Technical information
- Adware.Panda.1.origin
- Adware.Panda.8.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(TLS/1.0) digital####.google####.com:443
- TCP(TLS/1.0) 74.1####.205.94:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) 64.2####.164.102:443
- TCP(TLS/1.0) rr14---####.g####.com:443
- TCP(TLS/1.0) 1####.194.220.95:443
- TCP(TLS/1.0) rr13---####.g####.com:443
- TCP(TLS/1.2) 1####.194.220.95:443
- TCP(TLS/1.2) 64.2####.164.102:443
- TCP(TLS/1.2) 74.1####.205.94:443
- UDP 1####.194.220.95:443
- a####.u####.com
- a.appj####.com
- and####.cli####.go####.com
- and####.google####.com
- digital####.google####.com
- gmscomp####.google####.com
- loc.map.b####.com
- m####.go####.com
- md####.google####.com
- pla####.googleu####.com
- rr13---####.g####.com
- rr14---####.g####.com
- a####.u####.com/app_logs
- a.appj####.com/ad-service/ad/mark
- loc.map.b####.com/offline_loc
- loc.map.b####.com/sdk.php
- /data/data/####/.jg.ic
- /data/data/####/66db76741a824e4c211305ee9a6a5f8b.dex
- /data/data/####/66db76741a824e4c211305ee9a6a5f8b.dex.flock (deleted)
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/bd0-journal
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/config.xml
- /data/data/####/db1-journal
- /data/data/####/db2-journal
- /data/data/####/db3-journal
- /data/data/####/db4-journal
- /data/data/####/db5-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/firll.dat
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/libjiagu.so
- /data/data/####/ofl.config
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/proc_auxv
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/media/####/.cuid
- /data/media/####/.nomedia
- /data/media/####/66db76741a824e4c211305ee9a6a5f8b.zip
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/LOG-2023-05-07.log
- /data/media/####/conlts.dat
- /data/media/####/ller.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/misc/####/primary.prof
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- logcat *:e *:i | grep (3584)
- logcat *:e *:i | grep (3723)
- logcat *:e *:i | grep (3787)
- logcat *:e *:i | grep "(3584)"
- logcat *:e *:i | grep "(3723)"
- logcat *:e *:i | grep "(3787)"
- logcat *:e *:i | grep \
- libjiagu
- liblocSDK6a
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS5Padding
- DES