Technical information
- Adware.Kyview.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c####.baidust####.com:80
- TCP(HTTP/1.1) mo####.b####.com:80
- TCP(HTTP/1.1) ub####.baidust####.com:80
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(HTTP/1.1) wap.n.sh####.com:80
- TCP(HTTP/1.1) mobads-####.b####.com:80
- TCP(TLS/1.0) 1####.217.17.110:443
- TCP(TLS/1.0) mobads-####.b####.com:443
- TCP(TLS/1.0) c####.baidust####.com:443
- TCP(TLS/1.0) ext.b####.com:443
- TCP(TLS/1.0) c####.b####.com:443
- TCP(TLS/1.0) ch####.jom####.com:443
- TCP(TLS/1.0) co####.ad####.cn:443
- TCP(TLS/1.0) ss0.b####.com:443
- TCP(TLS/1.0) www.a.sh####.com:443
- TCP(TLS/1.0) box.jom####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) ss0.bdst####.com:443
- TCP(TLS/1.0) g####.bdst####.com:443
- TCP(TLS/1.0) wap.n.sh####.com:443
- TCP(TLS/1.0) cambria####.cdn.bc####.####.com:443
- and####.b####.qq.com
- c####.b####.com
- c####.b####.com
- c####.baidust####.com
- c####.baidust####.com
- cambria####.cdn.bc####.com
- co####.ad####.cn
- d.alpha-b####.com
- ext.b####.com
- g####.bdst####.com
- h####.b####.com
- hm.b####.com
- m.b####.com
- mo####.b####.com
- mobads-####.b####.com
- s.bdst####.com
- sp0.b####.com
- sp1.b####.com
- ss0.b####.com
- ss0.bdst####.com
- ss1.b####.com
- ss2.b####.com
- ss2.bdst####.com
- t7.b####.com
- ub####.baidust####.com
- wn.pos.b####.com
- c####.baidust####.com/cpro/exp/mob_exp/img/app_lu/slow_change.jpg
- c####.baidust####.com/cpro/expire/time2.js
- c####.baidust####.com/cpro/ui/noexpire/img/2.0.1/bd-logo4.png
- c####.baidust####.com/cpro/ui/noexpire/img/2.0.3/rs_img/image_sdk_1_dl.jpg
- c####.baidust####.com/cpro/ui/noexpire/ws/3rd/esl_b150bbf.js
- c####.baidust####.com/cpro/ui/noexpire/ws/3rd/jquery_d7db60e.js
- c####.baidust####.com/cpro/ui/noexpire/ws/3rd/lightslider_a994ffa.js
- c####.baidust####.com/cpro/ui/noexpire/ws/css/base_f258e90.css
- c####.baidust####.com/cpro/ui/noexpire/ws/css/lightslider_7f43969.css
- c####.baidust####.com/cpro/ui/noexpire/ws/css/ui_b99a586.css
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/logo-mob_94da672.png
- c####.baidust####.com/cpro/ui/noexpire/ws/js/anticheatMob_776abb3.js
- c####.baidust####.com/cpro/ui/noexpire/ws/js/util_f199241.js
- c####.baidust####.com/cpro/ui/noexpire/ws/widget/logo_94e2e1b.js
- c####.baidust####.com/sync.htm?cproid=####
- mo####.b####.com/ads/ads.appcache
- mo####.b####.com/ads/css/min/main.css
- mo####.b####.com/ads/index.htm
- mo####.b####.com/ads/js/ads.trunk.js
- mo####.b####.com/ads/js/c.js
- mo####.b####.com/ads/pa/__pasys.apk
- mo####.b####.com/ads/pa/__pasys.php
- mo####.b####.com/ads/pa/__pasys_remote_banner.jar
- mo####.b####.com/ads/pa/__pasys_remote_banner.php?v=####&tp=####&os=####...
- mo####.b####.com/cpro/ui/mads.php?code2=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323529702=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323529708=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323531066=####
- mobads-####.b####.com/dz.zb?type=37&adid=1&appsec=bee754f2_cpr&appsid=be...
- mobads-####.b####.com/dz.zb?type=38&adid=1&appsec=bee754f2_cpr&appsid=be...
- ub####.baidust####.com/media/v1/0f0000AfSpv-QgtmPolkH0.jpg
- ub####.baidust####.com/media/v1/0f0000npW7nekexyd7u1Ys.jpg
- ub####.baidust####.com/media/v1/0f00050rJsXR6ohV7K6aA0.jpg
- ub####.baidust####.com/media/v1/0f00070-9-ReavrHBWyh46.jpg
- ub####.baidust####.com/media/v1/0f000K6o71patKmJg1h3T0.jpg
- ub####.baidust####.com/media/v1/0f000KX0A_kSRO1EL64Fqs.jpg
- ub####.baidust####.com/media/v1/0f000Qk_Ry30LiewV_Natf.jpg
- ub####.baidust####.com/media/v1/0f000QtH4y9CBlwbTOCDDf.jpg
- ub####.baidust####.com/media/v1/0f000ZozOewU711o9XSPc0.jpg
- ub####.baidust####.com/media/v1/0f000cSWjTpsbpj3XMKgO6.jpg
- ub####.baidust####.com/media/v1/0f000nTw6mX7aaKXpq-Ces.jpg
- wap.n.sh####.com/mobads.php?060000a####
- wn.pos.b####.com/adx.php?c=####
- wn.pos.b####.com/adx.php?c=####&ext=####
- and####.b####.qq.com/rqd/async
- h####.b####.com/app.gif
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/CachedGeoposition.db
- /data/data/####/CachedGeoposition.db-journal
- /data/data/####/GeolocationPermissions.db-journal
- /data/data/####/WebViewSettings.xml
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__pasys.apk.beforesign.tm
- /data/data/####/__pasys_remote_banner.jar.beforesign.tm
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/__sdk_m_0f00070-9-ReavrHBWyh46.jpg.tm
- /data/data/####/__sdk_pasys_pkgs.xml
- /data/data/####/__sdk_pasys_pkgurls.xml
- /data/data/####/bugly_db_lejiagu-journal
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/index
- /data/data/####/legu_900015015.xml
- /data/data/####/legudzbait.zip
- /data/data/####/libshella-2.3.0.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/native_record_lock
- /data/data/####/reqinfo.db
- /data/data/####/reqinfo.db-journal
- /data/data/####/security_info
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libshella-2.3.0.so
- getprop ro.board.platform
- getprop ro.yunos.version
- Bugly
- libshella-2.3.0
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- AES
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding