Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(HTTP/1.1) d####.d####.mob.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) kan.c####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) api.shanz####.com.cn:80
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) sni.c####.q####.####.net:80
- TCP(HTTP/1.1) d####.b####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) t####.qq.com:80
- TCP(HTTP/1.1) 1####.254.116.117:80
- TCP(TLS/1.0) kan.c####.com:443
- TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP c####.g####.ig####.com:5225
- TCP sdk.o####.t####.####.com:5224
- TCP t####.qq.com:8080
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a####.u####.com
- api.s####.mob.com
- api.shanz####.com.cn
- ar.u####.com
- c####.g####.ig####.com
- c-h####.g####.com
- d####.b####.com
- d####.d####.mob.com
- h####.b####.com
- im####.shanz####.com.cn
- kan.c####.com
- m.d####.mob.com
- pi####.qq.com
- regi####.xm####.xi####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t####.qq.com
- api.shanz####.com.cn/index/index.php?c=####&m=####&a=####
- kan.c####.com/toutiao/index/index.php?c=####&m=####&a=####&aid=####
- m.d####.mob.com/cconf?appkey=####&plat=####&apppkg=####&appver=####&netw...
- sni.c####.q####.####.net/config/hz-hzv3.conf
- sni.c####.q####.####.net/tdata_MkX219
- sni.c####.q####.####.net/tdata_iGj879
- ti####.c####.l####.####.com/04872e6d695e4db79f82961065081a01.jpg
- ti####.c####.l####.####.com/0668b18788184f7c9c9f37fa4b7cb945.jpg
- ti####.c####.l####.####.com/14f8672a806543d3803371cbb787146b.jpg
- ti####.c####.l####.####.com/29ec8de53d02431a84df854bd928cc20.jpg
- ti####.c####.l####.####.com/2a0de941486a4af5b48d58ccf1529eab.jpg
- ti####.c####.l####.####.com/2ac8c9953ffa47f0a0a702a9741c5a79.jpg
- ti####.c####.l####.####.com/31986a74388c436c9d8fc03cb170ddbe.jpg?imageVi...
- ti####.c####.l####.####.com/3639c9b8e94640d09a3de774328e0221.gif?imageVi...
- ti####.c####.l####.####.com/3e5ff4c6db5e46039cf9026328bffd35.mp4
- ti####.c####.l####.####.com/5196ad8bf71241478230acedbcdb9e2d.jpg
- ti####.c####.l####.####.com/5359bec3ead2425cb6d9d2bf3f9f9c2b.jpg
- ti####.c####.l####.####.com/5429e919932e4b7c9f6abe6474bff688.jpg?imageVi...
- ti####.c####.l####.####.com/570c1eb366044bb38b2d9f0f62ecf24a.jpg?imageVi...
- ti####.c####.l####.####.com/5a53af0e44474e3abb235f5f9da0e3ab.jpg?imageVi...
- ti####.c####.l####.####.com/5de3a633f61f46cdb437dc20de167a88.jpg?imageVi...
- ti####.c####.l####.####.com/62442c2cd383489a94d4c7f4aab4479e.jpg
- ti####.c####.l####.####.com/73eec50f349640feb4189c0ae5ed5f80.jpg
- ti####.c####.l####.####.com/73eec50f349640feb4189c0ae5ed5f80.jpg?imageVi...
- ti####.c####.l####.####.com/74510a9eb8c443eb945fa46130575535.jpg?imageVi...
- ti####.c####.l####.####.com/791cc8c450a54709ad2d47a261b544d0.jpg
- ti####.c####.l####.####.com/7a46cfc5225a41668f6b8ebbf66681fe.jpg
- ti####.c####.l####.####.com/7b889918e3e94b888a4d7f5a35ede539.jpg?imageVi...
- ti####.c####.l####.####.com/808aa746b24040cf844b00236bea9f02.jpg
- ti####.c####.l####.####.com/82c4dcd336aa4702bb68a48123276e16.jpg
- ti####.c####.l####.####.com/82c4dcd336aa4702bb68a48123276e16.jpg?imageVi...
- ti####.c####.l####.####.com/88740ff4f69f4259be28599dcdc4cde9.jpg?imageVi...
- ti####.c####.l####.####.com/8919959e4fb64658baa58b6103c99b90.jpg
- ti####.c####.l####.####.com/91926794042f4a6e95b7a15267e9fb55.jpg
- ti####.c####.l####.####.com/9506b90668ac457e91b1fcba63439e7f.jpg
- ti####.c####.l####.####.com/98d9015aa4ff4d8ca2e2836b95db067e.jpg?imageVi...
- ti####.c####.l####.####.com/9b35eaa7681d4f73a819ec29b87e399c.jpg
- ti####.c####.l####.####.com/9c6ddb0cd848463690b78abbcb583310.gif?imageVi...
- ti####.c####.l####.####.com/a78a9f285bba47faa57fbc2d7ef82f64.jpg
- ti####.c####.l####.####.com/ab8f634a8c5e4cdb97576e6274e28ce9.jpg
- ti####.c####.l####.####.com/abfa075ce02c43c996e998250bf9e441.jpg
- ti####.c####.l####.####.com/b7cdb08219c3448593fe75009933eee1.jpg
- ti####.c####.l####.####.com/ba7c5226b63243f8bc7f86f23890fcc9.jpg?imageVi...
- ti####.c####.l####.####.com/c65a00bb15ff43809d8cddfe9f09bebc.jpg
- ti####.c####.l####.####.com/c96c755676844d80abae27085b8dbdfc.jpg
- ti####.c####.l####.####.com/ce2517382f8c44779ceb3527a580e2a1.jpg
- ti####.c####.l####.####.com/e868d96591c546eebf16ead99981d710.gif?imageVi...
- ti####.c####.l####.####.com/ed90013f4cd64126a21b83599dd6d117.jpg?imageVi...
- ti####.c####.l####.####.com/eefa748ebfb342a380b86c9704ad50e6.jpg
- ti####.c####.l####.####.com/f27fe3df71dd473dacea39a1542ae28b.jpg
- ti####.c####.l####.####.com/fbcd61d0a3ac4e518dbdb23e3c370d4c.jpg?imageVi...
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- api.shanz####.com.cn/index/index.php?c=####&m=####&a=####
- c-h####.g####.com/api.php?format=####&t=####
- d####.b####.com/xs.gif?k=cxN6g####&iv=Q45H####&c=0OgK9####&dm=Z18o####&a...
- d####.d####.mob.com/dinfo
- d####.d####.mob.com/dsign
- h####.b####.com/app.gif
- pi####.qq.com/mstat/report/?index=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- t####.qq.com/203.205.146.122:80/
- /data/data/####/-801585808
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/.tpns.service.xml.xml
- /data/data/####/.tpns.settings.xml.xml
- /data/data/####/.tpush_mta.xml
- /data/data/####/0TYRMwng5hkZphMvd9FKHxZaAEE.-1468918627.tmp
- /data/data/####/1MBLcNsGfZ2rVWcDpECZ9EYb1Pw.-279241054.tmp
- /data/data/####/278-FOrHDlgaRCsKqHGek4L2NMw.1598722366.tmp
- /data/data/####/6i9ZWG8G-skb_aONKs1leV81SjM.1353906309.tmp
- /data/data/####/945MQR1X6AXKFhDaroUhSOONvMs.-1431760640.tmp
- /data/data/####/AF58WaCUFUF9ooePN0k8MndV3BM.159798465.tmp
- /data/data/####/Kuw_RaFFQACiZbGWmANRxv3-E_4.-387117186.tmp
- /data/data/####/PAn5geGbG49-_QYIXSS1eMD1bFQ.-1490983276.tmp
- /data/data/####/SnFadY9utT7vwRlJf4Ue21SeG_k.-1162276090.tmp
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/XV-9UWmhr5SDjq-0ShgmTIErUvo.2127081458.tmp
- /data/data/####/ZlEzC04jIs8QCwSIPZbrZYvLihQ.169036769.tmp
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1531821541499
- /data/data/####/_ii-EfBDtk7H8DSvxDeYFvBKUbw.-1389768483.tmp
- /data/data/####/auCWys1SU9olid-ecW7fzUEwyPM.-1783966272.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.kangyuan.juzitoutiao_preferences.xml
- /data/data/####/dGEF1F2vm2KvrD3EHNPeqCo4AhY.-1271660553.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/device_id.xml
- /data/data/####/disk_entries_list_image_cache_-452553205.xml
- /data/data/####/dzw68aTHddgSHHGJTTLe5fqg5s0.82315199.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fK284R-HKRtd4bpRaxtYzFy240Y.-522233885.tmp
- /data/data/####/fRRdWQ4YI5Mm5RtW-UMPqFaIwLg.892456731.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/gcBUQnmIekCvdGRPHcM4l97GXOY.-1595443109.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/i_q1wfrbiIjjYA1NEawM0mh-IeU.1902923673.tmp
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libcuid.so
- /data/data/####/libjiagu1455706824.so
- /data/data/####/lmTrMZcmGJ7ZT3oVJzPXvnd3j44.757373451.tmp
- /data/data/####/mipush.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/mob_commons_1.xml
- /data/data/####/mob_sdk_exception_1.xml
- /data/data/####/multidex.version.xml
- /data/data/####/news.xml
- /data/data/####/o4i4K3zRf7p6lhAjrbYxUBOm57g.1952698340.tmp
- /data/data/####/pHK2ufPbQtgM280xeCgTSFP9TuA.-498637209.tmp
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/q1llo4S7AEWSXZY0AzKv81i_VfU.-1667478241.tmp
- /data/data/####/run.pid
- /data/data/####/share_sdk_1.xml
- /data/data/####/tdata_MkX219
- /data/data/####/tdata_MkX219.jar
- /data/data/####/tdata_iGj879
- /data/data/####/tdata_iGj879.jar
- /data/data/####/tencent_analysis.db-journal
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/uJRPxlev0R_VzxPxVQ9ABV84ZEU.-1803208145.tmp
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/xg_message.db
- /data/data/####/xg_message.db-journal
- /data/data/####/z3WDIorRw_PlSfjFDTF7PMnSt1U.-1205302577.tmp
- /data/data/####/z70gWH7gACVdI2EVoz3i79xyZG0.1339972319.tmp
- /data/media/####/-1013847548.0.tmp
- /data/media/####/-1159262682.0.tmp
- /data/media/####/-1467157452.0.tmp
- /data/media/####/-1648292844.0.tmp
- /data/media/####/-1710201460.0.tmp
- /data/media/####/-329416781.0.tmp
- /data/media/####/-73967233.0.tmp
- /data/media/####/-741938639.0.tmp
- /data/media/####/-951220106.0.tmp
- /data/media/####/.al
- /data/media/####/.ccLock
- /data/media/####/.ccc
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.dh-journal
- /data/media/####/.dhlock
- /data/media/####/.dic_lock
- /data/media/####/.dk
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.mid.txt
- /data/media/####/.nomedia
- /data/media/####/.nulal
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.plst
- /data/media/####/.rc_lock
- /data/media/####/.timestamp
- /data/media/####/.usLock
- /data/media/####/146406161.0.tmp
- /data/media/####/1634250374.0.tmp
- /data/media/####/1639481035.0.tmp
- /data/media/####/1669756687.0.tmp
- /data/media/####/1897112719.0.tmp
- /data/media/####/1960998785.0.tmp
- /data/media/####/2086197448.0.tmp
- /data/media/####/297106006.0.tmp
- /data/media/####/794363517.0.tmp
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.kangyuan.juzitoutiao.bin
- /data/media/####/com.kangyuan.juzitoutiao.db
- /data/media/####/journal.tmp
- /data/media/####/log.lock
- /data/media/####/log1.txt
- /data/media/####/tdata_MkX219
- /data/media/####/tdata_iGj879
- /data/media/####/test.log
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.DemoPushService 25496 300 0
- <Package Folder>/lib/libxguardian.so <Package>,2100215508; 55773 203.205.128.130 [{ idx :0, ts :%d, et :2000, si :0, ui : <IMEI> , ky : Axg%lu , mid : 0 , ev :{ ov : 18 , sr : 600*752 , md : <System Property> , lg : en , sv : 3.1 , mf : unknown , apn : %s }}] 0 18
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu1455706824.so
- grep -E -v root|shell|system
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.DemoPushService 25496 300 0
- top -d 0 -n 1
- MtaNativeCrash
- getuiext2
- imagepipeline
- libjiagu1455706824
- neh
- pl_droidsonroids_gif
- tpnsSecurity
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB8-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1PADDING
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CFB8-NoPadding
- DES-ECB-PKCS5Padding