Technical information
- Adware.Overlay.1.origin
- UDP(???) and####.google####.com:443
- TCP(???) cmftupo####.v.tr####.net:443
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) api.fa####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) p.1####.cn.####.net:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) uba.c####.com.cn:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) dfp.c####.com.cn:443
- TCP(TLS/1.2) 1####.250.74.74:443
- TCP(TLS/1.2) 2####.58.207.227:443
- TCP(TLS/1.2) 1####.250.74.36:443
- TCP(TLS/1.2) www.google####.com:443
- and####.a####.go####.com
- and####.google####.com
- api.fa####.com
- dfp.c####.com.cn
- f####.gst####.com
- hky####.kunlu####.com
- hkyzm####.kunlu####.com
- mca.c####.com
- p####.google####.com
- p.1####.cn
- uba.c####.com.cn
- www.google####.com
- dfp.c####.com.cn:443/dfp/public/sdkConfig/get_v2?channel=####&custID=###...
- uba.c####.com.cn:443/config/Android.conf?project=####&app_id=####
- api.fa####.com:443/faceid/v1/sdk/authm
- dfp.c####.com.cn:443/dfp/public/generate/post?channel=####&custID=####
- uba.c####.com.cn:443/sa?project=####
- /data/anr/traces.txt
- /data/dalvik-cache/####/system@framework@am.jar@classes.dex
- /data/dalvik-cache/####/system@framework@am.jar@classes.dex.flo...leted)
- /data/data/####/.DescriptionManagerImpl_init.lock
- /data/data/####/.edata
- /data/data/####/.init7zSo.lock
- /data/data/####/01da5d836734d04e_0
- /data/data/####/01da5d836734d04e_1
- /data/data/####/025682ffa454bc0f0f9cdbe65b6d41688bbe5c96f378782...c183.0
- /data/data/####/0380a88d53dfdab79097fdcde2e60a2c4c1562e8351b09b....0.tmp
- /data/data/####/0380a88d53dfdab79097fdcde2e60a2c4c1562e8351b09b...a338.0
- /data/data/####/05b2698862ee4b526f686303ecb5fc8b.0.tmp
- /data/data/####/05b2698862ee4b526f686303ecb5fc8b.1
- /data/data/####/0901d419da7a7aae6b31518c408e1f52116f512976afe49....0.tmp
- /data/data/####/093d08d7b324f9ed_0
- /data/data/####/093d08d7b324f9ed_1
- /data/data/####/099bf583021f4b82b4f3a7d7fa95550ecb30ca3f263fa6a...8f71.0
- /data/data/####/0e29a183ee6d5cf36ddd695af4da4c64b2e7d220e19dd5d....0.tmp
- /data/data/####/0f4460abb0562825d97dd4a8eb2301fb2aced260cf27cd9....0.tmp
- /data/data/####/0f4460abb0562825d97dd4a8eb2301fb2aced260cf27cd9...866b.0
- /data/data/####/0f633c1d9f30835db4d340f5ab01b83853e8df23e4ef097...5d13.0
- /data/data/####/102daa43fbf63aa6bac868892daa0a42a857e1237bf61fb...2c21.0
- /data/data/####/1280150092_12945259_347158862000
- /data/data/####/1280150092_12945259_347158862000_start (deleted)
- /data/data/####/14ab30561f429ae65bdf97bba5664fdd18607ece334cda1...7710.0
- /data/data/####/1719913690976920.tar
- /data/data/####/1768621190210_com.cmcc.hebao-main_mPaaSClientAndroid
- /data/data/####/1768621200869_com.cmcc.hebao-main_mPaaSAliveAndroid
- /data/data/####/17dd1ee864537695d1ae1692cc9911f9dd5b26d57bfa8f2....0.tmp
- /data/data/####/1934ed5327275b643988254b4c3e7758b748ac6a0892099...b19d.0
- /data/data/####/1c3929d823124a4fe7d3366797f3a320a624cc4ba68219f...91ad.0
- /data/data/####/1feef3e217213896b740da422dce4320cc4c7cee4d7fed5...4a42.0
- /data/data/####/2024091300000000.tar
- /data/data/####/2254f4f2dd86bcb33be8dd4297147a7a8ef90949b39ffaf...44cf.0
- /data/data/####/240f48f497b6c7959d48277465015984
- /data/data/####/251681c1eb286195e7b3c974638cc81cde1299a1db949b4...0819.0
- /data/data/####/279507654_y
- /data/data/####/29883c2a64aa450606484cb628d07992
- /data/data/####/2b7df737546c627104b5d5e04c037983262ed9c38ceb936...4433.0
- /data/data/####/2eb71b582306765381bf5761356c3abe29e029f9a6f005c...4a20.0
- /data/data/####/3131138373cfb341b9fdd8c6f36ec272c86f259560cf024...7de1.0
- /data/data/####/317ca21a643771d35dc6af12eb9959a9.0.tmp
- /data/data/####/317ca21a643771d35dc6af12eb9959a9.1
- /data/data/####/361bd8255292c6a53fb2605185382623
- /data/data/####/368b9bb1a37b6c1c_0
- /data/data/####/368b9bb1a37b6c1c_1
- /data/data/####/3b27c39bae93365e56eaad2e02a9615cd7c3cc256cceb5a...9e33.0
- /data/data/####/3c917c8cc5b71ba4fc7b94e7d6c1eb31547e915b2ea528d...ef61.0
- /data/data/####/3cbea71eb3c09947fb16b922896ea8e25bb5e6cd0b31df6...9447.0
- /data/data/####/40a6393f167f58598b071ee36079cd8699925da87757b99...426a.0
- /data/data/####/412a05e389750282b19783d1dbc9a28ac43376e513fd785....0.tmp
- /data/data/####/412a05e389750282b19783d1dbc9a28ac43376e513fd785...37cb.0
- /data/data/####/43c4c1a1f7bfa38aeca83005d3dee87ac609b55702a1f4b....0.tmp
- /data/data/####/44089160ad805f40d4812a48eac640a4a5df746ce2d25fe...1141.0
- /data/data/####/44f822f9018248dc2994741c6e1f7e24ea53daaec9fc93c...7736.0
- /data/data/####/465a3583cba37931a427bdeed3cdc624
- /data/data/####/475c8889f3035820bb1ef514455940032bab2bc6a46cb3a...566d.0
- /data/data/####/48bbe2c79db013a4afa7eaf84444df0e
- /data/data/####/4b74de3d17d00c69a789763943f836fea47f140dbcad978...824c.0
- /data/data/####/54b669c16c8f204000e0224611fd58ce1611964a1aa17e2...4d54.0
- /data/data/####/572c5bfb35cc8f25ebcd6ee9940ad5403f3df2f209a48a9....0.tmp
- /data/data/####/5a382f55d22b77a13cc486374c581532b5a75a4407c8000...a957.0
- /data/data/####/5b1614207ea6025ac9839c9af541e7fb73603edbf8a197e...c403.0
- /data/data/####/5bf5b8cd0fbd750cdfe973873cecadb9
- /data/data/####/5f7176daf6b0ab14295c28d6e77b9a306a91bfa41f580bd....0.tmp
- /data/data/####/5fe1e2c25ad99670e14a18197473a0cba0c1a1c3574e831...4a09.0
- /data/data/####/639b578e76df13ff0a659a809b5a93348b90253723f879a...4129.0
- /data/data/####/65c4eae29a5a27b3_0
- /data/data/####/67688583_1
- /data/data/####/679964455_y
- /data/data/####/68687029.tar
- /data/data/####/6a51aa15ff459e4ca959383843bcb2b7
- /data/data/####/6b6d0f9120b343e0_0
- /data/data/####/72a7785d3ef1698cb2720e0df9b5c9a8d084fc0c31d2c8c...eced.0
- /data/data/####/72cdfa9861b0294c4f714157fad6c1ee0d23aa64bedb0a3....0.tmp
- /data/data/####/747199d81f2b872f68eade49930189a46a4e88c17f6f6de...f3c7.0
- /data/data/####/76e35ad59f94c3dc295eab52a06522265402d00b271750a...2e85.0
- /data/data/####/7789c2d29fbc352394ac68017419c1a20c3f3df989735fd...ab2c.0
- /data/data/####/79166f12ae09f31516a984394b5760ed
- /data/data/####/8045b364428d3829_0
- /data/data/####/8045b364428d3829_1
- /data/data/####/84e81c8a46e1a3399c5e8a601b0180f2bb786fe2aa587a5...f980.0
- /data/data/####/8525105610a89fd4523b61ee1fbc91c56abcc56d63a4a8b....0.tmp
- /data/data/####/8525105610a89fd4523b61ee1fbc91c56abcc56d63a4a8b...08a0.0
- /data/data/####/8533913616526213.tar
- /data/data/####/8816ebdde2cafc54988ec5b4c6c5da698089f403098a4cb...9528.0
- /data/data/####/912007e55de787450b8134eb06e85f15b125b2f764a5f99...a65a.0
- /data/data/####/95bc3436de214af1a139129c5ef0916aa24d252f32293ea...1fa4.0
- /data/data/####/95c65caa2b935961_0
- /data/data/####/95c65caa2b935961_1
- /data/data/####/97d9af3354676375a7532a4b4d206287e798abd2807d9a9...f10d.0
- /data/data/####/9801ac38dbe98eb5eabcbf1018b67f0162af9c2491830ba....0.tmp
- /data/data/####/9a333d46cb6b9a1317eac769baa1dfb267bb17c1044bc5a...b6f3.0
- /data/data/####/9eb50bc4924533ef.xml
- /data/data/####/9eb50bc4924533ef.xml.bak
- /data/data/####/Alvin2.xml
- /data/data/####/AndroidManifest.xml
- /data/data/####/CERT.json
- /data/data/####/CURRENT
- /data/data/####/CacheMonitor.xml
- /data/data/####/CommonConfigAssist.xml
- /data/data/####/ContextData.xml
- /data/data/####/Cookies-journal
- /data/data/####/Databases.db-journal
- /data/data/####/LogStrategyConfig.xml
- /data/data/####/MANIFEST-000001
- /data/data/####/Manifest.xml
- /data/data/####/MegviiSDKPreference.xml
- /data/data/####/MegviiSDKPreference.xml.bak
- /data/data/####/MonitorPrivate_main.xml
- /data/data/####/QuotaManager-journal
- /data/data/####/SIGN.json
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/a7332d629bcab1f56b408a004e0a22ff
- /data/data/####/a82e399db629f7bf6d0b02f0a9585743e9e83a7ad488e57....0.tmp
- /data/data/####/a82e399db629f7bf6d0b02f0a9585743e9e83a7ad488e57...8bf5.0
- /data/data/####/ad7f49cd1d3e8ed3a74822c677cd4cb2d6c06af3b8a652a....0.tmp
- /data/data/####/ad7f49cd1d3e8ed3a74822c677cd4cb2d6c06af3b8a652a...9cb7.0
- /data/data/####/af4e6761d429b30dad84a80b08b0870a
- /data/data/####/af57fd518c9676698ef3396a1169873052aee589b141b9b...36d3.0
- /data/data/####/apm_local-journal
- /data/data/####/app_info.xml
- /data/data/####/b2ea0ad2f269b726d4cfe46818f82b3a
- /data/data/####/b30d23a396f60782fc51b88375a57d51
- /data/data/####/b36ce8d879e33bc88f717f74617ea05a
- /data/data/####/b500998b5ac44b31e5b640d683e5c16b0e364bf2045faed...9ae7.0
- /data/data/####/b8df20db4072c81a823bd659c5d9b3f7fe10d253007fd35....0.tmp
- /data/data/####/b919260928e2abbc_0
- /data/data/####/ba5a63c56784ac9be3b62f8a7ecd9dcfd02d53e39895e0c...b952.0
- /data/data/####/bb26139ef34570360bf0c502b5b64093ef19f744066b8a5....0.tmp
- /data/data/####/bb26139ef34570360bf0c502b5b64093ef19f744066b8a5...c086.0
- /data/data/####/bb7e618d292982a78a9994a412891ab01b16fc683b1f464...7235.0
- /data/data/####/bf606afbf50f78b1d7d336abf65bf3d9cd29893b5ead5f1...d7d9.0
- /data/data/####/c4fa977530365c643bccddb173db9107946ab13b5658fbf....0.tmp
- /data/data/####/c4fa977530365c643bccddb173db9107946ab13b5658fbf...124e.0
- /data/data/####/c6c4acd0a74a8e3e_0 (deleted)
- /data/data/####/c7474ec3f9453b5c_0
- /data/data/####/cd192d564e4216a643df06a66714aaeb727039164e0d231...be42.0
- /data/data/####/ceb9778588fdffdd8cf5ae2a3d5da96af246c0f0b04c4e1...ad41.0
- /data/data/####/cfcac81c68ab64fb8b582e94adae6a6f3441e7520056383...b249.0
- /data/data/####/classes.dex
- /data/data/####/classes.dve
- /data/data/####/classes.odex
- /data/data/####/classes.odex.flock (deleted)
- /data/data/####/com.cmcc.hebao-main.LoggingCache.xml
- /data/data/####/com.cmcc.hebao-main.LoggingCache.xml.bak
- /data/data/####/com.cmcc.hebao.config.xml
- /data/data/####/com.cmcc.hebao_preferences.xml
- /data/data/####/com.iflytek.id.xml
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDa...ml.bak
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDataAPI.xml
- /data/data/####/com_transp_sf.xml
- /data/data/####/com_transp_sf.xml.bak
- /data/data/####/core.jar
- /data/data/####/crash_dump.log
- /data/data/####/d34e958845d0fbf5072bcfefc6a32e454b99c59f545821a...dd29.0
- /data/data/####/d4bc848a27a184209740d4a862bb8c79b16a0dd6adccec3...f621.0
- /data/data/####/dac1da90845a6c7d77e2ef03e53d7e6c
- /data/data/####/daf6ad4e8b5c02dcab08c39d77e2395f80839549c6729f9...9033.0
- /data/data/####/dso_deps
- /data/data/####/dso_lock
- /data/data/####/dso_manifest
- /data/data/####/dso_state
- /data/data/####/e975d43558b08c699fb2d7fcbcb5b24448b3324108ff356...e15a.0
- /data/data/####/ed859ceccc2dfcdc4e213338bcd3c1e50ab62498d3bcc56...eeac.0
- /data/data/####/ef3cd9abf882efb19afd928c0bea7df8a6a4886d44ff5bf...7171.0
- /data/data/####/f372eca153152e52337b5d27ccd0ea0fdf3228028245907...24cb.0
- /data/data/####/f3b07a067de45d36e6ef7b0cbe1e1c2d
- /data/data/####/f498f963fa8ab2585824ad3d78a7b12525f7e3d31cf200f...4a56.0
- /data/data/####/f6ff4f9f9ce1c22511cff1b26b672f27
- /data/data/####/f96aacb3cb89a4d44bd2017279ef2d1bb874765f48467b0...ede9.0
- /data/data/####/fb307e26b1c507ac1b58acd6121df66bb883121f1ee838e...f7ca.0
- /data/data/####/fpathhash
- /data/data/####/home_image_cache.xml
- /data/data/####/https_p.10086.cn_0.localstorage-journal
- /data/data/####/index
- /data/data/####/journal
- /data/data/####/libAPMUOCPLIB.so
- /data/data/####/libAPSE_7.0.1.so
- /data/data/####/libAPSE_J.so
- /data/data/####/libAlipayBitmapNative.so
- /data/data/####/libDeepGuard.so
- /data/data/####/libDexHelper-x86.so
- /data/data/####/libDexHelper.so
- /data/data/####/libNative_cmft.so
- /data/data/####/libTransform.so
- /data/data/####/libWebViewCore_3.22.2.71.231122121339_7z_uc.so
- /data/data/####/libaliyunaf.so
- /data/data/####/libantssm.so
- /data/data/####/libap_bitmaps.so
- /data/data/####/libapm_bitmaps.so
- /data/data/####/libc++_shared.so
- /data/data/####/libcrashsdk.so
- /data/data/####/libcrypto.so
- /data/data/####/libcvenginelite.so
- /data/data/####/libdatabase_sqlcrypto.so
- /data/data/####/libdcblur.so
- /data/data/####/libdec7zmt-arm25977809.so
- /data/data/####/libdecode1002235b60ba.so
- /data/data/####/libdexvmp.so
- /data/data/####/libencrypt.so
- /data/data/####/libexbankcardrec.so
- /data/data/####/libexocrenginec.so
- /data/data/####/libfacedevice.so
- /data/data/####/libgifimage.so
- /data/data/####/libglide-webp.so
- /data/data/####/libiconv.so
- /data/data/####/libijiami_cmftlive.so
- /data/data/####/libijkeditor.so
- /data/data/####/libijkengine-gif.so
- /data/data/####/libijkffmpeg.so
- /data/data/####/libijkmmengine.so
- /data/data/####/libijkplayer.so
- /data/data/####/libijkrecorder.so
- /data/data/####/libijksdl.so
- /data/data/####/libijmdetect-drisk.so
- /data/data/####/libimage_processing_util_jni.so
- /data/data/####/libimagepipeline.so
- /data/data/####/libjsengine-api.so
- /data/data/####/libjsengine-loadso.so
- /data/data/####/libjsengine-platform.so
- /data/data/####/libjsi.so
- /data/data/####/liblivenessdetection_v2.4.8.so
- /data/data/####/libmmkv.so
- /data/data/####/libmpaas_crypto.so
- /data/data/####/libmpaascpu.so
- /data/data/####/libmsc.so
- /data/data/####/libnative-filters.so
- /data/data/####/libnative-imagetranscoder.so
- /data/data/####/libopenssl.so
- /data/data/####/libpaddle_light_api_shared.so
- /data/data/####/libpatcher.so
- /data/data/####/libpbo_jni.so
- /data/data/####/libpl_droidsonroids_gif.so
- /data/data/####/libpps-jni.so
- /data/data/####/libsecsdk.so
- /data/data/####/libsmfapi_jni.so
- /data/data/####/libsta.so
- /data/data/####/libstlport_shared.so
- /data/data/####/libtoyger.so
- /data/data/####/libucrash-core.so
- /data/data/####/libucrash.so
- /data/data/####/libucs-credential.so
- /data/data/####/libumeng-spy.so
- /data/data/####/libumonitor.so
- /data/data/####/libv8worker-native.so
- /data/data/####/libwebviewuc.so
- /data/data/####/libweexcore.so
- /data/data/####/libweexjsb.so
- /data/data/####/libweexjss.so
- /data/data/####/libweexjst.so
- /data/data/####/libxmcore.so
- /data/data/####/libzbar.so
- /data/data/####/libzkfv_tj.so
- /data/data/####/locale.xml
- /data/data/####/metrics_guid
- /data/data/####/mocam2.0_int6.db-journal
- /data/data/####/mocam_setting.xml
- /data/data/####/mpaas_crypto_plus.xml
- /data/data/####/mriver_app.db-journal
- /data/data/####/nw_conf_mng.db-journal
- /data/data/####/pref_ashmem_local_switcher.xml
- /data/data/####/proc_auxv
- /data/data/####/sdk_shell.dex
- /data/data/####/sdk_shell.dex.flock (deleted)
- /data/data/####/sdk_shell.jar
- /data/data/####/sensorsdata-journal
- /data/data/####/sensorsdata.exit.xml
- /data/data/####/sensorsdata.xml
- /data/data/####/sensorsdata.xml.bak
- /data/data/####/start_image_cache.xml
- /data/data/####/the-real-index
- /data/data/####/weex_default_settings.xml
- /data/media/####/.nomedia
- /data/media/####/1768618800000_com.cmcc.hebao-main_dev.2nd
- /data/media/####/1768621190208_com.cmcc.hebao-main_mPaaSClientAndroid
- /data/media/####/1768621200868_com.cmcc.hebao-main_mPaaSAliveAndroid
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/com.cmcc.hebao-main_APMultiMedia
- /data/media/####/com.cmcc.hebao-main_Push
- /data/media/####/com.cmcc.hebao-main_mPaaSAliveAndroid
- /data/media/####/com.cmcc.hebao-main_mPaaSAutomationAndroid
- /data/media/####/com.cmcc.hebao-main_mPaaSClientAndroid
- /data/media/####/com.cmcc.hebao-main_mPaaSPerformanceAndroid
- /data/media/####/iflyworkdir_test (deleted)
- /data/misc/####/primary.prof
- /data/user_de/####/aaid.xml
- /data/user_de/####/d
- /data/user_de/####/m
- /data/user_de/####/move_to_de_records.xml
- /data/user_de/####/p
- /data/user_de/####/push_client_self_info.xml
- /data/user_de/####/s
- /data/user_de/####/t
- <Package>:jse 38 40 1 /data/user/0/<Package>/app_crash/crash_dump.log
- cat /proc/4124/maps |grep "inf.red.virtual"
- cat /proc/4124/maps |grep frida
- cat /proc/4124/mountinfo | grep "/data/data/"
- cat /proc/4124/mountinfo |grep lsposed
- cat /proc/self/cgroup
- getprop ro.product.cpu.abilist
- grep /data/data/
- grep frida
- grep inf.red.virtual
- grep lsposed
- ps
- ps |grep frida
- sh
- sh -c ls /data/data |grep lsposed
- su -c ls /data/data |grep lsposed
- which su
- libAPMUOCPLIB
- libAlipayBitmapNative
- libDexHelper-x86
- libc++_shared
- libdatabase_sqlcrypto
- libdec7zmt-arm25977809
- libijiami_cmftlive
- libijmdetect-drisk
- liblivenessdetection_v2.4.8
- libmmkv
- libmpaascpu
- libmsc
- libpl_droidsonroids_gif
- libsecsdk
- libweexcore
- AES
- AES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- SM4-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding
- SM4-CBC-PKCS5Padding