Technical information
- Adware.Dowgin.3.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) hm.bd.5####.net:80
- TCP(HTTP/1.1) cd.cd.c####.####.net:80
- TCP(HTTP/1.1) btla####.b####.com:80
- btla####.b####.com
- cd.cd.c####.com
- h####.b####.com
- hm.bd.5####.net
- btla####.b####.com/baitong/index.php?r=####&m=####&api_key=####&secret=#...
- btla####.b####.com/baitong/wap/app/abanner.php
- btla####.b####.com/baitong/wap/app/ascreen.php
- btla####.b####.com/baitong/wap/app/css/ad.css
- btla####.b####.com/baitong/wap/app/css/bn.css
- btla####.b####.com/baitong/wap/app/images/screen.png
- btla####.b####.com/baitong/wap/app/js/swipe.js
- btla####.b####.com/baitong/wap/app/js/zepto.js
- btla####.b####.com/baitong/wap/app/js/zepto.js?2####
- cd.cd.c####.####.net/offer/20190531/201905311121559.png
- btla####.b####.com/baitong/index.php?r=####&m=####&ad_type=####&clientty...
- hm.bd.5####.net/10cyl0a594c3o/e407/p22
- hm.bd.5####.net/10cyl0a594c3o/e407/q22
- hm.bd.5####.net/10cyl0a594c3o/e407/s22
- hm.bd.5####.net/10cyl0a594c3o/e407/t22
- hm.bd.5####.net/10cyl0a594c3o/e407/w22
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/_mgo3c495a0lyc_r.xml
- /data/data/####/_mho3c495a0lycqs.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/index
- /data/data/####/lhfs.oqot.twdm.taixf.dex (deleted)
- /data/data/####/lhfs.oqot.twdm.taixf.jar
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/.nomedia
- /data/media/####/e5b9a3a11bea0
- /data/media/####/pr.p
- MD5_v1
- base64encoder_v1_4
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- DES
- AES
- DES