Technical information
- Adware.Dowgin.14.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) ip.ta####.com:80
- TCP(HTTP/1.1) googl####.g.doublec####.net:80
- TCP(HTTP/1.1) nd.td.ntnew####.####.net:80
- TCP(HTTP/1.1) si.hi.shpan####.cn:80
- TCP(TLS/1.0) t####.3g.qq.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP mazu-####.3g.qq.com:443
- googl####.g.doublec####.net
- ip.ta####.com
- mazu-####.3g.qq.com
- nd.td.ntnew####.cn
- si.hi.shpan####.cn
- t####.3g.qq.com
- googl####.g.doublec####.net/mads/static/mad/sdk/native/sdk-core-v40-load...
- googl####.g.doublec####.net/mads/static/mad/sdk/native/sdk-core-v40.html
- ip.ta####.com/service/getIpInfo.php?ip=####
- nd.td.ntnew####.####.net/offer/20171206/201712061752304.png
- nd.td.ntnew####.####.net/offer/20171206/201712061752829.png
- nd.td.ntnew####.####.net/offer/20181109/201811091511627.apk
- nd.td.ntnew####.####.net/offer/20181204/201812041054103.png
- nd.td.ntnew####.####.net/offer/20181204/201812041054759.png
- si.hi.shpan####.cn/263d/gfb
- si.hi.shpan####.cn/263d/h63
- si.hi.shpan####.cn/263d/j26
- si.hi.shpan####.cn/263d/k26
- si.hi.shpan####.cn/263d/lb2
- si.hi.shpan####.cn/263d/n3d
- si.hi.shpan####.cn/263d/v3d
- si.hi.shpan####.cn/263d/xd9
- si.hi.shpan####.cn/263d/zd9
- /data/data/####/3afcc.xml
- /data/data/####/4a3f5bd19.xml
- /data/data/####/533656e.xml
- /data/data/####/68fe28.xml
- /data/data/####/8019054z.jar
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/ConfigInfo.xml
- /data/data/####/DualSimConfigInfo.xml
- /data/data/####/FULL7100_1264_1539595124_fst.dat
- /data/data/####/Farming Princess.swf
- /data/data/####/MultiDex.lock
- /data/data/####/ShellConfig.dat
- /data/data/####/TMSPropertiesAntitheftProperty.xml
- /data/data/####/TMSPropertiesIpDialProperty.xml
- /data/data/####/TMSPropertiesNetInterfaceManager.xml
- /data/data/####/TMSPropertiesnetworkload.xml
- /data/data/####/TMSPropertiesoperator_data_sync_setting.xml
- /data/data/####/ads333079423.jar
- /data/data/####/application.xml
- /data/data/####/bc526.xml
- /data/data/####/bugly_db_
- /data/data/####/bugly_db_-journal
- /data/data/####/com.dfjefs.ertonga.quweinn.AIRSharedPref.xml
- /data/data/####/conch_cache.xml
- /data/data/####/curl-ca-bundle.crt
- /data/data/####/daemon_config.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/db_kg_info.xml
- /data/data/####/dbconfig.xml
- /data/data/####/extension.xml
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/freq_ctrl_profile2.xml
- /data/data/####/freq_ctrl_profile4.xml
- /data/data/####/freq_ctrl_profile5.xml
- /data/data/####/freq_ctrl_profile6.xml
- /data/data/####/freq_ctrl_taiji.xml
- /data/data/####/http_googleads.g.doubleclick.net_0.localstorage-journal
- /data/data/####/index
- /data/data/####/j_dd_fl.dat
- /data/data/####/javaTrustStore.tmp
- /data/data/####/kd
- /data/data/####/kv_profile_sp_name.xml
- /data/data/####/library.swf
- /data/data/####/local_crash_lock
- /data/data/####/mdzoe_statis.xml
- /data/data/####/meriExt.db-journal
- /data/data/####/meri_config.xml
- /data/data/####/multidex.version.xml
- /data/data/####/mutil_process
- /data/data/####/native_record_lock
- /data/data/####/p_lock
- /data/data/####/pgd_sp.xml
- /data/data/####/prfle_cnfg_dao.xml
- /data/data/####/prfle_cnfg_dao.xml.bak
- /data/data/####/qqsecure.db
- /data/data/####/qqsecure.db-journal
- /data/data/####/rqd.xml
- /data/data/####/sk.xml
- /data/data/####/skyesys_conf.xml
- /data/data/####/tjs.xml
- /data/data/####/tmp-com.tencent.qqpimsecure-1.apk.classes333079423.zip
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/x_rb_j_al_ct_2.dat
- /data/data/####/xdm
- /data/media/####/3be4c1031
- /data/media/####/78416b25d
- /data/media/####/aa8d616b6
- /data/media/####/b0efa663f65d4c9d3167df9c7092ac77.tmp
- /data/media/####/filesafe_db.sqlite-journal
- /data/media/####/mfz.d
- /system/bin/cat /proc/cpuinfo
- /system/bin/cat /proc/meminfo
- /system/bin/cat /sys/devices/system/cpu/present
- chmod 0755 /data/data/com.tencent.qqpimsecure/applib/kd
- chmod 0771 /data/data/com.tencent.qqpimsecure/applib
- chmod 777 /storage/emulated/0/download/c63f471//b0efa663f65d4c9d3167df9c7092ac77.tmp
- grep xdm
- pgrep xdm
- pidof xdm
- ps
- ps xdm
- sh
- sh -c ps | grep xdm
- libCore
- libstlport_shared
- DES
- AES-CBC-PKCS5Padding
- DES