Technical information
- Adware.Kyview.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(HTTP/1.1) d.alpha-b####.com:80
- TCP(HTTP/1.1) s.tou####.com:80
- TCP(HTTP/1.1) wap.n.sh####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) c####.baidust####.com:80
- TCP(HTTP/1.1) mobads-####.b####.com:80
- TCP(HTTP/1.1) s6.ps####.com.####.com:80
- TCP(HTTP/1.1) mo####.b####.com:80
- TCP(HTTP/1.1) ub####.baidust####.com:80
- TCP(HTTP/1.1) wn.pos.b####.com:80
- TCP(HTTP/1.1) res.1231####.com.####.com:80
- TCP(TLS/1.0) co####.ad####.cn:443
- TCP(TLS/1.0) nv####.n.sh####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) mobads-####.b####.com:443
- TCP(TLS/1.0) 2####.58.212.238:443
- and####.b####.qq.com
- c####.baidust####.com
- co####.ad####.cn
- d.alpha-b####.com
- h####.b####.com
- hm.b####.com
- m.b####.com
- mo####.b####.com
- mobads-####.b####.com
- res.1231####.com
- s.tou####.com
- s6.ps####.com
- sv.b####.com
- ub####.baidust####.com
- wn.pos.b####.com
- c####.baidust####.com/cpro/ui/luWrap/right.png
- c####.baidust####.com/cpro/ui/noexpire/css/2.1.5/img/mob-adIcon_2x.png
- c####.baidust####.com/cpro/ui/noexpire/css/2.1.5/img/mob-logo_2x.png
- c####.baidust####.com/cpro/ui/noexpire/css/2.1.5/template.min.css
- c####.baidust####.com/cpro/ui/noexpire/img/2.0.3/rs_img/image_sdk_1_dl.jpg
- c####.baidust####.com/cpro/ui/noexpire/js/2.0.1/oojs.js
- c####.baidust####.com/cpro/ui/noexpire/js/rs/business/1.0.2/anticheat_mo...
- c####.baidust####.com/cpro/ui/noexpire/js/rs/template/component/componen...
- c####.baidust####.com/cpro/ui/noexpire/js/rs/template/logoIsShowEvents_1...
- c####.baidust####.com/cpro/ui/noexpire/js/rs/template/slide.min.js
- c####.baidust####.com/cpro/ui/noexpire/ws/3rd/esl_b150bbf.js
- c####.baidust####.com/cpro/ui/noexpire/ws/css/base_f258e90.css
- c####.baidust####.com/cpro/ui/noexpire/ws/css/ui_b99a586.css
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/close_9d33a11.png
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/logo-fb-big_94547f...
- c####.baidust####.com/cpro/ui/noexpire/ws/images/logo/logo-mob_94da672.png
- c####.baidust####.com/cpro/ui/noexpire/ws/js/anticheatMob_776abb3.js
- c####.baidust####.com/cpro/ui/noexpire/ws/widget/logo_94e2e1b.js
- d.alpha-b####.com/U1b4/
- mo####.b####.com/ads/ads.appcache
- mo####.b####.com/ads/css/min/main.css
- mo####.b####.com/ads/index.htm
- mo####.b####.com/ads/js/ads.trunk.js
- mo####.b####.com/ads/js/c.js
- mo####.b####.com/ads/pa/__pasys.apk
- mo####.b####.com/ads/pa/__pasys.php
- mo####.b####.com/ads/pa/__pasys_remote_banner.jar
- mo####.b####.com/ads/pa/__pasys_remote_banner.php?v=####&tp=####&os=####...
- mo####.b####.com/cpro/ui/mads.php?code2=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323016763=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323016767=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323017754=####
- mo####.b####.com/cpro/ui/mads.php?code2=####&b1525323070459=####
- mobads-####.b####.com/dz.zb?type=37&adid=1&appsec=b461680f_cpr&appsid=b4...
- res.1231####.com.####.com/mailiang/201804/bdby.apk
- s.tou####.com/o375N/
- s6.ps####.com.####.com/package/apk/automobile/autolite_baidu_dsp77_and37...
- ub####.baidust####.com/media/v1/0f0000npW7nekexyd7u1Ys.jpg
- ub####.baidust####.com/media/v1/0f0000ogkjFPCxeoKP9xBf.jpg
- ub####.baidust####.com/media/v1/0f00050rJsXR6ohV7K6aA0.jpg
- ub####.baidust####.com/media/v1/0f00075oZgja_QK94H9mnf.jpg
- ub####.baidust####.com/media/v1/0f000AjEby-KjVL2oX7D06.jpg
- ub####.baidust####.com/media/v1/0f000KX0A_kSRO1EL64Fqs.jpg
- ub####.baidust####.com/media/v1/0f000KX0AoK-r5MEL64Fe6.jpg
- ub####.baidust####.com/media/v1/0f000Qk_Ry30LiewV_Natf.jpg
- ub####.baidust####.com/media/v1/0f000QtH4y9CBlwbTOCDDf.jpg
- ub####.baidust####.com/media/v1/0f000ZozOewU711o9XSPc0.jpg
- ub####.baidust####.com/media/v1/0f000c3SjJJH6Ti00s9nO0.jpg
- ub####.baidust####.com/media/v1/0f000nUyY6AUovlho9bca6.jpg
- ub####.baidust####.com/media/v1/0f000nYjaekmXb38jPksnf.jpg
- wap.n.sh####.com/mobads.php?060000a####
- wap.n.sh####.com/mobads.php?060000a####&ck=####
- wn.pos.b####.com/adx.php?c=####&ext=####
- and####.b####.qq.com/rqd/async
- h####.b####.com/app.gif
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/WebViewSettings.xml
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__pasys.apk.beforesign.tm
- /data/data/####/__pasys_remote_banner.jar.beforesign.tm
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/__sdk_m_0f000AjEby-KjVL2oX7D06.jpg.tm
- /data/data/####/__sdk_pasys_pkgs.xml
- /data/data/####/__sdk_pasys_pkgurls.xml
- /data/data/####/__sdk_remote_dl.xml
- /data/data/####/bugly_db_lejiagu-journal
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/http_mobads.baidu.com_0.localstorage-journal
- /data/data/####/index
- /data/data/####/legu_900015015.xml
- /data/data/####/legudzbait.zip
- /data/data/####/libshella-2.3.0.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/native_record_lock
- /data/data/####/reqinfo.db
- /data/data/####/reqinfo.db-journal
- /data/data/####/security_info
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/bdby.apk
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libshella-2.3.0.so
- getprop ro.board.platform
- getprop ro.yunos.version
- Bugly
- libshella-2.3.0
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- AES
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding