Technical information
- Android.DownLoader.1007.origin
- Android.RemoteCode.277.origin
- Android.Triada.510.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) geb####.slj####.com:17002
- TCP(HTTP/1.1) p####.hfc####.com:80
- TCP(HTTP/1.1) www.kpa####.cn:80
- TCP(HTTP/1.1) p####.gs####.cn:80
- TCP(HTTP/1.1) kyy####.wwe####.com:17001
- TCP(HTTP/1.1) kyy####.wwe####.com:17002
- TCP(TLS/1.0) p####.gs####.cn:443
- cdn.jiu####.com
- geb####.slj####.com
- jxs####.slj####.com
- kyy####.wwe####.com
- lla####.slj####.com
- m.lsxue####.cn
- orn####.wwe####.com
- p####.gs####.cn
- p####.hfc####.com
- s9.c####.com
- www.kpa####.cn
- ycb####.slj####.com
- p####.gs####.cn/zt4PU3Kr?siwt=####
- p####.hfc####.com/c/DayouuUTzt.zip
- p####.hfc####.com/c/dowyTuwo.zip
- p####.hfc####.com/c/hbasdasdq.zip
- p####.hfc####.com/c/khbbgytad.zip
- p####.hfc####.com/c/l/kuaishou1031.zip
- p####.hfc####.com/c/lqmbllh.zip
- p####.hfc####.com/c/uasjdnyfea.zip
- p####.hfc####.com/two/bhbasdd
- www.kpa####.cn/iqiyi_pcw_s6/
- www.kpa####.cn/iqiyi_pcw_s6/s.js
- www.kpa####.cn/you.ctrip=epxs/
- geb####.slj####.com:17002/6a4it/
- geb####.slj####.com:17002/jw1pw/
- kyy####.wwe####.com:17001/an2y3z/
- kyy####.wwe####.com:17001/cbcvu9/
- kyy####.wwe####.com:17001/karawc/
- kyy####.wwe####.com:17002/5rhxg/
- kyy####.wwe####.com:17002/6a4it/
- kyy####.wwe####.com:17002/jw1pw/
- /data/data/####/comguewsboogorug.xml
- /data/data/####/data_0
- /data/data/####/data_0 (deleted)
- /data/data/####/data_1
- /data/data/####/data_1 (deleted)
- /data/data/####/data_2
- /data/data/####/data_2 (deleted)
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/gfg.xml
- /data/data/####/hxiz.xml
- /data/data/####/index
- /data/data/####/index (deleted)
- /data/data/####/oKIxzNLd.jar
- /data/data/####/sp_bhvvkz.xml
- /data/data/####/sp_name.xml
- /data/data/####/sp_name.xml.bak
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal (deleted)
- /data/media/####/.did
- /data/media/####/.pk
- /data/media/####/070DB8922B8FBF91863EB365103C6B94.temp
- /data/media/####/070DB8922B8FBF91863EB365103C6B94.zip
- /data/media/####/0DA6795BC4C4A5E065B1DDF3489B2558
- /data/media/####/18EA68FABE99636534F3BA7EF5C2800A
- /data/media/####/33FC58C31FB491BC01333548F6507866.jar
- /data/media/####/33FC58C31FB491BC01333548F6507866.temp
- /data/media/####/4150B67B7A25EC827B10016C015401DC
- /data/media/####/51F834546E1B2B19B8BEF5098FAFFD19.temp
- /data/media/####/51F834546E1B2B19B8BEF5098FAFFD19.zip
- /data/media/####/6158DB86730967668148B48E5B64A9F3
- /data/media/####/75F0F1EC4161308CEB59CE7A4384ABBC.temp
- /data/media/####/75F0F1EC4161308CEB59CE7A4384ABBC.zip
- /data/media/####/865DDFDE477A3DC51518CBC284893178.temp
- /data/media/####/865DDFDE477A3DC51518CBC284893178.zip
- /data/media/####/922C897A26D153338DA898354117A83D.temp
- /data/media/####/922C897A26D153338DA898354117A83D.zip
- /data/media/####/B86803D2FB3414472BD7FADACFA59C6F.temp
- /data/media/####/B86803D2FB3414472BD7FADACFA59C6F.zip
- /data/media/####/BC59E3C934CF5C86751E684FC2D3BB1A.temp
- /data/media/####/BC59E3C934CF5C86751E684FC2D3BB1A.zip
- /data/media/####/D9DEC0AEAFB4B526B0654C7B4CA1599D
- /data/media/####/EC5002E6705A094944662C4782D8BA3E
- /data/media/####/F67204BA08EAFA75211D5FE1EB25E5F1
- /data/media/####/svtq
- /data/media/####/tb
- cat /proc/version
- cat /sys/class/net/wlan0/address
- getprop ro.yunos.build.version
- DataEncrypt
- AES-CBC-PKCS5Padding
- RSA-None-PKCS1Padding
- AES-CBC-PKCS5Padding
- RSA-None-PKCS1Padding