Technical information
- Adware.Dowgin.3.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) f2.doodlem####.com:80
- TCP(HTTP/1.1) api.vu####.com.####.net:80
- TCP(HTTP/1.1) googl####.g.doublec####.net:80
- TCP(HTTP/1.1) d####.fl####.com:80
- TCP(HTTP/1.1) bx.ix.0####.com:80
- TCP(HTTP/1.1) 13.2####.217.25:80
- TCP(HTTP/1.1) newfeat####.perfect####.com:80
- TCP(TLS/1.0) 52.7.1####.153:443
- TCP(TLS/1.0) h.online-####.net:443
- TCP(TLS/1.0) con####.ta####.com:443
- TCP(TLS/1.0) cdn.vu####.com.####.net:443
- TCP(TLS/1.0) ws.tapjo####.com:443
- TCP(TLS/1.0) s3.amazo####.com:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) ser####.sponso####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP(TLS/1.0) en####.sponso####.com:443
- api.vu####.com
- bx.ix.0####.com
- cd####.vu####.com
- cd.cd.c####.com
- con####.ta####.com
- con####.ta####.com
- d####.fl####.com
- d239g0z####.cloudf####.net
- en####.sponso####.com
- f2.doodlem####.com
- googl####.g.doublec####.net
- h.online-####.net
- newfeat####.perfect####.com
- rrx68gi####.d.aa.####.net
- s3.amazo####.com
- ser####.sponso####.com
- ssl.google-####.com
- ws.tapjo####.com
- googl####.g.doublec####.net/mads/static/mad/sdk/native/sdk-core-v40-load...
- googl####.g.doublec####.net/mads/static/sdk/native/sdk-core-v40.js
- api.vu####.com.####.net/api/v4/config
- api.vu####.com.####.net/api/v4/new?app_id=####&isu=####
- api.vu####.com.####.net/api/v4/requestAd
- api.vu####.com.####.net/api/v4/sessionStart
- bx.ix.0####.com//9871k
- bx.ix.0####.com//9871l
- bx.ix.0####.com/4106/7046a/e46
- bx.ix.0####.com/4106/7046a/p41
- bx.ix.0####.com/4106/7046a/q70
- bx.ix.0####.com/4106/7046a/r46
- bx.ix.0####.com/4106/7046a/s41
- bx.ix.0####.com/4106/7046a/t6a
- bx.ix.0####.com/4106/7046a/w04
- d####.fl####.com/aap.do
- f2.doodlem####.com/feature_server/fullScreen/get.php
- f2.doodlem####.com/feature_server/geo-ip/test.php
- newfeat####.perfect####.com/featureview/getfeatureview/
- newfeat####.perfect####.com/featureview/gettime/
- /data/data/####/.dmgames_prefs.xml
- /data/data/####/.flurryagent.7b3db56
- /data/data/####/58fa0493.xml
- /data/data/####/59caf6eb.xml
- /data/data/####/60e9e69a.xml
- /data/data/####/65b64cf4.db-journal
- /data/data/####/9bb12587.xml
- /data/data/####/CookiePrefsFile.xml
- /data/data/####/SponsorPayAdvertiserState.xml
- /data/data/####/SponsorPayPublisherState.xml
- /data/data/####/ThreatMetrixMobileSDK.xml
- /data/data/####/VUNGLE_PUB_APP_INFO.xml
- /data/data/####/_i1355579724.xml
- /data/data/####/_w1355579724.xml
- /data/data/####/ads-546540421.jar
- /data/data/####/cn.geohey.qouwis.jar
- /data/data/####/com.bnhbh.vswv.jar
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/gaClientId
- /data/data/####/google_analytics_v4.db-journal
- /data/data/####/index
- /data/data/####/sniper.xml
- /data/data/####/tjcPrefrences.xml
- /data/data/####/vungle-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.nomedia
- /data/media/####/aHR0cDovL2QyMzlnMHo2N2pjdGVkLmNsb3VkZnJvbnQubm...5qcGc=
- /data/media/####/aHR0cDovL2QyMzlnMHo2N2pjdGVkLmNsb3VkZnJvbnQubm...MucG5n
- /data/media/####/ad.html
- /data/media/####/coin.png
- /data/media/####/index.html
- /data/media/####/jquery-sakura.css
- /data/media/####/jquery-sakura.js
- /data/media/####/jquery.keyframes.min.js
- /data/media/####/jquery.min.js
- /data/media/####/jquery.mobile.min.js
- /data/media/####/landscape.jpg
- /data/media/####/localVideo.mp4
- /data/media/####/mraid-vungicon.eot
- /data/media/####/mraid-vungicon.svg
- /data/media/####/mraid-vungicon.ttf
- /data/media/####/mraid-vungicon.woff
- /data/media/####/portrait.jpg
- /data/media/####/postRoll.zip
- /data/media/####/style.css
- /data/media/####/vungle-hide-ui.css
- /data/media/####/vungle-map-clicks.js
- /data/media/####/vungle.css
- /data/media/####/vungle.js
- gdx
- trustdefender-jni
- DES
- AES-CBC-PKCS5Padding
- DES