Technical information
- Adware.Ninebox.4.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) adc-ad-####.ad####.com:80
- TCP(HTTP/1.1) u####.v.tr####.net:80
- TCP(HTTP/1.1) www.face####.com:80
- TCP(HTTP/1.1) events####.adco####.com:80
- TCP(HTTP/1.1) p.nin####.cn:80
- TCP(HTTP/1.1) eve####.adco####.com:80
- TCP(HTTP/1.1) s.nin####.cn:80
- TCP(TLS/1.0) cdn.fl####.com:443
- TCP(TLS/1.0) pag####.googlea####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP(TLS/1.0) m.face####.com:443
- TCP(TLS/1.0) face####.com:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) l####.chartb####.com:443
- TCP(TLS/1.0) ads.fl####.com:443
- TCP(TLS/1.0) www.face####.com:443
- TCP(TLS/1.0) api.face####.com:443
- TCP(TLS/1.0) v5.chartb####.com:443
- TCP(TLS/1.0) d####.fl####.com:443
- TCP(TLS/1.0) dire####.adco####.com:443
- TCP(TLS/1.0) a3.chartb####.com:443
- TCP(TLS/1.0) sconten####.xx.f####.net:443
- TCP(TLS/1.0) st####.xx.f####.net:443
- a3.chartb####.com
- adc-ad-####.ad####.com
- ads.fl####.com
- android####.adco####.com
- cdn.fl####.com
- d####.fl####.com
- eve####.adco####.com
- events####.adco####.com
- face####.com
- g####.face####.com
- googl####.g.doublec####.net
- l####.chartb####.com
- m.face####.com
- mi.ny####.com
- p.nin####.cn
- pag####.googlea####.com
- s.nin####.cn
- sconten####.xx.f####.net
- ssl.google-####.com
- st####.xx.f####.net
- v5.chartb####.com
- www.face####.com
- adc-ad-####.ad####.com/output_static/ui/rocket-icon-embossed.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-alert-bg-x2.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-alert-logo-x2.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-bg-full.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-btn-cancel-down-x2.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-btn-cancel-normal-x2.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-btn-confirm-down-x2.png
- adc-ad-####.ad####.com/output_static/ui/v4vc-btn-confirm-normal-x2.png
- u####.v.tr####.net/download/sci/2.png
- www.face####.com/kiragames
- eve####.adco####.com/t/5.0/install?pl=wTV2####
- events####.adco####.com/t/5.0/session_start?pl=wTV2####
- p.nin####.cn/admin/nbad.action
- s.nin####.cn/admin/sc.action?requestId=####
- /data/data/####/.FlurrySenderIndex.info.AnalyticsData_FXWHQ2QPB...9W_172
- /data/data/####/.FlurrySenderIndex.info.AnalyticsMain
- /data/data/####/.flurryadlog.6032d491
- /data/data/####/.flurryads.mediaassets.tmp
- /data/data/####/.flurryagent.6032d491
- /data/data/####/.flurrycachedasset.6032d491
- /data/data/####/.flurrydatasenderblock.53f1d675-9031-4322-82bb-...714418
- /data/data/####/.flurryfreqcap.6032d491
- /data/data/####/1.png
- /data/data/####/1544447269359.jar
- /data/data/####/1544447269376.jar
- /data/data/####/1544447269407.jar
- /data/data/####/1544447269417.jar
- /data/data/####/2.png
- /data/data/####/3.png
- /data/data/####/4.png
- /data/data/####/45106565280
- /data/data/####/5.png
- /data/data/####/6.png
- /data/data/####/7.png
- /data/data/####/8.png
- /data/data/####/AppEventsLogger.persistedsessioninfo
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/FLURRY_SHARED_PREFERENCES.xml
- /data/data/####/GAMEHELPER_SHARED_PREFS.xml
- /data/data/####/INSTALLATION
- /data/data/####/LocationType.xml
- /data/data/####/SIDEBAR_PRESENTS.xml
- /data/data/####/a3.chartboost.com.443
- /data/data/####/admob.xml
- /data/data/####/ads1928887015.jar
- /data/data/####/cbPrefs.xml
- /data/data/####/cbPrefs.xml.bak (deleted)
- /data/data/####/cb_previous_session_info
- /data/data/####/com.facebook.internal.preferences.APP_SETTINGS.xml
- /data/data/####/com.facebook.sdk.appEventPreferences.xml
- /data/data/####/com.facebook.sdk.attributionTracking.xml
- /data/data/####/com.fagnkuasifdsf.dfs.appirater.xml
- /data/data/####/com.fagnkuasifdsf.dfs.xml
- /data/data/####/com.google.android.gms.analytics.prefs.xml
- /data/data/####/com.google.android.gms.analytics.prefs.xml.bak (deleted)
- /data/data/####/com.kiragames.unblockmefree.UnblockMeFree.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dij.xml
- /data/data/####/dim.xml
- /data/data/####/f_000001
- /data/data/####/gaClientId
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/https_googleads.g.doubleclick.net_0.localstorage-journal
- /data/data/####/index
- /data/data/####/j-id.xml
- /data/data/####/manifest.txt
- /data/data/####/media_info.txt
- /data/data/####/mid.xml
- /data/data/####/multidex.version.xml
- /data/data/####/pdown
- /data/data/####/pdown-journal
- /data/data/####/puzzles.db
- /data/data/####/rp.xml
- /data/data/####/rs.xml
- /data/data/####/session_info.txt
- /data/data/####/short_create.xml
- /data/data/####/shortoutnamesha.xml
- /data/data/####/tracking_info.txt
- /data/data/####/type.xml
- /data/data/####/userdef
- /data/data/####/users.db
- /data/data/####/users.db-journal
- /data/data/####/version.dat
- /data/data/####/vs.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/xy.xml
- /data/data/####/zone_state.txt
- /data/media/####/.nomedia
- /data/media/####/12.dat
- /data/media/####/2.dat
- /data/media/####/3.dat
- /data/media/####/5b7ac4ecb436664252191a11_320-1534772460.mp4
- /data/media/####/5b7ac5f02b2fef31e97a1ab5_320-1534772720.mp4
- /data/media/####/5bcdfa27254a5c0ab9782c30_320-1540225575.mp4
- /data/media/####/5bd16aba9e982d2c868ef723_320-1540451002.mp4
- /data/media/####/5bf6686dd8e02e264ffa1dcd_320-1542875245.mp4
- /data/media/####/5bf669016233600b6b9ba282_320-1542875393.mp4
- /data/media/####/7.dat
- /data/media/####/77d906bd8225cfddee8bf01ee8dd64318a6f3264.png
- /data/media/####/7e265867124e773e7ee5144c9e05b36f20fe43bc.png
- /data/media/####/MID.DAT
- /data/media/####/abcce95ff069a1f8a3692d2b27d0766357cfda31.png
- /data/media/####/com.fagnkuasifdsf.dfs.png
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/names.dat
- /data/media/####/share.dat
- ubm
- AES
- DES
- AES-CBC-PKCS5Padding
- DES