Analysis

  • max time kernel
    179s
  • max time network
    186s
  • platform
    android_x86
  • resource
    android-x86-arm-20240624-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20240624-enlocale:en-usos:android-9-x86system
  • submitted
    01-07-2024 09:41

General

  • Target

    1ace9129ff651dc23822a7436525cee3_JaffaCakes118.apk

  • Size

    16.6MB

  • MD5

    1ace9129ff651dc23822a7436525cee3

  • SHA1

    a44d40423fb4d09e99636980eb6fadcd7201ef33

  • SHA256

    96b7e216e5cf6df9ac96d66de6a0a061f70eedb14d3f9c3cbe49a8d2ed019f2a

  • SHA512

    120eed9e6e23954458fcbec4c05ce6e9328ce8cfad5f8af8e1a233a8038511a84c0b4551b36ff748cd3399aa6ff37d7f7cb5080a7b9424556e308bc8333b0c9a

  • SSDEEP

    393216:BU4hIapcVa18A7GPosjyVL8VuK9Lwjeqzei:BU4hfgaR7gPt9Zti

Malware Config

Signatures

  • Checks if the Android device is rooted. 1 TTPs 2 IoCs
  • Loads dropped Dex/Jar 1 TTPs 11 IoCs

    Runs executable file dropped to the device during analysis.

  • Queries a list of all the installed applications on the device (Might be used in an attempt to overlay legitimate apps) 1 TTPs
  • Queries information about running processes on the device 1 TTPs 2 IoCs

    Application may abuse the framework's APIs to collect information about running processes on the device.

  • Domain associated with commercial stalkerware software, includes indicators from echap.eu.org 3 IoCs
  • Queries information about active data network 1 TTPs 2 IoCs
  • Queries information about the current Wi-Fi connection 1 TTPs 1 IoCs

    Application may abuse the framework's APIs to collect information about the current Wi-Fi connection.

  • Reads information about phone network operator. 1 TTPs
  • Registers a broadcast receiver at runtime (usually for listening for system events) 1 TTPs 2 IoCs
  • Uses Crypto APIs (Might try to encrypt user data) 1 TTPs 2 IoCs
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • com.xgbuy.xg
    1⤵
    • Checks if the Android device is rooted.
    • Loads dropped Dex/Jar
    • Queries information about running processes on the device
    • Queries information about active data network
    • Queries information about the current Wi-Fi connection
    • Registers a broadcast receiver at runtime (usually for listening for system events)
    • Uses Crypto APIs (Might try to encrypt user data)
    • Checks CPU information
    • Checks memory information
    PID:4315
    • chmod 755 /data/user/0/com.xgbuy.xg/.jiagu/libjiagu.so
      2⤵
        PID:4342
      • /system/bin/dex2oat --instruction-set=x86 --instruction-set-features=ssse3,-sse4.1,-sse4.2,-avx,-avx2,-popcnt --runtime-arg -Xhidden-api-checks --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --inline-max-code-units=0 --compact-dex-level=none --dex-file=/data/data/com.xgbuy.xg/.jiagu/tmp.dex --output-vdex-fd=44 --oat-fd=47 --oat-location=/data/data/com.xgbuy.xg/.jiagu/oat/x86/tmp.odex --compiler-filter=quicken --class-loader-context=&
        2⤵
        • Loads dropped Dex/Jar
        PID:4367
      • /system/bin/dex2oat --instruction-set=x86 --dex-file=/data/user/0/com.xgbuy.xg/.jiagu/classes.dex --dex-file=/data/user/0/com.xgbuy.xg/.jiagu/classes.dex!classes2.dex --dex-file=/data/user/0/com.xgbuy.xg/.jiagu/classes.dex!classes3.dex --oat-file=/data/user/0/com.xgbuy.xg/.jiagu/oat/x86/classes.odex --inline-max-code-units=0 --compiler-filter=speed
        2⤵
          PID:4650
        • sh -c ps
          2⤵
            PID:4696
          • ps
            2⤵
              PID:4696
          • com.xgbuy.xg:pushcore
            1⤵
            • Loads dropped Dex/Jar
            • Queries information about running processes on the device
            • Queries information about active data network
            • Registers a broadcast receiver at runtime (usually for listening for system events)
            • Uses Crypto APIs (Might try to encrypt user data)
            PID:4416

          Network

          MITRE ATT&CK Matrix

          Replay Monitor

          Loading Replay Monitor...

          Downloads

          • /data/data/com.xgbuy.xg/.jiagu/classes.dex
            Filesize

            7.9MB

            MD5

            e7e6b33de7857958262bbc7c1ad1d41e

            SHA1

            b559fabc04b720880ae075cef6dd4a5393b6b0e0

            SHA256

            35eb3f4b3460e928c78452f13f7ec2098b5e979e24b5d24cf3ff72c08b02b031

            SHA512

            01eef8e3164cea433bdb575d9646ae95e30a4ed140333672ed0b8afae1a422da362b518077c9898c542af28290616f5a7d1e6dbe9b0498cbb057f3c059f4c538

          • /data/data/com.xgbuy.xg/.jiagu/libjiagu.so
            Filesize

            382KB

            MD5

            aa01dd97609092ce310e17bf791069ce

            SHA1

            f000840a8f68ea7beb2e29ea466088daf55609db

            SHA256

            e432c191f918053ce368e1b1f155b2e1f9e84379611b93aabec0106172b73aa2

            SHA512

            766c120a06215d0950aae32026fcde3eafed8d18ae0de7bc8135a7378a9055c8f0040d61574d9af67fe2b5b90eeae64c62d787343858ae375bb6658df8afe7b4

          • /data/data/com.xgbuy.xg/.jiagu/tmp.dex
            Filesize

            284B

            MD5

            f1771b68f5f9b168b79ff59ae2daabe4

            SHA1

            0df6a835559f5c99670214a12700e7d8c28e5a42

            SHA256

            9f8898ce35a47aeafced99ea0d17c33e73037bb2307c7688e50819966f4ae939

            SHA512

            dae27d19727b89bec49398503baa6801640540355688dfabbe689c97545295c2c2d9b0f0dcd7cbc4cfbf701d0c0c3289e647a152f49ff242d1ecc741efe4145d

          • /data/data/com.xgbuy.xg/cache/image_manager_disk_cache/e0bac8c3c005c727bb9b0b2d00be3d7cf020743113c01c46c33a507d6275519a.0.tmp
            Filesize

            79KB

            MD5

            3ccf674803e2bcca74d940a369b98a1f

            SHA1

            b82beb53b74476af3563d05f4b49b4628611c19f

            SHA256

            897e90108102b4d93eed118fbc62f4bd208a2651c52da15431f3ece36f4ff274

            SHA512

            b98a53d48cee9d8d4fae804736e7b66c28beb429d4e84cad49f4f3e92f5a226c99eebe093fabee98d657d41729eab74fdf6081cc29b693e076b213e0e8e60a5f

          • /data/data/com.xgbuy.xg/cache/image_manager_disk_cache/journal
            Filesize

            179B

            MD5

            558e7c199f33a5304e4801764cd264ec

            SHA1

            9e9960d6db26ea7b066101023cb69041c6654ea9

            SHA256

            3c3af02a5f4e4d2b1334666d91e97bdfab7454f30723623c079f4cd9d0ba81e9

            SHA512

            fbd1e67831ef14fa6776c1b265eec6670b9be62e77599609cbbfbc6cba254d219392d37a5ec4d796349d954f37610579de457d005af864e2ac36a8cffb0d297a

          • /data/data/com.xgbuy.xg/cache/image_manager_disk_cache/journal.tmp
            Filesize

            31B

            MD5

            8c92de9ce46d41a22f3b20f77404cc1d

            SHA1

            8671a6dca00edb72be47363a7071be65cf270373

            SHA256

            68bb33ddeed9200be85a71f70b377985f9ee68e91578afbde8321463396f1274

            SHA512

            30f45fe9954215d6adafcc8f0a060a7ff41963a64f9b849a37f0d18fe045038d429ec13bf15226769c4ba78dad3c52f3d9e0dbbb4fcdea4828a1efe956e48f56

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            20KB

            MD5

            b1b0b9129b15d50c07a515b0f80486ae

            SHA1

            d5728560727aeea71e5dcc83fb35b86d18fb0939

            SHA256

            b55765fbfb0719ff28b4b69a263b1ecceda93160727984d0600aa7959be18ac7

            SHA512

            db4b0d72dbd38e4246cf99051c0139d9e148c6cd9b58355dbfa54d015747a76d9e6c13a17cf324752a0ca9f911646c8cc89b67c7cbbe39f7cd2be9e4eb316376

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            20KB

            MD5

            a0a443cf9d135ed2ec85e76b75415444

            SHA1

            afd4498c70cc87efa89b816d8a300524da2c72d0

            SHA256

            7a9b96074ad0028b435be816561c6441dd19f75ffd97dab86fc36e38ac84329e

            SHA512

            f94c039080b7fd789430b2d118d716dfd2fa5920898a135fe23027a59d09c1a97a2dd90640b1d6d961b91ac72b556d451e7814aabf04b4d51f31b0fd1bb3d213

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            20KB

            MD5

            26da10fd12f27a883bf93b0163e45189

            SHA1

            eca2a524d3721c09d6601292e79d7bdfa8328461

            SHA256

            977bf6e4e0de46879b752ff4351885da4502592638c818f594b5029030bb1e84

            SHA512

            299c9677febe74797a56f7e74d84e5a7045f47aab0affc070d3a48e437e72d70e9340af94a9e244b0161a2ec88cdc14744830d926fc988bc3fb78973b425cfdc

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            20KB

            MD5

            5c2d4ad6b8d4732db0a8862b9254e11f

            SHA1

            5bb6593b69035eefa26117b72ad02c9be269942e

            SHA256

            001ee2eaebba599744634212afec86f3c4c39612ed8227724ea90ae1769c9763

            SHA512

            8ecadb7653b3b269de94a76cc49a911fda19e426638fe28029e9183a8cc9cfb7a7bfa65682f18bef98b7e1f30bd988c140778802998d1b96268d84eade1e559e

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            20KB

            MD5

            08e113d065fa3a9e21965b05fa872917

            SHA1

            8a6dd360e639c60b99e608afc16d37de9091b547

            SHA256

            77101a668a645a444dc5da8c9d938e4c101a68bfd53a28649f86d46f363cbe63

            SHA512

            8b964f1a06e6b6ab3475549caba94c299ff59c76185d1e199e3e14ed01db6e7e255d8a465bfdd37c9e70f2dea4965c2371f304153400a6da86820ba95d814fdf

          • /data/data/com.xgbuy.xg/databases/Reyun.db
            Filesize

            28KB

            MD5

            efb2a8eb585c3c20e8dca588ec86dc95

            SHA1

            e6a55ed86943ee11a1ab47de857b0012bcfba7ef

            SHA256

            a04e9b923da6207ed3c0c9e2b8bf04b01f87fd1ace39ff9fea77267cda366ad5

            SHA512

            8b0fbb9c9f24957b082ad7561cbd142cb1301708d4a88a097aaf135fcc73de765a8e0c4740d6cbf431a31caa64604b5f957b495cd3c8b634990181f723730a80

          • /data/data/com.xgbuy.xg/databases/Reyun.db-journal
            Filesize

            512B

            MD5

            25ac04c094ac4dabc31ce6d180f69c47

            SHA1

            29fad3f973f7a9aeb0cd22035ec86f1828e227ac

            SHA256

            3ffe1e3830eb33857b84e6d4e1f869cb49f43944730aac5f3714a33a0ca4cf5e

            SHA512

            470a0e61a7d093054d1a24998134eaeb2445a6d313292a2c2553de418f33617afb168ecd53cc8f126c201b2eb74016a39be5ff5a6e622bec6a337ee1cf776b72

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            44KB

            MD5

            8b488007244505ca871e80b45ba5aaa0

            SHA1

            b016d925019600aa52774fc146c26504be407ac1

            SHA256

            346508cecb4eb765b6c18ccfcfe6c88a4763c75ac8008aeb724e1c32fe94f6fd

            SHA512

            b1e6364c6576dac73515f19fbc8049c9a111c115b58c23a569cf55ec714339e880931dc0daf2ef48e383757cb2c5bcb1c63e8b6eb8031b9f7503872e5f161d87

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            8KB

            MD5

            1291e3bb66ea6d3ab33ce35a60ca2cef

            SHA1

            0a4ecdf1265bb838157e3c792d27ab3d6d7c07d6

            SHA256

            1e16eb1a21a4b372212dd09a02232014523680de0ce55767b241ef3597af21e2

            SHA512

            4da317a598d4de6a609ef111f350e7a5fcff3dace7c3122227ca199920f44f8363a686cab88cd2bf676990e75297aa8f5c4605727021f6302c2edbe8dfef5de6

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            8KB

            MD5

            71d58f8abd2ebbeb02c3a16ceabc93a5

            SHA1

            f6f8f1cc770b1561441b5314451fc513829126ad

            SHA256

            61fca3caf1a456593b918781fdd66afd770c50ac91f694de83e1d65afcd43200

            SHA512

            dafca3317f444609a4d03e84c9a6dcc9e721fecf63b13454a9a7c3e43f531eea9ad2929d1d861b8748b4780bba6839e8cf6c5ecfa7b7a1748ae6e3821f9e3ee6

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            8KB

            MD5

            533eb81b21dd84dfa3da7f3fa4f4281e

            SHA1

            e06552df08b57e0b3984bf0f976e0421ed33d515

            SHA256

            a07c92c8ed08f94f0f1751eecd715a70543730ff64c18abc26042704ff9d1f4c

            SHA512

            e6b06dbd7a1f1988ae7f0a3c5cd36d4ba63074dc27817fdcf369d8105b0652c4561e1b431db521f80eb0614ee068bd1d1dc8f4732801c9634ed44d89a9a05623

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            8KB

            MD5

            f1e3100070dc1acfbd53ba8426243acc

            SHA1

            2b1f9246ed0a0d6fd80781745fb1eef7503d6724

            SHA256

            ec4532fa93123fb3b407c69da4ae37e4e9fb50325069f536b29442946f6e2fbe

            SHA512

            387272e8258783cb09dc9850697c40393b4b9d3eaa34a0bf857175ea880eb041e4c12f5a6da0cff2b4e698c86b98eed036d17a7aca46c618af1392521be9d688

          • /data/data/com.xgbuy.xg/databases/Reyun.db-wal
            Filesize

            24KB

            MD5

            1a2c67f6bffceec5b637102613e486df

            SHA1

            c65fcf3292c0d1e0f9b765769f1edced6cd1c4bc

            SHA256

            bbaad30fb1b6e61a6909630b332b4abd77106705b9e195d8ab945469531c8a12

            SHA512

            83e7ce6a5a256509cbe7d886369666ae3ad437586bf0c10558e51233ac25067bd5364197b4cb65123d474b172e17205221ce540b85e8cec20a65ce59216d47d8

          • /data/data/com.xgbuy.xg/databases/ThrowalbeLog.db-journal
            Filesize

            512B

            MD5

            8c772d404c7d205da704d0186b6eed11

            SHA1

            87de6fb6244abab93af98a07fffcb1a033c38dd2

            SHA256

            e423c9eda8609a506fcac327074f72544f9e221f39181007145e700c7da063c4

            SHA512

            f8304111d29db4ef421f634be014df27e398cbaab300ebcce9fb65f2340fc928d41d2675432d2c5d7d2545fe3a722571c5135ce8d3c957924179c5bcdc8a5bae

          • /data/data/com.xgbuy.xg/databases/ThrowalbeLog.db-wal
            Filesize

            140KB

            MD5

            c6cab86124e29776fe18f348155dc614

            SHA1

            9455b4abe59614d21288b8259029238c5728d41d

            SHA256

            0d911c28f682ee6dc8f9323245533521ab45fd000ba2656a6bb7289a254db0a0

            SHA512

            014ea024f9d1add4b3c8b734d7606c8fb1c4b8873c27104524f38b4a40b0b386d7de0318230bffcf565ba7ceba3ae7b1940865eb8f788e4f301bfdd44d8eb244

          • /data/data/com.xgbuy.xg/databases/cc/cc.db
            Filesize

            36KB

            MD5

            5d7ea1a23af19b4340cc8d90f28297d5

            SHA1

            4cfe95b23a9e98378d69c4290af81b51fbe76aea

            SHA256

            474c4a54534ed96beacad7cc9a805a3f53ec9c0522fc7bcc59771cf500a6a0da

            SHA512

            33071f4c92da0a3df01c4a61dd165df7c7e0f4f37753cafe02d19fc876a5e7fcbb01c069c804e140ab8bfa0644a55f50fd1373646d1c439f817baa5ffbd47f7b

          • /data/data/com.xgbuy.xg/databases/cc/cc.db
            Filesize

            36KB

            MD5

            ce6135aa1b1fe4f2c2db2a546d2a5558

            SHA1

            79b59582154017aadab783dc266fcb158c252940

            SHA256

            7b45f576c08c7f78220168cca4a0e33198b13e9bdc8b1da406ddb6887412000c

            SHA512

            2839075fe374c8567c839ae35ce2d33ec72fdaebf170aa7d224b555e5b0e74d4a43f2f67d17ed806dae841da883e9620d788ea052d06152678afa927307c7ce4

          • /data/data/com.xgbuy.xg/databases/cc/cc.db-journal
            Filesize

            512B

            MD5

            79f9c5604bee8f75bc42d564c29993d5

            SHA1

            5e93f3322d3e424a5ab0c98345256c995762834f

            SHA256

            fade0f28b2bab04dfa121fb0bd22d73c72a7d197aed714cf43529a941b8bc09a

            SHA512

            aa0ac295bd2cf37f25174b5bf325c8acb683871ef789caa225fb1788b23209e095b2b3ee06821bbaa722d0e14bc548206871eafd7e1c9cb0f004ab27f2236e7c

          • /data/data/com.xgbuy.xg/databases/cc/cc.db-wal
            Filesize

            48KB

            MD5

            edc1612205dfc7ddebd2be5602ac404a

            SHA1

            c82f5912fc0c3ba9e3170de096104628f944cc6b

            SHA256

            9b191fb14aecc8acbf7b5d05ecc12715fef28da50f381f13a47e414a96f64894

            SHA512

            ab79286ca2b72b70591608708ffcc3e13e3ba4e70815b5696b73dc2b37db51dda97c557fda173a153fbc410f1b54bcabf3dc3a95a156cd79e828103ff6278030

          • /data/data/com.xgbuy.xg/databases/cc/cc.db-wal
            Filesize

            16KB

            MD5

            24a9c8bd54de9df6a2fcafb48988046f

            SHA1

            bdf75a37fb24513d1525a667b3d7deb364b6f708

            SHA256

            01fca6a746314e48bd9469055fce26a13cc020e35f4033049419f068a0a0debc

            SHA512

            c8d475748400f0f67134bb444ad84d6f33c382e8c90ef4f9c1270180afb49ad8a41a00d32693cf607bda5c229f17d086d295fa2391ae4ecfbe4dda944a33790c

          • /data/data/com.xgbuy.xg/databases/je_1000_ISME9754_guest30092609177307163638366827053482749800-journal
            Filesize

            512B

            MD5

            82aa59786870bc61b87a8f5ca2703940

            SHA1

            aeb61af8584770b52283b92907854470070d1aeb

            SHA256

            4d97dce178c5cd3d884a771a9aa928d10f388aabf9a80ff38c2d723931dcfaf0

            SHA512

            ca4d13877c9e7622cd1c434a2fc7f44a80de390569f2f382363b5da06889ce8b3e34eebb316dd57f4f1ac1b160117e29913e06fd97853add761483b80bce0c8d

          • /data/data/com.xgbuy.xg/databases/je_1000_ISME9754_guest30092609177307163638366827053482749800-wal
            Filesize

            48KB

            MD5

            6a562b637e2c645a5a14040e8a0267af

            SHA1

            5751af02eca286f7a36e0de6d99cbb1575877cf7

            SHA256

            3ed60abe7709f333cdb8769532a5ddfcdb851365257c66937e482f46000b4ac4

            SHA512

            4d7722fcf67bc1b21002ad769922fdc2d1277b368cd180d99a44c67dc96c3ade84c91defbc329d565be0fc32410f4c37d795863da39f094c5ae693e572d02477

          • /data/data/com.xgbuy.xg/databases/jpush_statistics.db
            Filesize

            20KB

            MD5

            82ee681ba630625f6342fac10f329ee7

            SHA1

            b2aa2b5c618672f761aea0c5bc8c46a57b779392

            SHA256

            1a32764f9ff8458c8803d06e1fc027347117d250402f45fbfb2edb5632a04eef

            SHA512

            dae417eefabe530db7cf04056257d8fc42f99eaa28200ab573605e365fcdc06b7e5defa169b1ce7472c0f1e4a1ffbedc7e43a4ff65c95c62736b194a009b0b7c

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            32KB

            MD5

            b47ec4dcec7d73de1a4ba58f6838ce11

            SHA1

            2091441ef5327289fad22d4d330683275c454811

            SHA256

            0a72125e507c664662233f41d985f63e7beee5f1d48f25f23396bac37b41a81e

            SHA512

            5ef650533c2e4bbee8c8410d9ec4178d7177dcfe2b0971c4316e4826a0d4c1fb891ae87c245744a746e009ab6a06b1a99aae16df37cae29e9d1fcd9fa8c32ca4

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            16KB

            MD5

            d88fed7ea27814458fe4c556ab7a6fd2

            SHA1

            d438650417450f7212722479d26709d1e8a4695a

            SHA256

            d1c2f9ccc42a105b604d44f5322fbfd791890cf462474b21bfea2c3341bc924d

            SHA512

            672216ce1a475f8d8c202053f2ee051ea40d2b6e357f5d958ea464528908dd2c6600ffe8786b60f299628b962550a8e5db5083d8fd266a6640ef7d08be34207d

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            16KB

            MD5

            a48dc8c0f581a952c2e8468b72afe2b9

            SHA1

            858eea2eaad89da778b30b59790e4b4b0b304b30

            SHA256

            1c6a344beb33624109c25c219f2fb4815e5107814e2fec9db010cea0659ccb93

            SHA512

            8f278fe054a0364ef8861f35fa81c296e73108e71154f98bd79417505c82e194f86c18bcef27f833345487af106e985e5417d67156c5542c3d75dcdcb6dda899

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            32KB

            MD5

            d604a3bf1f8d992cc320ea5b1f7609bd

            SHA1

            247f88df0b55c7d523ea5398637711a0e4a483a4

            SHA256

            329940b4d46326d58e73c842dd099704061d0ef7338777bf31ad895f29013c17

            SHA512

            67e28f6713cb5c238a9664df128f01a89a2efb7c8c9330c1e45bc0d40ebab81fa20df5166743d84d81dc0386a89ff0329f022281c098339baa2e851ff0a1e1ab

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            16KB

            MD5

            ac6e8a4bc52e2e8bcc9efc16e596900a

            SHA1

            4ce939545963a38b2287f196edb9d603f18d4dbe

            SHA256

            8e3d2a981c05bf5ecec6f87b7ce17cc8df088cfd8b8940d431e88a0b8e7fb669

            SHA512

            1ff354ee8339666b8b65fa90b256611d08f5109b4e88f3f7c8b935561c08e3137ede5284022df684223d35558939e57d01566ceb314768e87a8df78641fe5e50

          • /data/data/com.xgbuy.xg/databases/ua.db
            Filesize

            16KB

            MD5

            904686eccd81cf5ad97c16ab926572a8

            SHA1

            91fdd106dbc9e68a5b60c705150d673f0a976c14

            SHA256

            d6239308fe30f0d85e2facd1637865534173f401ed6f35dfcf38cfcd2bcd16eb

            SHA512

            3091045184ed34e972464b61ca5b8ac1040fbc546b730acdaf41c9791dbdd2884c40c2ce1d83008640e27d8ca56d82650b57f42b16bbdeb5473bb27f9db8eb39

          • /data/data/com.xgbuy.xg/databases/ua.db-journal
            Filesize

            512B

            MD5

            7571938c11d8758740ef5bda1beeef21

            SHA1

            b7d083fb8fc43d2a5209ba8ba44b92f67f22a6e3

            SHA256

            6b4cd29dc39278f9808c195fa5fcfe87326328ce0320ee41961158c2b84c9d27

            SHA512

            e39f39ff05a6c104f01b82a5282ee17cb3c0277f19759ee0be3bd9043d1a68df750068e364ed7487caff9ae67e164536d65f9f53f0e44fe7c2a25e192e6ed38f

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            56KB

            MD5

            bdb0d6305a7d2fe7d51b64615b41ca17

            SHA1

            467a769a3fde1738900d21971f7bb1321166a30b

            SHA256

            59638263125d824f00680a63619697e059c7175551952dd9c9ce24b665a8d4d7

            SHA512

            813f3bdbf77541d6ae2c87a14c3b8fc7ac05a45d19b8b52834271405ee8600ca3878218776752705981fe82763597e225c9dfb9ca402723b3c82b9ee2a7c0ca4

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            4KB

            MD5

            acb87b322d519e8117d8d545b57b6a0e

            SHA1

            09471b1aa9c41af8402385c3a1afa93b9c118863

            SHA256

            249e489ebff9470b84c27d1235901ab3dd80c452b45439973a578d3a2afd6119

            SHA512

            0d99866260812bbd5dc0e72d4edd1a36afa9f9a7b5074d38e1fcb715a3424d88c1afe40ef2f026d2d1fd6d3ace56564a4dabe2fadbbf0de2b72979e828a03a61

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            4KB

            MD5

            69261d2291871744d123b0e01fe8eff8

            SHA1

            11b9aa176bd64fb0b50922b08ba42119b25f676e

            SHA256

            e586f732ce3d5f1e3c0aec1498b671919a6bd1fec4f1be2a98f7dfd4765328e9

            SHA512

            195ae5a4d47b3272c834ed3904941284159dc048f17cac65d8a53425351d77d8508d76d00b3bd1166e9f58b155657120d9916b59274d8060d50028dadc9420bb

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            8KB

            MD5

            4e942256ccee8e704e45dfd6b3859d06

            SHA1

            d4f74c342c4d0f806de1946a282f857c42bae102

            SHA256

            1c6be5e4f7ad4696c189616305128832f4144b011516ce6cdac8ea82bc13eaac

            SHA512

            f17da871e485fef99ede076164269dcf6a64392511ec8794c3c938107388cf8b74ed6d2e2d3ab76fa5402c76db5a7d703554fb4ef24753e0ddf87f963d7cb7a3

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            4KB

            MD5

            08b08c3c1ac4aa231c9793053f9ec5cf

            SHA1

            e43c2edbc13d4ee725389f023827f64d3e3099af

            SHA256

            21cd09d0c5bb629c6fbad73b70f76bac1d4174f8aca70347cbe187d1ad3a1eaa

            SHA512

            938c55387b8cbba14f32e100ce1f0a1f7474b45c45e7cfb35daaa2cf6a80cfa045aa806fe0d0f4cfbef5cf024afdf60b006d0fddfb4656cbcc3a8ddf7864d242

          • /data/data/com.xgbuy.xg/databases/ua.db-wal
            Filesize

            4KB

            MD5

            bc4b5b6325f77656ef745e333af5355c

            SHA1

            99ff7be4d52c9496ad950ad2d60ff205161f8df9

            SHA256

            eb8845cb2f45d79dfbf353c117e8307cd08c2165ce991b15ac5a46b9079550f0

            SHA512

            fa82f65d3329879c68d15f5a14facc468f61235602d87b8dd47c42a073db9c64a22f35f55ac1606093c68673cd965080747a42884d2e52fc67c856f68d6d95c4

          • /data/data/com.xgbuy.xg/databases/xinggou
            Filesize

            4KB

            MD5

            f2b4b0190b9f384ca885f0c8c9b14700

            SHA1

            934ff2646757b5b6e7f20f6a0aa76c7f995d9361

            SHA256

            0a8ffb6b327963558716e87db8946016d143e39f895fa1b43e95ba7032ce2514

            SHA512

            ec12685fc0d60526eed4d38820aad95611f3e93ae372be5a57142d8e8a1ba17e6e5dfe381a4e1365dddc0b363c9c40daaffdc1245bd515fddac69bf1abacd7f1

          • /data/data/com.xgbuy.xg/databases/xinggou-journal
            Filesize

            512B

            MD5

            9ec73ad1bf8fe5a5114b1e64c8b6bd6c

            SHA1

            c1fd3bdf9eee65b9e180a114f091a17bb88cd2da

            SHA256

            f596ca164f01fdef0ce292ed93d2b120e9bc435cef555ccb0f36a162fd809b4d

            SHA512

            1888ff3a9f8f311136be58b57167ed52811443ff789065ed69105e2b9b86abd61d91f11f1c7f9f2541b9f997f4c3f09e092cd7030aa48fa4783b649181f13297

          • /data/data/com.xgbuy.xg/databases/xinggou-shm
            Filesize

            32KB

            MD5

            bb7df04e1b0a2570657527a7e108ae23

            SHA1

            5188431849b4613152fd7bdba6a3ff0a4fd6424b

            SHA256

            c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479

            SHA512

            768007e06b0cd9e62d50f458b9435c6dda0a6d272f0b15550f97c478394b743331c3a9c9236e09ab5b9cb3b423b2320a5d66eb3c7068db9ea37891ca40e47012

          • /data/data/com.xgbuy.xg/databases/xinggou-wal
            Filesize

            96KB

            MD5

            bbfdbb5bf3aa587812e2055b8886f578

            SHA1

            cdf90381617981270b53cf29fde59649629fd6cc

            SHA256

            b7c4341fa1eedf382cbdd93cbf6f078df1e0d4258b9214a47ddd8afd77b9a186

            SHA512

            4b91ccc5c9b708b960590b0e4b36d14c4d5b4757d83885139511c0810b2e85cb875e667d1e9d65c93f9e2d49a50374c8c3706b64befc85139c7b7877e6e792d9

          • /data/data/com.xgbuy.xg/files/.imprint
            Filesize

            1012B

            MD5

            32a3102ce9004c66e8c2c8c3d6dd95dd

            SHA1

            a56ce7d3c9427d547e613a41bb46a72ae43814c0

            SHA256

            a036f8474dcdba888ddd3125631c8009e89db69d21ecbd26e4bd4bf2920e405c

            SHA512

            b2591cb2b2cd93684445c54b2107ed8bc319a8fc92eb1cbd88f7dbe7186bdc2c6c7f03645895ba970ab4d5c3f7cd9254bcd75a16608957ece3e80d63d6a39c29

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.ac
            Filesize

            40B

            MD5

            3911ad10a2d9a4f7ef7a09639a1b8cf3

            SHA1

            d8d5dae863fe04bef8d987202e25e065efce1e1f

            SHA256

            0ae3380b0712c9bcbb362bcdf7b72504b9e495fe2987cfc20aec121977dba19d

            SHA512

            d58dc5e805e0e2d11a79c725285dbb3f75d351d456c87ce79439af68c3a6c2506f5814bc16f09fbf16462c93f5c781437a5bbadc4d48977782899ce9d741dec8

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.ac
            Filesize

            40B

            MD5

            81024874f926b0c0c9e613997c9370b1

            SHA1

            a7b4c37570f3e5aa7bd575d0dbcc71ff9079a95c

            SHA256

            da5ea38fae9a292777936eae50a76aae4d2a589550448aa6970383e44aabe7d6

            SHA512

            8ae3ca2a1a4ea6c514fffeb911f4c42ff173433a7fd82980193d883196e748e458e83ee42051ccbabfa7f49792dabbf1eb8a72fea3db16c2f157e7ada4182830

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.di
            Filesize

            340B

            MD5

            1d0bd068af5d4acaa514b64000cd7a79

            SHA1

            67120ad32e25570c19866246645efabfaf2fd0d2

            SHA256

            583b2ab15d0daec2d971cbce67aaaea7dd31c382102de4d1b9395acf32698878

            SHA512

            104a902a44a2a3bb7480ec4314cd4aaee948ac696145055fd725dd69103728f58482a5bc194c5bd64bc11b3c30a23ff3f08b62c6e2a6b5aeeb1d4aebbb2752db

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.di
            Filesize

            340B

            MD5

            baab111a2ae8e41c024a8c50ce93458b

            SHA1

            0306d8863359d2da5f06d5f1b9ef7f7a943ea153

            SHA256

            ae0cd547cd4a1ff2bb28f600506ca48dde81a4743b6221337057404c3d2195b2

            SHA512

            8816c77bb396ec8e97c5f9529911bc66e5ba7e9c5a8e02d315a0e6e8a175e5f859562de9690899b650aae85b7e9185333504f22937be07af8227a78f822715e0

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.ic
            Filesize

            40B

            MD5

            1bd86b90e1b355f123e5ce8c93c3de53

            SHA1

            bee5683d6124650c8be0b3740ad66e771f29b178

            SHA256

            3ba28c4fe20d74ea96f6ced27333f04a01e03c50092717eed1b6e30152a8d152

            SHA512

            6ba3d7ac2b9da3bb2f7ca50488782bfb9f12a38bf17debc4f2853a161551a932885bedaedace0ecd3da9777e1cddbb407ca2360c13512b1b804bd6242e767abe

          • /data/data/com.xgbuy.xg/files/.jglogs/.jg.ri
            Filesize

            314B

            MD5

            6a922c9a394c128d8eab14bbafb4cf23

            SHA1

            c51e9d485c7f4b334142fb9df43f0313b07e8d17

            SHA256

            81b1ca01421973508994e86b85fa7545c9c6088298a53cf235d824138455562b

            SHA512

            d59aecffed45e42974cb91ab228be73f7614e6fa6ca66bf595ac667bde5a1663645605b4eafc9915146f531491a479c8fb6f1eb55543edc03b6210e783be57ff

          • /data/data/com.xgbuy.xg/files/.jiagu.lock
            Filesize

            27B

            MD5

            27986b19b9e5a5807d49c924dd3b6489

            SHA1

            5eee1ce44680effa11ac36e60fbc68ea64ad996d

            SHA256

            d08c8413c0ac0f3a8119b8024b73a504201c4358671c05caa08b85ef5f7bc73a

            SHA512

            98bd55493d7ed0e78af99303c3429c4dea15126ec9441755e4b7ab8b8a4674978e3b4aa77622b76e86b3ef6dd48d7376afc694495791de5decd58c5f5734b765

          • /data/data/com.xgbuy.xg/files/.umeng/exchangeIdentity.json
            Filesize

            162B

            MD5

            a788f0c246a93883f9696944cd8e3c1b

            SHA1

            ef7366e10d07e43d5d3eba2bf5cddfad466a9c9f

            SHA256

            4fab1a6b976ea633d792ea5faaf11102f4e4ef10aef31ff7a91449afa1304bfa

            SHA512

            40754e81eea1f10f0bfacb3f3f18d8728a10e6d248666ca87e4362e0100d171fe63d94b440e254c128a2e6899299fb4116a18359ed530fec0f1d40cad71f7ac9

          • /data/data/com.xgbuy.xg/files/Mob/mob_commons_1
            Filesize

            2B

            MD5

            99914b932bd37a50b983c5e7c90ae93b

            SHA1

            bf21a9e8fbc5a3846fb05b4fa0859e0917b2202f

            SHA256

            44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a

            SHA512

            27c74670adb75075fad058d5ceaf7b20c4e7786c83bae8a32f626f9782af34c9a33c2046ef60fd2a7878d378e29fec851806bbd9a67878f3a9f1cda4830763fd

          • /data/data/com.xgbuy.xg/files/Mob/share_sdk_1
            Filesize

            23B

            MD5

            8e24e79baab91c4d0604eaa9006a0cb3

            SHA1

            e427afc94a4b957a7096f73e395a10ea404c076b

            SHA256

            65ee797326cb9d94a4c8b13fb114a7273d80af9ae547496bf56556c479f75e4d

            SHA512

            45bde5e1b5da5e54f7f5baf24cf4d9158ccf5813f0babc05677437bfedf1d54c4707090a1c425089e8f9582a85fed80b25c1e1f30ec2051afc6fe68bb8a76bae

          • /data/data/com.xgbuy.xg/files/Mob/share_sdk_1
            Filesize

            62B

            MD5

            0ba5b716e4824e3e34b4c9c547f7c894

            SHA1

            a63eedfa96847246d2b4fe3eb9abd9f3fd84a345

            SHA256

            e5b9e112670a956fea13a972c52d3efaac8020a63f7fa9354626f5d671604030

            SHA512

            78a0daa56deab31361eed88104f4831586e48975c8c69609e7cf33a08ddb5e07d71f344bee89beedbd692979976b4b7a36f92e43cf5cfd505fa86ccf2150ac31

          • /data/data/com.xgbuy.xg/files/Mob/share_sdk_1
            Filesize

            86B

            MD5

            081377b88859e73ad70670318a6b06f0

            SHA1

            3dfbfd3a883949ae8014c5ec3cee871ba8312e5f

            SHA256

            cf58a1ce7a7cd5c4f805d0c27f7a7f1b40bc8eabfa1c585321ea851c6a715e10

            SHA512

            4ebed4ef398f706110cbf434f629444eca31748b204002538815cfa0a94e94ef2c5ffa8a8b4985650f6449061b34195e219acad72cee646ff2293767ecc10fda

          • /data/data/com.xgbuy.xg/files/exid.dat
            Filesize

            62B

            MD5

            05aecdceea11013fb3a431c43aa06c73

            SHA1

            0cdc30d9ce74044bdcb13bbe0978198192801292

            SHA256

            bf3c34b037bcadd55ad35bf1c9b12100e8d49b9b733aaf6a624db05deb2927a3

            SHA512

            27d8b52af7e6c12bc6a68b26354438879d7dd220911689fb1b9d1766a03d0f6168b619509e045a7352b36b8a82e5e239e638bd43b87eb8242c4f89e1932f8624

          • /data/data/com.xgbuy.xg/files/jpush_stat_cache.json
            Filesize

            131B

            MD5

            bbbce7d25ce237837cd9333beaef2735

            SHA1

            62b0a469cdc49b76337f50e6007acac73d65f90c

            SHA256

            8ecfba1e4e918db4f2ea06af435e5bb85a432092412c0a14efb8658f2de56592

            SHA512

            f75661a44b5fd7e560f1caa7e0191cc11cb6736276f4dbdc8e3b523cac46160b25f7dd2ff276d4ccf366bc0fdb5218eb9401db5bef14204e972e882a82dace6e

          • /data/data/com.xgbuy.xg/files/jpush_stat_cache.json
            Filesize

            190B

            MD5

            fafaef347eed5e5f8c6bd7f122961651

            SHA1

            55405d2e61b7636ea9f3d098e75ab2f7087a66c4

            SHA256

            d315c98b9e3fdbf95ac9129e54a65efaa24b39d4da9d817cab26a3008f4873ed

            SHA512

            65a7a66e7493b6bb40dcea85b04330610715a921e1da101f4c6e165f36eb7736afc424a0931ef124901a4260b7b247b822670be6c1e055c845cf7a40cbbc216f

          • /data/data/com.xgbuy.xg/files/sobot_chat_log/sobot_chat_20240701_log.txt
            Filesize

            40KB

            MD5

            494367dcd3fcbdbeb40077ea4b218b7e

            SHA1

            ab020524bc7e4c8ba4d57aea2b30f232a1446d73

            SHA256

            7b3cb0b48c7d9fe0a44c66a7e18213d91898b362d21ac9035d6f1d12b9dfc3ae

            SHA512

            85dc0524e33148eb8490f00c4abad049bc5655205bd6509b1ad5645e6e821adcbc362b5098c0c78b6432c74a747e4c456ebde273843ca72482c6e65842429e40

          • /data/data/com.xgbuy.xg/files/umeng_it.cache
            Filesize

            210B

            MD5

            fd73f080f172ab179d1cfd34e36dafbd

            SHA1

            add9a0ccd9f95fbe040b09a468e891003c9081f5

            SHA256

            08bc7dc6ed109aecc2f1aed1a62e8729c1e1662787f9cb4ac7d78dea2c686584

            SHA512

            0a681e7295d18a9fdaa7d26c46ea27aec1ecc9e534056f8970b0d65a8e20fea6d36d84f16258dfc3f488a183e192060148280197d47cd606eef73bd6cef39ca2

          • /data/data/com.xgbuy.xg/files/umeng_it.cache
            Filesize

            413B

            MD5

            cd365daae1de48bfe9f69860ed5fcd45

            SHA1

            26ba1e5c4f66e85a1f7ebc2d99d7984380a0ead5

            SHA256

            2074caab7f169e9501fde3189a0608416a49a80204b2dd6e176fe4bea6e77a9e

            SHA512

            8777df96b69e2c678618d536b9f79d7f03049f7c9df3727736bc640fc8c01ee895b639e89b7f87c7c8c2321b8dcf62abf8dd1794340e507fdfb385e5a5205e25

          • /data/user/0/com.xgbuy.xg/.jiagu/classes.dex
            Filesize

            6.5MB

            MD5

            1472339fa1cf65c80bc8c3552ffb60f7

            SHA1

            fd200f143508060f49ad674f788cdfd96b683381

            SHA256

            2b2dcf2eb59577c79596b221afb2af1b2761b6ffed5573aec7c03ab0689fbe52

            SHA512

            01be09365e215911090870c3af4fe6fb0ab420e40d0463a3f3c761d34c63da757fe55c140640359a00dab40ade29cb68931d334faa69ee558662f4420293d98c

          • /data/user/0/com.xgbuy.xg/.jiagu/classes.dex!classes2.dex
            Filesize

            6.5MB

            MD5

            4c178cfc952782ff8adca64a516d13ea

            SHA1

            54b888326e5e63b33bbf9ab47b5c13fd91eaacf5

            SHA256

            0c0df559fb40137de512a51eaf77a9eb7ff5932fb286ffbc0e614f0e84b085b5

            SHA512

            a78cbdeebdba65c893523e078a4212663b5f6440acbe24fef03ad6576b260294023e74faf5206529960e43c117cb6593480ebbd4288759fa22aba7f2889716a7

          • /data/user/0/com.xgbuy.xg/.jiagu/classes.dex!classes3.dex
            Filesize

            1.8MB

            MD5

            dda881239476737c7afdf941bc0434ef

            SHA1

            1e06bb960a817097c6e7da630b0147a119553832

            SHA256

            6c2a21536bf028061d5c6c598c0f7f4939c40ec55f4caecc31e0230597a16ac6

            SHA512

            8ce15f0cc9762e012aef64ba3e0ddaea7d64f57a45e976b3623c79c533fd22f8931111467537a462da54b482ae64fc06bf94f23317755e179281c985079631b7

          • /storage/emulated/0/360/.deviceId
            Filesize

            48B

            MD5

            1d8d16c4e3b19ebf18988530d9b9a757

            SHA1

            bc94c1cce05cd848a53271ecb9c5311e27ffebf5

            SHA256

            abd87140da8de3d0aa39a24a8d52bfe7b2eb28f7a3d505f205471c7e8f4964d7

            SHA512

            4562d1eedbc5c2dd7f25cd1c70343053fd451026403585182b142a64f17016c1bd0bf6ad51667b439b220e425640e55fbbda08517e7106376cdc220a4555da82

          • /storage/emulated/0/360/.iddata
            Filesize

            80KB

            MD5

            997fcf87a90e557645003ce6cb9e3234

            SHA1

            523b4179d951318c707d96cde4d5420f08d2d7d4

            SHA256

            f7fd555d3d66bce9e4e07786faccce6307ddb18815ed60bd0b117ca98344c1bf

            SHA512

            ed212d6808df0858638a8db1f484b1547fdd8448ff4a04cf119217078d8a49cda1f29bd3c99fa30b61e0e8f6c0726de414db3b725769106d8e478f5522d25786

          • /storage/emulated/0/Mob/.slw
            Filesize

            66B

            MD5

            19402718bfb1c685a726b4e1d846ad98

            SHA1

            02a7e30044a67085f2f1da24e16e4ecfede65b72

            SHA256

            079f790e6a1934a94542559f53a89a824aafd3173d956b6019291955aeeb33d0

            SHA512

            25254318c22cfd301c8bcd479f45797d502b6ab5f14265dadfa3d87b4dd1942a629d3cbc2f0b600cf73b4fe910e3773432f56a0a7b4343e280e20c5a6af0320b

          • /storage/emulated/0/Mob/comm/.di
            Filesize

            512B

            MD5

            1b84351ac5450b386aa218debb4e7a0f

            SHA1

            561a9e4a98bf6e48e0ea217dcb78dde0b6618548

            SHA256

            28bf49ded62e45183674d1bdf86abab69600da93cd525e4531b9997495dd60e4

            SHA512

            7e3ad41d1b0706565f533bb73af646db4d50d8fb0492174a9dc285b11c54753f3047c3bf86155eb223aedf45a2b18e59442222d2b7b78be2d93933525419f621

          • /storage/emulated/0/Mob/comm/.di
            Filesize

            57B

            MD5

            70a42cba408700f9a6c01c7941a8829e

            SHA1

            eab01cc2c0671538795fb0b1146017dc099d0984

            SHA256

            499576707ce2623293166979e59c832be5b8636c64ad39aa63ebcf961910c35f

            SHA512

            8900d4dc8eed0430babbacb72942401bd22ef7fe5430cad90d3ce0c2c53010220d666aa0e2eb1026f3ec81d574c7fa12585b49222a5f15b01637f6ba134fe70c

          • /storage/emulated/0/data/.push_deviceid
            Filesize

            32B

            MD5

            e7f1618576d30efe2a56ec2929149414

            SHA1

            72063750a9d19f9d19453ab85e49ab0b85b81582

            SHA256

            901bda5fb0e87a20435f8cc330ba0a9bea8b165ccd896ec42df81bd8b28d4248

            SHA512

            7bf8547c3adb949d68cf46dd0f6e74bbb1691c3b5b9fcd9a2001a6b1a8c8abec715c6570b83317b5068a5d64b063f040db5090527408b80c1b01431b3e2e2cfa