Technical information
- Adware.Egame.1
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.96.49.16:80
- TCP(HTTP/1.1) g####.lov####.com:80
- TCP(HTTP/1.1) do####.aishe####.com:80
- TCP(HTTP/1.1) 2####.102.39.23:80
- TCP(HTTP/1.1) 1####.29.29.29:80
- TCP(HTTP/1.1) 1####.96.49.15:80
- UDP(NTP) 1.cn.p####.####.org:123
- TCP(TLS/1.0) av1.x####.com:443
- TCP(TLS/1.0) feed####.on####.mobi:443
- TCP(TLS/1.0) api-acc####.edges####.net:443
- TCP(TLS/1.0) ads.on####.mobi:443
- TCP(TLS/1.0) wild####.moa####.com.####.net:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) c####.x####.com:443
- TCP(TLS/1.2) 1####.250.27.102:443
- TCP(TLS/1.2) www.google####.com:443
- TCP(TLS/1.2) 1####.250.102.94:443
- 1.cn.p####.####.org
- ads.api.vu####.com
- ads.on####.mobi
- and####.google####.com
- api.vu####.com
- av1.x####.com
- c####.x####.com
- do####.aishe####.com
- feed####.on####.mobi
- g####.lov####.com
- i####.cn
- id1.cn.8.####.8
- p####.google####.com
- p####.lov####.com
- pg.x####.com
- pg.x####.com.####.8
- www.google####.com
- z.moa####.com
- ads.on####.mobi:443/adSetting?publishId=####&did=####&imei=####&aid=####
- ads.on####.mobi:443/webview/1.3.3/release/config.json?sdkVersionName=###...
- c####.x####.com:443/sdk/conf?id=####&p=####&v=####&sv=####&cv=####
- do####.aishe####.com/getdomain.php?chid=####&subchid=####
- feed####.on####.mobi:443/webview/2.0.91/release/index.html
- g####.lov####.com/chksdkupdate.php?sdkver=####&compver=####&mainver=####...
- g####.lov####.com/genuser.php?chid=####&subchid=####&vercode=####&type=#...
- wild####.moa####.com.####.net:443/VNG/android/3f2ae9c/status.json?ts=###...
- ads.on####.mobi:443/cia?publishId=####&token=####&sdkVersion=####
- api-acc####.edges####.net:443/api/v5/ads
- api-acc####.edges####.net:443/config
- /data/anr/traces.txt
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/EGAME_SDK.dat
- /data/data/####/EGAME_SDK.jar
- /data/data/####/GoogleBackupTransport.dex
- /data/data/####/GoogleBackupTransport.dex.flock (deleted)
- /data/data/####/Signature
- /data/data/####/TDCloudSettingsConfig7E2D24B24A5B4BE4A69D07630C...ml.bak
- /data/data/####/TDCloudSettingsConfig7E2D24B24A5B4BE4A69D07630CE02A09.xml
- /data/data/####/TD_app_pefercen_profile.xml
- /data/data/####/TD_app_pefercen_profile.xml (deleted)
- /data/data/####/TDpref_longtime.xml
- /data/data/####/TDpref_shorttime.xml
- /data/data/####/TDtcagent.db
- /data/data/####/TDtcagent.db-journal
- /data/data/####/VUNGLE_PUB_APP_INFO.xml
- /data/data/####/VungleSDKLog.0
- /data/data/####/VungleSDKLog.0.1
- /data/data/####/VungleSDKLog.0.1.lck
- /data/data/####/VungleSDKLog.0.2
- /data/data/####/VungleSDKLog.0.2.lck
- /data/data/####/VungleSDKLog.0.lck
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/apkInfo
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/cn_egame_openapi_opt.xml
- /data/data/####/cn_egame_sdk_log.xml
- /data/data/####/cn_egame_vip_consumer.xml
- /data/data/####/com.gameimax.mysweetbabykittycare.egame_preferences.xml
- /data/data/####/com.ltayx.pay.ltplugin.dex
- /data/data/####/com.ltayx.pay.ltplugin.dex.flock (deleted)
- /data/data/####/domain.xml
- /data/data/####/egame_finger_print.png
- /data/data/####/egame_s1574608481.tmp
- /data/data/####/egame_s279711309.tmp
- /data/data/####/egame_sdk_1.png
- /data/data/####/egame_sdk_16.png
- /data/data/####/egame_sdk_25.png
- /data/data/####/egame_sdk_4.png
- /data/data/####/egame_sdk_9.png
- /data/data/####/egame_sdk_bg.9.png
- /data/data/####/egame_sdk_bg_pay.9.png
- /data/data/####/egame_sdk_bg_ticket_left.9.png
- /data/data/####/egame_sdk_bg_ticket_right.9.png
- /data/data/####/egame_sdk_btn_back_normal.9.png
- /data/data/####/egame_sdk_btn_back_pressed.9.png
- /data/data/####/egame_sdk_btn_gold_store.png
- /data/data/####/egame_sdk_btn_green_normal.9.png
- /data/data/####/egame_sdk_btn_green_pressed.9.png
- /data/data/####/egame_sdk_game_icon_default.png
- /data/data/####/egame_sdk_ico_bag.png
- /data/data/####/egame_sdk_ico_forum.png
- /data/data/####/egame_sdk_ico_list.png
- /data/data/####/egame_sdk_ico_question.png
- /data/data/####/egame_sdk_ico_raiders.png
- /data/data/####/egame_sdk_icon_back.png
- /data/data/####/egame_sdk_icon_close.png
- /data/data/####/egame_sdk_icon_loading.png
- /data/data/####/egame_sdk_icon_pack_up.png
- /data/data/####/egame_sdk_icon_password.png
- /data/data/####/egame_sdk_icon_rmb.png
- /data/data/####/egame_sdk_icon_selected.png
- /data/data/####/egame_sdk_icon_spread_out.png
- /data/data/####/egame_sdk_icon_ticket_more.png
- /data/data/####/egame_sdk_icon_unselected.png
- /data/data/####/egame_sdk_input_box.9.png
- /data/data/####/egame_sdk_logo_aibei.png
- /data/data/####/egame_sdk_logo_chongzhika.png
- /data/data/####/egame_sdk_logo_dianka.png
- /data/data/####/egame_sdk_logo_huafei.png
- /data/data/####/egame_sdk_logo_jdzhifu.png
- /data/data/####/egame_sdk_logo_more.png
- /data/data/####/egame_sdk_logo_weixin.png
- /data/data/####/egame_sdk_logo_yinlian.png
- /data/data/####/egame_sdk_logo_yizhifu.png
- /data/data/####/egame_sdk_logo_zhifubao.png
- /data/data/####/egame_sdk_password_input_box_left.9.png
- /data/data/####/egame_sdk_password_input_box_mid.9.png
- /data/data/####/egame_sdk_password_input_box_right.9.png
- /data/data/####/egame_sdk_popup_btn_blue_normal.9.png
- /data/data/####/egame_sdk_popup_btn_blue_pressed.9.png
- /data/data/####/egame_sdk_pressed.9.png
- /data/data/####/egame_sdk_tag_selected.9.png
- /data/data/####/egame_sdk_tag_unselected.9.png
- /data/data/####/egame_temp.jar
- /data/data/####/egame_temp_.jar
- /data/data/####/gameInfo.xml
- /data/data/####/index
- /data/data/####/kxqpChannal.xml
- /data/data/####/kxqpChannal.xml (deleted)
- /data/data/####/kxqpVersion.xml
- /data/data/####/kxqpplatform2.dex
- /data/data/####/kxqpplatform2.dex.flock (deleted)
- /data/data/####/kxqpplatform2.jar.lock
- /data/data/####/lb_amcfg
- /data/data/####/lb_packages
- /data/data/####/libegamepay_private_dr2.so
- /data/data/####/libexecloader.so
- /data/data/####/libjiagu.so
- /data/data/####/libkxqpplatform.sinfo
- /data/data/####/libkxqpplatform.so
- /data/data/####/libzmapk.so
- /data/data/####/libzvmhelper.so
- /data/data/####/main.dex
- /data/data/####/main.dex.flock (deleted)
- /data/data/####/main.jar
- /data/data/####/metrics_guid
- /data/data/####/platform.xml
- /data/data/####/proc_auxv
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/sig_0.key
- /data/data/####/soUpdate.xml
- /data/data/####/talkingdata_app.db-journal
- /data/data/####/talkingdata_app_process_preferences_file
- /data/data/####/talkingdata_app_version_preferences_file
- /data/data/####/td.lock
- /data/data/####/tdid.xml
- /data/data/####/tdlock.txt
- /data/data/####/the-real-index
- /data/data/####/tmp1087969707tmp
- /data/data/####/tmp1087969707tmp (deleted)
- /data/data/####/tmp1089075735tmp
- /data/data/####/tmp1089075735tmp (deleted)
- /data/data/####/tmp1131446333tmp
- /data/data/####/tmp1131446333tmp (deleted)
- /data/data/####/tmp1171121442tmp
- /data/data/####/tmp1171121442tmp (deleted)
- /data/data/####/tmp1185465571tmp
- /data/data/####/tmp1185465571tmp (deleted)
- /data/data/####/tmp1226492976tmp (deleted)
- /data/data/####/tmp1297781475tmp (deleted)
- /data/data/####/tmp1339320445tmp (deleted)
- /data/data/####/tmp1371337014tmp
- /data/data/####/tmp1371337014tmp (deleted)
- /data/data/####/tmp1436552211tmp
- /data/data/####/tmp1436552211tmp (deleted)
- /data/data/####/tmp1472781054tmp
- /data/data/####/tmp1472781054tmp (deleted)
- /data/data/####/tmp1495973257tmp
- /data/data/####/tmp1495973257tmp (deleted)
- /data/data/####/tmp149655307tmp (deleted)
- /data/data/####/tmp1512652722tmp
- /data/data/####/tmp1512652722tmp (deleted)
- /data/data/####/tmp1601151938tmp
- /data/data/####/tmp1620550421tmp
- /data/data/####/tmp1620550421tmp (deleted)
- /data/data/####/tmp1628388176tmp
- /data/data/####/tmp1628388176tmp (deleted)
- /data/data/####/tmp1639915319tmp
- /data/data/####/tmp1639915319tmp (deleted)
- /data/data/####/tmp1648302210tmp (deleted)
- /data/data/####/tmp1692107014tmp (deleted)
- /data/data/####/tmp1702219975tmp
- /data/data/####/tmp1702219975tmp (deleted)
- /data/data/####/tmp173722908tmp
- /data/data/####/tmp173722908tmp (deleted)
- /data/data/####/tmp1795738623tmp
- /data/data/####/tmp1824210042tmp
- /data/data/####/tmp1845154133tmp
- /data/data/####/tmp1845154133tmp (deleted)
- /data/data/####/tmp1857298447tmp
- /data/data/####/tmp1919458053tmp
- /data/data/####/tmp1919458053tmp (deleted)
- /data/data/####/tmp1952331425tmp
- /data/data/####/tmp1952331425tmp (deleted)
- /data/data/####/tmp1959810715tmp
- /data/data/####/tmp1959810715tmp (deleted)
- /data/data/####/tmp2008120016tmp
- /data/data/####/tmp2008120016tmp (deleted)
- /data/data/####/tmp2034282941tmp
- /data/data/####/tmp2034282941tmp (deleted)
- /data/data/####/tmp2051380953tmp
- /data/data/####/tmp2066198285tmp
- /data/data/####/tmp2066198285tmp (deleted)
- /data/data/####/tmp2077928627tmp
- /data/data/####/tmp225348868tmp
- /data/data/####/tmp225348868tmp (deleted)
- /data/data/####/tmp262437267tmp
- /data/data/####/tmp262437267tmp (deleted)
- /data/data/####/tmp272424786tmp (deleted)
- /data/data/####/tmp359755128tmp
- /data/data/####/tmp359755128tmp (deleted)
- /data/data/####/tmp366277665tmp
- /data/data/####/tmp366277665tmp (deleted)
- /data/data/####/tmp40514141tmp
- /data/data/####/tmp40514141tmp (deleted)
- /data/data/####/tmp441948227tmp
- /data/data/####/tmp460572073tmp
- /data/data/####/tmp460572073tmp (deleted)
- /data/data/####/tmp46300774tmp
- /data/data/####/tmp46300774tmp (deleted)
- /data/data/####/tmp537727189tmp
- /data/data/####/tmp537727189tmp (deleted)
- /data/data/####/tmp545307805tmp
- /data/data/####/tmp545307805tmp (deleted)
- /data/data/####/tmp553681191tmp
- /data/data/####/tmp553681191tmp (deleted)
- /data/data/####/tmp611877244tmp (deleted)
- /data/data/####/tmp624771436tmp (deleted)
- /data/data/####/tmp639067251tmp
- /data/data/####/tmp639067251tmp (deleted)
- /data/data/####/tmp641290530tmp
- /data/data/####/tmp641290530tmp (deleted)
- /data/data/####/tmp644730847tmp
- /data/data/####/tmp644730847tmp (deleted)
- /data/data/####/tmp652823676tmp (deleted)
- /data/data/####/tmp663424858tmp
- /data/data/####/tmp663424858tmp (deleted)
- /data/data/####/tmp833005677tmp (deleted)
- /data/data/####/tmp860736349tmp (deleted)
- /data/data/####/tmp881959985tmp
- /data/data/####/tmp881959985tmp (deleted)
- /data/data/####/tmp925926883tmp (deleted)
- /data/data/####/tmp965389200tmp
- /data/data/####/tmp965389200tmp (deleted)
- /data/data/####/userInfo.xml
- /data/data/####/vungle
- /data/data/####/vungle-journal
- /data/media/####/.tcookieid
- /data/media/####/1.play
- /data/media/####/OnewaySdkStorage-ow-pri.json
- /data/media/####/OnewaySdkStorage-ow-pub.json
- /data/media/####/OnewaySdkWebApp.html
- /data/media/####/am
- /data/media/####/amj
- /data/media/####/com.ltayx.pay.ltplugin.apk
- /data/media/####/compVersion
- /data/media/####/pa
- /data/media/####/verinfo.cfg
- /data/misc/####/primary.prof
- /system/bin/cat /proc/cpuinfo
- chmod 755 /data/user/0/<Package>/.platformcache/kxqpplatform2.jar
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- chmod 755 <SD-Card>/<Package>/apk/1.play
- libegamepay_dr2
- libjiagu
- libkxqpplatform
- libzmapk
- libzvmhelper
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES
- AES-CBC-PKCS7Padding
- RSA-ECB-PKCS1Padding