Technical information
- Adware.Waps.5.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) t####.qq.com:8080
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) oc.u####.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(HTTP/1.1) app.w####.cn:80
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(HTTP/1.1) t####.qq.com:443
- TCP(HTTP/1.1) btla####.b####.com:80
- TCP t####.qq.com:8080
- TCP t####.qq.com:443
- a####.exc.mob.com
- a####.mta.qq.com
- a####.u####.com
- app.w####.cn
- btla####.b####.com
- h####.b####.com
- loc.map.b####.com
- oc.u####.com
- pi####.qq.com
- t####.qq.com
- app.w####.cn/action/connect/active?app_id=####&udid=####&imsi=####&net=#...
- btla####.b####.com/baitong/wap/app/abanner.php
- btla####.b####.com/baitong/wap/app/css/bn.css
- btla####.b####.com/baitong/wap/app/js/swipe.js
- btla####.b####.com/baitong/wap/app/js/zepto.js?2####
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- app.w####.cn/action/user_info
- btla####.b####.com/baitong/index.php?r=####&m=####&ad_type=####&clientty...
- h####.b####.com/app.gif
- loc.map.b####.com/offline_loc
- loc.map.b####.com/sdk.php
- oc.u####.com/check_config_update
- pi####.qq.com/mstat/report/?index=####
- t####.qq.com:443/203.205.211.75:443/
- t####.qq.com:8080/203.205.211.75:8080/
- /data/data/####/.com.kukukk.kfkdroid;xg_service_v2.xg.stat..xml
- /data/data/####/.imprint
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.tpns.xml.xml
- /data/data/####/.tpush_mta.xml
- /data/data/####/AppSettings.xml
- /data/data/####/CacheTime.dat
- /data/data/####/SMSSDK_VCODE_1.xml
- /data/data/####/ShowAdFlag.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/com.kukukk.kfkdroid_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/device_id.xml
- /data/data/####/f_000001
- /data/data/####/firll.dat
- /data/data/####/index
- /data/data/####/libjiagu.so
- /data/data/####/mob_sdk_exception_1.xml
- /data/data/####/mobclick_agent_online_setting_com.kukukk.kfkdroid.xml
- /data/data/####/ofl.config
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/pri_tencent_analysis.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/tencent_analysis.db-journal
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/.mid.txt
- /data/media/####/.nomedia
- /data/media/####/AppPackage.dat
- /data/media/####/CacheTime.dat
- /data/media/####/UnPackage.dat
- /data/media/####/android
- /data/media/####/conlts.dat
- /data/media/####/ller.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/test.0
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- <Package Folder>/lib/libxguardian.so <Package>,2100006283; 55502 203.205.128.130 [{"idx":0,"ts":%d,"et":2000,"si":0,"ui":"<IMEI>","ky":"Axg%lu","mid":"2ccd575698a05f2e471f998dccfdf676ebdb82cd","ev":{"ov":"18","sr":"600*752","md":"<System Property>","lg":"en","sv":"2.46","mf":"unknown","apn":"%s"}}] 0 18
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- sh <Package Folder>/lib/libxguardian.so <Package>,2100006283; 55502 203.205.128.130 [{ idx :0, ts :%d, et :2000, si :0, ui : <IMEI> , ky : Axg%lu , mid : 2ccd575698a05f2e471f998dccfdf676ebdb82cd , ev :{ ov : 18 , sr : 600*752 , md : <System Property> , lg : en , sv : 2.46 , mf : unknown , apn : %s }}] 0 18
- MD5_v1
- MtaNativeCrash
- base64encoder_v1_4
- libjiagu
- locSDK6a
- neh
- smssdk
- tpnsSecurity
- AES-CBC-PKCS5Padding
- AES-CFB8-NoPadding
- AES-ECB-PKCS5Padding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1PADDING
- AES
- AES-CFB8-NoPadding
- DES-CBC-PKCS5Padding