Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) ai####.anal####.cn:8089
- TCP(HTTP/1.1) ur####.anal####.cn:8089
- TCP(HTTP/1.1) mem####.3####.net:80
- TCP(HTTP/1.1) f####.fengkon####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) d.ifen####.com.####.com:80
- TCP(TLS/1.0) fp.fraudme####.cn:443
- TCP(TLS/1.0) api.icl####.i####.com:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) d.ifen####.com.####.com:443
- TCP(TLS/1.0) 1####.251.36.10:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) u####.icl####.i####.com:443
- TCP(TLS/1.0) api.shu####.cn:443
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) d####.shu####.cn:443
- TCP(TLS/1.2) 1####.251.36.10:443
- TCP(TLS/1.2) connect####.gst####.com:443
- ai####.anal####.cn
- and####.b####.qq.com
- and####.cli####.go####.com
- api.icl####.i####.com
- api.map.b####.com
- api.shu####.cn
- cloud####.fengkon####.com
- connect####.gst####.com
- d####.shu####.cn
- d.ifen####.com
- f####.fengkon####.com
- fp.fraudme####.cn
- m####.go####.com
- p####.google####.com
- pla####.google####.com
- pla####.googleu####.com
- st####.i####.com
- t####.qq.com
- u####.icl####.i####.com
- ur####.anal####.cn
- v.i####.com
- www.3####.org
- api.icl####.i####.com:443/client_base_config?configType=####&&gv=####&av...
- api.icl####.i####.com:443/client_base_config?gv=####&av=####&uid=####&de...
- api.icl####.i####.com:443/commentEmojiConfig
- d.ifen####.com.####.com/appData/video/player_config.js
- mem####.3####.net/dyndns/getip
- u####.icl####.i####.com:443/Active_Redpackactivity/getConf?gv=####&av=##...
- ai####.anal####.cn:8089/
- and####.b####.qq.com/rqd/async?aid=####
- api.shu####.cn:443/report?v=####&c=####&e=####
- d####.shu####.cn:443/report?v=####&t=####&e=####
- f####.fengkon####.com/v2/device/conf
- f####.fengkon####.com/v2/device/profile
- fp.fraudme####.cn:443/android3/profile.json?sctoken=####&partner=####&ve...
- ur####.anal####.cn:8089/
- /data/data/####/.td-3
- /data/data/####/.tpns.settings.xml.xml
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/1c840db577a5b6ade6979ae3c787331e4feb6faf6a64d7c...0c0c.0
- /data/data/####/1e28c92a9d92e0dd822834c0d56246c1929f9d3486d26ec...35cc.0
- /data/data/####/21543fcb468fd5f951d8ad6e56f5de07a38912393815080...af7d.0
- /data/data/####/2debbd3100553f930af8d8cdc196d76c15b865f1e7f20bd...1a76.0
- /data/data/####/37d0c583ea7d0139
- /data/data/####/45c395dc6a2065ff6c83bd4f9aebd8d58336e1e96371b2e...e926.0
- /data/data/####/6add71f21567e3776e94b154973f9d01d92d410fb53b868...d2ac.0
- /data/data/####/BUGLY_COMMON_VALUES.xml
- /data/data/####/FirstLogin.xml
- /data/data/####/TeleSign.db
- /data/data/####/TeleSign.db-journal
- /data/data/####/WInfo.xml
- /data/data/####/amaze.png
- /data/data/####/angel.png
- /data/data/####/angry.png
- /data/data/####/applause.png
- /data/data/####/arch.xml
- /data/data/####/arrogant.png
- /data/data/####/astonished.png
- /data/data/####/authStatus_com.ifeng.kuaitoutiao;remote.xml
- /data/data/####/awkward.png
- /data/data/####/bigcry.png
- /data/data/####/bugly_db_
- /data/data/####/bugly_db_-journal
- /data/data/####/bye.png
- /data/data/####/c10ed1e0eca154c53b53779f5a3d142b9cf51f61d56f84a...52b7.0
- /data/data/####/cheer.png
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/com.ifeng.kuaitoutiao.BETA_VALUES.xml
- /data/data/####/com.ifeng.kuaitoutiao_dna.xml
- /data/data/####/com.ifeng.kuaitoutiao_preferences.xml
- /data/data/####/com.ifeng.kuaitoutiao_prefs.xml
- /data/data/####/com.ifeng.kuaitoutiao_prefs.xml.bak (deleted)
- /data/data/####/com.shumei.xml
- /data/data/####/comic.png
- /data/data/####/config.conf
- /data/data/####/crashrecord.xml
- /data/data/####/crashrecord.xml (deleted)
- /data/data/####/crashrecord.xml.bak
- /data/data/####/crashrecord.xml.bak (deleted)
- /data/data/####/crazy.png
- /data/data/####/cry.png
- /data/data/####/cute.png
- /data/data/####/daze.png
- /data/data/####/default.zip
- /data/data/####/defaultemoji.png
- /data/data/####/device_info.xml
- /data/data/####/dizzy.png
- /data/data/####/doubt.png
- /data/data/####/du.lock
- /data/data/####/eguan.db
- /data/data/####/eguan.db-journal
- /data/data/####/eguan_app.db
- /data/data/####/eguan_app.db-journal
- /data/data/####/f2b0f931841781b3
- /data/data/####/facepalmcry.png
- /data/data/####/fallill.png
- /data/data/####/fm_shared.xml
- /data/data/####/follow.png
- /data/data/####/frown.png
- /data/data/####/geofencing.db
- /data/data/####/geofencing.db-journal
- /data/data/####/heart.png
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/ifeng_log_SM-T555.txt
- /data/data/####/ifeng_statitics+6.2.6.dat
- /data/data/####/journal.tmp
- /data/data/####/kiss.png
- /data/data/####/laughcry.png
- /data/data/####/lechery.png
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/mac.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/mipush_region
- /data/data/####/mipush_region.lock
- /data/data/####/native_record_lock
- /data/data/####/native_record_lock (deleted)
- /data/data/####/pathetic.png
- /data/data/####/praise.png
- /data/data/####/proc_auxv
- /data/data/####/push_record.db
- /data/data/####/push_record.db-journal
- /data/data/####/qtsession.xml
- /data/data/####/rose.png
- /data/data/####/security_info
- /data/data/####/shutup.png
- /data/data/####/shy.png
- /data/data/####/simper.png
- /data/data/####/sleep.png
- /data/data/####/sleepy.png
- /data/data/####/sp_replace_flag.sp
- /data/data/####/sp_replace_flag.sp.bak
- /data/data/####/sputil.sp
- /data/data/####/sputil.sp.bak
- /data/data/####/struggle.png
- /data/data/####/sweat.png
- /data/data/####/td_fm.dex.flock (deleted)
- /data/data/####/td_fm.jar
- /data/data/####/teethlaugh.png
- /data/data/####/titter.png
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/tracker.db
- /data/data/####/tracker.db-journal
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_config.xml.bak
- /data/data/####/umeng_common_config.xml.bak (deleted)
- /data/data/####/umeng_general_config.xml
- /data/data/####/vomit.png
- /data/data/####/wane.png
- /data/data/####/watermelon.png
- /data/misc/####/primary.prof
- cat /proc/cpuinfo
- date
- df
- getprop
- id
- ip link
- logcat -d -v threadtime
- logcat -d -v time ifengNews:v System.err:v *:s
- ls -l /system/xbin/su
- ls /dev/socket
- ls /system/fonts
- mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
- ps
- ps -P
- service call iphonesubinfo 1
- sh -c cat /proc/meminfo
- sh -c cat /sys/class/net/eth0/address
- sh -c cd /proc/;cat cpuinfo
- sh -c cd /proc/net/ && cat arp
- sh -c cd /proc/self/;cat status
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c echo RTUyODc0MjRGNzA5ODJBNzlGMjRDRTRBMUNGODE0NTI3MTdBNjc6QUNFNzhEOkZDN0E2Qg== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c echo RTUyODc0MjRGNzA5ODJBNzlGMjRDRTRBMUNGODE0NTI3MTdBNjc6QUNFNzhEOkZDN0E2Qg== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- toolbox ps -p -P -x -c
- libdu
- libifeng_secure
- libjiagu
- libsecurityenv
- libsign
- libsmsdk
- libtongdun
- libtpnsSecurity
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- DESede-CBC-PKCS5Padding
- RSA
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-GCM-NoPadding
- DES-ECB-NoPadding