Technical information
- Adware.Youmi.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) bk####.10####.com:80
- TCP(HTTP/1.1) adash####.man.aliy####.com:80
- TCP(HTTP/1.1) log.sn####.com.####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) u####.u####.com:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) gtm.c####.qufen####.vip:443
- TCP(TLS/1.0) 64.2####.162.94:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) i.sn####.com.####.com:443
- TCP(TLS/1.0) 2####.107.1.97:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) is.sn####.com.####.net:443
- TCP(TLS/1.0) plb####.u####.com:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 64.2####.164.101:443
- TCP(TLS/1.2) 1####.177.14.104:443
- UDP pla####.google####.com:443
- UDP www.gst####.com:443
- TCP supe####.c####.com.####.com:443
- TCP ms####.m.u####.com:80
- 2####.nd####.y####.com
- 8####.nd####.y####.com
- a####.man.aliy####.com
- amdc####.m.ta####.com
- and####.b####.qq.com
- android####.go####.com
- aos.w####.y####.net
- bk####.10####.com
- gmscomp####.google####.com
- i.sn####.com
- is.sn####.com
- l####.tbs.qq.com
- log.sn####.com
- nb.qufen####.vip
- p####.google####.com
- pla####.google####.com
- plb####.u####.com
- rr2---s####.g####.com
- s####.gw.y####.net
- s.y####.net
- supe####.c####.com
- t####.dmp.y####.net
- u####.u####.com
- umen####.m.ta####.com
- umengj####.m.ta####.com
- www.gst####.com
- bk####.10####.com/BookCollect/bookCollectList?versionName=####&encryptId...
- bk####.10####.com/BookForm/bookFormList?versionName=####&imeiTime=####&p...
- bk####.10####.com/Index/quitAdvert?versionName=####&imeiTime=####&pid=##...
- bk####.10####.com/Index/welcomeAdvert?versionName=####&imeiTime=####&pid...
- bk####.10####.com/User/UserRegC?versionName=####&imeiTime=####&pid=####&...
- gtm.c####.qufen####.vip:443/v1/appupdate?_ts=####&_sign=####&_appid=####...
- gtm.c####.qufen####.vip:443/v1/getads?codeId=####&width=####&height=####...
- adash####.man.aliy####.com/man/api?ak=####&s=####
- and####.b####.qq.com/rqd/async?aid=####
- gtm.c####.qufen####.vip:443/v1/binduser
- gtm.c####.qufen####.vip:443/v1/init
- i.sn####.com.####.com:443/api/ad/union/sdk/stats/
- is.sn####.com.####.net:443/api/ad/union/sdk/get_ads/
- is.sn####.com.####.net:443/api/ad/union/sdk/settings/
- is.sn####.com.####.net:443/api/ad/union/sdk/upload/app_info/
- l####.tbs.qq.com/ajax?c=####&k=####
- log.sn####.com.####.com/service/2/app_log_exception/?os_api=####&device_...
- plb####.u####.com:443/umpx_internal
- u####.u####.com:443/unify_logs
- /data/com.mengmengda.free/####/0OO00l111l1l
- /data/com.mengmengda.free/####/bugly_db_yaq
- /data/data/####/-19833011771020646758
- /data/data/####/.dex2oatlock
- /data/data/####/.imprint
- /data/data/####/.updateIV.dat
- /data/data/####/0000000lllll_0.dex
- /data/data/####/0000000lllll_1.dex
- /data/data/####/000O00ll111l_0.dex
- /data/data/####/000O00ll111l_1.dex
- /data/data/####/00O000ll111l_0.dex
- /data/data/####/00O000ll111l_0.dex (deleted)
- /data/data/####/00O000ll111l_0.dex.flock
- /data/data/####/00O000ll111l_0.dex.flock (deleted)
- /data/data/####/00O000ll111l_1.dex
- /data/data/####/00O000ll111l_1.dex (deleted)
- /data/data/####/00O000ll111l_1.dex.flock
- /data/data/####/00O000ll111l_1.dex.flock (deleted)
- /data/data/####/0OO00l111l1l
- /data/data/####/0OO00l111l1l.lock
- /data/data/####/1004
- /data/data/####/1133113055-389582513
- /data/data/####/1137855445-1384185838
- /data/data/####/129280270683289207
- /data/data/####/1639560349-1138636772
- /data/data/####/1727755291151
- /data/data/####/1791002366788405166
- /data/data/####/1817858676-679988718
- /data/data/####/291de79acb0a9cd7835080f79c145c60-journal
- /data/data/####/726978221-294747075
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml.bak
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/ContextData.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/OxgHkj2lz09F
- /data/data/####/OxgHkj2lz09F-journal
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/a==7.5.4&&2.0.1_1727755245234_envelope.log
- /data/data/####/accs.db-journal
- /data/data/####/agoo.pid
- /data/data/####/bugly_db_-journal
- /data/data/####/bugly_db_yaq
- /data/data/####/bugly_db_yaq-journal
- /data/data/####/collection.xml
- /data/data/####/com.mengmengda.free_preferences.xml
- /data/data/####/com.mengmengda.freeinfoc_sdk_preferences.xml
- /data/data/####/com.mengmengda.freeinfoc_sdk_preferences.xml.bak
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNzI3NzU1MjQ0MTA1;
- /data/data/####/dd09232ce9af05ea7d90d9124ddbb52d
- /data/data/####/dd09232ce9af05ea7d90d9124ddbb52d-journal
- /data/data/####/debug.conf
- /data/data/####/downloader.db-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f724fb30145a8e3230a161ee5af750b4
- /data/data/####/f724fb30145a8e3230a161ee5af750b4-journal
- /data/data/####/httpdns_config_cache.xml
- /data/data/####/i==1.2.0&&2.0.1_1727755243749_envelope.log
- /data/data/####/info.xml
- /data/data/####/jni_log_1727755300834.txt
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/kctrl.dat
- /data/data/####/kfmt.dat
- /data/data/####/libCMBaseInfoc.so
- /data/data/####/libshellx-super.2019.so
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/map_record.txt
- /data/data/####/message_accs_db
- /data/data/####/message_accs_db-journal
- /data/data/####/metrics_guid
- /data/data/####/native_record_lock
- /data/data/####/o0oooOO0ooOo.dat
- /data/data/####/proc_auxv
- /data/data/####/reg_record.txt
- /data/data/####/rqd_record.eup
- /data/data/####/security_info
- /data/data/####/sys_log_1727755300834.txt
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tomb.zip
- /data/data/####/tomb_1727755244785.txt
- /data/data/####/tomb_1727755262902.txt
- /data/data/####/tosversion
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopenadsdk.xml.bak
- /data/data/####/ttopensdk.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/data/####/ymdex.dex
- /data/data/####/ymdex.dex.flock (deleted)
- /data/data/####/ymdex.jar
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/i42d45df023jnkdd93la483f9xGFKXI
- /data/media/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
- /data/media/####/tbslog.txt
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/cat /sys/devices/system/cpu/kernel_max
- /system/bin/sh -c getprop
- cat /sys/class/net/wlan0/address
- getprop
- getprop ro.build.version.emui
- getprop ro.letv.release.version
- getprop ro.product.cpu.abi
- getprop ro.vivo.os.build.display.id
- logcat -d -v threadtime -s dalvikvm art zygote zygote64 OpenGLRenderer Bugly-libunwind:S
- logcat -t 1000 -v threadtime Bugly-libunwind:S
- ls /
- ls /sys/class/thermal
- libBugly-yaq
- libCMBaseInfoc
- libabcdefgh
- libnms
- librealm-jni
- libshellx-super.2019
- libtnet-3.1.14
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- PBEWITHMD5andDES
- RC4
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- PBEWITHMD5andDES