Technical information
- Android.Triada.584.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) hy####.ray####.com:443
- TCP(TLS/1.0) firebas####.crashly####.com:443
- TCP(TLS/1.0) rr9---s####.g####.com:443
- TCP(TLS/1.0) e####.tradpl####.com:443
- TCP(TLS/1.0) api.tradpl####.com:443
- TCP(TLS/1.0) bi####.tradpl####.com:443
- TCP(TLS/1.0) fk-set####.ray####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) app-mea####.com:443
- TCP(TLS/1.0) ad####.ray####.com:443
- TCP(TLS/1.0) h####.wt####.com:33111
- TCP(TLS/1.0) de01####.ray####.com:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) d1tru86####.cloudf####.net:443
- TCP(TLS/1.2) p####.google####.com:443
- TCP(TLS/1.2) 1####.251.1.94:443
- TCP d2zi34f####.cloudf####.net:443
- TCP analy####.ray####.com:443
- TCP youtub####.l.go####.com:443
- TCP ir-new-####.ray####.com:443
- TCP fk-conf####.ray####.com:443
- ad####.ray####.com
- analy####.ray####.com
- and####.a####.go####.com
- and####.google####.com
- api.tradpl####.com
- app-mea####.com
- bi####.tradpl####.com
- c####.ray####.com
- confi####.ray####.com
- d1tru86####.cloudf####.net
- d2zi34f####.cloudf####.net
- de01####.ray####.com
- e####.tradpl####.com
- f####.gst####.com
- firebas####.crashly####.com
- firebas####.google####.com
- gmscomp####.google####.com
- h####.wt####.com
- hy####.ray####.com
- ir-new-####.ray####.com
- ir-new-####.ray####.com
- l####.ray####.com
- m####.go####.com
- p####.google####.com
- pla####.google####.com
- po####.ray####.com
- rr9---s####.g####.com
- www.you####.com
- ad####.ray####.com:443/impression?opri=NjRlYWRmYTlkYTE5Y2QwMHAWdNds8ZNyS...
- api.tradpl####.com:443/api/v1_2/adconf?device_type=####&ct=####&rom=####...
- api.tradpl####.com:443/api/v1_2/open?device_ram=####&z=####&did=####&app...
- bi####.tradpl####.com:443/api/v1/notify?adseat_uid=####&app_uid=####&asp...
- bi####.tradpl####.com:443/api/v1/notify?adseat_uid=5C00D86165D29EBFF6A77...
- bi####.tradpl####.com:443/api/v1/notify?adseat_uid=634B5080E031F207409EF...
- bi####.tradpl####.com:443/api/v1/notify?adseat_uid=EB8AA9A6F176E47A62B12...
- de01####.ray####.com:443/impression?k=####&z=MTI4M####&q=a_i09####&x=###...
- de01####.ray####.com:443/onlyImpression?k=####&p=MzU3N####&csp=inJ####&c...
- firebas####.crashly####.com:443/spi/v2/platforms/android/gmp/1:163365166...
- fk-set####.ray####.com:443/setting?app_id=####&sign=####&vtag=####&open=...
- fk-set####.ray####.com:443/setting?app_id=####&sign=####&vtag=####&st_ne...
- fk-set####.ray####.com:443/setting?unit_ids=####&app_id=####&sign=####&v...
- hy####.ray####.com:443/rv-zip-2023/0726/splash-726a43d8d7e62e648aceb8e5d...
- bi####.tradpl####.com:443/api/v1/headbidding
- e####.tradpl####.com:443/api/v1_2/ev
- h####.wt####.com:33111/3ezdjk/
- p####.google####.com:443/v1/projects/yomate-68b64/installations
- /data/data/####/54cd036e96db8828_0
- /data/data/####/54cd036e96db8828_0 (deleted)
- /data/data/####/Cookies-journal
- /data/data/####/Dryuh.xml
- /data/data/####/FirebaseHeartBeatW0RFRkFVTFRd+MToxNjMzNjUxNjYzO...Rh.xml
- /data/data/####/PersistedInstallation1478127163tmp
- /data/data/####/PersistedInstallation635837911tmp
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/Xde.xml
- /data/data/####/_has_set_default_values.xml
- /data/data/####/androidx.work.workdb-journal (deleted)
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes.oat.flock (deleted)
- /data/data/####/classes2.dex
- /data/data/####/classes2.oat
- /data/data/####/classes2.oat.flock (deleted)
- /data/data/####/classes3.dex
- /data/data/####/classes3.oat
- /data/data/####/classes3.oat.flock (deleted)
- /data/data/####/classes4.dex
- /data/data/####/classes4.oat
- /data/data/####/classes4.oat.flock (deleted)
- /data/data/####/classes5.dex
- /data/data/####/classes5.oat
- /data/data/####/classes5.oat.flock (deleted)
- /data/data/####/com.crashlytics.settings.json
- /data/data/####/com.google.android.datatransport.events-journal
- /data/data/####/com.google.android.gms.measurement.prefs.xml
- /data/data/####/com.google.firebase.crashlytics.xml
- /data/data/####/com.yomate.v2.playerprefs.xml
- /data/data/####/com.yomate_preferences.xml
- /data/data/####/com.yomate_preferences.xml.bak
- /data/data/####/config_info_def.xml
- /data/data/####/first_enter_index.xml
- /data/data/####/generatefid.lock
- /data/data/####/google_app_measurement_local.db
- /data/data/####/google_app_measurement_local.db-journal
- /data/data/####/index
- /data/data/####/initialization_marker
- /data/data/####/journal.tmp
- /data/data/####/l36bb1970.so
- /data/data/####/mbridge.msdk.db-journal
- /data/data/####/metrics_guid
- /data/data/####/newpipe.db-journal (deleted)
- /data/data/####/report
- /data/data/####/sp_Ecowi.xml
- /data/data/####/start-time
- /data/data/####/temp-index
- /data/data/####/the-real-index
- /data/data/####/tradplus.db
- /data/data/####/tradplus.db-journal
- /data/data/####/tradplus.db-journal (deleted)
- /data/data/####/tradplus_sdk.xml
- /data/data/####/tradplus_sdk.xml.bak
- /data/data/####/unityads-installinfo.xml
- /data/data/####/userlog.tmp
- /data/media/####/-1194101897.tmp
- /data/media/####/-627808896
- /data/media/####/-627808896.tmp
- /data/media/####/.Zikoh
- /data/media/####/63dd0da03831919c3770635142f6c7f0.zip
- /data/media/####/Ptyg
- /data/media/####/Smu
- /data/media/####/btn_close.png
- /data/media/####/circle.png
- /data/media/####/exc_log.kva
- /data/media/####/exc_log.kvb
- /data/media/####/finger.png
- /data/media/####/gift-love.gif
- /data/media/####/icon-download.png
- /data/media/####/icon-finger1.png
- /data/media/####/icon-finger2.png
- /data/media/####/icon-gdt.png
- /data/media/####/icon-go.png
- /data/media/####/icon-idcd-finger.gif
- /data/media/####/icon-idcd-finger.png
- /data/media/####/icon-mtg.png
- /data/media/####/icon-privacy-black.png
- /data/media/####/icon-right-arrow.png
- /data/media/####/icon_close.png
- /data/media/####/icon_mtg.png
- /data/media/####/light.png
- /data/media/####/loadingMtg.gif
- /data/media/####/logo-black.bak.png
- /data/media/####/logo-gray.bak.png
- /data/media/####/logo-gray.png
- /data/media/####/logo-white.bak.png
- /data/media/####/mbridge.kva
- /data/media/####/mbridge.kvb
- /data/media/####/privacy-shadow.png
- /data/media/####/privacy.png
- /data/media/####/shake-btn-icon.png
- /data/media/####/share_date.kva
- /data/media/####/share_date.kvb
- /data/media/####/splash.css
- /data/media/####/splash.css.map
- /data/media/####/splash.html
- /data/media/####/splash.js
- /data/media/####/star-gray.png
- /data/media/####/star-yellow.png
- /data/media/####/subscripts.png
- /data/media/####/user-gray.png
- chmod 755 /data/user/0/<Package>/files/.ss/l36bb1970.so
- l36bb1970
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7PADDING
- RSA-None-PKCS1Padding
- AES-CBC-PKCS5Padding
- PBEWithMD5AndDES
- RSA-None-PKCS1Padding