Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) norma-e####.m####.com:80
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) gs.g####.com:80
- TCP(HTTP/1.1) www.i####.cn:80
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(TLS/1.0) 1####.217.19.202:443
- TCP(TLS/1.0) 4f8f13c####.qcloud####.com:443
- TCP(TLS/1.0) 2####.58.208.106:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.195:443
- TCP(TLS/1.2) 1####.250.179.206:443
- TCP(TLS/1.2) 1####.217.19.202:443
- TCP sdk.o####.t####.####.com:5224
- TCP cm-1####.g####.com:5224
- TCP 2####.129.163.50:443
- UDP 1####.217.19.202:443
- TCP 8####.69.64.111:443
- and####.google####.com
- b####.g####.com
- b34fb84####.bug####.com
- bb####.dxy.cn
- c####.g####.com
- c####.g####.com
- c-h####.g####.com
- cdn-sdk####.g####.com
- cm-1####.g####.com
- gs.g####.com
- l####.tbs.qq.com
- m####.go####.com
- md####.google####.com
- newd####.dxy.cn
- norma-e####.m####.com
- sdk-ope####.g####.com
- sdk.c####.g####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- www.i####.cn
- cdn-sdk####.g####.com.####.com/tdata_XYq933
- cdn-sdk####.g####.com.####.com/tdata_pKN446
- cdn-sdk####.g####.com.####.com/tdata_trp703
- cdn-sdk####.g####.com.####.com/tdata_xEA084
- d####.c####.l####.####.com/config/hzv9.conf
- norma-e####.m####.com/android/exchange/getpublickey.do
- www.i####.cn/iyuji/s/NE9qYnJVanFQdTRUeU5WM2NHUDNUUT09/1560777700402593
- c####.g####.com/api.php?format=####&t=####
- gs.g####.com/encryption/key/fetch
- gs.g####.com/geshu/sdkStatistics/bd
- norma-e####.m####.com/push/android/external/add.do
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/28f15bc1cf2872ed.txt
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/SP_AROUTER_CACHE.xml
- /data/data/####/SP_AROUTER_CACHE.xml.bak
- /data/data/####/app_config.xml
- /data/data/####/app_config.xml.bak
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex.flock (deleted)
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.oat
- /data/data/####/classes.oat.flock (deleted)
- /data/data/####/com.x.y.1.xml
- /data/data/####/com.x.y.2.xml
- /data/data/####/core_info
- /data/data/####/dxy-hybrid.xml
- /data/data/####/dxy-hybrid.xml.bak
- /data/data/####/dxy_sso_v2.xml
- /data/data/####/getui_sp.xml
- /data/data/####/gtc.db-journal
- /data/data/####/ias.db-journal
- /data/data/####/ias_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal
- /data/data/####/libjiagu.so
- /data/data/####/mydata.xml
- /data/data/####/mz_push_preference.xml
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushgdc.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_XYq933
- /data/data/####/tdata_XYq933.jar
- /data/data/####/tdata_pKN446
- /data/data/####/tdata_pKN446.dex
- /data/data/####/tdata_pKN446.dex.flock (deleted)
- /data/data/####/tdata_pKN446.jar
- /data/data/####/tdata_trp703.tmp (deleted)
- /data/data/####/tdata_xEA084
- /data/data/####/tdata_xEA084.dex
- /data/data/####/tdata_xEA084.dex.flock (deleted)
- /data/data/####/tdata_xEA084.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/user_config.xml
- /data/misc/####/primary.prof
- getprop ro.product.cpu.abi
- logcat -v time -t 500 3691
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding