Technical information
- Adware.Dowgin.3.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) ds.dd.15####.####.net:80
- TCP(HTTP/1.1) btla####.b####.com:80
- TCP(HTTP/1.1) is.ca.15####.cn:80
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(TLS/1.0) and####.cli####.go####.com:443
- and####.cli####.go####.com
- btla####.b####.com
- ds.dd.15####.cn
- h####.b####.com
- is.ca.15####.cn
- mt####.go####.com
- btla####.b####.com/baitong/index.php?r=####&m=####&api_key=####&secret=#...
- btla####.b####.com/baitong/wap/app/abanner.php
- btla####.b####.com/baitong/wap/app/css/bn.css
- btla####.b####.com/baitong/wap/app/js/swipe.js
- btla####.b####.com/baitong/wap/app/js/zepto.js?2####
- ds.dd.15####.####.net/apk/20171207/201712071116111.png
- ds.dd.15####.####.net/apk/20180606/201806061136852.png
- ds.dd.15####.####.net/apk/20180626/201806261432114.apk
- ds.dd.15####.####.net/apk/20180702/20180702174395.apk
- btla####.b####.com/baitong/index.php?r=####&m=####&ad_type=####&clientty...
- h####.b####.com/app.gif
- is.ca.15####.cn/eb187c9/zaa
- is.ca.15####.cn/eb187c9/zia
- is.ca.15####.cn/eb187c9/zib
- is.ca.15####.cn/eb187c9/zic
- is.ca.15####.cn/eb187c9/zid
- is.ca.15####.cn/eb187c9/zie
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/_acopinz.xml
- /data/data/####/_bcopinn.xml
- /data/data/####/_gcopins.xml
- /data/data/####/afc.pro
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/index
- /data/data/####/pinq.jar
- /data/data/####/uscom.db
- /data/data/####/uscom.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/.nomedia
- /data/media/####/201712071116111#png
- /data/media/####/201806061136852#png
- /data/media/####/afc.pro
- /data/media/####/e1608c4f085e.tmp
- /data/media/####/e5a7bcdc1e87.tmp
- /data/media/####/egnaro_etceles_egap_d
- /data/media/####/egnaro_gbntb_d
- /data/media/####/ehcac_ntb_mottob
- /data/media/####/elcric_cs_d
- /data/media/####/enil_efas
- /data/media/####/enil_efas_d
- /data/media/####/enil_jt_d
- /data/media/####/erahs_ntb_mottob
- /data/media/####/eulb_gbntb_d
- /data/media/####/gb_datuctrohs_d
- /data/media/####/gb_gmi
- /data/media/####/gb_gmi_d
- /data/media/####/gb_mottob
- /data/media/####/gb_pot
- /data/media/####/gb_pot_d
- /data/media/####/gb_sdrowda
- /data/media/####/gb_tluafed_d
- /data/media/####/kcab_pop
- /data/media/####/kcab_pop_d
- /data/media/####/lecnac_ntb_mottob_d
- /data/media/####/llatsni_ntb
- /data/media/####/llatsni_ntb_d
- /data/media/####/llatsni_ntb_mottob
- /data/media/####/lomron_egap_d
- /data/media/####/n_kcehcp
- /data/media/####/na_csppa_d
- /data/media/####/neerg_gbntb_d
- /data/media/####/noci_efas
- /data/media/####/noci_efas_d
- /data/media/####/ntb_erom_pc_d
- /data/media/####/ntb_meti
- /data/media/####/ntb_mottob_pop
- /data/media/####/ntb_mottob_pop_d
- /data/media/####/ntb_rehto_pc_d
- /data/media/####/ntbesolc_pot_x
- /data/media/####/ntbesolc_potd_d
- /data/media/####/nwod_worra
- /data/media/####/nwod_worra_d
- /data/media/####/p_kcehcp
- /data/media/####/pot_ntbseolc_d
- /data/media/####/pu_worra
- /data/media/####/pu_worra_d
- /data/media/####/rats_m
- /data/media/####/tnetnocppa
- /data/media/####/wolley_gbntb_d
- chmod 777 /storage/emulated/0/download/zpin//e1608c4f085e.tmp
- chmod 777 /storage/emulated/0/download/zpin//e5a7bcdc1e87.tmp
- MD5_v1
- base64encoder_v1_4
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- DES
- AES