Technical information
- Adware.Was.1.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) sda.savecat####.com:80
- TCP(HTTP/1.1) a.da####.com:9127
- TCP(HTTP/1.1) ma####.savecat####.com:80
- TCP(TLS/1.0) sa.unionst####.com:443
- TCP(TLS/1.0) api.face####.com:443
- TCP(TLS/1.0) kk####.oss-cn-####.aliy####.com:443
- TCP(TLS/1.0) 1####.251.36.42:443
- TCP(TLS/1.0) safebro####.google####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) 2####.58.214.14:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) api.savecat####.com:443
- TCP(TLS/1.0) 1####.250.179.174:443
- TCP(TLS/1.2) 2####.58.208.99:443
- TCP(TLS/1.2) 1####.251.39.106:443
- TCP(TLS/1.2) 1####.250.179.202:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 1####.251.36.46:443
- a.da####.com
- api.savecat####.com
- g####.face####.com
- instant####.google####.com
- kk####.oss-cn-####.aliy####.com
- m####.go####.com
- ma####.savecat####.com
- md####.google####.com
- sa.unionst####.com
- safebro####.google####.com
- sda.savecat####.com
- www.gst####.com
- a.da####.com:9127/ll/gs?baseversion=####&version=####&channel=####&appid...
- api.face####.com:443/v2.10/176218609924201?fields=####&format=####&sdk=#...
- api.savecat####.com:443/config/init
- api.savecat####.com:443/config/tssca
- kk####.oss-cn-####.aliy####.com:443/unity_xm_lp_39917.action
- sa.unionst####.com:443/log/base?appid=####&type=####
- sda.savecat####.com/cfg/ggclpz?adsType=####
- sda.savecat####.com/cfg/mdtpz
- api.face####.com:443/v2.10/176218609924201/activities?access_token=####&...
- api.face####.com:443/v2.10/176218609924201/activities?format=####&sdk=####
- ma####.savecat####.com/log/send?appid=####
- sa.unionst####.com:443/log/event?appid=####
- /data/data/####/-1583416625-103-en_US.0
- /data/data/####/-851394415-103-en_US.0
- /data/data/####/.jg.ic
- /data/data/####/61185270-103-en_US.0
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3BeginSession.cls_temp
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3BeginSession.json
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionApp.cls_temp
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionApp.json
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionDevice.cls_temp
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionDevice.json
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionOS.cls_temp
- /data/data/####/61CA4F3303E5-0001-0D3F-D8CB82EB96F3SessionOS.json
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3BeginSession.cls_temp
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3BeginSession.json
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionApp.cls_temp
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionApp.json
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionCrash.cls_temp
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionDevice.cls_temp
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionDevice.json
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionOS.cls_temp
- /data/data/####/61CA4F40020E-0001-0DE9-D8CB82EB96F3SessionOS.json
- /data/data/####/ADSTRATEGY.xml
- /data/data/####/BASE.xml
- /data/data/####/SHARED_PREFERENCES_ANALYTICS.xml
- /data/data/####/TwitterAdvertisingInfoPreferences.xml
- /data/data/####/appsflyer-data.xml
- /data/data/####/cash.xml
- /data/data/####/cheuu
- /data/data/####/classes.dex
- /data/data/####/classes2.dex
- /data/data/####/com.crashlytics.prefs.xml
- /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
- /data/data/####/com.facebook.internal.preferences.APP_SETTINGS.xml
- /data/data/####/com.facebook.sdk.appEventPreferences.xml
- /data/data/####/com.facebook.sdk.attributionTracking.xml
- /data/data/####/com.google.android.gms.appid-no-backup
- /data/data/####/com.google.android.gms.appid.xml
- /data/data/####/com.google.android.gms.measurement.prefs.xml
- /data/data/####/com.google.android.gms.measurement.prefs.xml.bak
- /data/data/####/com.physics.sim.game.savecats.mt_preferences.xml
- /data/data/####/com.physics.sim.game.savecats.mt_preferences.xml.bak
- /data/data/####/crash_marker
- /data/data/####/google_app_measurement_local.db
- /data/data/####/google_app_measurement_local.db-journal
- /data/data/####/initialization_marker
- /data/data/####/journal.tmp
- /data/data/####/kva
- /data/data/####/libjiagu.so
- /data/data/####/onemobile_analytics.xml
- /data/data/####/proc_auxv
- /data/data/####/sa_63c41c8d-9a90-408f-adf5-492e032429c6_1640648507490.tap
- /data/data/####/sa_affac360-9ca2-448c-97a1-2ea56ffeb165_1640648519234.tap
- /data/data/####/sa_fb4cd675-bf3c-42d4-a35f-6bf615fbafa3_1640648517136.tap
- /data/data/####/session_analytics.tap
- /data/data/####/session_analytics.tap (deleted)
- /data/data/####/session_analytics.tap.tmp
- /data/data/####/tmd
- /data/data/####/tv
- /data/data/####/uuloi
- /data/data/####/vva
- /data/data/####/vva.dex
- /data/data/####/vva.dex.flock (deleted)
- /data/data/####/vva.jar
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- AES-CBC-PKCS5Padding