Technical information
- Adware.Plague.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) serv####.dressup####.com:80
- TCP(TLS/1.0) d####.fl####.com:443
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- d####.fl####.com
- serv####.dressup####.com
- t.q####.com
- t1.q####.com
- serv####.dressup####.com/analytics/csv_merge/upload/v1.3/
- a####.u####.com/app_logs
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- serv####.dressup####.com/analytics/csv_merge/upload/v1.3/
- /data/data/####/.FlurrySenderIndex.info.AnalyticsData_43CGQJRGW...PW_171
- /data/data/####/.FlurrySenderIndex.info.AnalyticsMain
- /data/data/####/.flurryagent.-14cc4f3
- /data/data/####/.flurrydatasenderblock.16d70e48-4a74-41e5-8491-...bda02a
- /data/data/####/.flurrydatasenderblock.25c87f53-66ce-44dc-9526-...33a4f3
- /data/data/####/.flurrydatasenderblock.2a641b80-fd69-4d8e-9a72-...67064c
- /data/data/####/.flurrydatasenderblock.35e948b4-7020-45ad-a747-...c0d42d
- /data/data/####/.flurrydatasenderblock.36629465-14a0-4e07-b718-...bebe22
- /data/data/####/.flurrydatasenderblock.3af59659-b4af-4d20-8659-...ab65a7
- /data/data/####/.flurrydatasenderblock.3bb404cd-8412-4657-bb9d-...e1044b
- /data/data/####/.flurrydatasenderblock.41118e01-f6d4-429b-a5d8-...7b8319
- /data/data/####/.flurrydatasenderblock.55366d57-1474-4767-9ad7-...38ef7c
- /data/data/####/.flurrydatasenderblock.5e0b9414-377a-4421-82b0-...23a863
- /data/data/####/.flurrydatasenderblock.657e62f3-6582-4fcf-9604-...c6cb81
- /data/data/####/.flurrydatasenderblock.6eedf735-e460-493b-adaa-...08a78e
- /data/data/####/.flurrydatasenderblock.729e8f46-165c-4ad3-ac8b-...e6f2a2
- /data/data/####/.flurrydatasenderblock.7804d20e-d7e0-4a34-becb-...ac8961
- /data/data/####/.flurrydatasenderblock.84ebd163-3d44-465f-b166-...d5bbec
- /data/data/####/.flurrydatasenderblock.85aacb9a-23bb-43a7-a005-...344b15
- /data/data/####/.flurrydatasenderblock.9af89e29-2728-482b-853c-...49eb40
- /data/data/####/.flurrydatasenderblock.a1777436-f8d9-4d3c-b037-...e875fe
- /data/data/####/.flurrydatasenderblock.a3047259-c774-4347-bf01-...4e036d
- /data/data/####/.flurrydatasenderblock.a816e022-233a-4f5f-8832-...cf9335
- /data/data/####/.flurrydatasenderblock.b29a792d-a8de-4a61-90e1-...5ed71d
- /data/data/####/.flurrydatasenderblock.b4c9af3f-e65d-4268-9fbc-...1341ea
- /data/data/####/.flurrydatasenderblock.c3f0fc88-1593-4e9d-afd1-...110688
- /data/data/####/.flurrydatasenderblock.d0e2be62-f5fe-478e-98eb-...bf9b5f
- /data/data/####/.flurrydatasenderblock.d4a36a56-baa1-471a-aee5-...f9abeb
- /data/data/####/.flurrydatasenderblock.df2e0865-b422-407e-b9e4-...81bae3
- /data/data/####/.flurrydatasenderblock.e09832e6-5216-428b-9cb7-...5c2533
- /data/data/####/.flurrydatasenderblock.e64fb384-24b6-432b-9355-...6ab38a
- /data/data/####/.flurrydatasenderblock.ec86e67e-9936-418d-9928-...0da1e3
- /data/data/####/.flurrydatasenderblock.ed0e8006-ba29-4bd7-bd44-...b28a56
- /data/data/####/.flurrydatasenderblock.fe8323b9-62e1-4624-bf2d-...f1f2e9
- /data/data/####/.flurrydatasenderblock.ffc7401a-7d15-47a2-aa44-...d82896
- /data/data/####/.imprint
- /data/data/####/AnalyticsShar.xml
- /data/data/####/bugly_db_lejiagu-journal
- /data/data/####/classes.jar
- /data/data/####/dbsmlv-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/legu_900015015.xml
- /data/data/####/libshella-2.4.2.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/mobclick_agent_cached_com.fgds.baixuegongzhumoh...160908
- /data/data/####/native_record_lock
- /data/data/####/security_info
- /data/data/####/sharedPre_flurry.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libshella-2.4.2.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- Bugly
- cocos2dcpp
- libshella-2.4.2
- AES-GCM-NoPadding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES-GCM-NoPadding