Technical information
- Adware.Ninebox.4.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.m.ta####.com:80
- TCP(HTTP/1.1) a####.u####.com.####.com:80
- TCP(HTTP/1.1) s.nin####.cn:80
- a####.m.ta####.com
- a####.u####.com
- b.nin####.cn
- donutma####.kool####.com
- s.nin####.cn
- a####.m.ta####.com/rest/abtest?ak=####&av=####&c=####&v=####&s=####&d=##...
- a####.m.ta####.com/rest/gc?ak=####&av=####&c=####&v=####&s=####&d=####&s...
- a####.u####.com.####.com/app_logs
- s.nin####.cn/admin/sc.action?requestId=####
- s.nin####.cn/admin/scs.action?requestId=####
- /data/data/####/9j_recommend.xml
- /data/data/####/9j_sidebar.xml
- /data/data/####/Alvin2.xml
- /data/data/####/AppStore.xml
- /data/data/####/ContextData.xml
- /data/data/####/DaemonServer
- /data/data/####/LocationType.xml
- /data/data/####/UTMCBase.xml
- /data/data/####/UTMCLog1577865031.xml
- /data/data/####/agoo.pid
- /data/data/####/bigPoins.xml
- /data/data/####/bj.jar
- /data/data/####/cachetimesha.xml
- /data/data/####/cachetimesha_sidebar.xml
- /data/data/####/dij.xml
- /data/data/####/dim.xml
- /data/data/####/donut_koolearn.db
- /data/data/####/donut_koolearn.db-journal
- /data/data/####/j-id.xml
- /data/data/####/jh.jar
- /data/data/####/lo.jar
- /data/data/####/mid.xml
- /data/data/####/mobclick_agent_cached_com.koolearn.storyhouseic
- /data/data/####/mobclick_agent_header_com.koolearn.storyhouseic.xml
- /data/data/####/mobclick_agent_state_com.koolearn.storyhouseic.xml
- /data/data/####/s_update.xml
- /data/data/####/so.jar
- /data/data/####/type.xml
- /data/data/####/umeng_message_state.xml
- /data/data/####/wh.jar
- /data/data/####/xy.xml
- /data/media/####/12.dat
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/MID.DAT
- /data/media/####/names.dat
- /data/media/####/share.dat
- <Package Folder>/files/DaemonServer <Package Folder>/lib/ runServer startservice -a <Package>.intent.action.COCKROACH --es cockroach cockroach-PPreotect --es pack <Package> --user 0 <Package Folder> 600 agoo.pid
- chmod 500 <Package Folder>/files/DaemonServer
- sh
- cocos2dlua
- AES-CBC-PKCS5Padding
- DES
- AES-CBC-PKCS5Padding
- DES