Technical information
- Android.Triada.531.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) zxcon####.zhaoxi####.com:80
- TCP(HTTP/1.1) beacon####.aliy####.com:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) norma-e####.m####.com:80
- TCP(HTTP/1.1) f.gm.m####.com:80
- TCP(HTTP/1.1) sdk.xinxi####.com:8100
- TCP(HTTP/1.1) gs.g####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) cdn.st####.17k.com:80
- TCP(HTTP/1.1) l.gm.m####.com:80
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(HTTP/1.1) b####.g####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(TLS/1.0) dig.b####.net:443
- TCP(TLS/1.0) zxbook####.zhaoxi####.com:443
- TCP(TLS/1.0) dm.ps####.com:443
- TCP(TLS/1.0) ada####.m.ta####.com:443
- TCP(TLS/1.0) al####.u####.com:443
- TCP(TLS/1.0) sf3-ttc####.ps####.com:443
- TCP(TLS/1.0) 1####.217.17.74:443
- TCP(TLS/1.0) media####.oss-cn-####.aliy####.com:443
- TCP(TLS/1.0) bookc####.yu####.com.####.com:443
- TCP(TLS/1.0) sh.wagbr####.aliyun####.com:443
- TCP(TLS/1.0) c####.zhaoxi####.com:443
- TCP(TLS/1.0) sf3-fe####.pglstat####.com:443
- TCP(TLS/1.0) api16-a####.pa####.io.####.net:443
- TCP(TLS/1.0) gs.g####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) ad1.azh####.com:9190
- TCP(TLS/1.0) dm.tou####.com:443
- TCP(TLS/1.0) azh####.com:9061
- TCP(TLS/1.2) 1####.217.168.206:443
- TCP(TLS/1.2) 1####.217.17.74:443
- TCP(TLS/1.2) 1####.217.20.74:443
- TCP(TLS/1.2) 1####.217.19.195:443
- TCP cm-1####.g####.com:5227
- TCP sdk.o####.t####.####.com:5224
- a####.man.aliy####.com
- ad1.azh####.com
- ad3.azh####.com
- ada####.ut.ta####.com
- api.s####.mob.com
- api16-a####.pa####.io
- azh####.com
- b####.g####.com
- beacon####.aliy####.com
- bookc####.yu####.com
- c####.g####.com
- c####.g####.com
- c####.zhaoxi####.com
- c-h####.g####.com
- cdn-sdk####.g####.com
- cdn.st####.17k.com
- cm-1####.g####.com
- cow.zhaoxi####.com
- dig.b####.net
- dm.byted####.com
- dm.ps####.com
- dm.tou####.com
- f####.zhaoxi####.com
- f.gm.m####.com
- gs.g####.com
- l.gm.m####.com
- media####.oss-cn-####.aliy####.com
- norma-e####.m####.com
- p####.google####.com
- pang####.sn####.com
- sdk-ope####.g####.com
- sdk.c####.g####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sdk.xinxi####.com
- sf3-fe####.pglstat####.com
- sf3-ttc####.ps####.com
- to####.ctobsn####.com
- u####.u####.com
- zxbook####.zhaoxi####.com
- zxcon####.zhaoxi####.com
- cdn-sdk####.g####.com.####.com/tdata_EDB102
- cdn-sdk####.g####.com.####.com/tdata_lQn698
- cdn-sdk####.g####.com.####.com/tdata_sWb803
- cdn-sdk####.g####.com.####.com/tdata_sqy483
- cdn-sdk####.g####.com.####.com/tdata_tHk848
- cdn.st####.17k.com//cp/book/600x800/439157.jpg
- d####.c####.l####.####.com/config/hzv9.conf
- f.gm.m####.com/privacy/policy/ms/version?appkey=####&apppkg=####&appver=...
- l.gm.m####.com/privacy/policy/authorization/status?appkey=####&apppkg=##...
- norma-e####.m####.com/android/exchange/getpublickey.do
- sdk.o####.p####.####.com/api/addr.htm
- zxcon####.zhaoxi####.com/image/book/196/837828/ce616ae84caf711e0f4e4b8aa...
- zxcon####.zhaoxi####.com/image/book/485/750053/2e6999fe18ca3eb0f0c9f699a...
- zxcon####.zhaoxi####.com/image/book/49/826417/6e719c939e251c649146c716c1...
- zxcon####.zhaoxi####.com/image/book/569/763449/455abb0f8e08894fbfeacf59b...
- zxcon####.zhaoxi####.com/image/book/708/813764/cd0181ddc084531328a2b6b2c...
- zxcon####.zhaoxi####.com/image/book/904/797576/fea42b1d05d6c51bc688c180e...
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/snsconf
- b####.g####.com/api.php?format=####&t=####
- beacon####.aliy####.com/beacon/fetch/config/byappkey
- c####.g####.com/api.php?format=####&t=####
- gs.g####.com/geshu/sdk/getBaseConfs
- gs.g####.com/geshu/sdkStatistics/bd
- gs.g####.com/geshu/sdkStatistics/ubi
- norma-e####.m####.com/push/android/external/add.do
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- sdk.xinxi####.com:8100/api/getAppVersion
- sdk.xinxi####.com:8100/api/sdk/init2
- /data/data/####/.artc_lock
- /data/data/####/.at_lock
- /data/data/####/.dic_lock
- /data/data/####/.du_lock
- /data/data/####/.duid
- /data/data/####/.dvcv_lock
- /data/data/####/.globalLock
- /data/data/####/.im_lock
- /data/data/####/.imprint
- /data/data/####/.lesd_lock
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrecord (deleted)
- /data/data/####/.mrlock
- /data/data/####/.pkg_lock
- /data/data/####/.pkgs_lock
- /data/data/####/.slw
- /data/data/####/.statistics
- /data/data/####/.vpl_lock
- /data/data/####/000392aecf36118418a483c2e29ba933c79ef6ecfc67291....0.tmp
- /data/data/####/002e093c57a98a235c147772c2813376e44f02a2d4b2c89....0.tmp
- /data/data/####/07f5159ac695d905cae74009f5d301db9b066677387dfee....0.tmp
- /data/data/####/09d926e1490cd05b8b70f9eb259a3d51c29705c002feb32....0.tmp
- /data/data/####/12083322c1dd1d917c43f73ce6052c6f.0.tmp
- /data/data/####/12083322c1dd1d917c43f73ce6052c6f.1
- /data/data/####/144f99b8a8953355166ef5db8c0d5ab3e76423e17201a72....0.tmp
- /data/data/####/178b77e09cc3
- /data/data/####/17c851a5c7183b7ac0149709980d0764.0.tmp
- /data/data/####/17c851a5c7183b7ac0149709980d0764.1
- /data/data/####/19b6abd855e7b036f0ec382180bb39cca91b3766fae5d42...875a.0
- /data/data/####/1b7b1c2dbee99ba0b65a2354273ca2a9c64fb317e67be5a....0.tmp
- /data/data/####/1d2d9aa62ae18ef8ac4cc4d6652b097b42034546225a7f4...8a95.0
- /data/data/####/24de4355e1bcb2a9de5f5f2ee20e03081f5a18dea78341a....0.tmp
- /data/data/####/2bd2b2d66963f08fb28d954dff6cbdd5.0
- /data/data/####/2bd2b2d66963f08fb28d954dff6cbdd5.1
- /data/data/####/2ce6f4c5fb14f131bc0ab73147543d0e.0
- /data/data/####/2ce6f4c5fb14f131bc0ab73147543d0e.1
- /data/data/####/3091463084c31a98d2d87eea0ae6c294417156d745d94d1....0.tmp
- /data/data/####/42bb07944afcacd0447366224332a6ce37011c405fef87c....0.tmp
- /data/data/####/43fa6267513f65fffe629fd9642a83a3.0.tmp
- /data/data/####/43fa6267513f65fffe629fd9642a83a3.1
- /data/data/####/4ed2c426
- /data/data/####/52726f5171595a4dd304f900e5910b2e.0
- /data/data/####/52726f5171595a4dd304f900e5910b2e.1
- /data/data/####/5bae02b7b21afabb10aa848a52d9b8ec.0.tmp
- /data/data/####/5bae02b7b21afabb10aa848a52d9b8ec.1
- /data/data/####/6026bc51c9c4ab458fc0d55e9dceed381755390366e860b....0.tmp
- /data/data/####/6878d21b8a899d0feff807333ca4b805595dec491abb4aa....0.tmp
- /data/data/####/6ff32456c264cf8eefe861e83a125475a6fbaf98cd23061...11ce.0
- /data/data/####/70d524d5
- /data/data/####/718b80f0db960b3e590c4806587fddaeaf49b8c47ffed93....0.tmp
- /data/data/####/7b652fa8b2d85fb03bd8ef1979f3aef65a10c340d52e6e3....0.tmp
- /data/data/####/7dc6dc69e71ff395c7c7067e4246168ec0a7a05b1259496....0.tmp
- /data/data/####/7f5e7d13bdd3c3911c0e7731f738d254.0
- /data/data/####/7f5e7d13bdd3c3911c0e7731f738d254.1
- /data/data/####/8097cddaa620974ccfe55d69dbc83e84.0.tmp
- /data/data/####/8097cddaa620974ccfe55d69dbc83e84.1
- /data/data/####/89fe1e1108573fbb33f5c99c059d0f46.0
- /data/data/####/89fe1e1108573fbb33f5c99c059d0f46.1
- /data/data/####/8d7733426e092ba8ed0f6aec237cdcf7bec1da4e1dc8883....0.tmp
- /data/data/####/8ef38661006ec5bd93a2571bb16a423f47a1b618329f041....0.tmp
- /data/data/####/8ff5449f79caeccc7bac9bbef8b09c7e8556ce20a089fbe....0.tmp
- /data/data/####/9042a5196e5f6ee31fe9048e442f1774764f776a6601f8f....0.tmp
- /data/data/####/98e9b75bf35143ca8f9955418eba78613f4280c13725ec1....0.tmp
- /data/data/####/9cabb436a49b59717f7bd9f492c22671e0dbedf3d7aa26c....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MOBGUARD_100
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UTCommon.xml
- /data/data/####/UTCommon.xml.bak
- /data/data/####/a11b7efafe0754cd76c9f5029fa1cc7b.0.tmp
- /data/data/####/a11b7efafe0754cd76c9f5029fa1cc7b.1.tmp
- /data/data/####/a==7.5.3&&6.0.615_1600118271857_envelope.log
- /data/data/####/ad_config.xml
- /data/data/####/ad_loader_config.xml
- /data/data/####/ad_show_time.xml
- /data/data/####/adashbc.ut.taobao.com.443
- /data/data/####/ap.Lock
- /data/data/####/app_channel.xml
- /data/data/####/b18e2141de3ef46b8866c57c2231572a.0.tmp
- /data/data/####/b18e2141de3ef46b8866c57c2231572a.1.tmp
- /data/data/####/b23bbbf5a20a2a069eb9e9c8b602c07b.0.tmp
- /data/data/####/b23bbbf5a20a2a069eb9e9c8b602c07b.1
- /data/data/####/b3c484a8edb8fa31375d6cf4708f333c9f761d0d444ae29....0.tmp
- /data/data/####/bd_embed_tea_agent.db-journal
- /data/data/####/birdopenadsdk.xml
- /data/data/####/birdopenadsdk.xml.bak
- /data/data/####/c1c95b91c8ad69c68965a733c65d0067.0
- /data/data/####/c1c95b91c8ad69c68965a733c65d0067.0.tmp
- /data/data/####/c1c95b91c8ad69c68965a733c65d0067.1.tmp
- /data/data/####/c4d6dd7f52ca2fb97b94cbe7c4f8a593ba212d9cac7bd40....0.tmp
- /data/data/####/c563fe34f925b3d90e1752c4b16f6e816c3c809a5e72fd3...014a.0
- /data/data/####/c626e37009cf1dc866f8d55f0deff965.0.tmp
- /data/data/####/c626e37009cf1dc866f8d55f0deff965.1.tmp
- /data/data/####/chapter_end_reward_video_config.xml
- /data/data/####/cmshljo_x.xml
- /data/data/####/com.x.y.1.xml
- /data/data/####/com.x.y.2.xml
- /data/data/####/com.zhaoxitech.cbook.xml
- /data/data/####/com.zhaoxitech.cbook_sdk_opt.xml
- /data/data/####/com_alibaba_aliyun_crash_defend_sdk_info
- /data/data/####/config.xml
- /data/data/####/cta.xml
- /data/data/####/d26c344c
- /data/data/####/d28b4aba9b915d6c4d2e728d8149800d.0
- /data/data/####/d28b4aba9b915d6c4d2e728d8149800d.1
- /data/data/####/devyok.DATA_PROVIDER.xml
- /data/data/####/df8ff6a433224d1514c7d3755bf08215f53f46c9711902a...666b.0
- /data/data/####/dfb4427532ed3602de172bbc54e846de.0
- /data/data/####/dfb4427532ed3602de172bbc54e846de.1
- /data/data/####/downloader.db-journal
- /data/data/####/e527783732853271b519fec1f0b3448088b94b43b89d072....0.tmp
- /data/data/####/e584647c4e5af581291a7e99e0347528a923e72de539131....0.tmp
- /data/data/####/e8a32175aa3270b10afb7075c239e912d202cb9796c8ab1....0.tmp
- /data/data/####/embed_applog_stats.xml
- /data/data/####/embed_header_custom.xml
- /data/data/####/embed_last_sp_session.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f770adae8d8b1bcfe0574fe8b74abf9b3976bb44f4cb43e...d31a.0
- /data/data/####/fe816b8abc51e0ba91fa8affb1fa681718da1089fb76150....0.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gtc.db-journal
- /data/data/####/gx_sp.xml
- /data/data/####/hfnbirddownloader.db-journal
- /data/data/####/ias.db-journal
- /data/data/####/ias_sp.xml
- /data/data/####/ias_sp.xml.bak
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/init_code_id_12039_1660476884
- /data/data/####/journal.tmp
- /data/data/####/lotus.dex
- /data/data/####/lotus.dex.flock (deleted)
- /data/data/####/lotus.jar
- /data/data/####/mob_commons_1
- /data/data/####/mz_push_preference.xml
- /data/data/####/npth.xml
- /data/data/####/npth_log.db-journal
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/push_info.xml
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/share_sdk_1
- /data/data/####/sharesdk.db-journal
- /data/data/####/snssdk_openudid.xml
- /data/data/####/sp_push_time.xml
- /data/data/####/tdata_lQn698
- /data/data/####/tdata_lQn698.dex.flock (deleted)
- /data/data/####/tdata_lQn698.jar
- /data/data/####/tdata_sWb803
- /data/data/####/tdata_sWb803.dex.flock (deleted)
- /data/data/####/tdata_sWb803.jar
- /data/data/####/tdata_sqy483
- /data/data/####/tdata_sqy483.dex.flock (deleted)
- /data/data/####/tdata_sqy483.jar
- /data/data/####/tdata_tHk848
- /data/data/####/tdata_tHk848.dex
- /data/data/####/tdata_tHk848.dex.flock (deleted)
- /data/data/####/tdata_tHk848.jar
- /data/data/####/tt_dns_settings.xml
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/tt_sdk_settings.xml.bak
- /data/data/####/tt_sp_app_list.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_config.xml.bak
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/zxbook.db-journal (deleted)
- /data/data/####/zxbook.xml
- /data/data/####/zxbook.xml.bak
- /data/media/####/.di
- /data/media/####/.mn_1666188972
- /data/media/####/2020-09-15.log.txt
- /data/media/####/20200915.txt
- /data/media/####/44963dfebec8dd4bb6eefe8f0ed555c3.tmp
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/a099306b296b6ea0a961f7e95a395fa9.tmp
- /data/media/####/clientudid.dat
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.zhaoxitech.cbook.bin
- /data/media/####/com.zhaoxitech.cbook.db
- /data/media/####/com.zhaoxitech.cbook_.db
- /data/media/####/config.txt
- /data/media/####/gkt
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/plcfg.xml
- /data/media/####/plcfg.xml.bak
- /data/media/####/temp_pkg_info.json
- /data/media/####/test.log
- /data/media/####/zdid1
- /data/media/####/zx_did1
- /data/misc/####/primary.prof
- /system/bin/cat /proc/cpuinfo
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/jar/lotus.jar --oat-fd=177 --oat-location=/data/user/0/<Package>/files/jar/lotus.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_lQn698.jar --oat-fd=51 --oat-location=/data/user/0/<Package>/files/tdata_lQn698.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_sWb803.jar --oat-fd=66 --oat-location=/data/user/0/<Package>/files/tdata_sWb803.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_sqy483.jar --oat-fd=65 --oat-location=/data/user/0/<Package>/files/tdata_sqy483.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_tHk848.jar --oat-fd=65 --oat-location=/data/user/0/<Package>/files/tdata_tHk848.dex --compiler-filter=speed
- cat /proc/uid_stat/10065/tcp_rcv
- cat /proc/uid_stat/10065/tcp_snd
- cat /sys/class/net/wlan0/address
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.sv.version
- getprop ro.lenovo.lvp.version
- getprop ro.letv.release.version
- getprop ro.miui.ui.version.code
- getprop ro.miui.ui.version.name
- getprop ro.smartisan.version
- getprop ro.vivo.os.build.display.id
- getprop ro.vivo.os.version
- mount
- sh
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- Des-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- Des-ECB-NoPadding