Technical information
- Android.DownLoader.342.origin
- Android.DownLoader.343.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.go####.com:80
- TCP(HTTP/1.1) www.babyhaz####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) ai.io.wo####.net:80
- TCP(TLS/1.0) goog####.hit.ge####.pl:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) p####.everest####.net:443
- TCP(TLS/1.0) p4-eia3####.ds.me####.####.com:443
- TCP(TLS/1.0) www.googlet####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP(TLS/1.0) pugm220####.pubm####.com:443
- TCP(TLS/1.0) tpc.googles####.com:443
- TCP(TLS/1.0) amp-err####.app####.com:443
- TCP(TLS/1.0) s0.2####.net:443
- TCP(TLS/1.0) odr.moo####.com:443
- TCP(TLS/1.0) www.babyhaz####.com:443
- TCP(TLS/1.0) pag####.googles####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) fcm####.go####.com:443
- TCP(TLS/1.0) g####.n####.com:443
- TCP(TLS/1.0) p4-eia3####.v4.me####.####.com:443
- TCP(TLS/1.0) adser####.go####.nl:443
- TCP(TLS/1.0) csi.gst####.com:443
- TCP(TLS/1.0) im####.google####.com:443
- TCP(TLS/1.0) ssum####.casalem####.com.####.net:443
- TCP(TLS/1.0) f####.google####.com:443
- TCP(TLS/1.0) use.fontawe####.com:443
- TCP(TLS/1.0) cdn.amppro####.org:443
- TCP(TLS/1.0) www.google-####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- a####.u####.com
- adser####.go####.com
- adser####.go####.nl
- ai.io.wo####.net
- amp-err####.app####.com
- cdn.amppro####.org
- cm.g.doublec####.net
- csi.gst####.com
- e.dlx.add####.com
- f####.google####.com
- f####.gst####.com
- fcm####.go####.com
- fcm####.you####.com
- goog####.hit.ge####.pl
- googl####.g.doublec####.net
- i.hesh####.com
- im####.google####.com
- im####.pubm####.com
- n.hesh####.com
- odr.moo####.com
- p####.everest####.net
- p4-eia3####.ds.me####.####.com
- p4-eia3####.me####.gst####.com
- p4-eia3####.v4.me####.####.com
- pag####.googles####.com
- s0.2####.net
- ssum####.casalem####.com
- tpc.googles####.com
- use.fontawe####.com
- www.babyhaz####.com
- www.go####.com
- www.google-####.com
- www.googlet####.com
- www.babyhaz####.com/
- www.go####.com/complete/search?hl=####&client=####&q=####
- a####.u####.com/app_logs
- ai.io.wo####.net/16da74e6/1emiTgninaelClezaHybaB/nia
- ai.io.wo####.net/16da74e6/1emiTgninaelClezaHybaB/nib
- /data/data/####/.imprint
- /data/data/####/.jiagu.ls
- /data/data/####/3004CA92FCB7A8B8-journal
- /data/data/####/72B798E9EB9734D5.xml
- /data/data/####/7E25BD4259177A68.xml
- /data/data/####/CBDCD-journal
- /data/data/####/CDAACE
- /data/data/####/CDAACE-journal
- /data/data/####/E6261C0823068CA2.xml
- /data/data/####/__pasys_remote_banner.tmp.jar
- /data/data/####/_hBabyHazelCleaningTimeo.xml
- /data/data/####/analytics.sxx
- /data/data/####/application.xml
- /data/data/####/axbjlk.t
- /data/data/####/baby-hazel-cleaning-time.swf
- /data/data/####/cnapk.BHCT.BabyHazelCleaningTime.AIRSharedPref.xml
- /data/data/####/curl-ca-bundle.crt
- /data/data/####/javaTrustStore.tmp
- /data/data/####/libjiagu.so
- /data/data/####/mobclick_agent_online_setting_cnapk.BHCT.BabyHa...me.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/unlock_kit_unlock-journal
- /data/media/####/XH.txt
- /data/media/####/YOif
- /data/media/####/YOif.zip
- /data/media/####/__pasys_remote_banner.jar
- /data/media/####/axbjlk
- /data/media/####/bcnapk.BHCT.BabyHazelCleaningTime.jar
- /data/media/####/btn_install_all.png
- /data/media/####/btn_install_single.png
- /data/media/####/buttom_back.png
- /data/media/####/check_back.png
- /data/media/####/checked_back.png
- /data/media/####/close_btn.jpg
- /data/media/####/close_btn.png
- /data/media/####/congsmall.png
- /data/media/####/default.png
- /data/media/####/dialog_title_icon.png
- /data/media/####/enter_button.png
- /data/media/####/index.png
- /data/media/####/pic.png
- /data/media/####/scroll.png
- /data/media/####/skip.png
- /data/media/####/top_back.png
- /data/media/####/top_part.png
- /data/media/####/tsaz_bottom_part.png
- /data/media/####/tsaz_emo_icon.png
- /data/media/####/tsaz_install_all_btn.png
- /data/media/####/tsaz_install_btn.png
- /data/media/####/tsaz_item_scroll.png
- /data/media/####/tsaz_top_part.png
- /data/media/####/vi.png
- /data/media/####/vnhfq
- /data/media/####/vnhfq.zip
- /data/media/####/vzhfq
- /data/media/####/vzhfq.zip
- /data/media/####/yimeng222222222.png
- /system/bin/cat /proc/cpuinfo
- /system/bin/cat /proc/meminfo
- /system/bin/cat /sys/devices/system/cpu/present
- <Package Folder>/axbjlk -p <Package> -r am start --user 0 -n <Package>/xh.unbr.femqz -a daemon -h http://127.0.0.1:7123/report/allData -i 2526
- chmod 777 <Package Folder>/axbjlk
- sh <Package Folder>/axbjlk -p <Package> -r am start --user 0 -n <Package>/xh.unbr.femqz -a daemon -h http://127.0.0.1:7123/report/allData -i 2526
- jxqwu
- libCore
- libjiagu
- DES
- RSA-ECB-PKCS1Padding
- DES