs-10-10-3.jar
- /data/data/####/libjiagu.so
- /data/data/####/libpl_droidsonroids_gif.so
- /data/data/####/location_pressed2d.png
- /data/data/####/location_selected2d.png
- /data/data/####/location_unselected2d.png
- /data/data/####/maps_dav_compass_needle_large2d.png
- /data/data/####/marker_default2d.png
- /data/data/####/marker_gps_no_sharing2d.png
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/p.l
- /data/data/####/plugin_v3_financial-account-10-10-6.jar.lock
- /data/data/####/plugin_v3_lbs-10-10-3.jar.lock
- /data/data/####/plugin_v3_sign-10-10-4.jar.lock
- /data/data/####/proc_auxv
- /data/data/####/share_sdk_1
- /data/data/####/sharesdk.db
- /data/data/####/sharesdk.db-journal
- /data/data/####/sign-10-10-4.jar
- /data/data/####/sobot_chat_20210531_log.txt
- /data/data/####/sobot_config.xml
- /data/data/####/talkingDataMapGomeFinanceConverge.json
- /data/data/####/td.lock
- /data/data/####/tdid.xml
- /data/data/####/ywPrefsTools.xml
- /data/data/####/zoomin_pressed2d.png
- /data/data/####/zoomin_selected2d.png
- /data/data/####/zoomin_unselected2d.png
- /data/data/####/zoomout_pressed2d.png
- /data/data/####/zoomout_selected2d.png
- /data/data/####/zoomout_unselected2d.png
- /data/misc/####/primary.prof
- /system/bin/dex2oat --instruction-set=arm --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes2.dex --dex-file=<Package Folder>/.jiagu/classes3.dex --dex-file=<Package Folder>/.jiagu/classes4.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_plugins_v3/financial-account-10-10-6.jar --oat-fd=50 --oat-location=/data/user/0/<Package>/app_plugins_v3_odex/financial-account-10-10-6.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_plugins_v3/financial-account-10-10-6.jar --oat-fd=99 --oat-location=/data/user/0/<Package>/app_plugins_v3_odex/financial-account-10-10-6.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_plugins_v3/lbs-10-10-3.jar --oat-fd=116 --oat-location=/data/user/0/<Package>/app_plugins_v3_odex/lbs-10-10-3.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_plugins_v3/sign-10-10-4.jar --oat-fd=96 --oat-location=/data/user/0/<Package>/app_plugins_v3_odex/sign-10-10-4.dex --compiler-filter=speed
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- DES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- DES-CBC-PKCS5Padding