Technical information
- Adware.Plague.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) md.ope####.360.cn:80
- TCP(HTTP/1.1) web.f####.w####.####.cn:80
- TCP(HTTP/1.1) api.f####.w####.####.cn:80
- TCP(HTTP/1.1) apilo####.a####.com:80
- TCP(HTTP/1.1) s.3####.cn:80
- TCP(HTTP/1.1) d####.360####.com:80
- TCP(HTTP/1.1) c####.w####.360.cn:80
- TCP(HTTP/1.1) ope####.mob####.360.cn:80
- TCP(HTTP/1.1) and####.api.36####.com:80
- TCP(HTTP/1.1) s0.q####.com:80
- TCP(HTTP/1.1) p0.q####.com:80
- TCP(SSL/3.0) s.ssl.q####.com:443
- TCP(TLS/1.0) s.ssl.q####.com:443
- TCP 1####.39.205.50:80
- an.ite####.com
- an1.ite####.com
- an2.ite####.com
- and####.api.36####.com
- api####.a####.com
- api.f####.w####.####.cn
- c####.w####.360.cn
- d####.360####.com
- free####.360.cn
- fzb.leidi####.com
- i.qs####.org
- md.ope####.360.cn
- ope####.mob####.360.cn
- p0.q####.com
- s.3####.cn
- s.ssl.q####.com
- s0.q####.com
- sta####.leidi####.com
- web.f####.w####.####.cn
- and####.api.36####.com/group/?method=####&n=####
- c####.w####.360.cn/intf.php?check_update_key=####&qid=####&devtype=####&...
- d####.360####.com/360mse/360mse_nb00091.apk
- ope####.mob####.360.cn/AppStore/getIsUpdate?pname=####&vercode=####&vern...
- p0.q####.com/t01207ab6afdc5a8fd4.png
- p0.q####.com/t01510ee2b01ec14bd8.png
- s.3####.cn/w360/s.htm?p=####&u=####&id=####&guid=####&b=####&c=####&r=##...
- s0.q####.com/monitor/;monitor/0ddb3eeb.js
- web.f####.w####.####.cn/conf/browser.html
- web.f####.w####.####.cn/resource/js/newsfeed/dataManager.js
- web.f####.w####.####.cn/resource/js/newsfeed/downApp.js
- web.f####.w####.####.cn/resource/js/newsfeed/loadList.js
- web.f####.w####.####.cn/resource/js/newsfeed/logForDJ.js
- web.f####.w####.####.cn/vest/index?t=####
- api.f####.w####.####.cn/intf.php?qid=####&devtype=####&nettype=####&manu...
- api.f####.w####.####.cn/intf.php?random=####&qid=####&devtype=####&netty...
- apilo####.a####.com/v3/log/init
- c####.w####.360.cn/intf.php?check_update_key=####&qid=####&devtype=####&...
- c####.w####.360.cn/intf.php?md5=####&qid=####&devtype=####&nettype=####&...
- c####.w####.360.cn/intf.php?qid=####&devtype=####&nettype=####&manufactu...
- md.ope####.360.cn/list/get?product=####&version=####
- web.f####.w####.####.cn/intf.php?qid=####&devtype=####&nettype=####&manu...
- /data/data/####/-1633430244-738756840
- /data/data/####/.jg.ic
- /data/data/####/360freewifi.db-journal
- /data/data/####/360freewifi_push.xml
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/GlobalFlag.xml
- /data/data/####/GlobalFlag.xml.bak
- /data/data/####/QH_SDK_M2.xml
- /data/data/####/QH_SDK_UserData.xml
- /data/data/####/QH_SDK_sessionID.xml
- /data/data/####/apk_info.xml
- /data/data/####/business_info.db-journal
- /data/data/####/classes.jar
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dbitnz-journal
- /data/data/####/deamon_wifi_1_1
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/hongbao_pref.xml
- /data/data/####/index
- /data/data/####/keep_alive2
- /data/data/####/last_know_location.xml
- /data/data/####/libjiagu.so
- /data/data/####/notice.db-journal
- /data/data/####/qihoo360_accounts_inuse.ini
- /data/data/####/sharedpref.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.nomedia
- /data/media/####/360mse_nb00091.apk.apk (deleted)
- /data/media/####/360mse_nb00091.apk.apk.tmp
- /data/media/####/Y24ubzcxOTAuYTE2YTMzYTg=
- /data/media/####/goldfallen.mp3
- /data/media/####/journal.tmp
- /data/media/####/log.nb
- /system/bin/ps
- <Package Folder>/files/deamon_wifi_1_1 freewifi am startservice --user 0 -n com.qihoo.freewifi/.service.WifiService deamon_wifi_1_1
- am startservice --user 0 -n com.qihoo.freewifi/.service.WifiService
- app_process /system/bin com.android.commands.am.Am startservice --user 0 -n com.qihoo.freewifi/.service.WifiService
- chmod 493 <Package Folder>/files/so_libs
- chmod 700 <Package Folder>/files/deamon_wifi_1_1
- chmod 700 <Package Folder>/files/so_libs/keep_alive2
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- libjiagu
- libsecurity
- AES-ECB-PKCS5Padding
- DES-ECB-PKCS5Padding
- DESede-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- DESede-ECB-PKCS5Padding