Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Packed.49154

Added to the Dr.Web virus database: 2019-11-24

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.906.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • UDP(DNS) 1####.114.114.114:53
  • TCP(HTTP/1.1) t####.a####.top:80
  • TCP(HTTP/1.1) c.c####.com:80
  • TCP(HTTP/1.1) res####.a####.top:80
  • TCP(HTTP/1.1) s####.jom####.com:80
  • TCP(HTTP/1.1) d####.cn:80
  • TCP(HTTP/1.1) dup.baidust####.com:80
  • TCP(HTTP/1.1) ip.j####.com:999
  • TCP(HTTP/1.1) ip.j####.com:99
  • TCP(HTTP/1.1) pco####.ta####.com:80
  • TCP(HTTP/1.1) s.zhito####.com:88
  • TCP(HTTP/1.1) pos.b####.com:80
  • TCP(HTTP/1.1) 58.2####.201.145:654
  • TCP(HTTP/1.1) gd.a.s####.com:80
  • TCP(HTTP/1.1) 58.2####.198.157:999
  • TCP(HTTP/1.1) cgi.con####.qq.com:80
  • TCP(HTTP/1.1) 1####.62.44.93:80
  • TCP(HTTP/1.1) cu.c####.cn:80
  • TCP(HTTP/1.1) j####.g####.vip:80
  • TCP(HTTP/1.1) 58.2####.203.36:654
  • TCP(HTTP/1.1) 1####.29.29.29:80
  • TCP(HTTP/1.1) m.xiaoshu####.cn:80
  • TCP(HTTP/1.1) s.zhito####.com:808
  • TCP(HTTP/1.1) z####.heyc####.net:80
  • TCP(HTTP/1.1) cdn.i.arie####.com:80
  • TCP(HTTP/1.1) c####.z####.net:80
  • TCP(HTTP/1.1) api.yunco####.com:80
  • TCP(HTTP/1.1) ivy.pcon####.com.cn:80
  • TCP(HTTP/1.1) gm.mm####.com:80
  • TCP(HTTP/1.1) api.lubang####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) 47.1####.185.46:80
  • TCP(HTTP/1.1) down####.baiyuns####.com:80
  • TCP(HTTP/1.1) filt####.a####.top:80
  • TCP(HTTP/1.1) wap.n.sh####.com:80
  • TCP(HTTP/1.1) dsp.huoli####.cn:80
  • TCP(HTTP/1.1) s.zhito####.com:807
  • TCP(HTTP/1.1) api.g####.vip:80
  • TCP(HTTP/1.1) res2####.xqk####.com:80
  • TCP(HTTP/1.1) i####.pcon####.com.cn:80
  • TCP(HTTP/1.1) m.7####.net:80
  • TCP(HTTP/1.1) 47.1####.211.73:80
  • TCP(HTTP/1.1) q####.0####.com:13967
  • TCP(TLS/1.0) wild####.go-mp####.net.####.net:443
  • TCP(TLS/1.0) instant####.google####.com:443
  • TCP(TLS/1.0) wildca####.go-mp####.net.####.net:443
  • TCP(TLS/1.0) ae.bdst####.com.####.com:443
  • TCP(TLS/1.0) pc####.i####.com:443
  • TCP(TLS/1.0) sb.scoreca####.com.####.net:443
  • TCP(TLS/1.0) c####.pc####.com.cn:443
  • TCP(TLS/1.0) gm.mm####.com:443
  • TCP(TLS/1.0) pos.b####.com:443
  • TCP(TLS/1.0) se####.v####.i####.com:443
  • TCP(TLS/1.0) lhyysdk####.oss-cn-####.aliy####.com:443
  • TCP(TLS/1.0) z.c####.com:443
  • TCP(TLS/1.0) w####.jd.com:443
  • TCP(TLS/1.0) 688.wapyi####.cn:443
  • TCP(TLS/1.0) 1####.217.168.206:443
  • TCP(TLS/1.0) l####.b####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) wt.i####.cn:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) i####.com.edg####.net:443
  • TCP(TLS/1.0) cili####.cn:443
  • TCP(TLS/1.0) img.pcon####.com.####.cn:443
  • TCP(TLS/1.0) wl.jd.com.####.com:443
  • TCP(TLS/1.0) v.adma####.com.cn:443
  • TCP(TLS/1.0) ur####.jd.com:443
  • TCP(TLS/1.0) c####.i####.com:443
  • TCP(TLS/1.0) ec####.b####.com:443
  • TCP(TLS/1.0) p####.m.jd.com:443
  • TCP(TLS/1.0) 1####.217.168.202:443
  • TCP(TLS/1.0) m####.m.jd.com:443
  • TCP(TLS/1.0) nl####.i####.com:443
  • TCP(TLS/1.0) api.g####.vip:443
  • TCP(TLS/1.0) i####.i####.com:443
  • TCP(TLS/1.0) cr.3con####.com:443
  • TCP(TLS/1.0) tu.7####.cn.####.net:443
  • TCP(TLS/1.0) mvo.g####.xyz:443
  • TCP(TLS/1.0) mg####.pcon####.com.cn:443
  • TCP(TLS/1.0) js.3con####.com:443
  • TCP(TLS/1.0) cf.k0####.cn:443
  • TCP(TLS/1.0) tx.h####.xyz:443
  • TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) i####.pcon####.com.cn:443
  • TCP(TLS/1.0) www.pc####.com.####.cn:443
  • TCP(TLS/1.0) t.hy####.com.cn:443
  • TCP(TLS/1.0) p####.pc####.com.cn:443
  • TCP(TLS/1.0) i####.j####.com:443
  • TCP(TLS/1.0) c.c####.com:443
  • TCP(TLS/1.0) ivy.pcon####.com.cn:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) contr####.i####.com:443
  • TCP(TLS/1.0) wap.n.sh####.com:443
  • TCP(TLS/1.0) a####.i####.com.####.net:443
  • TCP(TLS/1.0) mo.a####.xyz:443
  • TCP(TLS/1.0) m####.qy.net:443
  • TCP(TLS/1.0) g.cn.miao####.com:443
  • TCP(TLS/1.0) dup.baidust####.com:443
  • TCP(TLS/1.0) nl-no####.i####.com:443
  • TCP(TLS/1.0) u.j####.com:443
  • TCP(TLS/1.0) ad.doublec####.net:443
  • TCP(TLS/1.0) stc.iqiy####.com:443
  • TCP(TLS/1.0) iqiy####.com.edg####.net:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) cdn.boo####.com.####.com:443
  • TCP(TLS/1.0) st####.i####.com.####.net:443
  • TCP(TLS/1.2) 1####.217.168.206:443
  • TCP(TLS/1.2) 1####.217.168.202:443
DNS requests:
  • 617.a####.top
  • 617.a####.top.####.8
  • 68####.8####.com
  • 688.wapyi####.cn
  • ad.doublec####.net
  • ae.bdst####.com
  • and####.google####.com
  • api.g####.vip
  • api.lubang####.com
  • api.meiju####.n####.####.8
  • api.meiju####.net/
  • api.s####.b####.com
  • api.yunco####.com
  • c####.i####.com
  • c####.i####.com
  • c####.m.i####.com
  • c####.mm####.com
  • c####.pc####.com.cn
  • c####.v####.i####.com
  • c####.z####.net
  • c####.zhito####.com
  • c.c####.com
  • c.go-mp####.net
  • cdn.boo####.com
  • cdn.i.arie####.com
  • cf.k0####.cn
  • cgi.con####.qq.com
  • cili####.cn
  • contr####.i####.com
  • cr.3con####.com
  • cu.c####.cn
  • d####.b####.com
  • d####.cn
  • down####.baiyuns####.com
  • dsp.huoli####.cn
  • dup.baidust####.com
  • ec####.b####.com
  • filt####.a####.top
  • g.cn.miao####.com
  • h5s####.m.jd.com
  • hm.b####.com
  • i####.360bu####.com
  • i####.360bu####.com
  • i####.i####.com
  • i####.iqiy####.com
  • i####.pcon####.com.cn
  • if####.i####.com
  • im####.pc####.com.cn
  • img.pcon####.com.cn
  • instant####.google####.com
  • ip.j####.com
  • ip.zhito####.com
  • ivy.pc####.com.cn
  • ivy.pcon####.com.cn
  • j####.g####.vip
  • jh.b####.cn
  • js.3con####.com
  • kou####.a####.top
  • l####.b####.com
  • le####.gl####.cn
  • lhyysdk####.oss-cn-####.aliy####.com
  • m####.b####.com
  • m####.m.jd.com
  • m####.qy.net
  • m.360bu####.com
  • m.7####.net
  • m.iqiy####.com
  • m.xiaoshu####.cn
  • mg####.pcon####.com.cn
  • mo.a####.xyz
  • msg.v####.q####.com
  • mvo.g####.xyz
  • mvo.y####.xyz
  • nl####.i####.com
  • nl-no####.i####.com
  • o6####.ns####.cn
  • p####.google####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.iqiy####.com
  • p####.m.jd.com
  • p####.pc####.com.cn
  • p####.zhanz####.b####.com
  • pc####.i####.com
  • pco####.c####.com
  • pcw####.i####.com
  • plb####.u####.com
  • pos.b####.com
  • pv.s####.com
  • q####.0####.com
  • res####.a####.top
  • res2####.xqk####.com
  • s.go-mp####.net
  • s.zhito####.com
  • s13.c####.com
  • s22.c####.com
  • s23.c####.com
  • s4.c####.com
  • s5.c####.com
  • s9.c####.com
  • sb.scoreca####.com
  • se####.v####.i####.com
  • secu####.i####.com
  • st####.i####.com
  • st####.q####.com
  • stc.iqiy####.com
  • sto####.360bu####.com
  • t####.a####.top
  • t-####.hy####.com.cn
  • t7z.c####.i####.com
  • tu.7####.cn
  • tx.h####.xyz
  • u####.a####.top
  • u####.u####.com
  • u.j####.com
  • ur####.jd.com
  • v.adma####.com.cn
  • v1.c####.com
  • w####.jd.com
  • w####.jd.com
  • w####.pc####.com.cn
  • w####.pc####.com.cn
  • w####.pc####.com.cn
  • w####.pch####.com.cn
  • w####.pcon####.com.cn
  • w####.pcon####.com.cn
  • wq.360bu####.com
  • wt.i####.cn
  • www.i####.com
  • www.iqiy####.com
  • www.pc####.com.cn
  • www.pcon####.com.cn
  • xiongz####.b####.com
  • z####.heyc####.net
  • z1.c####.com
  • z12.c####.com
  • z3.c####.com
  • z5.c####.com
  • z6.c####.com
  • z9.c####.com
HTTP GET requests:
  • api.g####.vip/landing.js
  • c####.z####.net/v.js?YpmIYb366yxeJn6fRC9sqmj4ucj2Bp71AraI4LCigLM=####
  • c.c####.com/core.php?web_id=####&t=####
  • c.c####.com/z_stat.php?id=####
  • cdn.i.arie####.com/e/i.js
  • cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?status_os=####&stat...
  • cu.c####.cn/v1.0/pages?ao=####&pid=####&aid=####&keyword=####&model=####...
  • d####.cn/aawc.html
  • d####.cn/aawm.html
  • d####.cn/baiduwm.html
  • d####.cn/bbwc.html
  • d####.cn/bbwm.html
  • d####.cn/yhyd.html
  • d####.cn/yhyd2.html
  • down####.baiyuns####.com/cy.js
  • down####.baiyuns####.com/jquery.lazyload.min.js
  • down####.baiyuns####.com/jquery.min.js
  • dsp.huoli####.cn/fenpei.html?3####
  • dsp.huoli####.cn/web/app.html
  • dsp.huoli####.cn/web/wap.html
  • dsp.huoli####.cn/xincan.html?3####
  • dsp.huoli####.cn/xincan.html?4####
  • dup.baidust####.com/js/os.js
  • filt####.a####.top/617.html
  • filt####.a####.top/filter_control_617.json
  • gd.a.s####.com/cityjson?ie=####
  • gm.mm####.com/9.gif?abc=####&rnd=####
  • i####.pcon####.com.cn/blank.gif
  • ip.j####.com:99/IP/Index/geturls
  • ip.j####.com:99/Public/Access/js/main.js
  • ip.j####.com:99/Public/Access/js/modules/common.js
  • ip.j####.com:99/Public/Access/js/modules/creifr.js
  • ip.j####.com:99/ip/index.html
  • ip.j####.com:999/wap/index.php?0####
  • ivy.pcon####.com.cn/click?id=####&adid=####&watch=####
  • j####.g####.vip/ggx.js
  • j####.g####.vip/jwdd.js
  • j####.g####.vip/xs240.js
  • m.7####.net/favicon.ico
  • m.7####.net/mbook_images/header-back.gif
  • m.7####.net/mbook_images/header-backhome.gif
  • m.7####.net/mbook_js/common.js
  • m.7####.net/mbook_js/index.js
  • m.7####.net/mbook_js/read.js
  • m.7####.net/mbook_js/yuedu.js
  • m.7####.net/mbook_js/zepto.min.js
  • m.7####.net/mbyq/1050/1390.html
  • m.7####.net/mbyq/18090/146.html
  • m.xiaoshu####.cn/favicon.ico
  • m.xiaoshu####.cn/mbook_images/header-back.gif
  • m.xiaoshu####.cn/mbook_images/header-backhome.gif
  • m.xiaoshu####.cn/mbook_js/common.js
  • m.xiaoshu####.cn/mbook_js/index.js
  • m.xiaoshu####.cn/mbook_js/read.js
  • m.xiaoshu####.cn/mbook_js/stat.js
  • m.xiaoshu####.cn/mbook_js/yuedu.js
  • m.xiaoshu####.cn/mbook_js/zepto.min.js
  • m.xiaoshu####.cn/mbxs240/1282/
  • m.xiaoshu####.cn/mbxs240/1282/15.html
  • m.xiaoshu####.cn/mbxs240/1471/6/
  • pco####.ta####.com/app.gif?&cna=####
  • pos.b####.com/acym?psi=####&di=####&dri=####&dis=####&dai=####&ps=####&e...
  • pos.b####.com/kcym?psi=096bd7f090a463f6341ceaa20f04b0c2&di=6611856&dri=0...
  • pos.b####.com/mcrm?psi=60b917b4931ecdb7e4e74805c97004ea&di=6611856&dri=0...
  • pos.b####.com/pcsm?conwid=####&conhei=####&rtbid=####&rdid=####&dc=####&...
  • pos.b####.com/pcsm?psi=####&di=####&dri=####&dis=####&dai=####&ps=####&e...
  • res####.a####.top/LHYY.png
  • res####.a####.top/sdk1.png
  • res####.a####.top/sdk13_2.png
  • res####.a####.top/sdk17.png
  • res####.a####.top/sdk18.png
  • res####.a####.top/sdk5_2.png
  • res####.a####.top/sdk8.png
  • res2####.xqk####.com//13/3/大仙官/cover.jpg
  • res2####.xqk####.com//70/0/我就是能进球/cover.jpg
  • s####.jom####.com/push.js
  • s####.jom####.com/s.gif?r=####&l=####
  • s.zhito####.com:807/528/jf0622.html
  • s.zhito####.com:807/ip/ip.html
  • s.zhito####.com:808/0622/index.html
  • s.zhito####.com:808/0622/style="display:
  • s.zhito####.com:808/0622/yrc_001mobile.js
  • s.zhito####.com:808/favicon.ico
  • s.zhito####.com:88/wap.html
  • t####.a####.top/channl_adong3.png
  • t####.a####.top/kouling.json
  • wap.n.sh####.com/sdk/c.js?appid=####
  • z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
HTTP POST requests:
  • api.lubang####.com/domain.php
  • api.lubang####.com/srp.php
  • api.yunco####.com/service/rest
  • q####.0####.com:13967/x5qn0/
  • z####.heyc####.net/getlist
  • z####.heyc####.net/xlogin
File system changes:
Creates the following files:
  • /data/data/####/.__mob_ad_data.xml
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/.jgck
  • /data/data/####/.zx
  • /data/data/####/005bb92749461c36_0
  • /data/data/####/0252c49094046d92_0
  • /data/data/####/02eeb739472e38cc_0
  • /data/data/####/0325798c3add3389_0
  • /data/data/####/0325798c3add3389_1
  • /data/data/####/032ae719ffba63f8_0
  • /data/data/####/032ae719ffba63f8_1
  • /data/data/####/0389ab9faa3d953a_0 (deleted)
  • /data/data/####/03d7216bebb6d699_0
  • /data/data/####/03d7216bebb6d699_1
  • /data/data/####/0412fe6c22dd1079_0
  • /data/data/####/053705ee411688f9_0
  • /data/data/####/056b791bbb692693_0
  • /data/data/####/059a96a7b5796db4_0
  • /data/data/####/061b2580b662f390_0
  • /data/data/####/06f723a54a89a4a7_0
  • /data/data/####/083efbb3348d77f2_0
  • /data/data/####/08d13031694928d1_0
  • /data/data/####/0910e5873a9931b5_0
  • /data/data/####/09b1ee953a40a248_0
  • /data/data/####/09f101986ddfd8c6_0
  • /data/data/####/0c464fad23ca9b07_0
  • /data/data/####/0c464fad23ca9b07_1
  • /data/data/####/0ccac113416d2047_0
  • /data/data/####/0d92d189da6eed23_0
  • /data/data/####/0e53ec1e4a025bef_0
  • /data/data/####/0f07d2d6d1fa3e35_0
  • /data/data/####/1.dex
  • /data/data/####/1.dex.flock (deleted)
  • /data/data/####/1.jar
  • /data/data/####/10036244cdf60fe9_0
  • /data/data/####/101151132a7f5180_0
  • /data/data/####/10306f64688d2dc3_0
  • /data/data/####/10306f64688d2dc3_1
  • /data/data/####/1134ba700d73887a_0
  • /data/data/####/1230ba3f28326e0b_0
  • /data/data/####/1230ba3f28326e0b_1
  • /data/data/####/12a2eea978927047_0
  • /data/data/####/12a2eea978927047_1
  • /data/data/####/13_2.dex (deleted)
  • /data/data/####/13_2.dex.flock (deleted)
  • /data/data/####/13_2.jar
  • /data/data/####/164b235337a0cb2c_0
  • /data/data/####/164b235337a0cb2c_1
  • /data/data/####/1692f994c70cef73_0 (deleted)
  • /data/data/####/17.dex
  • /data/data/####/17.dex.flock (deleted)
  • /data/data/####/17.jar
  • /data/data/####/17e49458c548ef8c_0
  • /data/data/####/17f39d20e9dc2ca5_0
  • /data/data/####/18.dex (deleted)
  • /data/data/####/18.dex.flock (deleted)
  • /data/data/####/18.jar
  • /data/data/####/1876349c89fd3dc4_0
  • /data/data/####/1876349c89fd3dc4_0 (deleted)
  • /data/data/####/18bcc7085f6ce73d_0 (deleted)
  • /data/data/####/18f309eb1fe22646_0
  • /data/data/####/1904bebf53048c4e_0
  • /data/data/####/1904bebf53048c4e_1
  • /data/data/####/192ad207468c1bf4_0
  • /data/data/####/192ad207468c1bf4_1
  • /data/data/####/1a9a0d3b2be4a912_0
  • /data/data/####/1aeabca88eacd4fd_0
  • /data/data/####/1b15a8aec6124c17_0
  • /data/data/####/1c222ec45fc25b0e_0
  • /data/data/####/1ca230189be064fa_0
  • /data/data/####/1cf7821863f4f4e5_0
  • /data/data/####/1d2c77bd5290718f_0
  • /data/data/####/1dcc26f052e5c9c6_0
  • /data/data/####/1dcc26f052e5c9c6_1
  • /data/data/####/1de7a629c2baf307_0
  • /data/data/####/1deed7936f7b7aa8_0
  • /data/data/####/1e06b64de541371d_0
  • /data/data/####/1e113ece9b8c76de_0
  • /data/data/####/1e113ece9b8c76de_1
  • /data/data/####/1fd07fbe4f2049ea_0 (deleted)
  • /data/data/####/20e567da4750c06e_0
  • /data/data/####/20e567da4750c06e_1
  • /data/data/####/20fb5bd7ecd81d58_0
  • /data/data/####/21997fce6031cd5c_0 (deleted)
  • /data/data/####/21c03159ba1aef56_0
  • /data/data/####/2271c6211a94bfeb_0
  • /data/data/####/229f96b5e786246f_0
  • /data/data/####/23aa0a8a5ba87210_0
  • /data/data/####/23aa0a8a5ba87210_1
  • /data/data/####/23f55bce25ca399f_0
  • /data/data/####/25e2a682195eb2b3_0
  • /data/data/####/25e2a682195eb2b3_1
  • /data/data/####/25f6a25104c9c9ae_0
  • /data/data/####/269855efb55f0314_0
  • /data/data/####/269855efb55f0314_1
  • /data/data/####/27dac8705e581c47_0
  • /data/data/####/27dac8705e581c47_1
  • /data/data/####/280449a6c9ea1e96_0
  • /data/data/####/29afebbbddc8eb46_0
  • /data/data/####/29d8a6ef09b519d0_0 (deleted)
  • /data/data/####/2a7a48c54391d7af_0
  • /data/data/####/2ad0a9b7cee9a483_0
  • /data/data/####/2b9d48e3e2d30fba_0
  • /data/data/####/2bc3149f47b86c90_0
  • /data/data/####/2c649830da04d7ad_0
  • /data/data/####/2c8d21495d359712_0
  • /data/data/####/2db596a7ac30f1fb_0
  • /data/data/####/2dc3f1a4a0189b75_0
  • /data/data/####/2dc3f1a4a0189b75_1
  • /data/data/####/2e3b1af82330bccf_0
  • /data/data/####/2ea1421a3283a9bc_0
  • /data/data/####/2ed6bab873cee0f6_0
  • /data/data/####/2f19fe64b147995b_0
  • /data/data/####/2f2cde2256c783b2_0
  • /data/data/####/2fa4c93bec7a5e71_0
  • /data/data/####/2fc628ce935949e9_0
  • /data/data/####/30b9d51bda8afe17_0
  • /data/data/####/31c82e67b8185757_0
  • /data/data/####/31c82e67b8185757_1
  • /data/data/####/31cc14aee4191da3_0
  • /data/data/####/31cc14aee4191da3_1
  • /data/data/####/3305ac33696d7d2f_0
  • /data/data/####/3483c8b52ecc6d9e_0
  • /data/data/####/3483c8b52ecc6d9e_0 (deleted)
  • /data/data/####/348fbb835f87434d_0
  • /data/data/####/34f2963160300618_0
  • /data/data/####/35b424714d3a7d5e_0
  • /data/data/####/35b424714d3a7d5e_1
  • /data/data/####/366721c304299bec_0
  • /data/data/####/39ac2e95d1ce73a1_0
  • /data/data/####/39f38ddb2b7146ce_0
  • /data/data/####/3b1ae851d5a48313_0 (deleted)
  • /data/data/####/3ba6bfe1b6979c0f_0
  • /data/data/####/3be8da3d1394c8fc_0
  • /data/data/####/3be8da3d1394c8fc_1
  • /data/data/####/4073a8a97a53804c_0
  • /data/data/####/40830b5f2f35bec2_0
  • /data/data/####/40ab830d5edfc749_0 (deleted)
  • /data/data/####/40fc0bba27a3ab92_0
  • /data/data/####/413d0e9ba19b6af5_0
  • /data/data/####/4393c157f9687f16_0
  • /data/data/####/4393c157f9687f16_1
  • /data/data/####/443423be30dfe7ca_0 (deleted)
  • /data/data/####/44b1702640a23c7b_0
  • /data/data/####/44ded89f884d07f5_0
  • /data/data/####/4602c4748d68c731_0
  • /data/data/####/46b977c339d447fd_0 (deleted)
  • /data/data/####/477011b794487c99_0
  • /data/data/####/483f77c312fb7de6_0
  • /data/data/####/485b221cdbf7aa92_0
  • /data/data/####/485b221cdbf7aa92_0 (deleted)
  • /data/data/####/485b221cdbf7aa92_1
  • /data/data/####/49274d3838db4b23_0
  • /data/data/####/49274d3838db4b23_1
  • /data/data/####/49fa58c0822d7a87_0
  • /data/data/####/49fa58c0822d7a87_1
  • /data/data/####/49fc355e9fea0c55_0
  • /data/data/####/49fc355e9fea0c55_0 (deleted)
  • /data/data/####/49fc355e9fea0c55_1
  • /data/data/####/4a84212d8891d521_0
  • /data/data/####/4e8a36fbde479d35_0
  • /data/data/####/4fe7bd89a01cf83a_0
  • /data/data/####/4fe7bd89a01cf83a_0 (deleted)
  • /data/data/####/50bf12df37dffaf6_0
  • /data/data/####/50bf12df37dffaf6_1
  • /data/data/####/52332115bea2e5702d7659cb48fa5c3a.db
  • /data/data/####/52d1447140c248aa_0
  • /data/data/####/54c05d94d7c9f0f6_0
  • /data/data/####/5534c817fdf4846d_0 (deleted)
  • /data/data/####/556ea2a5968c6e3d_0
  • /data/data/####/55b3ff090066d7dd_0
  • /data/data/####/56349230e9a2f8e8_0
  • /data/data/####/56859df1bc08940e_0 (deleted)
  • /data/data/####/572e7f720a22affe_0
  • /data/data/####/5730d4a2ed80e567_0
  • /data/data/####/5_2.dex
  • /data/data/####/5_2.dex.flock (deleted)
  • /data/data/####/5_2.jar
  • /data/data/####/5aadcc9bf6104098_0 (deleted)
  • /data/data/####/5c38b9a44963b176_0
  • /data/data/####/5caee178439e9614_0
  • /data/data/####/5caee178439e9614_1
  • /data/data/####/5cd67cccc443c6eb_0 (deleted)
  • /data/data/####/5d58bcda667657f3_0
  • /data/data/####/5db5808d5087811f_0
  • /data/data/####/5dcf658cee623b90_0
  • /data/data/####/5dcf658cee623b90_1
  • /data/data/####/5e09fa91fad1f1c0_0 (deleted)
  • /data/data/####/5e15ba786ab77c61_0
  • /data/data/####/5e1cabf7132ae37e_0
  • /data/data/####/5e1cabf7132ae37e_0 (deleted)
  • /data/data/####/5e43e309e6af847c_0
  • /data/data/####/5e43e309e6af847c_1
  • /data/data/####/5e4c97e8c9973d15_0
  • /data/data/####/5e4c97e8c9973d15_1
  • /data/data/####/5e5e4cc9c4d4414f_0
  • /data/data/####/5ea9f7714fa171ff_0
  • /data/data/####/5f37b19ea8d17548_0
  • /data/data/####/5f74ecdaaa2a44e9_0
  • /data/data/####/5f936479c56c9171_0
  • /data/data/####/5fa26b0e101890c0_0
  • /data/data/####/600b6322e5b5cb57_0
  • /data/data/####/61c490d6d27b31f6_0
  • /data/data/####/61c490d6d27b31f6_1
  • /data/data/####/61e4aacd738d0bc4fcd42b8dde25e76b.db
  • /data/data/####/61e4aacd738d0bc4fcd42b8dde25e76b.dex
  • /data/data/####/61e4aacd738d0bc4fcd42b8dde25e76b.dex.flock (deleted)
  • /data/data/####/61e4aacd738d0bc4fcd42b8dde25e76b.jar
  • /data/data/####/62f5e31f64cc3835_0
  • /data/data/####/63f9a721aa7477f0_0
  • /data/data/####/6461ecef5115ecda_0
  • /data/data/####/6514c35db627e057_0
  • /data/data/####/65465f12a6f31f2d_0
  • /data/data/####/663b03b0b665834d_0
  • /data/data/####/66f42d97bff91c48_0
  • /data/data/####/66f42d97bff91c48_0 (deleted)
  • /data/data/####/6804c0bb0b5e17b0_0
  • /data/data/####/6804c0bb0b5e17b0_1
  • /data/data/####/68e22fababf67d56_0
  • /data/data/####/68e22fababf67d56_1
  • /data/data/####/6990cea56b1e5a35_0
  • /data/data/####/6a2ff114678d635c_0
  • /data/data/####/6a97283703a165e8_0
  • /data/data/####/6ac15a3826bd8a16_0
  • /data/data/####/6b2bcdd2e6c330c5_0
  • /data/data/####/6c5194f42d8e5d71_0
  • /data/data/####/6cf1eed3c3368618_0
  • /data/data/####/6cf1eed3c3368618_0 (deleted)
  • /data/data/####/6d0ebcc2ae290998_0
  • /data/data/####/6d0ebcc2ae290998_1
  • /data/data/####/6dbc84fe09f079b9_0
  • /data/data/####/6dcd34475fb31deb_0
  • /data/data/####/70772331cf89b0de_0
  • /data/data/####/70c1d51663b60f5e_0
  • /data/data/####/713fd7a9b3f68fef_0
  • /data/data/####/717ef3657a45ad89_0
  • /data/data/####/717ef3657a45ad89_1
  • /data/data/####/71b0ad7baf3ef66e_0
  • /data/data/####/71ceadf139c5abf5_0
  • /data/data/####/71d4101115bebb30_0
  • /data/data/####/71d4101115bebb30_1
  • /data/data/####/7295ece1696c2c3e0ee9a8b27f4b49a3.db
  • /data/data/####/72ae2abe0e42d02e_0
  • /data/data/####/72f347ba86f1e638_0
  • /data/data/####/72f347ba86f1e638_1
  • /data/data/####/735e0911ab158d7f_0
  • /data/data/####/735e0911ab158d7f_1
  • /data/data/####/73c67236ec976a11_0
  • /data/data/####/7445b1a08b6b17ac_0
  • /data/data/####/7445b1a08b6b17ac_1
  • /data/data/####/74533cd9c52aeda7_0
  • /data/data/####/74533cd9c52aeda7_1
  • /data/data/####/747ad95e46ea5e47_0
  • /data/data/####/76451315b4428c44_0
  • /data/data/####/76860f687f4d3d96_0
  • /data/data/####/76a12070ce601320_0
  • /data/data/####/786c2308289855c6_0
  • /data/data/####/7881087791d53a7e_0
  • /data/data/####/7890ec333c4e2969_0 (deleted)
  • /data/data/####/78b85ba9a73b90de_0
  • /data/data/####/7958388b2794a276_0
  • /data/data/####/795b27ac2858be56_0
  • /data/data/####/7aad9d3aa3f0d756_0
  • /data/data/####/7cebdd758d1e562e_0
  • /data/data/####/7d8341334bf6f6a4_0
  • /data/data/####/7dc761c7145bf8b1_0
  • /data/data/####/7e1075960aa1dd46_0
  • /data/data/####/7e1075960aa1dd46_1
  • /data/data/####/7f543d273413a4b7_0
  • /data/data/####/8.dex
  • /data/data/####/8.dex.flock (deleted)
  • /data/data/####/8.jar
  • /data/data/####/803c409daf04c25d_0 (deleted)
  • /data/data/####/808ae25b8aeba0a0_0
  • /data/data/####/80cb346fe3580cb8_0
  • /data/data/####/812f9be91f48e629_0
  • /data/data/####/815887e26b8c65b6_0
  • /data/data/####/815eb6a8a3ff7ca9_0
  • /data/data/####/815eb6a8a3ff7ca9_1
  • /data/data/####/8268aa3754cade2a_0
  • /data/data/####/82c26aef614506d6_0
  • /data/data/####/840e52098413385e_0
  • /data/data/####/840e52098413385e_0 (deleted)
  • /data/data/####/84b89be5e70dbfb9_0
  • /data/data/####/84b89be5e70dbfb9_1
  • /data/data/####/866937e0029710d9_0
  • /data/data/####/86fe2099d90735fa_0
  • /data/data/####/87c7c53415dfaee7_0
  • /data/data/####/8945e58ffbe4a4c1_0
  • /data/data/####/8945e58ffbe4a4c1_1
  • /data/data/####/89db8239622cf716_0
  • /data/data/####/89f8af66b88c5b48_0
  • /data/data/####/8a18578dab58078a_0
  • /data/data/####/8ab911a166a7c1dc_0
  • /data/data/####/8ab911a166a7c1dc_1
  • /data/data/####/8adab2394ce98e42_0
  • /data/data/####/8b985113e42fd567_0
  • /data/data/####/8c32712f7e2e9cc8_0
  • /data/data/####/8c32712f7e2e9cc8_1
  • /data/data/####/8cc6e85bf56b28b4_0
  • /data/data/####/8cc6e85bf56b28b4_1
  • /data/data/####/8d92334a735b1305_0
  • /data/data/####/8d92334a735b1305_1
  • /data/data/####/8d999de25cda553b_0
  • /data/data/####/8d999de25cda553b_1
  • /data/data/####/8e236583e7d97c5b_0
  • /data/data/####/8e75ff5ab24c0925_0
  • /data/data/####/8efb693685797826_0
  • /data/data/####/8f422138e79dc6a4_0
  • /data/data/####/8f63c962f4e70b80_0
  • /data/data/####/8f98327ae6c2a087_0
  • /data/data/####/914D1DA6187D0B324FCDA22FC3668D79.temp
  • /data/data/####/91a1f46e8b77120b_0
  • /data/data/####/91ad8bd2050da9c4_0
  • /data/data/####/923e32e37465fc78_0 (deleted)
  • /data/data/####/9261fcf76b792bb1_0
  • /data/data/####/931f76d09623ed68_0
  • /data/data/####/931f76d09623ed68_1
  • /data/data/####/9381131534569cb0_0
  • /data/data/####/94f25a802b1b0786_0
  • /data/data/####/94f91eadbe75fcbb_0
  • /data/data/####/95be0bd2975e4eef_0
  • /data/data/####/9624a75c5d8657eb_0
  • /data/data/####/965781cd579ed490_0
  • /data/data/####/966b538464b9bf04_0
  • /data/data/####/966b538464b9bf04_1
  • /data/data/####/96d50d0114a1e2ea_0
  • /data/data/####/979d153e23121e62_0
  • /data/data/####/98106801662fbd95_0 (deleted)
  • /data/data/####/985958d976619751_0
  • /data/data/####/985958d976619751_1
  • /data/data/####/989e067590d53440_0 (deleted)
  • /data/data/####/990811e8eb5ae860_0
  • /data/data/####/99318d2cc3f43e32_0
  • /data/data/####/999a6ec1eb8f3e35_0
  • /data/data/####/999a6ec1eb8f3e35_1
  • /data/data/####/9a51ae6b891c1205_0
  • /data/data/####/9a51ae6b891c1205_1
  • /data/data/####/9a78e5e91329986f_0
  • /data/data/####/9afa3c7a83bc7a0d_0
  • /data/data/####/9c3115d9a4165a3e_0
  • /data/data/####/9c3115d9a4165a3e_1
  • /data/data/####/9c45071a4b54ea6c_0
  • /data/data/####/9c9aba6c1dde921b_0
  • /data/data/####/9e7c5e9a20cbe093_0
  • /data/data/####/9eccf9a9c7c1dcc3_0
  • /data/data/####/9eccf9a9c7c1dcc3_1
  • /data/data/####/9ed4c179605a8d71_0
  • /data/data/####/9f18f12b971e2616_0
  • /data/data/####/9f18f12b971e2616_0 (deleted)
  • /data/data/####/9ff63083d56153a8_0
  • /data/data/####/9ff63083d56153a8_1
  • /data/data/####/AC6E3274059BAE8EB9EE9421F4C7ADAB.temp
  • /data/data/####/Cookies-journal
  • /data/data/####/HttpDNSConstantsJson.xml
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/XkdjsIx132mMskey1.xml
  • /data/data/####/XkdjsIx132mMtasks.xml
  • /data/data/####/_p.xml
  • /data/data/####/_pn
  • /data/data/####/_sh.xml
  • /data/data/####/_shn
  • /data/data/####/a02acb6bf0aab84f_0
  • /data/data/####/a16ea8c5628c2212_0
  • /data/data/####/a1ba1c9a11de5aac_0
  • /data/data/####/a25fbf6df5202c0d_0
  • /data/data/####/a3ae92db9ed250d2_0
  • /data/data/####/a3ae92db9ed250d2_1
  • /data/data/####/a400477b4a240046_0
  • /data/data/####/a400477b4a240046_1
  • /data/data/####/a63f0c23724f5bc2_0
  • /data/data/####/a70cc74efa1082c3_0
  • /data/data/####/a91941514f9cf530_0
  • /data/data/####/a942aa1c505ddd65_0
  • /data/data/####/a942aa1c505ddd65_1
  • /data/data/####/a9c0a5939e37a5e0_0
  • /data/data/####/a9deb99febd5319e_0
  • /data/data/####/aa3170a74eb9815e_0
  • /data/data/####/aac02126d6cc5b85_0 (deleted)
  • /data/data/####/aacdf3653153d34f_0
  • /data/data/####/ab9573eb07133c84_0
  • /data/data/####/accb641e487648a8_0
  • /data/data/####/ad34bbc9fdff56f5_0
  • /data/data/####/ae7b15bc697765cf_0
  • /data/data/####/aec67997babe7e68_0 (deleted)
  • /data/data/####/af2c69c61b7b25c4_0
  • /data/data/####/ahq_spu_ti.xml
  • /data/data/####/b02b6ad0ef4da244_0 (deleted)
  • /data/data/####/b04ec9cf1f22e252_0 (deleted)
  • /data/data/####/b2010cb3a084eb14_0
  • /data/data/####/b27c5293778b45a7_0
  • /data/data/####/b3252a85bb63bd34_0
  • /data/data/####/b3252a85bb63bd34_1
  • /data/data/####/b3ce81e24d9228bb_0
  • /data/data/####/b400189797553fb8_0
  • /data/data/####/b408ab04610bb431_0 (deleted)
  • /data/data/####/b41c2c12e52d7b35_0
  • /data/data/####/b4818ca5b79ec006_0
  • /data/data/####/b4aa053480442bf6_0
  • /data/data/####/b4b087dcbcac375c_0
  • /data/data/####/b4b087dcbcac375c_1
  • /data/data/####/b4ea476f78e7d5e5_0
  • /data/data/####/b75c120f986ba77c_0
  • /data/data/####/b75c120f986ba77c_1
  • /data/data/####/b852ca709c76e4cd_0
  • /data/data/####/b8dbdbab09fcb037_0
  • /data/data/####/b8eca20d89aa0402_0
  • /data/data/####/b8f297c1f442d05a_0
  • /data/data/####/b99b3148d1c610b5_0
  • /data/data/####/b9fbe5aad4cf45d9_0
  • /data/data/####/bc64e597188877b1_0
  • /data/data/####/be94fd46c5d6851d_0
  • /data/data/####/c027544d47a8bdce_0
  • /data/data/####/c027544d47a8bdce_0 (deleted)
  • /data/data/####/c08ab5f047611547_0
  • /data/data/####/c1b3f59631fcf877_0 (deleted)
  • /data/data/####/c1b78db80c75cd3b_0
  • /data/data/####/c2aa9bb5c6b97e29_0
  • /data/data/####/c2b7ff9e3373702b_0
  • /data/data/####/c437b5c40a0d6011_0
  • /data/data/####/c451f8536b0b29b6_0 (deleted)
  • /data/data/####/c4b8f5423aab0352_0 (deleted)
  • /data/data/####/c54d60fce6fa0a1a_0
  • /data/data/####/c584f0dd61640ef5_0 (deleted)
  • /data/data/####/c5c22e45f19cc3e3_0
  • /data/data/####/c5c22e45f19cc3e3_1
  • /data/data/####/c5ec200a7caa274e_0
  • /data/data/####/c5ec200a7caa274e_1
  • /data/data/####/c6021535edc1fe02_0
  • /data/data/####/c6021535edc1fe02_1
  • /data/data/####/c6598a514c178581_0
  • /data/data/####/c66b930c3b6365e9b546ec8b3d0364aa.db
  • /data/data/####/c6d1808eb11dc201_0
  • /data/data/####/c7b6deaf19f54bc3_0
  • /data/data/####/c7ce1868366f1643_0
  • /data/data/####/c8a532928c86509d_0
  • /data/data/####/cb0b8ab8cf124a52_0 (deleted)
  • /data/data/####/cb207d285fd4105b_0
  • /data/data/####/cd5df220b541161c_0
  • /data/data/####/cd5df220b541161c_0 (deleted)
  • /data/data/####/cd76a202682142db_0
  • /data/data/####/cecd9e3c202946ab_0
  • /data/data/####/cecd9e3c202946ab_1
  • /data/data/####/ceeecf7666ff75e9_0
  • /data/data/####/cf3ff1efbc6b3770_0
  • /data/data/####/cf4cf4444e75fcfe_0
  • /data/data/####/cfbb08d5bc74deb5_0
  • /data/data/####/cfbb08d5bc74deb5_1
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.oat
  • /data/data/####/com.meiju592.app.xml
  • /data/data/####/com.meiju592.app.xml.bak
  • /data/data/####/com.meiju592.app_preferences.xml
  • /data/data/####/com.meiju592.app_preferences.xml.bak
  • /data/data/####/com.tencent.open.config.json.1106779540
  • /data/data/####/countIp.xml
  • /data/data/####/d01e1e4edab7fc26_0 (deleted)
  • /data/data/####/d07444cce2869831_0
  • /data/data/####/d07444cce2869831_1
  • /data/data/####/d0a3cf5503129b83_0
  • /data/data/####/d0a3cf5503129b83_1
  • /data/data/####/d1247334212a8d57_0
  • /data/data/####/d133d07aab2d1e0a_0
  • /data/data/####/d1e1e1e1cb485376_0 (deleted)
  • /data/data/####/d22bc883aa3b3c33_0
  • /data/data/####/d242a02e3b9100f0_0
  • /data/data/####/d2717bddf166962e_0
  • /data/data/####/d2e3475894e6f274_0
  • /data/data/####/d2e3475894e6f274_0 (deleted)
  • /data/data/####/d3d0f248f330ce1e_0
  • /data/data/####/d4219fff9a178666_0
  • /data/data/####/d4219fff9a178666_1
  • /data/data/####/d5ddc695a31aa53e_0
  • /data/data/####/d610f1c85c12d6d3_0
  • /data/data/####/d7d918848a64f8c0_0
  • /data/data/####/d855220268c2032c_0
  • /data/data/####/d855220268c2032c_1
  • /data/data/####/d85e497d719ffa8f_0
  • /data/data/####/d870c33211690f82_0
  • /data/data/####/d9381d63054a9ffc_0
  • /data/data/####/d93a5c8d2a783d45_0
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTc0NjI0OTY1ODU2;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTc0NjI0OTYxNDE1;
  • /data/data/####/daa6099ed2b291c3_0
  • /data/data/####/dac9a24d54809757_0
  • /data/data/####/dac9a24d54809757_1
  • /data/data/####/dae5355817bcc91b_0
  • /data/data/####/dae66dec4c423d23_0
  • /data/data/####/db7ddb2a5d0efd2e_0
  • /data/data/####/dc8a29de32503482_0
  • /data/data/####/dd8d6ed6ba4ddee1bd53a4222dd60c3e.db
  • /data/data/####/de0ea50a2279c247_0
  • /data/data/####/deeb263f45008a8c_0
  • /data/data/####/deeb263f45008a8c_1
  • /data/data/####/device_id.xml.xml
  • /data/data/####/dns_ip_info.db
  • /data/data/####/dns_ip_info.db-journal
  • /data/data/####/downUmeng.dex
  • /data/data/####/downUmeng.dex.flock (deleted)
  • /data/data/####/downUmeng.jar
  • /data/data/####/dpi
  • /data/data/####/e02d55a47307a7a8_0
  • /data/data/####/e0f8cdcef93626b0_0
  • /data/data/####/e14ac9dc0d13a9a7_0
  • /data/data/####/e1629e0eb7e821b7_0
  • /data/data/####/e3c9ed4781766ed8_0
  • /data/data/####/e409414b89fcda32_0
  • /data/data/####/e41653f03c521a54_0
  • /data/data/####/e41653f03c521a54_1
  • /data/data/####/e617102427cd199b_0
  • /data/data/####/e617102427cd199b_0 (deleted)
  • /data/data/####/e6740be65e62f6b4_0
  • /data/data/####/e6740be65e62f6b4_0 (deleted)
  • /data/data/####/e699cc18448408e9_0
  • /data/data/####/e717a310ceb0c850_0
  • /data/data/####/e717a310ceb0c850_1
  • /data/data/####/e7b51d3e8b85e8a9_0
  • /data/data/####/e7b51d3e8b85e8a9_1
  • /data/data/####/e7b7757407075848_0
  • /data/data/####/e7b7757407075848_1
  • /data/data/####/e88b18d81613c4e6_0
  • /data/data/####/e95f79a1dc3b5cb9_0
  • /data/data/####/ec5348860a4a7f8f_0
  • /data/data/####/ec5348860a4a7f8f_1
  • /data/data/####/ec9f263e4ea5b94c_0
  • /data/data/####/ec9f263e4ea5b94c_1
  • /data/data/####/edd21f355173cd10_0
  • /data/data/####/ede52e461db063ae_0
  • /data/data/####/ee6802e5fa51650a_0
  • /data/data/####/efcadb0c3b38fd82_0
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f04479f10ab9d876_0
  • /data/data/####/f055a623f8dfd329_0
  • /data/data/####/f06bfe2193714bff_0
  • /data/data/####/f0889ec40a54f99b_0
  • /data/data/####/f281915c927681cb_0
  • /data/data/####/f28daa933bb512c6_0 (deleted)
  • /data/data/####/f2db67a5d8e38e68_0
  • /data/data/####/f3a6498a64561854_0
  • /data/data/####/f8532e5afce21c13_0
  • /data/data/####/f8756f4f3ac5d9e5_0
  • /data/data/####/f955c37a69f9f870_0
  • /data/data/####/f9accb3e7d070b55_0 (deleted)
  • /data/data/####/fa877d23945bf0cb_0
  • /data/data/####/fa8e8d1c1ec4cb31_0
  • /data/data/####/fb7138146f4281e9_0
  • /data/data/####/fe17a3067d3ace52_0
  • /data/data/####/fe17a3067d3ace52_1
  • /data/data/####/fe2eafa6027d2eab_0
  • /data/data/####/fef55d4f1d592b0f_0
  • /data/data/####/ff051d47c233e80e_0
  • /data/data/####/ff92fa8ee764d768_0
  • /data/data/####/hhq_spu_ti.xml
  • /data/data/####/hid.db
  • /data/data/####/http_s.zhitoudsp.com_808.localstorage-journal
  • /data/data/####/https_pos.baidu.com_0.localstorage-journal
  • /data/data/####/https_www.iqiyi.com_0.localstorage-journal
  • /data/data/####/i==1.2.0&&5.3.8_1574624961601_envelope.log
  • /data/data/####/index
  • /data/data/####/info.xml
  • /data/data/####/libjiagu.so
  • /data/data/####/meijuniaoV2.db-journal
  • /data/data/####/metrics_guid
  • /data/data/####/msy.xml
  • /data/data/####/proc_auxv
  • /data/data/####/the-real-index
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_common_location.xml
  • /data/data/####/umeng_down_18.db
  • /data/data/####/umeng_down_5_2.db
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes.dex:classes2.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/cache/cacheUmeng/oatCache/downUmeng.jar --oat-fd=90 --oat-location=/data/user/0/<Package>/cache/cacheUmeng/oatCache/downUmeng/downUmeng.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/1.jar --oat-fd=144 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/1.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/13_2.jar --oat-fd=130 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/13_2.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/17.jar --oat-fd=140 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/17.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/18.jar --oat-fd=140 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/18.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/5_2.jar --oat-fd=141 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/5_2.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/61e4aacd738d0bc4fcd42b8dde25e76b.jar --oat-fd=167 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/61e4aacd738d0bc4fcd42b8dde25e76b.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/cache/cacheUmeng/8.jar --oat-fd=91 --oat-location=/data/user/0/<Package>/files/cache/cacheUmeng/8.dex --compiler-filter=speed
  • /system/bin/sh
  • cat /proc/cpuinfo
  • cat /sys/class/android_usb/android0/idProduct
  • cat /sys/class/android_usb/android0/idVendor
  • cat /sys/class/net/wlan0/address
  • getprop
  • ls -l /dev
  • ls -l /dev/__properties__
  • ls -l /dev/block
  • ls -l /dev/block/pci
  • ls -l /dev/block/pci/pci0000:00
  • ls -l /dev/block/pci/pci0000:00/0000:00:01.1
  • ls -l /dev/block/pci/pci0000:00/0000:00:01.1/by-num
  • ls -l /dev/block/vold
  • ls -l /dev/bus
  • ls -l /dev/bus/usb
  • ls -l /dev/bus/usb/001
  • ls -l /dev/com.android.settings
  • ls -l /dev/com.android.settings.daemon
  • ls -l /dev/cpuctl
  • ls -l /dev/cpuset
  • ls -l /dev/cpuset/background
  • ls -l /dev/cpuset/foreground
  • ls -l /dev/cpuset/foreground/boost
  • ls -l /dev/cpuset/system-background
  • ls -l /dev/cpuset/top-app
  • ls -l /dev/fscklogs
  • ls -l /dev/graphics
  • ls -l /dev/input
  • ls -l /dev/memcg
  • ls -l /dev/memcg/apps
  • ls -l /dev/pts
  • ls -l /dev/snd
  • ls -l /dev/socket
  • ls -l /dev/stune
  • ls -l /dev/stune/background
  • ls -l /dev/stune/foreground
  • ls -l /dev/stune/top-app
  • ls /
  • ls /sys/class/thermal
  • ps
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Displays its own windows over windows of other apps.
Manages Wi-Fi connectivity.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android