Technical information
- Adware.Plague.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c####.baidust####.com:80
- TCP(HTTP/1.1) ada.b####.com:80
- TCP(HTTP/1.1) wap.n.sh####.com:80
- TCP(HTTP/1.1) c####.b####.com:80
- TCP(HTTP/1.1) mobads-####.b####.com:80
- TCP(HTTP/1.1) mo####.b####.com:80
- TCP(HTTP/1.1) ub####.baidust####.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(TLS/1.0) c####.baidust####.com:443
- TCP(TLS/1.0) mo####.b####.com:443
- TCP(TLS/1.0) dow####.b####.com:443
- TCP(TLS/1.0) down####.b####.com:443
- TCP(TLS/1.0) mobads-####.b####.com:443
- ada.b####.com
- an.ite####.com
- an1.ite####.com
- an2.ite####.com
- c####.b####.com
- c####.baidust####.com
- c####.baidust####.com
- dow####.b####.com
- down####.b####.com
- m.b####.com
- mo####.b####.com
- mobads-####.b####.com
- ub####.baidust####.com
- wn.pos.b####.com
- ada.b####.com/ecom?cp=####&word=####&k_words=####&ds=####&wsw=####&wsh=#...
- c####.b####.com/cpro/ui/uijs.php?en=####&adx=####&c=####&cf=####&cp=####...
- c####.baidust####.com/cpro/exp/mob_exp/img/app_lu/slow_change.jpg
- c####.baidust####.com/cpro/expire/time2.js
- c####.baidust####.com/cpro/ui/noexpire/img/2.0.1/bd-logo4.png
- c####.baidust####.com/cpro/ui/noexpire/ws/3rd/esl_b150bbf.js
- c####.baidust####.com/cpro/ui/noexpire/ws/css/base_f258e90.css
- c####.baidust####.com/cpro/ui/noexpire/ws/css/ui_b99a586.css
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/close_9d33a11.png
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/logo-mob_94da672.png
- c####.baidust####.com/cpro/ui/noexpire/ws/js/anticheatMob_776abb3.js
- c####.baidust####.com/cpro/ui/noexpire/ws/widget/logo_5b92275.js
- c####.baidust####.com/sync.htm?cproid=####
- mo####.b####.com/ads/ads.appcache
- mo####.b####.com/ads/css/min/main.css
- mo####.b####.com/ads/index.htm
- mo####.b####.com/ads/js/ads.trunk.js
- mo####.b####.com/ads/js/c.js
- mo####.b####.com/ads/pa/__pasys_remote_banner.jar
- mo####.b####.com/ads/pa/__pasys_remote_banner.php?v=####&tp=####&os=####...
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1537896814174=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1537896814756=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1537896825556=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1537896860284=####
- mobads-####.b####.com/dz.zb?type=####&a0=####&a1=####&a2=####&a3=####&a4...
- mobads-####.b####.com/dz.zb?type=37&adid=1&appsec=c21f4170_cpr&appsid=c2...
- ub####.baidust####.com/media/v1/0f0005DSCaf20k-gKT7tE0.jpg
- wap.n.sh####.com/mobads.php?Ks0000K####&ck=####
- wn.pos.b####.com/adx.php?c=####
- wn.pos.b####.com/adx.php?c=####&ext=####
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/__pasys.apk.tmp.tm
- /data/data/####/__pasys_remote_banner.jar.tm
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/__sdk_avgclr.xml
- /data/data/####/__sdk_pasys_pkgs.xml
- /data/data/####/__sdk_pasys_pkgurls.xml
- /data/data/####/__sdk_remote_adlist.xml
- /data/data/####/__sdk_remote_dl.xml
- /data/data/####/classes.jar
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dbnrfj-journal
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/http_mobads.baidu.com_0.localstorage-journal
- /data/data/####/index
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- DES-ECB-PKCS5Padding