Technical information
- Android.Click.234
- Android.RemoteCode.88.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) net.salmo####.com:80
- TCP(HTTP/1.1) www.cu####.com:80
- TCP(HTTP/1.1) www.zfr####.com:80
- TCP(HTTP/1.1) api.salmo####.com:80
- a####.u####.com
- api.salmo####.com
- net.salmo####.com
- www.cu####.com
- www.zfr####.com
- www.cu####.com/20170907171543.ExpDex_5.2.1_201709071714.zip
- www.zfr####.com/up.do
- <Package Folder>/databases/cc.db
- <Package Folder>/databases/cc.db-journal
- <Package Folder>/databases/downloads.db-journal
- <Package Folder>/databases/fire.api.db-journal
- <Package Folder>/databases/ua.db
- <Package Folder>/databases/ua.db-journal
- <Package Folder>/databases/user_domino-journal
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/####/sr_agent_log
- <Package Folder>/files/d.zip
- <Package Folder>/files/d.zip (deleted)
- <Package Folder>/files/dtemp.apk
- <Package Folder>/files/exid.dat
- <Package Folder>/files/ob1.zip
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/shared_prefs/AdVisitConfig.xml
- <Package Folder>/shared_prefs/DeviceConfig.xml
- <Package Folder>/shared_prefs/GlobalConfig.xml
- <Package Folder>/shared_prefs/HijackConfig.xml
- <Package Folder>/shared_prefs/StrategyConfig.xml
- <Package Folder>/shared_prefs/UserConfig.xml
- <Package Folder>/shared_prefs/cn_rs.xml
- <Package Folder>/shared_prefs/fire_sp.xml
- <Package Folder>/shared_prefs/fire_sp.xml.bak
- <Package Folder>/shared_prefs/fire_sp.xml.bak (deleted)
- <Package Folder>/shared_prefs/m_cfg.xml
- <Package Folder>/shared_prefs/m_cfg.xml (deleted)
- <Package Folder>/shared_prefs/sdk_scl_pid_config.xml
- <Package Folder>/shared_prefs/t_ini.xml
- <Package Folder>/shared_prefs/t_ini.xml (deleted)
- <Package Folder>/shared_prefs/t_ini.xml.bak
- <Package Folder>/shared_prefs/t_ini.xml.bak (deleted)
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <SD-Card>/.googlex9/.xamdecoq0962
- <SD-Card>/Android/####/83f760269276683211d805cb5a4281cd
- <SD-Card>/Android/####/e68dc6d37bbe5f40fed85418ba064019