Technical information
- Adware.Youmi.1.origin
- UDP(DNS) <Google DNS>
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) a.dia####.com:80
- TCP(HTTP/1.1) gi####.jsp.j####.cn:80
- TCP(HTTP/1.1) www.ilaj####.cn:80
- TCP(TLS/1.0) 2####.58.211.227:443
- TCP(TLS/1.0) 2####.58.210.138:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) rr6---s####.g####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) 64.2####.165.138:443
- TCP(TLS/1.2) 1####.194.73.95:443
- TCP(TLS/1.2) 1####.177.14.106:443
- TCP(TLS/1.2) 1####.251.1.95:443
- TCP(TLS/1.2) 64.2####.165.138:443
- TCP(TLS/1.2) 64.2####.164.95:443
- TCP(TLS/1.2) 2####.58.211.227:443
- UDP 2####.0.0.1:9998
- 2####.nd####.y####.com
- a####.u####.com
- a.appj####.com
- a.dia####.com
- aos.w####.y####.net
- gi####.jsp.j####.cn
- gmscomp####.google####.com
- p####.google####.com
- pla####.google####.com
- rr2---s####.g####.com
- rr6---s####.g####.com
- s####.gw.y####.net
- s.y####.net
- t####.dmp.y####.net
- www.ilaj####.cn
- a.dia####.com/dev/api/adlist/adlist.php?device_id=####&imsi=####&device_...
- www.ilaj####.cn/appsdk/advapp/appAdvapp?advapp.appId=####
- a####.u####.com/app_logs
- a.dia####.com/dev/api/connect.php?device_id=####&imsi=####&device_name=#...
- a.dia####.com/dev/api/e_package_update.php
- gi####.jsp.j####.cn/wxface_appWfImgList.action
- gi####.jsp.j####.cn/wxface_appWfPackageList.action
- /data/data/####/.jg.ic
- /data/data/####/663377a5bdd68a00c54a3084ff9d4fbd-journal
- /data/data/####/Alvin2.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/ContextData.xml
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/OxgHkj2lz09F-journal
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/ab801ef866e11a22fa6f1f0da7e4c8bc
- /data/data/####/ab801ef866e11a22fa6f1f0da7e4c8bc-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/d84da7bba77a0b9561f813661ba8513b
- /data/data/####/d84da7bba77a0b9561f813661ba8513b-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/libjiagu.so
- /data/data/####/libshiwugcome.so
- /data/data/####/preferences.xml
- /data/data/####/proc_auxv
- /data/data/####/prop.dat
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_general_config.xml.bak (deleted)
- /data/data/####/umeng_it.cache
- /data/data/####/usa129xa
- /data/data/####/usa129xa-journal
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/data/####/xUtils_http_cookie.db
- /data/data/####/xUtils_http_cookie.db-journal
- /data/data/####/xUtils_http_cookie.db-journal (deleted)
- /data/data/####/xUtils_http_cookie.db-shm (deleted)
- /data/data/####/xUtils_http_cookie.db-wal (deleted)
- /data/data/####/ymdex.dex
- /data/data/####/ymdex.dex.flock (deleted)
- /data/data/####/ymdex.jar.new
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/djaof.dll
- /data/media/####/i42d45df023jnkdd93la483f9xGFKXI
- /data/media/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/kernel_max
- cat /sys/class/net/wlan0/address
- chmod 755 /data/user/0/<Package>/files/libjiagu.so
- getprop
- sh -c getprop > /data/user/0/<Package>/files/prop.dat
- libjiagu
- libshiwugcomc
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- PBEWITHMD5andDES
- RSA-ECB-PKCS1Padding
- PBEWITHMD5andDES