Technical information
- Adware.Plague.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) p0.ps####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) ib.sn####.com.####.net:80
- TCP(HTTP/1.1) dynamic####.sn####.com.####.com:80
- TCP(HTTP/1.1) res####.a####.com:80
- TCP(HTTP/1.1) oc.u####.com:80
- TCP(TLS/1.0) dynamic####.sn####.com.####.com:443
- TCP(TLS/1.0) sett####.crashly####.com:443
- a####.u####.com
- api####.a####.com
- dm.tou####.com
- e.anzhua####.com
- e1.anzhua####.com
- e2.anzhua####.com
- hot####.sn####.com
- ib.sn####.com
- ic.sn####.com
- log.sn####.com
- mon.sn####.com
- oc.u####.com
- p0.ps####.com
- sett####.crashly####.com
- dynamic####.sn####.com.####.com/get_domains/v3/?ac=####&channel=####&aid...
- dynamic####.sn####.com.####.com/monitor/settings/?ac=####&channel=####&a...
- ib.sn####.com.####.net/promotion/app/lt/?ac=####&channel=####&aid=####&a...
- ib.sn####.com.####.net/service/settings/v2/?app=####&default=####&ac=###...
- p0.ps####.com/origin/1466/2732701471
- p0.ps####.com/service/12/app_ad/?_unused=####&carrier=####&mcc_mnc=####&...
- a####.u####.com/app_logs
- dynamic####.sn####.com.####.com/service/2/app_log_config/?ac=####&channe...
- oc.u####.com/v2/check_config_update
- oc.u####.com/v2/get_update_time
- res####.a####.com/v3/log/init
- /data/data/####/.imprint
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000BeginSession.cls_temp
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000SessionApp.cls_temp
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000SessionDevice.cls_temp
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000SessionOS.cls_temp
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000SessionUser.cls_temp
- /data/data/####/5F2DE3AE03C0-0001-0886-8701D0F13000user.meta
- /data/data/####/5F2DE3B40117-0001-0926-8701D0F13000BeginSession.cls_temp
- /data/data/####/5F2DE3B40117-0001-0926-8701D0F13000SessionApp.cls_temp
- /data/data/####/5F2DE3B40117-0001-0926-8701D0F13000SessionDevice.cls_temp
- /data/data/####/5F2DE3B40117-0001-0926-8701D0F13000SessionOS.cls_temp
- /data/data/####/5F2DE3B40117-0001-0926-8701D0F13000user.meta
- /data/data/####/TwitterAdvertisingInfoPreferences.xml
- /data/data/####/aixin.png
- /data/data/####/aoman.png
- /data/data/####/app_setting.xml
- /data/data/####/bikong.png
- /data/data/####/bizui.png
- /data/data/####/ciyan.png
- /data/data/####/classes.jar
- /data/data/####/com.crashlytics.prefs.xml
- /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
- /data/data/####/com.crashlytics.settings.json
- /data/data/####/com.ss.spipe_setting.xml
- /data/data/####/custom_channels.xml
- /data/data/####/dazuiba.png
- /data/data/####/dblvguy-journal
- /data/data/####/duqi.png
- /data/data/####/essay.db-journal
- /data/data/####/fadai.png
- /data/data/####/feizao.png
- /data/data/####/funny.mp3
- /data/data/####/gaoxing.png
- /data/data/####/haixiu.png
- /data/data/####/haochi.png
- /data/data/####/hehe.png
- /data/data/####/huaixiao.png
- /data/data/####/huang.png
- /data/data/####/huanggua.png
- /data/data/####/initialization_marker
- /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.android.o.xml
- /data/data/####/jianfeizao.png
- /data/data/####/jingya.png
- /data/data/####/ku.png
- /data/data/####/last_know_location.xml
- /data/data/####/leng.png
- /data/data/####/mask.png
- /data/data/####/mobclick_agent_online_setting_org.x7ff92a7.h7a00a79.xml
- /data/data/####/multi_process_config.xml
- /data/data/####/multi_process_config.xml.bak (deleted)
- /data/data/####/multidex.version.xml
- /data/data/####/neiku.png
- /data/data/####/org.x7ff92a7.h7a00a79-1.apk.classes-1387002104.zip
- /data/data/####/penxue.png
- /data/data/####/push_setting.xml
- /data/data/####/qinqin.png
- /data/data/####/rain.mp3
- /data/data/####/renxing.png
- /data/data/####/sa_f2c4b404-6f9e-4c76-887e-83f1b08470dd_1596842928007.tap
- /data/data/####/session_analytics.tap
- /data/data/####/session_analytics.tap (deleted)
- /data/data/####/session_analytics.tap.tmp
- /data/data/####/snssdk_openudid.xml
- /data/data/####/sp_live_setting.xml
- /data/data/####/ss_app_config.xml
- /data/data/####/ss_app_log.db-journal
- /data/data/####/ss_splash_ad.xml
- /data/data/####/tanqi.png
- /data/data/####/tempimage-1387002104.tmp
- /data/data/####/tu.png
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/weiqu.png
- /data/data/####/wushi.png
- /data/data/####/xiangjiao.png
- /data/data/####/yun.png
- /data/data/####/zhu.png
- /data/media/####/AppShareIcon.jpg
- /data/media/####/clientudid.dat
- /data/media/####/journal
- /data/media/####/journal.tmp
- <Package Folder>/lib/libsupervisor.so <Package> com.ss.android.message.NotifyService <Package>:push <Package Folder> 0
- sh <Package Folder>/lib/libsupervisor.so <Package> com.ss.android.message.NotifyService <Package>:push <Package Folder> 0
- weibosdkcore
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding