Technical information
- Adware.Ninebox.4.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) p0.ps####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) oc.u####.com:80
- TCP(HTTP/1.1) dm.tou####.com:80
- TCP(HTTP/1.1) i####.sn####.com.####.net:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(HTTP/1.1) res####.a####.com:80
- TCP(TLS/1.0) sett####.crashly####.com:443
- a####.u####.com
- a0.ps####.com
- api####.a####.com
- dm.tou####.com
- i####.sn####.com
- ib.sn####.com
- ic.sn####.com
- loc.map.b####.com
- log.sn####.com
- mon.sn####.com
- oc.u####.com
- p0.ps####.com
- sett####.crashly####.com
- dm.tou####.com/get_domains/?ac=####&channel=####&aid=####&app_name=####&...
- dm.tou####.com/monitor/settings/?ac=####&channel=####&aid=####&app_name=...
- dm.tou####.com/service/12/app_ad/?_unused=####&carrier=####&mcc_mnc=####...
- dm.tou####.com/service/settings/v2/?app=####&default=####&ac=####&channe...
- i####.sn####.com.####.net/2/user/info/?ac=####&channel=####&aid=####&app...
- p0.ps####.com/origin/1466/2732701471
- a####.u####.com/app_logs
- dm.tou####.com/service/2/app_log_config/?ac=####&channel=####&aid=####&a...
- loc.map.b####.com/sdk.php
- oc.u####.com/v2/check_config_update
- oc.u####.com/v2/get_update_time
- res####.a####.com/v3/log/init
- /data/data/####/.imprint
- /data/data/####/1596617011469.jar
- /data/data/####/1596617011925.jar
- /data/data/####/1596617011929.jar
- /data/data/####/1596617011944.jar
- /data/data/####/1596617011957.jar
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32FBeginSession.cls_temp
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32FSessionApp.cls_temp
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32FSessionDevice.cls_temp
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32FSessionOS.cls_temp
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32FSessionUser.cls_temp
- /data/data/####/5F2A712D017A-0001-086B-372895DCB32Fuser.meta
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32FBeginSession.cls_temp
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32FSessionApp.cls_temp
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32FSessionDevice.cls_temp
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32FSessionOS.cls_temp
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32FSessionUser.cls_temp
- /data/data/####/5F2A712F02F9-0001-089F-372895DCB32Fuser.meta
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32FBeginSession.cls_temp
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32FSessionApp.cls_temp
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32FSessionDevice.cls_temp
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32FSessionOS.cls_temp
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32FSessionUser.cls_temp
- /data/data/####/5F2A71370023-0001-09E6-372895DCB32Fuser.meta
- /data/data/####/5F2A713B034F-0001-0B41-372895DCB32FBeginSession.cls_temp
- /data/data/####/5F2A713B034F-0001-0B41-372895DCB32FSessionApp.cls_temp
- /data/data/####/5F2A713B034F-0001-0B41-372895DCB32FSessionDevice.cls_temp
- /data/data/####/5F2A713B034F-0001-0B41-372895DCB32FSessionOS.cls_temp
- /data/data/####/5F2A713B034F-0001-0B41-372895DCB32Fuser.meta
- /data/data/####/LocationType.xml
- /data/data/####/TwitterAdvertisingInfoPreferences.xml
- /data/data/####/aixin.png
- /data/data/####/aoman.png
- /data/data/####/app_setting.xml
- /data/data/####/applog_stats.xml
- /data/data/####/bikong.png
- /data/data/####/bizui.png
- /data/data/####/ciyan.png
- /data/data/####/com.crashlytics.prefs.xml
- /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
- /data/data/####/com.crashlytics.settings.json
- /data/data/####/com.ss.spipe_setting.xml
- /data/data/####/custom_channels.xml
- /data/data/####/dazuiba.png
- /data/data/####/dij.xml
- /data/data/####/dim.xml
- /data/data/####/duqi.png
- /data/data/####/essay.db-journal
- /data/data/####/fadai.png
- /data/data/####/feizao.png
- /data/data/####/firll.dat
- /data/data/####/funny.mp3
- /data/data/####/gaoxing.png
- /data/data/####/haixiu.png
- /data/data/####/haochi.png
- /data/data/####/hehe.png
- /data/data/####/huaixiao.png
- /data/data/####/huang.png
- /data/data/####/huanggua.png
- /data/data/####/initialization_marker
- /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.android.o.xml
- /data/data/####/j-id.xml
- /data/data/####/jianfeizao.png
- /data/data/####/jingya.png
- /data/data/####/ku.png
- /data/data/####/last_know_location.xml
- /data/data/####/leng.png
- /data/data/####/mask.png
- /data/data/####/mid.xml
- /data/data/####/mobclick_agent_online_setting_com.ss.android.es...eb.xml
- /data/data/####/multi_process_config.xml
- /data/data/####/multidex.version.xml
- /data/data/####/neiku.png
- /data/data/####/observerFile3
- /data/data/####/offinfo.dat
- /data/data/####/penxue.png
- /data/data/####/push_setting.xml
- /data/data/####/qinqin.png
- /data/data/####/rain.mp3
- /data/data/####/renxing.png
- /data/data/####/sa_c08e555c-47b6-4a78-8918-78ee3da49957_1596617005427.tap
- /data/data/####/session_analytics.tap
- /data/data/####/session_analytics.tap.tmp
- /data/data/####/snssdk_openudid.xml
- /data/data/####/ss_app_config.xml
- /data/data/####/ss_app_log.db-journal
- /data/data/####/ss_location.xml
- /data/data/####/ss_splash_ad.xml
- /data/data/####/tanqi.png
- /data/data/####/tempimage-759890401.tmp
- /data/data/####/tu.png
- /data/data/####/type.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/weiqu.png
- /data/data/####/wushi.png
- /data/data/####/xiangjiao.png
- /data/data/####/xy.xml
- /data/data/####/yun.png
- /data/data/####/zhu.png
- /data/media/####/.cuid
- /data/media/####/12.dat
- /data/media/####/MID.DAT
- /data/media/####/clientudid.dat
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/names.dat
- /data/media/####/share.dat
- /data/media/####/yoh.dat
- /data/media/####/yol.dat
- /data/media/####/yom.dat
- /data/user/0/<Package>/lib/libsupervisor.so <Package> com.ss.android.message.NotifyService <Package>:push /data/user/0/<Package> 0
- locSDK5
- nhmm_sf
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding
- DES