Technical information
- Android.RemoteCode.155.origin
- TCP(/s?adspaceid=5kaQPKkCOO&os=Android%204.3.1&imei=356507059351895&imei_md5=EF12F5026515954B73B08063249B2E7E&imsi=250026699187743&imsi_md5=0FD02D697A6923DCEEA0C7128A88D9FF&mac=&mac_md5=&model=GT-I8190&channelid=4&sdkv=1.12.1113&appv=2.0&screenwidth=600&screenheight=752&so=1&density=0.8125&adsizewidth=420&adsizeheight=526&appname=%E6%BC%AB%E7%94%BB%E5%A4%A7%E5%85%A8&apppkg=tt1.evs.mgggaa&istest=0&net=00%3A00%3A00%3A00%3A00%3A06&adtype=1&it=1544442820750&ic=113614DB1442E4ED2B20D979DC6E3C534123D91D39A57D42BD6D72D2199E1823&androidid=abc97688ec4ecdc8&androidid_md5=B4E073D36B13885B72D0BAF62FE7549B&lastbannerid=&longitude=&latitude=&brand=samsung&carrier=310004&m2id=9ED1FF6BDE59A432313E3F10080A3396&serialid=525bbcde&devicetype=2&uid=60B0A6DB79) s####.m.me####.com:80
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) t####.me####.com:80
- TCP(HTTP/1.1) b####.s####.com.cn:80
- TCP(HTTP/1.1) s####.m.me####.com:80
- TCP(HTTP/1.1) zt-adfi####.oss-cn-####.aliy####.com:80
- TCP(TLS/1.0) mbd.n.sh####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) wap.n.sh####.com:443
- TCP(TLS/1.0) ssls####.jom####.com:443
- TCP(TLS/1.0) m.g####.cn:443
- TCP(TLS/1.0) www.a.sh####.com:443
- TCP(TLS/1.0) na0.bdst####.com.####.com:443
- TCP(TLS/1.0) box.jom####.com:443
- TCP(TLS/1.0) hpd.b####.com:443
- TCP(TLS/1.0) sslb####.jom####.com:443
- b####.s####.com.cn
- ext.b####.com
- f####.b####.com
- g####.bdst####.com
- hm.b####.com
- hpd.b####.com
- img.safetys####.mobi
- m.b####.com
- m.g####.cn
- mvp.me####.com
- na0.bdst####.com
- s####.m.me####.com
- s.bdst####.com
- ss0.b####.com
- ss1.b####.com
- ss2.b####.com
- sv.bdst####.com
- t####.me####.com
- www.b####.com
- zt-adfi####.oss-cn-####.aliy####.com
- b####.s####.com.cn/s/blog_15e2e8ff70102w3bu.html
- s####.m.me####.com/
- s####.m.me####.com/s?adspaceid=####&os=####&imei=####&imei_md5=####&imsi...
- s####.m.me####.com/s?switch=1?os=####&imei=####&imsi=####&mac=####&model...
- s####.m.me####.com/update?sdkv=####&nsdkv=####&imei=####&model=####&chan...
- zt-adfi####.oss-cn-####.aliy####.com/1512/rt/gx.bin
- t####.me####.com/t?type=####
- /data/data/####/.engine.apk
- /data/data/####/.jg.ic
- /data/data/####/.key.apk
- /data/data/####/QHAD_ACTON_COUNT20181209.xml
- /data/data/####/QHAD_ADCOUNTER_UPLOADED_20181209.xml
- /data/data/####/WebViewSettings.xml
- /data/data/####/android_pre.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/gx
- /data/data/####/index
- /data/data/####/libcrypt.so
- /data/data/####/libjiagu.so
- /data/data/####/libloader.so
- /data/data/####/qh_crash.log
- /data/data/####/qh_swich.cfg
- /data/data/####/qhad_PkgInfoHandler_181210.xml
- /data/data/####/qhad_dynamic1113.jar
- /data/data/####/qhadsdkerrordaycheck.xml
- /data/data/####/shell_pre.xml
- /data/data/####/temp.jar
- /data/data/####/ver_info.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/qhad_sdk_error.log
- /data/media/####/qhad_updatesdk_error
- /data/media/####/sys_nicholas.txt
- cat /proc/version
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- chmod 777 <Package Folder>/files/gxTmp
- chmod 777 <Package Folder>/files/gxTmp/gx
- crypt
- libjiagu
- libloader
- AES-ECB-PKCS5Padding
- DES