Technical information
- Adware.Dowgin.3.origin
- Android.DownLoader.192.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) an.ca.15####.cn:80
- TCP(HTTP/1.1) dn.dd.15####.####.net:80
- a.y####.club
- an.ca.15####.cn
- b.y####.club
- dn.dd.15####.cn
- s1.h####.pub
- s2.h####.pub
- dn.dd.15####.####.net/apk/20171207/201712071116111.png
- dn.dd.15####.####.net/apk/20180606/201806061136852.png
- dn.dd.15####.####.net/apk/20180702/20180702174395.apk
- an.ca.15####.cn//2b31d684/zia
- an.ca.15####.cn//2b31d684/zib
- an.ca.15####.cn//2b31d684/zic
- an.ca.15####.cn//2b31d684/zid
- an.ca.15####.cn//2b31d684f3/zba
- /data/data/####/Download-journal
- /data/data/####/Downloado
- /data/data/####/Downloado-journal
- /data/data/####/Log-journal
- /data/data/####/Logo
- /data/data/####/Logo-journal
- /data/data/####/_acodeskboolz.xml
- /data/data/####/_cocodeskboolr.xml
- /data/data/####/_cocodeskboolr.xml.bak
- /data/data/####/_dcodeskbooly.xml
- /data/data/####/_gcodeskbools.xml
- /data/data/####/config.xml
- /data/data/####/configo.xml
- /data/data/####/deskbooloc.jar
- /data/data/####/deskboolq.jar
- /data/data/####/uscom.db-journal
- /data/data/####/webview.db-journal
- /data/media/####/.android.dat
- /data/media/####/.android.dat-journal
- /data/media/####/201712071116111#png
- /data/media/####/201806061136852#png
- /data/media/####/com.fire.pare.jkoz.a.dex
- /data/media/####/com.fire.pare.jkoz.a.dex (deleted)
- /data/media/####/com.fire.pare.jkpz.a.dex
- /data/media/####/com.fire.pare.jkpz.a.dex (deleted)
- /data/media/####/egnaro_etceles_egap_d
- /data/media/####/egnaro_gbntb_d
- /data/media/####/ehcac_ntb_mottob
- /data/media/####/elcric_cs_d
- /data/media/####/enil_efas
- /data/media/####/enil_efas_d
- /data/media/####/enil_jt_d
- /data/media/####/erahs_ntb_mottob
- /data/media/####/eulb_gbntb_d
- /data/media/####/gb_datuctrohs_d
- /data/media/####/gb_gmi
- /data/media/####/gb_gmi_d
- /data/media/####/gb_mottob
- /data/media/####/gb_pot
- /data/media/####/gb_pot_d
- /data/media/####/gb_sdrowda
- /data/media/####/gb_tluafed_d
- /data/media/####/id
- /data/media/####/kcab_pop
- /data/media/####/kcab_pop_d
- /data/media/####/lecnac_ntb_mottob_d
- /data/media/####/llatsni_ntb
- /data/media/####/llatsni_ntb_d
- /data/media/####/llatsni_ntb_mottob
- /data/media/####/logo.png
- /data/media/####/lomron_egap_d
- /data/media/####/n_kcehcp
- /data/media/####/na_csppa_d
- /data/media/####/neerg_gbntb_d
- /data/media/####/noci_efas
- /data/media/####/noci_efas_d
- /data/media/####/ntb_erom_pc_d
- /data/media/####/ntb_meti
- /data/media/####/ntb_mottob_pop
- /data/media/####/ntb_mottob_pop_d
- /data/media/####/ntb_rehto_pc_d
- /data/media/####/ntbesolc_pot_x
- /data/media/####/ntbesolc_potd_d
- /data/media/####/nwod_worra
- /data/media/####/nwod_worra_d
- /data/media/####/p_kcehcp
- /data/media/####/pot_ntbseolc_d
- /data/media/####/pu_worra
- /data/media/####/pu_worra_d
- /data/media/####/rats_m
- /data/media/####/tnetnocppa
- /data/media/####/wolley_gbntb_d
- getprop ro.product.cpu.abi
- engine
- DES
- DES-CBC-PKCS5Padding
- AES-CFB-NoPadding