Technical information
- Android.HiddenAds.79.origin
- Android.Xiny.1.origin
- Android.HiddenAds.79.origin
- 1####.####.95
- 1####.####.95:8031
- 24113e8####.####.com
- 3460dc7####.####.com
- 94d9733####.####.com
- a####.####.com
- a15ec9a####.####.net
- a375783####.####.net
- a76b95a####.####.net
- a82d0b4####.####.net
- ae34e69####.####.net
- afdec6c####.####.net
- api-ce####.####.org
- busines####.com
- c####.####.co
- c####.####.com
- c####.####.net
- c####.####.org
- c2f2208####.####.com
- ce####.####.org
- cloudfr####.####.com
- con####.####.net
- d####.####.com
- d####.####.net
- e####.####.com
- e####.####.com:8088
- f####.####.com
- feedp####.####.com
- gl####.####.com
- h####.com
- i####.####.com
- m####.####.com
- m####.####.nl
- n####.nl
- p####.####.com
- po####.####.com:84
- s####.####.com
- st####.####.com
- sta####.####.de
- stat####.####.com
- syn####.####.net
- t####.####.com
- teleg####.nl
- tra####.####.com
- u####.####.com
- 1####.####.95/m/umeng:58eb5c26c8957657a0000583/601/At0U3YyreKS0D0m04csoq...
- 1####.####.95:8031/m/umeng:58eb5c26c8957657a0000583/601/At0U3YyreKS0D0m0...
- 24113e8####.####.com/597eadea761f554803cb99b4_500x286.jpg
- 3460dc7####.####.com/5980dc14761f554803ff65aa_500x331.jpg
- 94d9733####.####.com/59825f8f761f55480326fec5_500x375.jpg
- a####.####.com/2017/08/03/095110289.zip
- a####.####.com/api/s2s/goto?id=####&channel=####&provider=####&iid=####&...
- a####.####.com/articles/59805763761f554803f28f7d
- a####.####.com/link/buy/android/com.accor.appli.hybrid/e1?clinkID=####&p...
- a15ec9a####.####.net/test.png
- a375783####.####.net/test.png
- a76b95a####.####.net/test.png
- a82d0b4####.####.net/test.png
- ae34e69####.####.net/test.png
- afdec6c####.####.net/test.png
- api-ce####.####.org/v3/commentlist-1511717-8940347a77c5dec111cb133d956a3...
- busines####.com/tesla-model-s-assist-uss-u2-spy-planes-during-takeoff-20...
- c####.####.co/api/v4/click?campaign_id=####&publisher_id=####&rt=####&_p...
- c####.####.com/cms?partner_id=####
- c####.####.com/dp/navegg.php?pid=####&uid=####
- c####.####.com/files/0f2ce5a615946c8eb2ffce96f6365687
- c####.####.net/pixel?google_nid=####&google_cm=####&id=####&google_tc=####
- c####.####.org/2017-07-04/9098e514a90a687f951299c684e2c0d8.jpg
- c####.####.org/v2/system/models-99.json
- c2f2208####.####.com/54b64cfa07830f459b000000.ico
- ce####.####.org/v3/system/countrys.json
- cloudfr####.####.com/x.png
- con####.####.net/en_US/sdk.js
- d####.####.com/r/dd/id/L2NzaWQvMS9jaWQvMjYzNTYzMzIvdC8y/dpuid/33571616633/
- d####.####.net/ibs:dpid=822&dpuuid=33571616633&redir=https%3A//sync.navd...
- f####.####.com/css?family=####
- f####.####.com/s/opensans/v14/cJZKeOuBrn4kERxqtaUH3SZ2oysoEQEeKwjgmXLRnT...
- f####.####.com/tl?a=####&o=####&s1=####&sc=####&s3=####&s4=####
- feedp####.####.com/~r/businessinsider/~3/DeAJnBQVyBg/tesla-model-s-assis...
- gl####.####.com/trace?offer_id=####&app_id=####&type=####&aff_sub=####&a...
- h####.com/article/59805f43761f554803f33cae
- i####.####.com/s
- m####.####.nl/buitenland/article/28830878/brandweerman-ontdekt-dode-doch...
- n####.nl/static/CACHE/js/4f97031e47b9.js
- p####.####.com/sync/img?redir=####&mm####&mm####
- p####.####.com/ul_cb/aa/y8a2thbi7v8xdodcoa82
- p####.####.com/ups/19764/sync?uid=####&_origin=####&redir=####&verify=####
- s####.####.com/sync?prtid=####&id=####&google_gid=####&google_cver=####
- st####.####.com/c/hotjar-113364.js?sv=####
- sta####.####.de/image/5981ed048754330cb7238db0-1318/screen%20shot%202017...
- stat####.####.com/connect/xd_arbiter/r/XBwzv5Yrm_1.js?version=####
- syn####.####.net/upi/pid/DuqQKWX7/?redir=####
- t####.####.com/?aff_id=####&offer_id=####&aff_sub2=####&aff_sub=####
- t####.####.com/?offer_id=####&pub_id=####&google_aid=####&aff_sub=####&i...
- t####.####.com/agentapi/click?cid=####&aid=####&postbac####
- t####.####.com/req?v=####&id=####&acc=####&tit=####
- t####.####.com/site/31436?dt=####&r=####&sig=####&bkca=####
- t####.####.com/utag/tmggroup/telegraaf-mobile/prod/utag.sync.js
- teleg####.nl/graphics/videopage/play25.474a26e5402cfd0d6409653450650986....
- tra####.####.com/redir/?tgds=####&tgda=####&tgdid=####&tgdredir=####
- u####.####.com/spdyip/?appkey=####&ttid=####&deviceId=####&imei=####&nt=...
- a####.####.com/app_logs
- e####.####.com/e
- e####.####.com/sdk/api/regclient
- e####.####.com:8088/sdk/api/ad/hull_v2
- m####.####.com/v2/register
- po####.####.com:84/sdk/aff_getpolicy
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_cache/ApplicationCache.db-journal (deleted)
- <Package Folder>/app_dex/reach-sdk.zip
- <Package Folder>/app_dex/reach-sdk.zip.tmp
- <Package Folder>/app_tmpdex/reach-sdk.zip
- <Package Folder>/cache/####/542324769-1749282151
- <Package Folder>/cache/####/6016474671982023963
- <Package Folder>/cache/####/data_0
- <Package Folder>/cache/####/data_0 (deleted)
- <Package Folder>/cache/####/data_1
- <Package Folder>/cache/####/data_1 (deleted)
- <Package Folder>/cache/####/data_2
- <Package Folder>/cache/####/data_2 (deleted)
- <Package Folder>/cache/####/data_3
- <Package Folder>/cache/####/data_3 (deleted)
- <Package Folder>/cache/####/f_000001
- <Package Folder>/cache/####/f_000002
- <Package Folder>/cache/####/f_000003
- <Package Folder>/cache/####/f_000004
- <Package Folder>/cache/####/f_000005
- <Package Folder>/cache/####/f_000006
- <Package Folder>/cache/####/f_000007
- <Package Folder>/cache/####/f_000008
- <Package Folder>/cache/####/f_000009
- <Package Folder>/cache/####/f_00000a
- <Package Folder>/cache/####/f_00000b
- <Package Folder>/cache/####/f_00000c
- <Package Folder>/cache/####/f_00000d
- <Package Folder>/cache/####/f_00000e
- <Package Folder>/cache/####/f_00000f
- <Package Folder>/cache/####/f_000010
- <Package Folder>/cache/####/f_000011
- <Package Folder>/cache/####/f_000012
- <Package Folder>/cache/####/f_000013
- <Package Folder>/cache/####/f_000014
- <Package Folder>/cache/####/f_000015
- <Package Folder>/cache/####/f_000016
- <Package Folder>/cache/####/f_000017
- <Package Folder>/cache/####/f_000018
- <Package Folder>/cache/####/f_000019
- <Package Folder>/cache/####/f_00001a
- <Package Folder>/cache/####/index
- <Package Folder>/cache/####/index (deleted)
- <Package Folder>/databases/MsgLogStore.db-journal
- <Package Folder>/databases/UmengLocalNotificationStore.db-journal
- <Package Folder>/databases/Zuoyoo_db
- <Package Folder>/databases/Zuoyoo_db-journal
- <Package Folder>/databases/app.manager-journal
- <Package Folder>/databases/com.amplitude.api
- <Package Folder>/databases/com.amplitude.api-journal
- <Package Folder>/databases/db_snowfox.db
- <Package Folder>/databases/db_snowfox.db-journal
- <Package Folder>/databases/droid_clean_event
- <Package Folder>/databases/droid_clean_event-journal
- <Package Folder>/databases/reach.database.ad-journal
- <Package Folder>/databases/snowfoxad_msg.db
- <Package Folder>/databases/snowfoxad_msg.db-journal
- <Package Folder>/databases/virgo_mpsp.db
- <Package Folder>/databases/virgo_mpsp.db-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/databases/webviewCookiesChromium.db-journal
- <Package Folder>/databases/webviewCookiesChromium.db-journal (deleted)
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/####/libadecloc.so
- <Package Folder>/files/.YFlurrySenderIndex.info.AnalyticsData_68ZGVS9TVHMTQ54WBGK9_216
- <Package Folder>/files/.YFlurrySenderIndex.info.AnalyticsMain
- <Package Folder>/files/.imprint
- <Package Folder>/files/.yflurrydatasenderblock.82740a3f-9266-48b3-9d6c-4f7574fac794
- <Package Folder>/files/.yflurryreport.-19a1baa3c3b56721
- <Package Folder>/files/<Package>.zip
- <Package Folder>/files/DaemonServer
- <Package Folder>/files/agoo.pid
- <Package Folder>/files/dat.dat
- <Package Folder>/files/lib.dat
- <Package Folder>/files/mesosphere.jar
- <Package Folder>/files/mesosphere.so
- <Package Folder>/files/snowfox_sdk_so-v22d.jar
- <Package Folder>/files/snowfox_v22d.jar
- <Package Folder>/files/snowfox_v22d.so
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/shared_prefs/<Package>_preferences.xml
- <Package Folder>/shared_prefs/<Package>_preferences.xml.bak
- <Package Folder>/shared_prefs/AGOO_CONNECT.xml
- <Package Folder>/shared_prefs/AGOO_HOST.xml
- <Package Folder>/shared_prefs/Alvin2.xml
- <Package Folder>/shared_prefs/AppStore.xml
- <Package Folder>/shared_prefs/AppStore.xml.bak
- <Package Folder>/shared_prefs/BSModelForPlaced.xml
- <Package Folder>/shared_prefs/ContextData.xml
- <Package Folder>/shared_prefs/CountryRelevant.xml
- <Package Folder>/shared_prefs/CurArticleInfo.xml
- <Package Folder>/shared_prefs/FLURRY_SHARED_PREFERENCES.xml
- <Package Folder>/shared_prefs/GATHER.xml
- <Package Folder>/shared_prefs/GATHER.xml.bak
- <Package Folder>/shared_prefs/MASTER_DATA.xml
- <Package Folder>/shared_prefs/Module_Switch_DATA.xml
- <Package Folder>/shared_prefs/Module_Switch_DATA.xml.bak
- <Package Folder>/shared_prefs/PhoneUtil.xml
- <Package Folder>/shared_prefs/Prophet.xml
- <Package Folder>/shared_prefs/Reach.xml
- <Package Folder>/shared_prefs/Reach.xml.bak
- <Package Folder>/shared_prefs/WebViewSettings.xml
- <Package Folder>/shared_prefs/com.amplitude.api.<Package>.xml
- <Package Folder>/shared_prefs/coolook.minisite.xml
- <Package Folder>/shared_prefs/multidex.version.xml
- <Package Folder>/shared_prefs/snowfoxprf.xml
- <Package Folder>/shared_prefs/sp_cache.xml
- <Package Folder>/shared_prefs/sp_cache.xml.bak
- <Package Folder>/shared_prefs/test.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml.bak
- <Package Folder>/shared_prefs/umeng_message_state.xml
- <Package Folder>/shared_prefs/updateVer.xml
- <Package Folder>/shared_prefs/v2_local_login.xml
- <SD-Card>/.DataStorage/ContextData.xml
- <SD-Card>/.UTSystemConfig/####/Alvin2.xml
- <SD-Card>/<Package>/####/9098e514a90a687f951299c684e2c0d8.jpg
- <SD-Card>/Android/####/.nomedia
- <SD-Card>/Android/####/1z6zvfpz292r66bw5lmgi6f8b.0.tmp
- <SD-Card>/Android/####/25rq5n07ym2zjjisy8bf92jc0.0.tmp
- <SD-Card>/Android/####/2ql0blcc9oztuoqwf5zxfinte.0.tmp
- <SD-Card>/Android/####/3531AC0BBCED63E3DAA47C07EE788ABB
- <SD-Card>/Android/####/4iy7jxd7mwrjkadxsu7xh0o2j.0.tmp
- <SD-Card>/Android/####/59bdjkv1xkb26ovo7t487fgha.0
- <SD-Card>/Android/####/5j5d90d4rstsz20wimgudy55o.0.tmp
- <SD-Card>/Android/####/5pkon9g2vsjkxno38qbwi40nh.0.tmp
- <SD-Card>/Android/####/6i37snv1m9z7hxvuic474q7jn.0
- <SD-Card>/Android/####/72ua7q3op5xoe7k7l5r4xq8ne.0.tmp
- <SD-Card>/Android/####/794067776576665AEA3729A3D76B3760
- <SD-Card>/Android/####/delay_20170727073845674_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073857693_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073901950_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073906270_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073908268_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073911569_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073914135_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073914985_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073915706_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073921081_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/delay_20170727073921241_8940347a77c5dec111cb133d956a3a1b_s.dat
- <SD-Card>/Android/####/dev_936bcda4.txt
- <SD-Card>/Android/####/imei.txt
- <SD-Card>/Android/####/journal.tmp
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -a <Package>.intent.action.COCKROACH --es cockroach cockroach-PPreotect --es pack <Package> --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 9527 -U tb_android_daemon_1.1.0 -L http://100.69.168.33/agoo/report -D %7B%22package%22%3A%22<Package>%22%2C%22appKey%22%3A%22umeng%3A58eb5c26c8957657a0000583%22%2C%22utdid%22%3A%22WXmYg6Z%2F3wcDAGdzx1G5cdnE%22%2C%22sdkVersion%22%3A%2220151015%22%7D -I 100.69.168.33 -O 80 -T -Z
- chmod 500 <Package Folder>/files/DaemonServer
- chmod 755 /data/data/com.poboo.news.headline/.jiagu/libjiagu.so
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- sh
- libadecloc
- libjiagu
- tnet-2.1.20
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- DES
- AES
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding