Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) t.g####.qq.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) hq.si####.cn:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) l####.cc:80
- TCP(TLS/1.0) hx####.si####.com:443
- TCP(TLS/1.0) 1####.177.119.138:443
- TCP(TLS/1.0) sen####.ba####.com:4106
- TCP(TLS/1.0) outers####.q####.cn:443
- TCP m####.ba####.com:1883
- api.s####.mob.com
- hq.si####.cn
- hx####.si####.com
- l####.cc
- m####.ba####.com
- outers####.q####.cn
- s####.e.qq.com
- sen####.ba####.com
- t.g####.qq.com
- hq.si####.cn/wskt?list=####
- t.g####.qq.com/conv/sdk/spa/conv?vx=X41s####&encver=####
- t.g####.qq.com/conv/sdk/spa/conv?vx=wFsl####&encver=####
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/log4
- api.s####.mob.com/snsconf
- l####.cc/i/sdk/install
- s####.e.qq.com/msg
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/ActivateTimePref.xml
- /data/data/####/LKME_Server_Request_Queue.xml
- /data/data/####/MultiDex.lock
- /data/data/####/SessionTimePref.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/channel_file.xml
- /data/data/####/com.baidao.nugget-journal
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDataAPI.xml
- /data/data/####/libjiagu1047562769.so
- /data/data/####/linkedme_referral_shared_pref.xml
- /data/data/####/mob_commons_1.xml
- /data/data/####/mqttAndroidService.db-journal
- /data/data/####/multidex.version.xml
- /data/data/####/nugget.db-journal
- /data/data/####/online_config.xml
- /data/data/####/sensorsdata.xml
- /data/data/####/share_sdk_1.xml
- /data/data/####/sharesdk.db-journal
- /data/media/####/.dic_lock
- /data/media/####/.globalLock
- /data/media/####/.lck
- /data/media/####/.lm_device_id
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.rcTag
- /data/media/####/.rc_lock
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu1047562769.so
- sh
- libjiagu1047562769
- neh
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding
- AES-ECB-NoPadding