Technical information
- Adware.YtAd.1.origin
- Android.SkyMobi.6.origin
- Android.Triada.155.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) and####.5####.com:8077
- TCP(HTTP/1.1) api.var####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) img.ace####.com:80
- a####.u####.com
- and####.5####.com
- api.var####.com
- col####.1u####.com
- dl.eleve####.net
- img.ace####.com
- mo####.1u####.com
- pa####.1u####.com
- img.ace####.com/ando-res/m/hQFsvuTOjQG2grLU8T2VCshw4jkuJadBny-GDQ
- img.ace####.com/ando-res/m/s3KOUSTUNwqwJOgW89Tsl-Qlaroq07gDVNfYRzW-w*Av*...
- a####.u####.com/app_logs
- and####.5####.com:8077/android/sms/netpay/prefetch.do
- api.var####.com/ando/x/lis?app_id=####&r=####
- api.var####.com/ando/x/liv?app_id=a6290d72-6171-40db-867d-9e21cd358691&r...
- /data/data/####/.imprint
- /data/data/####/100300062711-181209
- /data/data/####/1544366491936.apk
- /data/data/####/1544366492129.apk
- /data/data/####/1544366492299.apk
- /data/data/####/1544366492443.apk
- /data/data/####/3fXTl3cSRIRUu21p.dex
- /data/data/####/3fXTl3cSRIRUu21p.zip
- /data/data/####/8K2r86cGS2Zbkcrgcxb9M6Dm1BA=.temp
- /data/data/####/8RAi7uHf_TfP4ij9zMjdcRUDleYHx9tK5V1C_g==.new
- /data/data/####/9bOif9wkIkoFRoHFdTAgGQ6zbH-kt13T.new
- /data/data/####/ACCOUNT_SYSTEM_ACCOUNT_INFO.xml
- /data/data/####/BOOT_SMS_INFO.xml
- /data/data/####/BOOT_SMS_SENT_TIME.xml
- /data/data/####/Cocos2dxPrefsFile.xml
- /data/data/####/D8mjkGx0Ee0ABl1CPi14svKacM-C3a1b3UeT6w==_FCjORc...ournal
- /data/data/####/D8mjkGx0Ee0ABl1CPi14svKacM-C3a1b3UeT6w==_QrYV62...ournal
- /data/data/####/D8mjkGx0Ee0ABl1CPi14svKacM-C3a1b3UeT6w==_b4F0f2...ournal
- /data/data/####/D8mjkGx0Ee0ABl1CPi14svKacM-C3a1b3UeT6w==_r9Mu6G...ournal
- /data/data/####/Data_sync.db-journal
- /data/data/####/DownloadBillingList_100300062711_00001264_00000...nanaly
- /data/data/####/E0cbofVeeWYJU6jcLrDDWHfohMjc0std.new
- /data/data/####/Faqf76S1pEBbiRC2C8eBwqsdGqc=.new
- /data/data/####/GOemZR1EoxP8cAVr
- /data/data/####/L8GAmueEkuYYxG7uMfYodHVCJRqwZyKr.new
- /data/data/####/MC7sgFUB_Bh2sfEPguJtdVg6VpQ=
- /data/data/####/MrATMVoIm1lPTZPPoCqKAf7ffg4=.new
- /data/data/####/NlZh3AG1yp5rB5lUWN0xj-IPEAbtmMVep_4a0Q==
- /data/data/####/Ob7o2qaVhZl_l4Ny9ub-5w==
- /data/data/####/PFW5teLMNk01TZze6a0bcw==
- /data/data/####/PFW5teLMNk01TZze6a0bcw==.new
- /data/data/####/Q633h60aGmn3q5l9.new
- /data/data/####/S1wRrtvpRmZxZC_sW2PGFA==.new
- /data/data/####/XfbROtMuuLFk6rNop7fP6nDrT-IaLCrK.new
- /data/data/####/apk.dex (deleted)
- /data/data/####/apk.zip
- /data/data/####/base-1.apk
- /data/data/####/base-1.dex
- /data/data/####/bc4InMS3TKyKX2wyGV2rphU4Kh_KMt7UEu_MSxaEsz0=.new
- /data/data/####/classes.dex
- /data/data/####/com.souying.pay.plugmain_sy_pay_record
- /data/data/####/com.souying.pay.plugmain_sy_pay_record-journal
- /data/data/####/com.souying.pay.xml
- /data/data/####/data.dat.tmp
- /data/data/####/defrayPriority100300062711250026699187743.dat
- /data/data/####/eOUnVJ5PPTUb05g2HmwORQ==.new
- /data/data/####/exchangeIdentity.json
- /data/data/####/ibnmVIEXM0Beg7f1gnALN05EA7yu6ynZIFM4_QnWQwk=.new
- /data/data/####/ifYKzzQRSMgCJH03Jdkl5f5rhC0=.new
- /data/data/####/iyoupay.so
- /data/data/####/iyoupay_data.dex
- /data/data/####/iyouypay.xml
- /data/data/####/iyouypay.xml.bak
- /data/data/####/iyouypay.xml.bak (deleted)
- /data/data/####/kNfb-mqf76HYcbk0
- /data/data/####/l2Ebt218xBieFaD7HWPXf7jSFXpEe3-uRilx0A==.new
- /data/data/####/libexec.so
- /data/data/####/libexecmain.so
- /data/data/####/ljQMPZUABse927-7AxE7tMCDRfrDlLGpkV6UzA==.new
- /data/data/####/mobclick_agent_cached_com.bsfzkz.zspbpb2892
- /data/data/####/o4CiD_qYCSHehKZetd0dYAT0HtwhU56T.new
- /data/data/####/plugins.installed.xml
- /data/data/####/plugins.serviceMapping.xml
- /data/data/####/rdata
- /data/data/####/rdata.new
- /data/data/####/recordInfo
- /data/data/####/recordInfo-journal
- /data/data/####/res-20160928-218-NewServer-NoHY.bin
- /data/data/####/runner_info.prop.new
- /data/data/####/sm.apk
- /data/data/####/smaip.apk
- /data/data/####/smt.apk
- /data/data/####/sn.apk
- /data/data/####/sy_pay_config.xml
- /data/data/####/sy_pay_record
- /data/data/####/sy_pay_record-journal
- /data/data/####/tQQh5DHLxGSBOrhVECJDFPyD1BFcA_26.new
- /data/data/####/tffaq_f.dex
- /data/data/####/tffaq_f.zip
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak (deleted)
- /data/data/####/umeng_it.cache
- /data/data/####/uuPi7PebPASdxTvB6Z93Gg==.new
- /data/data/####/vS7FSTs4YVfMz2dv-WiY6Ex8u4FwiDKr.new
- /data/data/####/wqpzyIyz_T-98QinUY7ha_ve9mYJtDdK.new
- /data/data/####/zJUNH7Cwlkj0lNAYD6VgmjuKfVU=.new
- /data/media/####/.nomedia
- /data/media/####/.uunique.new
- /data/media/####/5NCMj4FHDAiNMsrjQKob6JdxZXM=.new
- /data/media/####/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M
- /data/media/####/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M.lk
- /data/media/####/IYouPay_error_log20181209_14-41-47.log
- /data/media/####/IYouPay_error_log20181209_14-41-51.log
- /data/media/####/IYouPay_error_log20181209_14-42-01.log
- /data/media/####/IYouPay_error_log20181209_14-42-05.log
- /data/media/####/IYouPay_error_log20181209_14-42-17.log
- /data/media/####/IYouPay_error_log20181209_14-42-23.log
- /data/media/####/MP8MtaBuguN9jnuSwtN1kQ==
- /data/media/####/com.skymobi.pay.plugin.main.data
- /data/media/####/com.skymobi.pay.plugin.recordupload.data
- /data/media/####/com.skymobi.pay.plugin.smspay.data
- /data/media/####/crash-1544366493773.log
- /data/media/####/crash-1544366499195.log
- /data/media/####/crash-1544366515975.log
- /data/media/####/crash-1544366530470.log
- /data/media/####/crash-1544366547058.log
- /data/media/####/iyoupay_data.jar
- /data/media/####/r_pkDgN4OhnkSa0D
- /data/media/####/user.sys
- <Package Folder>/code-6758314/GOemZR1EoxP8cAVr <Package> com.asfaka.aspapa.vfraaa.a.a.c.b /storage/emulated/0/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M /storage/emulated/0/Download/ladung
- cat /proc/version
- chmod 666 /storage/emulated/0/Android/data/com.skymobi.pay.newsdk/plugins/com.skymobi.pay.plugin.main.data
- chmod 666 /storage/emulated/0/Android/data/com.skymobi.pay.newsdk/plugins/com.skymobi.pay.plugin.recordupload.data
- chmod 666 /storage/emulated/0/Android/data/com.skymobi.pay.newsdk/plugins/com.skymobi.pay.plugin.smspay.data
- getprop ro.product.cpu.abi
- sh <Package Folder>/code-6758314/GOemZR1EoxP8cAVr <Package> com.asfaka.aspapa.vfraaa.a.a.c.b /storage/emulated/0/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M /storage/emulated/0/Download/ladung
- cocos2dcpp
- iyoupay
- libexec
- libexecmain
- zimon
- DES-CBC-PKCS5Padding