Technical information
- Adware.Dowgin.3.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) s####.i####.cn:80
- TCP(HTTP/1.1) cd.md.c####.####.net:80
- TCP(HTTP/1.1) ni.ei.ne####.cn:80
- TCP(TLS/1.0) 2####.58.208.110:443
- a####.u####.com
- cd.md.c####.cn
- ni.ei.ne####.cn
- s####.i####.cn
- cd.md.c####.####.net/offer/20181204/201812041054759.png
- cd.md.c####.####.net/offer/20190403/201904031138116.apk
- cd.md.c####.####.net/offer/20190403/201904031407486.png
- s####.i####.cn/t?r=####&p=####
- a####.u####.com/app_logs
- ni.ei.ne####.cn/fgjdsgfudsi/c532/e70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/p70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/q70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/r70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/s70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/t70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/u70
- ni.ei.ne####.cn/fgjdsgfudsi/c532/w70
- /data/data/####/-WlMEGMeHMbVn-QMOptTXLurFEE=-journal
- /data/data/####/20BdQqfRsHH1CQPqGU-zN5fasXk=.xml
- /data/data/####/27zS238CvcQCnmr8_j2hXA==-journal
- /data/data/####/4UXG7oGA-Y1QEyc_eYpAX7qUdxo=.xml
- /data/data/####/D5oBCDtqlY5fHT4_W3I6hgaQnauuMXKeSfAD2Q==.xml
- /data/data/####/F4QcGqYUmtjt7nid8zzSqX68EgU=
- /data/data/####/FKSO-PTG-6bHG6iKfVdjtUdNFkk=
- /data/data/####/G3wN5TAX0UITIDzU3g3JwgeDoVYYcIm8.xml
- /data/data/####/I9PY9Bfo9OQy4W58-journal
- /data/data/####/JCYJQ-OOoEM3wZjZoLrWUQ==
- /data/data/####/Jgt3M_5Vhn8Rcaj8dRecimW0MNgEJN9_.xml
- /data/data/####/Kbs3XetlM2SXICbdG56LqA==-journal
- /data/data/####/NgOrZpol79RfIlGDsAEtDimKutyQ_DWe_Mohxg==.xml
- /data/data/####/PT62goNasKVqr0tUP1UeJg==-journal
- /data/data/####/Q6SoI48vGt6E7NJX.zip
- /data/data/####/QrwGC9TVwWZTdNGB3bsSfDRzXfIcAH3-gFbXXA==.xml
- /data/data/####/QsWnXGzdepfnm7BtNHfpmg==
- /data/data/####/Rx5MmlgW-7BfuUsPcMp-tQ==.xml
- /data/data/####/TzxVa9cImSXWY3-DX1e7lhQh2-o=
- /data/data/####/U3Y8l64LPEV967D0o3uR7kRYuG8=
- /data/data/####/XzYrRiETElpbAEJc.dex
- /data/data/####/XzYrRiETElpbAEJc.zip
- /data/data/####/_mhisdufgsdjgfqs.xml
- /data/data/####/_mjtisdufgsdjgfp.xml
- /data/data/####/_msisdufgsdjgf_r.xml
- /data/data/####/aAkaNlu8V1xDBQxOZ7WQKN9TXL0=.xml
- /data/data/####/aO4B_vpFEVi2L9NpESk0JOh07Os=.xml
- /data/data/####/arekvX4lfBPlk_Pn7jc7oIDfEHm0ZJJGoXQSxA==.xml
- /data/data/####/daemon_exe
- /data/data/####/data.dat.tmp
- /data/data/####/dh-o5MsqXMQCHBJBZh-ahcZpWgokQVcWWhBwXA==
- /data/data/####/e77DEMA7B7Csg5vqZqZvHg==
- /data/data/####/gSqpfoID8DoEsiD2YTYJRC-YSa0goY0gvpBkXQfLazU=.xml
- /data/data/####/j1FBI_eDeBFw-aB8.xml
- /data/data/####/libtt.so
- /data/data/####/libtt_441613e8-3f46-49f6-a197-2acd6552258f.so
- /data/data/####/mobclick_agent_header_com.safkjgsa.isdufgsdjgf.xml
- /data/data/####/mobclick_agent_state_com.safkjgsa.isdufgsdjgf.xml
- /data/data/####/pldkf6DzbP-SDwBeeImC_oX9aIjkATXarR2x7Q==.xml
- /data/data/####/rYqszvIxWVPhoMGt-journal
- /data/data/####/rteFMdh6psyiKtZ3tm7QqNi-MgNoLF4XAHYCtg==.xml
- /data/data/####/taqV8ikBAoOIXbuclM-4WEMp_6Y=-journal
- /data/data/####/ukdm.frd.ud.tlk.jar
- /data/data/####/zImbgVVxT9gLotLoQo92Uf2GrgA=
- /data/data/####/zscom.db
- /data/data/####/zscom.db-journal
- /data/media/####/7fc000b614430
- /data/media/####/8950f1cae1554
- /data/media/####/8fbec85d084f84a32336fbbd8852c38e.tmp
- /data/media/####/FKSO-PTG-6bHG6iKfVdjtUdNFkk=
- /data/media/####/com.safkjgsa.isdufgsdjgf.p
- /data/media/####/pr.p
- ./daemon_exe com.eoe.wifishare.wu
- /system/bin/app_process /system/bin ukdm.frd.ud.tlk.rth 2302 <Package>
- chmod 777 /storage/emulated/0/download/omsa//8fbec85d084f84a32336fbbd8852c38e.tmp
- com.google.mservice
- sh ./daemon_exe com.eoe.wifishare.wu
- libtt_441613e8-3f46-49f6-a197-2acd6552258f
- DES
- DES