Technical information
- Adware.Dowgin.3.origin
- Android.DownLoader.343.origin
- Android.DownLoader.723
- Android.DownLoader.725
- Android.Packed.4861
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) j####.xiaom####.cn:80
- TCP(HTTP/1.1) a####.u####.com:80
- a####.u####.co
- a####.u####.com
- a.wangdai####.com
- ic.ie.0####.com
- j####.xiaom####.cn
- s1.33####.com
- a####.u####.com/app_logs
- j####.xiaom####.cn/app/init
- /data/data/####/.md5
- /data/data/####/.sec_version
- /data/data/####/3AB59E88A35D6ECA.xml
- /data/data/####/43F98BDA046DD0F0.xml
- /data/data/####/57F3C539EAF32969.xml
- /data/data/####/B58050C27928141889B2F8696582AB6F.xml
- /data/data/####/BA0972C968F8525A-journal
- /data/data/####/BAFAA-journal
- /data/data/####/C14DAA89B184F741784CCB94F6F286E0.xml
- /data/data/####/C96360D41D7E5480.xml
- /data/data/####/FBF
- /data/data/####/FBF-journal
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/_mgmakeupbride_r.xml
- /data/data/####/bciwsrwxtetfdqddayoyoycx.dex
- /data/data/####/classes.dex
- /data/data/####/classes.jar
- /data/data/####/com.hfuedle.mnvhe.dex (deleted)
- /data/data/####/com.hfuedle.mnvhe.jar
- /data/data/####/downmodel.db
- /data/data/####/downmodel.db-journal
- /data/data/####/dxt_yx_sdk
- /data/data/####/dxt_yx_sdk-journal
- /data/data/####/dzubitltxmfksyyqbsgnbwsz.dex
- /data/data/####/init_config.xml
- /data/data/####/isoubvjeyiwlgbdqvcodbrpkf.dex
- /data/data/####/keySP.xml
- /data/data/####/libsecexe.x86.so
- /data/data/####/libsecmain.x86.so
- /data/data/####/libsecpreload.x86.so
- /data/data/####/lidiesuktggpxumdsqdprinjzi.dex
- /data/data/####/lyxihpibuelkzmyftm.dex
- /data/data/####/mobclick_agent_cached_org.games.makeupbride121
- /data/data/####/nrbmpgeyumlbugciasbrhs.dex
- /data/data/####/obbaedurnzxccfmfab.dex
- /data/data/####/ooa001.dex
- /data/data/####/org.games.makeupbride
- /data/data/####/org.games.makeupbride.art
- /data/data/####/org.games.makeupbride.art.20
- /data/data/####/owurpwrrogfpxznxx.dex
- /data/data/####/rszmaldszvlqhxjozdfomefit.dex (deleted)
- /data/data/####/ulgep.dex
- /data/data/####/ulgep.dex (deleted)
- /data/data/####/um_cache_1553724928242.env
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umgep.dex
- /data/data/####/umgep.dex (deleted)
- /data/data/####/uygep.dex (deleted)
- /data/data/####/wubhtkpdybxcdsgqojc.dex (deleted)
- /data/data/####/zwaikj.t
- /data/media/####/004D5060328DBECE25AC0190E422A9F8
- /data/media/####/0FD4EC63CB5BDBC0
- /data/media/####/242A75F527CB43E9
- /data/media/####/28359C3DD49BCB57AE2DA032296E1148
- /data/media/####/28359C3DD49BCB57D1960D85EE20DCDF
- /data/media/####/2A076B309F8F6841714259A6155DA338E6C8AF6F3835C1A3
- /data/media/####/37E9E930795C0F05313CFE881E92765FF39E3169BDD9D4...35C1A3
- /data/media/####/37E9E930795C0F05542A8A9673072CB82F6F75A2C9909111
- /data/media/####/43F2E2DC03FC48D6ADAB3AF1CCC1BF28D1960D85EE20DCDF
- /data/media/####/462155DA72985AB3D03EBB61F0DA5453
- /data/media/####/5E629142FB1CE3341ED95AAF5588B3982F6F75A2C9909111
- /data/media/####/62209B20E2FC39B81351C803722B5453
- /data/media/####/64C7986616106A6A18A889185E98DA6768DECDDB8B33D216
- /data/media/####/64C7986616106A6A69B5CD886435AA017917F7661D061A46
- /data/media/####/887AAC2B6F5B52B3906A8266A1B2C2A3E6C8AF6F3835C1A3
- /data/media/####/8AF2F7ACFE81A1532F6F75A2C9909111
- /data/media/####/8C89D352C3B77B710BF33E44CE9A5B2C
- /data/media/####/A0BA2F0F5473FC240E952F7064193A1E26BCB4E4E2A56444
- /data/media/####/AFF71D4BECB096800BF33E44CE9A5B2C
- /data/media/####/B6A6EF7050ADCDBBE6C8AF6F3835C1A3
- /data/media/####/B8239EA307FD57570BF33E44CE9A5B2C
- /data/media/####/C21D09484789E28DDBB0AB7E4BE2AE742F6F75A2C9909111
- /data/media/####/C7D1EBC8298B9F10810ACE8182FF9F7368DECDDB8B33D216
- /data/media/####/CF38A6B3AFEC5F8268DECDDB8B33D216
- /data/media/####/DD42EFFD7D447B6326BCB4E4E2A56444
- /data/media/####/DE9821D629A6A27C2F6F75A2C9909111
- /data/media/####/F38AD1990B5C0CE54E6AFBD26C127F4526BCB4E4E2A56444
- /data/media/####/FBA1FBFFF22E161BF648794234A2C7AE
- /data/media/####/XH.txt
- /data/media/####/__pasys_remote_banner.jar
- /data/media/####/bciwsrwxtetfdqddayoyoycx.zip
- /data/media/####/dzubitltxmfksyyqbsgnbwsz.zip
- /data/media/####/isoubvjeyiwlgbdqvcodbrpkf.zip
- /data/media/####/lidiesuktggpxumdsqdprinjzi.zip
- /data/media/####/lyxihpibuelkzmyftm.zip
- /data/media/####/mvbxmcrspkronllvrmaxfyuj.zip
- /data/media/####/nrbmpgeyumlbugciasbrhs.zip
- /data/media/####/obbaedurnzxccfmfab.zip
- /data/media/####/ooa001.jar
- /data/media/####/owurpwrrogfpxznxx.zip
- /data/media/####/rszmaldszvlqhxjozdfomefit.zip
- /data/media/####/ulgep
- /data/media/####/ulgep.zip
- /data/media/####/umgep
- /data/media/####/umgep.zip
- /data/media/####/uygep
- /data/media/####/uygep.zip
- /data/media/####/wubhtkpdybxcdsgqojc.zip
- /data/media/####/zwaikj
- <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 2832
- <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 2946
- <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 3069
- <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 3246
- <Package> <Package> -1835455720 0 /data/app/<Package>-1.apk 41 <Package> 46 47 1 0
- <Package> <Package> -1836455144 0 /data/app/<Package>-1.apk 41 <Package> 43 44 1 0
- <Package> <Package> -1836455144 0 /data/app/<Package>-1.apk 41 <Package> 46 47 1 0
- <Package> <Package> -1836455144 0 /data/app/<Package>-1.apk 41 <Package> 48 50 1 0
- chmod 755 <Package Folder>/.cache/<Package>
- chmod 755 <Package Folder>/.cache/<Package>.art
- chmod 755 <Package Folder>/.cache/<Package>.art.20
- chmod 777 <Package Folder>/zwaikj
- getprop ro.product.cpu.abi
- sh <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 2832
- sh <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 2946
- sh <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 3069
- sh <Package Folder>/zwaikj -p <Package> -r am start --user 0 -n <Package>/ytdu.tx.wsfmgu -a daemon -h http://127.0.0.1:7123/report/allData -i 3246
- game
- libsecexe.x86
- DES
- RSA-ECB-PKCS1Padding
- DES
- DES-CBC-PKCS5Padding