Technical information
- Android.HiddenAds.137.origin
- i####.####.cn
- mt####.####.com
- sett####.####.com
- v####.####.com
- w####.####.xyz
- i####.####.cn/iplookup/iplookup.php?format=####
- w####.####.xyz/ad/adu?gffw=####&frrw=####&dlkvv=####&wdazz=####&fkk9ll=#...
- v####.####.com/api/va
- w####.####.xyz/ad/adc?gffw=####&frrw=####&dlkvv=####&wdazz=####&fkk9ll=#...
- <Package Folder>/cache/####/data_0
- <Package Folder>/cache/####/data_1
- <Package Folder>/cache/####/data_2
- <Package Folder>/cache/####/data_3
- <Package Folder>/cache/####/index
- <Package Folder>/databases/easv.data-journal
- <Package Folder>/databases/plug.dataBase
- <Package Folder>/databases/plug.dataBase-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/databases/webviewCookiesChromium.db-journal
- <Package Folder>/files/####/598469D30360-0001-0843-564ABEC5DFD5BeginSession.cls_temp
- <Package Folder>/files/####/598469D30360-0001-0843-564ABEC5DFD5SessionApp.cls_temp
- <Package Folder>/files/####/598469D30360-0001-0843-564ABEC5DFD5SessionDevice.cls_temp
- <Package Folder>/files/####/598469D30360-0001-0843-564ABEC5DFD5SessionOS.cls
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5BeginSession.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5SessionApp.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5SessionCrash.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5SessionDevice.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5SessionOS.cls_temp
- <Package Folder>/files/####/598469D401F8-0001-0871-564ABEC5DFD5SessionUser.cls_temp
- <Package Folder>/files/####/598469D501E2-0002-0843-564ABEC5DFD5BeginSession.cls_temp
- <Package Folder>/files/####/598469D501E2-0002-0843-564ABEC5DFD5SessionApp.cls_temp
- <Package Folder>/files/####/598469D501E2-0002-0843-564ABEC5DFD5SessionDevice.cls_temp
- <Package Folder>/files/####/598469D501E2-0002-0843-564ABEC5DFD5SessionOS.cls_temp
- <Package Folder>/files/####/598469DA024E-0001-0899-564ABEC5DFD5BeginSession.cls_temp
- <Package Folder>/files/####/598469DA024E-0001-0899-564ABEC5DFD5SessionApp.cls_temp
- <Package Folder>/files/####/598469DA024E-0001-0899-564ABEC5DFD5SessionDevice.cls_temp
- <Package Folder>/files/####/598469DA024E-0001-0899-564ABEC5DFD5SessionOS.cls_temp
- <Package Folder>/files/####/com.crashlytics.settings.json
- <Package Folder>/files/####/crash_marker
- <Package Folder>/files/####/initialization_marker
- <Package Folder>/files/####/session_analytics.tap
- <Package Folder>/files/####/session_analytics.tap (deleted)
- <Package Folder>/files/####/session_analytics.tap.tmp
- <Package Folder>/files/DEAB89CE10FEAA11
- <Package Folder>/filesbb.jar
- <Package Folder>/shared_prefs/Prefres.xml
- <Package Folder>/shared_prefs/SSP.xml
- <Package Folder>/shared_prefs/SSPPrefe.xml
- <Package Folder>/shared_prefs/SSPPrefe.xml.bak
- <Package Folder>/shared_prefs/TwitterAdvertisingInfoPreferences.xml
- <Package Folder>/shared_prefs/com.crashlytics.prefs.xml
- <Package Folder>/shared_prefs/com.crashlytics.sdk.android;answers;settings.xml
- <Package Folder>/shared_prefs/io.fabric.sdk.android;fabric;io.fabric.sdk.android.Onboarding.xml
- <Package Folder>/shared_prefs/kbkbUpdateVerPreference.xml
- <Package Folder>/shared_prefs/local_storage0.xml
- <Package Folder>/shared_prefs/local_storage1.xml
- <Package Folder>/shared_prefs/sp.xml
- <Package Folder>/shared_prefs/sp.xml.bak
- <SD-Card>/Android/####/.nomedia
- <SD-Card>/Ysfiles/aaa.jar
- <SD-Card>/Ysfiles/mmm.jar
- <SD-Card>/pasv.txt
- <Package Folder>/lib/libnat-lib3537.so -pkg <Package> -pid 2161 -svr <Package>/com.game91.fastrun.keep.ClkService -url http://www.sunny-day.xyz/ad/adc?ohmamami=ohno&fkk9ll=<IMEI>&cvsds=<IMSI>&frrw=64500&f4rr=00:00:00:00:00:15 -log
- cat /sys/class/net/wlan0/address
- sh <Package Folder>/lib/libnat-lib3537.so -pkg <Package> -pid 2161 -svr <Package>/com.game91.fastrun.keep.ClkService -url http://www.sunny-day.xyz/ad/adc?ohmamami=ohno&fkk9ll=<IMEI>&cvsds=<IMSI>&frrw=64500&f4rr=00:00:00:00:00:15 -log
- mod-jni
- nat-lib3537
- AES-ECB-PKCS7Padding
- DES-CBC-PKCS5Padding
- DES
- DES-CBC-PKCS5Padding
- DESede