Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) api.icaipia####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
- TCP(TLS/1.0) api.icaipia####.com:443
- TCP(TLS/1.0) ada####.m.ta####.com:443
- TCP(TLS/1.0) sh.wagbr####.ta####.com:443
- TCP(TLS/1.0) u.zhug####.com:443
- TCP(TLS/1.0) 1####.217.20.78:443
- a####.man.aliy####.com
- a####.u####.com
- ada####.ut.ta####.com
- adas####.ut.ta####.com
- api.icaipia####.com
- p.wangca####.com
- s0.icaipia####.com
- u.zhug####.com
- api.icaipia####.com/api/v1/c/p?p=####
- api.icaipia####.com/api/v5/server/timestamp
- t####.c####.q####.####.com/avatar/180918/e3be8328645fd676a55540ff2e78cbc...
- t####.c####.q####.####.com/avatar/181008/73e1808e9a07beb3c4d3fa80e4626da...
- t####.c####.q####.####.com/avatar/181114/36e40d0918027456786fdd5cc56fc38...
- a####.u####.com/app_logs
- api.icaipia####.com/api/v5/server/activate
- sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
- /data/data/####/-11788933491545824674
- /data/data/####/-14932529442085446822
- /data/data/####/-149325294475075523
- /data/data/####/-1610420295-96403297
- /data/data/####/-1870901461-579702014
- /data/data/####/-19096045061170456815
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/1143457836734966984
- /data/data/####/175433065-684110328
- /data/data/####/1772903567502243903
- /data/data/####/1811787038-1976127514
- /data/data/####/21090119561046727059
- /data/data/####/4a47797ae91a44dd7d6b4cdb5e881d1618d4add36fe80c0....0.tmp
- /data/data/####/574751531-1176246128 (deleted)
- /data/data/####/730891274-1759013948
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/UTCommon.xml
- /data/data/####/__cfg_lk_1312
- /data/data/####/ap.Lock
- /data/data/####/b987f12f71b78341d30d9b6f17d45028cf24b107ad788cb....0.tmp
- /data/data/####/cache.xml
- /data/data/####/cache_int.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/config.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f62e5c3fe5a47e6cc8dde17f206021834ac8cb1ddc3bce1....0.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu478028315.so
- /data/data/####/multidex.version.xml
- /data/data/####/pailiefive.main.xml
- /data/data/####/pailiefive.main_preferences.xml
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/data/####/zhuge
- /data/data/####/zhuge-journal
- /data/media/####/4dfn7105q3p6ct7y1bwjlc7v0
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- chmod 755 <Package Folder>/.jiagu/libjiagu478028315.so
- getuiext2
- libjiagu478028315
- ut_c_api
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES