Technical information
- Adware.Youmi.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) l####.cc:80
- TCP(HTTP/1.1) amap####.cn-hang####.oss####.####.com:80
- TCP(TLS/1.0) openins####.io:443
- TCP(TLS/1.0) res####.a####.com:443
- TCP(TLS/1.0) s####.j####.cn:443
- TCP(TLS/1.0) 1####.250.115.94:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) bea####.gcp.g####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) 1####.250.189.234:443
- TCP(TLS/1.2) 1####.250.115.94:443
- TCP(TLS/1.2) 1####.250.189.202:443
- TCP(TLS/1.2) 64.2####.164.101:443
- TCP(TLS/1.2) 1####.177.14.99:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 1####.250.189.234:443
- UDP rr17---####.g####.com:443
- UDP p####.google####.com:443
- UDP 1####.251.46.174:443
- UDP bea####.gcp.g####.com:443
- UDP 2####.0.0.1:9998
- TCP 1####.70.144.172:7006
- UDP s.j####.cn:19000
- 3####.nd####.y####.com
- a####.exc.mob.com
- a####.u####.com
- amap####.cn-hang####.oss####.####.com
- android####.go####.com
- aos.w####.y####.net
- bea####.gcp.g####.com
- gmscomp####.google####.com
- l####.cc
- my.ai####.com
- openins####.io
- p####.google####.com
- res####.a####.com
- rr17---####.g####.com
- rr2---s####.g####.com
- s####.gw.y####.net
- s####.j####.cn
- s.j####.cn
- s.y####.net
- t####.dmp.y####.net
- up####.sdk.jig####.cn
- www.gst####.com
- z####.ai####.com
- amap####.cn-hang####.oss####.####.com/sdkcoor/android/armeabi-v7a/libJni...
- l####.cc/i/sdk/is_gal?os=####&android_id_md5=####&imei_md5=####×tam...
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- l####.cc/i/sdk/install
- openins####.io:443/api/v2/android/yjtmj2/init?deviceId=####&androidId=##...
- res####.a####.com:443/v3/iasdkauth?key=####&ts=####&scode=####
- s####.j####.cn:443/v2/report
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/172778b87f3fed15_0 (deleted)
- /data/data/####/20b088962fc44854_0 (deleted)
- /data/data/####/22ee5ab56629b1ef_0 (deleted)
- /data/data/####/3257204efce9f004_0 (deleted)
- /data/data/####/37331630779337.0
- /data/data/####/4f37fda732ab2e7b_0 (deleted)
- /data/data/####/57d4e834985c816c_0 (deleted)
- /data/data/####/67f5625c0ff114b1_0 (deleted)
- /data/data/####/8416c5722e56e590_0 (deleted)
- /data/data/####/8ef6dd78e88239a6_0 (deleted)
- /data/data/####/954c39d94c70979f_0 (deleted)
- /data/data/####/96898d31ef01970e0ebeeeb4714a9157
- /data/data/####/96898d31ef01970e0ebeeeb4714a9157-journal
- /data/data/####/AppPreferences.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/Cookies-journal
- /data/data/####/FM_config.xml
- /data/data/####/JPushSA_Config.xml
- /data/data/####/LKME_Server_Request_Queue.xml
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/OxgHkj2lz09F-journal
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/a99815641746d12f84a9275f2006a6d9-journal
- /data/data/####/aab6e1d7efce9499_0 (deleted)
- /data/data/####/appPackageNames
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/com.weikuai.wknews_preferences.xml
- /data/data/####/com.weikuai.wknewsbfd7cba836e3440d8500f71601b2912b.xml
- /data/data/####/dd8df020c84f26a1_0 (deleted)
- /data/data/####/domain_1
- /data/data/####/e16538ed7d419aa2_0 (deleted)
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f039265ea0df00f7_0 (deleted)
- /data/data/####/f1ac31c0c950c808_0 (deleted)
- /data/data/####/f6342ce224495fc68777e315db492e6c
- /data/data/####/f6342ce224495fc68777e315db492e6c-journal
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/index
- /data/data/####/journal
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_local_notification.db-journal (deleted)
- /data/data/####/jpush_local_notification.db-wal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/jpush_state.xml
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/jpush_statistics.db-journal (deleted)
- /data/data/####/jpush_statistics.db-shm (deleted)
- /data/data/####/jpush_statistics.db-wal
- /data/data/####/jpush_statistics.db-wal (deleted)
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/libjiagu.so
- /data/data/####/linkedme_referral_shared_pref.xml
- /data/data/####/linkedme_referral_shared_pref.xml.bak
- /data/data/####/loctemp.so
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/metrics_guid
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/pref.xml
- /data/data/####/proc_auxv
- /data/data/####/share_first_start_name.xml
- /data/data/####/sp_sophix.xml
- /data/data/####/the-real-index
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/updateinfo.xml
- /data/data/####/usa129xa
- /data/data/####/usa129xa-journal
- /data/data/####/userhobby
- /data/data/####/userhobby-journal
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/data/####/ymdex.dex
- /data/data/####/ymdex.dex.flock (deleted)
- /data/data/####/ymdex.jar
- /data/data/####/zhuge
- /data/data/####/zhuge-journal
- /data/media/####/.artc_lock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.lm_device_id
- /data/media/####/.mn_1666188972
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.push_deviceid
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/alsn.db
- /data/media/####/alsn.db-journal
- /data/media/####/i42d45df023jnkdd93la483f9xGFKXI
- /data/media/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
- /data/media/####/wk_uuid
- /data/media/####/yjtmj2
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/kernel_max
- cat /sys/class/net/wlan0/address
- libabcdefgh
- libjcore118
- libjiagu
- libmd5
- libproperty_get
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- PBEWITHMD5andDES
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- PBEWITHMD5andDES