Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) im####.w####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) www.wdj####.com:8099
- TCP(HTTP/1.1) sni.c####.q####.####.net:80
- TCP(HTTP/1.1) reso####.msg.xi####.net:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) www.w####.com:443
- TCP(TLS/1.0) lbs.net####.im:443
- TCP(TLS/1.0) dsp.w####.com:443
- TCP(TLS/1.0) qy-swa####.qi####.com:443
- TCP(TLS/1.0) p####.w####.com:443
- TCP(TLS/1.0) st####.w####.com:443
- TCP(TLS/1.0) myacc####.go####.com:443
- TCP(TLS/1.0) www.youji####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) bbs.w####.com:443
- TCP(TLS/1.0) nim.qi####.com:443
- TCP(TLS/1.0) av####.wdzjim####.com:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) s####.g.doublec####.net:443
- TCP(TLS/1.0) dn-gro####.q####.me:443
- TCP(TLS/1.0) phpser####.w####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) imgmy####.w####.com:443
- TCP(TLS/1.0) a####.go####.com:443
- TCP(TLS/1.0) m.w####.com:443
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) www.google-####.com:443
- TCP(TLS/1.0) p####.go####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) dxp.b####.com:443
- TCP(TLS/1.0) h####.b####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) regi####.xm####.gl####.####.com:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP c####.g####.ig####.com:5224
- TCP sdk.o####.t####.####.com:5224
- TCP l####.net####.im:8080
- TCP app.c####.gl####.####.net:5222
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a####.go####.com
- a####.u####.com
- adser####.go####.com
- api.growi####.com
- app.c####.gl####.####.net
- av####.wdzjim####.com
- bbs.w####.com
- c####.g####.ig####.com
- c-h####.g####.com
- dn-gro####.q####.me
- dsp.w####.com
- dxp.b####.com
- f####.gst####.com
- h####.b####.com
- hm.b####.com
- im####.w####.com
- imgmy####.w####.com
- l####.net####.im
- l####.tbs.qq.com
- lbs.net####.im
- m.w####.com
- myacc####.go####.com
- nim.qi####.com
- p####.go####.com
- p####.w####.com
- phpser####.w####.com
- qy-swa####.qi####.com
- regi####.xm####.gl####.####.com
- reso####.msg.xi####.net
- s####.g.doublec####.net
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- ssl.google-####.com
- ssl.gst####.com
- st####.w####.com
- t####.growi####.com
- wfd.net####.im
- www.go####.com
- www.go####.nl
- www.google-####.com
- www.gst####.com
- www.w####.com
- www.wdj####.com
- www.youji####.com
- im####.w####.com/webimages/prod/rebate/201804021455019.png_100x100
- im####.w####.com/webimages/prod/rebate/o_1cc34haiknlk120s1hqf19mb3fm8.jp...
- reso####.msg.xi####.net/gslb/?ver=4.0&type=wap&conpt=dvidpodv >>4>>4>>4...
- sni.c####.q####.####.net/config/hz-hzv3.conf
- sni.c####.q####.####.net/tdata_YYn966
- sni.c####.q####.####.net/tdata_eOt091
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- l####.tbs.qq.com/ajax?c=####&k=####
- l####.tbs.qq.com/ajax?c=####&v=####&k=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- www.wdj####.com:8099/app/app/appVersion/update
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/36a9700125054abec405df91badfcade48f115689150848....0.tmp
- /data/data/####/MySp.xml
- /data/data/####/NIMSDK_Config_2a616f7a002a98cd9cfb3167bda9a80e.xml
- /data/data/####/NIMSDK_Config_2a616f7a002a98cd9cfb3167bda9a80e_...5e.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/Unicorn.2a616f7a002a98cd9cfb3167bda9a80e.xml
- /data/data/####/XMPushServiceConfig.xml
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1533037792917
- /data/data/####/baidu_mtj_sdk_record.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.qiyukf.analytics.xml
- /data/data/####/com.youjin360.netloan;pushservice
- /data/data/####/core_info
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/debug.conf
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/gdaemon_20161017
- /data/data/####/geofencing.db
- /data/data/####/geofencing.db-journal
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libcuid.so
- /data/data/####/libjiagu137803921.so
- /data/data/####/mipush.xml
- /data/data/####/mipush_account.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/mipush_region
- /data/data/####/mipush_region.lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/msg.db-journal
- /data/data/####/mtj_autoTracker.js
- /data/data/####/multidex.version.xml
- /data/data/####/pref_registered_pkg_names.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/qiyu_save_2a616f7a002a98cd9cfb3167bda9a80e.xml
- /data/data/####/run.pid
- /data/data/####/sp_client_report_status.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_YYn966
- /data/data/####/tdata_YYn966.jar
- /data/data/####/tdata_eOt091
- /data/data/####/tdata_eOt091.jar
- /data/data/####/trace_circle.data
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/unicorn#cheese#
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.artc_lock
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.im_lock
- /data/media/####/.lecd
- /data/media/####/.lesd_lock
- /data/media/####/.mn_-1464060969
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/.timestamp
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.youjin360.netloan.bin
- /data/media/####/com.youjin360.netloan.db
- /data/media/####/log.lock
- /data/media/####/log1.txt
- /data/media/####/tdata_YYn966
- /data/media/####/tdata_eOt091
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GePushService 24987 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu137803921.so
- getprop ro.build.display.id
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GePushService 24987 300 0
- getuiext2
- libjiagu137803921
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- DESede-ECB-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding