Technical information
- Adware.Plague.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) d.show####.com:80
- TCP(HTTP/1.1) pic.leh####.com.####.com:80
- TCP(HTTP/1.1) hm.b####.com:80
- TCP(HTTP/1.1) p####.leh####.com.####.com:80
- TCP(HTTP/1.1) api.w####.com:80
- TCP(HTTP/1.1) p####.show####.com.####.com:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(HTTP/1.1) m.show####.com:80
- TCP(HTTP/1.1) cgi.con####.qq.com:80
- TCP(TLS/1.0) xz1.aaf####.cc.####.com:443
- TCP(TLS/1.0) e1.leh####.com:443
- TCP 54.2####.228.8:5333
- ap.ga####.com
- ap1.ga####.com
- ap2.ga####.com
- api.w####.com
- cgi.con####.qq.com
- d.show####.com
- d2.show####.com
- e1.leh####.com
- hm.b####.com
- loc.map.b####.com
- m.show####.com
- p####.leh####.com
- p####.show####.com
- pic.leh####.com
- xz1.aaf####.cc
- api.w####.com/oauth2/getaid.json?appkey=####&mfp=####&packagename=####&k...
- cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?sdkv=####&appid=###...
- d.show####.com/down+91.html
- hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
- hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
- hm.b####.com/hm.js?8ce1ca6####
- m.show####.com/css/download.css
- m.show####.com/favicon.ico
- m.show####.com/img/bg1.jpg
- m.show####.com/img/bg2.jpg
- m.show####.com/img/bg3.jpg
- m.show####.com/img/bg4.jpg
- m.show####.com/img/bg5.jpg
- m.show####.com/img/btn.png
- m.show####.com/img/weixin_tishi.png
- m.show####.com/piracy
- p####.leh####.com.####.com/event/poster/1473744242_9071.jpg
- p####.leh####.com.####.com/event/poster/1496307400_1073.jpg
- p####.leh####.com.####.com/event/poster/1496991063_9214.jpg
- p####.leh####.com.####.com/event/poster/1497411546_226.jpg
- p####.leh####.com.####.com/event/poster/1499154705_7643.jpg
- p####.leh####.com.####.com/event/poster/1523965485_4579.jpg
- p####.leh####.com.####.com/event/poster/1526473820_8979.jpg
- p####.leh####.com.####.com/operation/level1/shall_level_H2.png
- p####.leh####.com.####.com/operation/level1/shall_level_H3.png
- p####.leh####.com.####.com/operation/level1/shall_level_H4.png
- p####.leh####.com.####.com/operation/level1/shall_level_H5.png
- p####.leh####.com.####.com/operation/level1/shall_level_H6.png
- p####.leh####.com.####.com/operation/level1/shall_level_H7.png
- p####.leh####.com.####.com/operation/level1/shall_level_X2.png
- p####.leh####.com.####.com/operation/level1/shall_level_X4.png
- p####.show####.com.####.com/js/common/jquery-1.9.1.js
- pic.leh####.com.####.com/avatar/avatar01-1520857949694876.jpg@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1522686101108331.png@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1523889739742188.jpg@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1524393152156151.jpg@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1524471044265481.jpg@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1524834835923358.jpg@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1525956608844728.png@!style_l
- pic.leh####.com.####.com/avatar/avatar01-1526338665440827.jpg@!style_p
- pic.leh####.com.####.com/avatar/avatar01-1526369224315244.jpg@!style_p
- pic.leh####.com.####.com/avatar/avatar01-1526382799540981.jpg@!style_p
- pic.leh####.com.####.com/avatar/avatar01-1526427507525712.jpg@!style_l
- loc.map.b####.com/sdk.php
- /data/data/####/120093733-1080029749
- /data/data/####/120093733-1158585011
- /data/data/####/120093733-1281172895
- /data/data/####/120093733-132098452
- /data/data/####/120093733-1400437440
- /data/data/####/120093733-1737131197
- /data/data/####/120093733-1747528147
- /data/data/####/120093733-94364750
- /data/data/####/1200937331423708298
- /data/data/####/120093733400058391
- /data/data/####/120093733568191908
- /data/data/####/1689457630-1969343737
- /data/data/####/80204637-454365108
- /data/data/####/80204637-456212150
- /data/data/####/80204637-909660961
- /data/data/####/80204637-910584482
- /data/data/####/80204637-911508003
- /data/data/####/80204637-912431524
- /data/data/####/80204637-913355045
- /data/data/####/80204637-914278566
- /data/data/####/833579088-1083919280
- /data/data/####/833579088-1330840998
- /data/data/####/833579088-155072736
- /data/data/####/833579088-1647293428
- /data/data/####/833579088-322467637
- /data/data/####/833579088-422425372
- /data/data/####/classes.jar
- /data/data/####/com.haifan.tianiogpwtetas_preferences.xml
- /data/data/####/com.haifan.tianiogpwtetas_preferences.xml.bak
- /data/data/####/com.tencent.open.config.json.1104567533
- /data/data/####/dbrabv-journal
- /data/data/####/foxmessage.db
- /data/data/####/foxmessage.db-journal
- /data/data/####/lehai_achievement_switch.xml
- /data/data/####/lehai_find_switch.xml
- /data/data/####/lehai_other_switch.xml
- /data/data/####/lehai_store_switch.xml
- /data/data/####/login_info.xml
- /data/data/####/luckuser_info.xml
- /data/data/####/md5_info.xml
- /data/data/####/media_db-journal
- /data/data/####/myLoginInfo.xml
- /data/data/####/note.xml
- /data/data/####/pref_key.xml
- /data/data/####/showself_guide.xml
- /data/data/####/system_info.xml
- /data/data/####/tencent_analysis.db-journal
- /data/media/####/.cuid
- /data/media/####/con.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/yoh.dat
- /data/media/####/yol.dat
- /data/media/####/yom.dat
- aes
- locSDK4
- weibosdkcore
- AES-CBC-PKCS5Padding
- DES
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- DES