Technical information
- Android.Triada.248.origin
- Android.Triada.309
- Android.Triada.373.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.75.3.32:8961
- TCP(HTTP/1.1) dl.api.kxcon####.com:80
- TCP(HTTP/1.1) api.klaun####.com:80
- TCP(HTTP/1.1) deliver####.leji####.com:80
- TCP(HTTP/1.1) d365####.cdn.uc####.####.cn:80
- TCP(HTTP/1.1) ads####.cf.lov####.####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) x####.kap####.com:80
- TCP(HTTP/1.1) api.ila####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) ads####.cr.lov####.####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) api.kxcon####.com:666
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) rcv.ila####.com:80
- TCP(HTTP/1.1) mo####.b####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) si####.jom####.com:80
- TCP(HTTP/1.1) lar####.c####.l####.####.com:80
- TCP(HTTP/1.1) 1####.75.3.32:8881
- TCP(HTTP/1.1) ws1.xiangyu####.com:80
- TCP(HTTP/1.1) ads####.cs.lov####.####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) p####.k####.com:80
- TCP(HTTP/1.1) c####.b####.com:80
- TCP(HTTP/1.1) ip.izhu####.com:80
- TCP(TLS/1.0) yun.t####.cn:443
- TCP(TLS/1.0) cpu.b####.com:443
- TCP(TLS/1.0) wn.pos.b####.com:443
- TCP(TLS/1.0) ws1.xiangyu####.com:443
- TCP(TLS/1.0) publish####.b####.com.####.com:443
- TCP(TLS/1.0) ec####.b####.com:443
- TCP(TLS/1.0) en####.lveha####.com:443
- TCP(TLS/1.0) pos.b####.com:443
- TCP(TLS/1.0) cac####.b####.com:443
- TCP(TLS/1.0) c####.b####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) hpd.b####.com:443
- TCP(TLS/1.0) g####.bdst####.com:443
- TCP(TLS/1.0) si####.jom####.com:443
- TCP c####.g####.ig####.com:5225
- TCP sdk.o####.t####.####.com:5224
- 7fki####.cf.lov####.com
- 7fki####.cr.lov####.com
- 7fki####.cs.lov####.com
- 7j####.c####.z0.####.com
- a####.u####.com
- api.ila####.com
- api.klaun####.com
- api.kxcon####.com
- c####.b####.com
- c####.g####.ig####.com
- c-h####.g####.com
- cac####.b####.com
- cdn.lov####.com
- cpu.b####.com
- deliver####.leji####.com
- dl.api.kxcon####.com
- ec####.b####.com
- en####.lveha####.com
- f10.b####.com
- f12.b####.com
- g####.bdst####.com
- g####.bdst####.com
- hm.b####.com
- hpd.b####.com
- ip.izhu####.com
- kdyn####.u####.uc####.####.cn
- l####.tbs.qq.com
- lu####.b####.com
- mo####.b####.com
- p####.k####.com
- pos.b####.com
- publish####.b####.com
- rcv.ila####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t10.b####.com
- t11.b####.com
- t12.b####.com
- wn.pos.b####.com
- ws1.xiangyu####.com
- x####.kap####.com
- yun.t####.cn
- ads####.cf.lov####.####.com//getresdomain.php?chid=####&vercode=####&cpm...
- ads####.cf.lov####.####.com/sdkstctr.php?chid=####&cpmeta=####&vercode=#...
- ads####.cr.lov####.####.com/chksdkupdate.php?chid=####&sdkver=####&mainv...
- ads####.cs.lov####.####.com/gensdkuser.php?chid=####&cpmeta=####&vercode...
- ads####.cs.lov####.####.com/pickoverlay.php?chid=####&cpmeta=####&vercod...
- ads####.cs.lov####.####.com/picksdkgame.php?chid=####&cpmeta=####&vercod...
- ads####.cs.lov####.####.com/sdkstatistics.php?action=####&data=ey####
- api.ila####.com/c/_i_?_=####
- api.ila####.com/c/szssl_16_sdk
- api.ila####.com/e/i.html
- api.ila####.com/e/i.js
- api.ila####.com/update_ch/common/core.jar
- api.ila####.com/update_ch/common/coreconfig.jar
- api.klaun####.com/v1/card/gettime/
- api.klaun####.com/v2/config/funclist?cid=####
- api.klaun####.com/v2/config/getPal
- api.klaun####.com/v2/config/getService
- c####.b####.com/cpro/ui/uijs.php?en=####&adx=####&c=####&cf=####&cp=####...
- c####.b####.com/cpro/ui/uijs.php?rs=####&u=####&p=####&c=####&n=####&t=#...
- d365####.cdn.uc####.####.cn/1521473393183_utils.ttf
- deliver####.leji####.com/emitControl/emitAppList
- ip.izhu####.com/cleanball/cityverify
- lar####.c####.l####.####.com/mainjarupdate/gamesdk/empty/empty109/150500...
- lar####.c####.l####.####.com/vmupdate/pack/empty/empty/51107/vm_x86/109/...
- mo####.b####.com/cpro/ui/mads.php?u=####&fwt=####&func=####&ie=####&n=##...
- rcv.ila####.com/report2?t=####&h1=####&c=####&v=####&op1=####&op2=####&n...
- si####.jom####.com/it/u=2383638222,3419487030&fm=76
- si####.jom####.com/it/u=2594222363,3786436383&fm=76
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_TSb400
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a####.u####.com/app_logs
- api.kxcon####.com:666/v1/config
- c-h####.g####.com/api.php?format=####&t=####
- dl.api.kxcon####.com/v2/load/mobile
- l####.tbs.qq.com/ajax?c=####&k=####
- l####.tbs.qq.com/ajax?c=####&v=####&k=####
- p####.k####.com/upload/event.jsp
- p####.k####.com/upload/sdklongheartbeat.jsp
- p####.k####.com/upload/shortheartbeat.jsp
- sdk.o####.p####.####.com/api.php?format=####&t=####
- ws1.xiangyu####.com/NewCounterlog/counterlogsnew.jsp
- x####.kap####.com/upload/longheartbeat.jsp
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lbsdk.jar.sinfo
- /data/data/####/7fe5893d36b0fe2bcb5883985f3f262ba2f3fff7fba0095....0.tmp
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/COUNTLY_STORE.xml
- /data/data/####/COUNTLY_STORE_PL.xml
- /data/data/####/LANQ7IiqRjkAvEHC.zip
- /data/data/####/LpFPFZTY-Uy67uqWtfQ9Zg==.new
- /data/data/####/WUAAzh0wB0A9BFO4b09tPg==
- /data/data/####/YjVe6-Qp28nq6X60i-JAWQ==.new
- /data/data/####/__x_adsdk_agent_header__.xml
- /data/data/####/alarm_sp_12.xml
- /data/data/####/alarm_sp_2.xml
- /data/data/####/android-util.ttf
- /data/data/####/android-util.zip
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/common_sp.xml
- /data/data/####/condition.xml.xml
- /data/data/####/core.jar.tm
- /data/data/####/core_info
- /data/data/####/coreconfig.jar.tm
- /data/data/####/corelib.tmp.jar
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/debug.conf
- /data/data/####/default.xml
- /data/data/####/defaultpref1.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/excl_lb_dloadInfo.xml
- /data/data/####/excl_lb_gameInfo.xml
- /data/data/####/excl_lb_md5Info.xml
- /data/data/####/excl_lb_queryInfo.xml
- /data/data/####/excl_lb_updateInfo.xml
- /data/data/####/excl_lb_userInfo.xml
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/f_000016
- /data/data/####/f_000017
- /data/data/####/f_000018
- /data/data/####/f_000019
- /data/data/####/f_00001a
- /data/data/####/f_00001b
- /data/data/####/file_multithreading_info.db-journal
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gqoug_f.zip
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/j6KNuayGVi-nNRdN-zmtRA==
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/journal.tmp
- /data/data/####/kboost_sp.xml
- /data/data/####/kk_spf.xml
- /data/data/####/lbsdk.jar.tmp
- /data/data/####/lbvmrt.jar.tmp
- /data/data/####/lebian_base.xml
- /data/data/####/libjiagu.so
- /data/data/####/log_report-journal
- /data/data/####/main.zip.dload
- /data/data/####/odddk.xml
- /data/data/####/pal.dat
- /data/data/####/pl_sp.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/rdata_comenrgyeyecon.new
- /data/data/####/run.pid
- /data/data/####/rws_sp.xml
- /data/data/####/share_file.xml
- /data/data/####/sp_config.xml
- /data/data/####/sp_file.xml
- /data/data/####/sp_rvp.xml
- /data/data/####/sp_rvp2.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_TSb400
- /data/data/####/tdata_TSb400.jar
- /data/data/####/tmp-595016485tmp
- /data/data/####/u3FLHdo7D_OjoTAx
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/vm.zip.dload
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromium.db-journal (deleted)
- /data/data/####/xconfig.xml
- /data/data/####/xsdk_preference.xml
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.system.cleanball.bin
- /data/media/####/com.system.cleanball.db
- /data/media/####/sdkinfo.txt
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_TSb400
- /data/media/####/test.log
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- <Package Folder>/files/gdaemon_20161017 0 <Package>/a.b.c.s.getui.GetuiDemoPushService 25014 300 0
- app_process /system/bin com.android.commands.pm.Pm list packages
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop ro.product.cpu.abi
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/a.b.c.s.getui.GetuiDemoPushService 25014 300 0
- applypatch
- getuiext2
- jni
- lbcrashhandler
- libjiagu
- AES-CBC-PKCS7Padding
- DESede-ECB-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- 1
- DES-CBC-PKCS5Padding