Technical information
- Adware.Dowgin.14.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 6####.com:80
- TCP(HTTP/1.1) ads.m####.com:80
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) www.tinyp####.net:80
- TCP(HTTP/1.1) api-acc####.edges####.net:80
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) l####.chartb####.com:443
- TCP(TLS/1.0) t2.chartb####.com:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) d####.fl####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) connect####.gst####.com:443
- 6####.com
- a2.chartb####.com
- ads.m####.com
- and####.cli####.go####.com
- api.vu####.com
- c.appj####.com
- connect####.gst####.com
- d####.fl####.com
- diguolo####.ap-nort####.elb.####.com
- googl####.g.doublec####.net
- l####.chartb####.com
- lh3.googleu####.com
- ssl.google-####.com
- t2.chartb####.com
- www.google####.com
- www.tinyp####.net
- 6####.com/GameManage3/appRewardConf.shtml?appId=####&appVersion=####&mac...
- ads.m####.com/m/ad?v=####&id=####&nv=####&dn=####&bundle=####&z=####&o=#...
- www.tinyp####.net/GameManage/mobile.shtml?appId=####&appVersion=####&dev...
- api-acc####.edges####.net/api/v4/config
- api-acc####.edges####.net/api/v4/new?app_id=####&ifa=####
- api-acc####.edges####.net/api/v4/requestAd
- api-acc####.edges####.net/api/v4/sessionStart
- c.appj####.com/ad/splash/stats.html
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_SS79B7R2...D7_216
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsMain
- /data/data/####/.appInfo
- /data/data/####/.jg.ic
- /data/data/####/.yflurrydatasenderblock.12edffe2-6d58-4d03-b805...d942bf
- /data/data/####/123414410242
- /data/data/####/1557357152169.dex
- /data/data/####/1557357152169.dex.flock (deleted)
- /data/data/####/1557357152169.jar
- /data/data/####/1557357152169.tmp
- /data/data/####/5a6b9.xml
- /data/data/####/5a6b9.xml.bak
- /data/data/####/Cookies-journal
- /data/data/####/SHARED_PRENFERENCE_LOCAL_ADDRESS.xml
- /data/data/####/SHARED_PRENFERENCE_LOCAL_ADDRESS.xml.bak
- /data/data/####/UserDefault.xml
- /data/data/####/VUNGLE_PUB_APP_INFO.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/ad_show_time.xml
- /data/data/####/admob.xml
- /data/data/####/c9455dd475b1974d_0
- /data/data/####/cbPrefs.xml
- /data/data/####/cb_previous_session_info
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/com.g6677.android.cdentist_preferences.xml
- /data/data/####/com.google.android.gms.analytics.prefs.xml
- /data/data/####/dfe6b2497a7513ba_0
- /data/data/####/f038e94cb33282ab_0
- /data/data/####/gaClientId
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/http_auth.db-journal
- /data/data/####/https_googleads.g.doubleclick.net_0.localstorage-journal
- /data/data/####/index
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jg_app_update_settings_random.xml.bak
- /data/data/####/libjiagu.so
- /data/data/####/metrics_guid
- /data/data/####/org.vakq.bz.dex
- /data/data/####/org.vakq.bz.dex.flock (deleted)
- /data/data/####/org.vakq.bz.jar
- /data/data/####/proc_auxv
- /data/data/####/the-real-index
- /data/data/####/vungle-journal
- /data/media/####/.adId
- /data/media/####/320x480
- /data/media/####/320x480.png
- /data/media/####/55419c5ac909a62c0ff713d0.114
- /data/media/####/55419c5ac909a62c0ff713d0.114.png
- /data/media/####/playable-core-v2-CBCloseButton-1005936858
- /data/media/####/static-etna-112132548
- /data/media/####/video-v3_01--46197445
- /data/media/####/webview-30x30
- /data/media/####/webview-30x30.png
- /data/misc/####/primary.prof
- /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes2.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/cache/1557357152169.jar --oat-fd=43 --oat-location=/data/user/0/<Package>/cache/1557357152169.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/org.vakq.bz.jar --oat-fd=45 --oat-location=/data/user/0/<Package>/files/org.vakq.bz.dex --compiler-filter=speed
- chmod 755 /data/user/0/<Package>/.jiagu/libjiagu.so
- AES-CBC-PKCS5Padding
- DES
- RSA
- AES-CBC-PKCS5Padding