Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(SSL/3.0) das.bai####.cn:443
- TCP(TLS/1.0) fp.fraudme####.cn:443
- TCP(TLS/1.0) acc####.kejidai####.com:443
- TCP(TLS/1.0) fe####.zhenron####.com:443
- TCP(TLS/1.0) das.bai####.cn:443
- TCP(TLS/1.0) bt.kejidai####.com:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP(TLS/1.0) b####.oss-cn-####.aliy####.com:443
- TCP c####.g####.ig####.com:5227
- TCP c####.g####.ig####.com:5224
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- acc####.kejidai####.com
- b####.oss-cn-####.aliy####.com
- bt.kejidai####.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- das.bai####.cn
- fe####.zhenron####.com
- fp.fraudme####.cn
- sdk.c####.ig####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t####.growi####.com
- t.growi####.com
- t####.c####.q####.####.com/config/hz-hzv3.conf
- /data/data/####/.jg.ic
- /data/data/####/.xml
- /data/data/####/06335408f89bcaa32fd9e57a4140070b.0.tmp
- /data/data/####/06335408f89bcaa32fd9e57a4140070b.1.tmp
- /data/data/####/065ce66492a100a98b096a9bcfd4c620.0.tmp
- /data/data/####/065ce66492a100a98b096a9bcfd4c620.1.tmp
- /data/data/####/0fcaef862b73ec4a7ddf5b2eec159183.0.tmp
- /data/data/####/0fcaef862b73ec4a7ddf5b2eec159183.1.tmp
- /data/data/####/100credit_contents_zw.xml
- /data/data/####/100credit_contents_zw.xml (deleted)
- /data/data/####/13b58bc7709bc840cbf9b81683ce06af.0.tmp
- /data/data/####/13b58bc7709bc840cbf9b81683ce06af.1.tmp
- /data/data/####/19ebc975d1dc0e58bec3500b9819eddc.0.tmp
- /data/data/####/19ebc975d1dc0e58bec3500b9819eddc.1.tmp
- /data/data/####/1a06269c52b77566a1dcef60e6d8d3f7.0.tmp
- /data/data/####/1a06269c52b77566a1dcef60e6d8d3f7.1.tmp
- /data/data/####/33d7061116cc8b61fcd29d55b22e40dc.0.tmp
- /data/data/####/33d7061116cc8b61fcd29d55b22e40dc.1.tmp
- /data/data/####/3d6b93b595607239124751a0c75dc714.0.tmp
- /data/data/####/3d6b93b595607239124751a0c75dc714.1.tmp
- /data/data/####/5b327e07256729b5eacedc651aaa22d8.0.tmp
- /data/data/####/5b327e07256729b5eacedc651aaa22d8.1.tmp
- /data/data/####/5f75a188d3eea068b09f916c9c4d6c47.0.tmp
- /data/data/####/5f75a188d3eea068b09f916c9c4d6c47.1.tmp
- /data/data/####/6b7dad37bf9eb6af8248e4728a53413e.0.tmp
- /data/data/####/6b7dad37bf9eb6af8248e4728a53413e.1.tmp
- /data/data/####/7871bf7cb45905ef8cc9eb0a6b95cd07.0.tmp
- /data/data/####/7871bf7cb45905ef8cc9eb0a6b95cd07.1.tmp
- /data/data/####/8976f793d353172e94949cd7aa364def.0.tmp
- /data/data/####/8976f793d353172e94949cd7aa364def.1.tmp
- /data/data/####/8c55ecaefc08cecd3798830900784d45.0.tmp
- /data/data/####/8c55ecaefc08cecd3798830900784d45.1.tmp
- /data/data/####/8d4da83904c5c329f5153b48d12e99df.0.tmp
- /data/data/####/8d4da83904c5c329f5153b48d12e99df.1.tmp
- /data/data/####/958a1baebff1086319fcf43ab3de0030.0.tmp
- /data/data/####/958a1baebff1086319fcf43ab3de0030.1.tmp
- /data/data/####/9a387154d7a079a431aee91dac556fb4.0.tmp
- /data/data/####/9a387154d7a079a431aee91dac556fb4.1.tmp
- /data/data/####/9be66a12744106c953b24edee6e3ff4c.0.tmp
- /data/data/####/9be66a12744106c953b24edee6e3ff4c.1.tmp
- /data/data/####/MultiDex.lock
- /data/data/####/a3c5592f57220bc91331a9281a0a03e8.0.tmp
- /data/data/####/a3c5592f57220bc91331a9281a0a03e8.1.tmp
- /data/data/####/ab63b1900b0e79646871bb1591a8d3c7.0.tmp
- /data/data/####/ab63b1900b0e79646871bb1591a8d3c7.1.tmp
- /data/data/####/ac08cb7c91eb72c6c6dc193b5af86741.0.tmp
- /data/data/####/ac08cb7c91eb72c6c6dc193b5af86741.1.tmp
- /data/data/####/add5fe64d0d1728b390193a8e346ccd6.0.tmp
- /data/data/####/add5fe64d0d1728b390193a8e346ccd6.1.tmp
- /data/data/####/c8a96573f0d0011042984e6e15bf2a70.0.tmp
- /data/data/####/c8a96573f0d0011042984e6e15bf2a70.1.tmp
- /data/data/####/com.kwkx.songjindai;pushservice.growing.db-journal
- /data/data/####/deb828542742c3e01ab8c0c42dd85e02.0.tmp
- /data/data/####/deb828542742c3e01ab8c0c42dd85e02.1.tmp
- /data/data/####/device_id.xml.xml
- /data/data/####/e116bc602cd9196e1da15d5fd6975b79.0.tmp
- /data/data/####/e116bc602cd9196e1da15d5fd6975b79.1.tmp
- /data/data/####/e699c76a0d84f39add6724d23419582c.0.tmp
- /data/data/####/e699c76a0d84f39add6724d23419582c.1.tmp
- /data/data/####/ebbab59bd0f673fc0559bb3a1cbb971f.0.tmp
- /data/data/####/ebbab59bd0f673fc0559bb3a1cbb971f.1.tmp
- /data/data/####/fdda1d88b282d930645538378c782c73.0.tmp
- /data/data/####/fdda1d88b282d930645538378c782c73.1.tmp
- /data/data/####/fm_shared.xml
- /data/data/####/getui_sp.xml
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid.xml
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/ikwkx.db-journal
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu1036419398.so
- /data/data/####/multidex.version.xml
- /data/data/####/push.pid
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/sp_cache.xml
- /data/data/####/td_fm.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/media/####/.dev_id.txt
- /data/media/####/.nomedia
- /data/media/####/.uuid_bairong
- /data/media/####/1547283082005
- /data/media/####/1547283082139
- /data/media/####/1547283088538
- /data/media/####/1547283097532
- /data/media/####/1547283103818
- /data/media/####/1547283106111
- /data/media/####/1547283115083
- /data/media/####/1547283115256
- /data/media/####/1547283122936
- /data/media/####/1547283126473
- /data/media/####/1547283136156
- /data/media/####/1547283137296
- /data/media/####/1547283145773
- /data/media/####/1547283147983
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.kwkx.songjindai.bin
- /data/media/####/com.kwkx.songjindai.db
- /data/media/####/exception_log.txt
- /system/bin/cat /proc/cpuinfo
- cat /sys/class/net/wlan0/address
- getprop net.dns1
- ls -l /system/xbin/su
- basesec_client
- basesec_client_jni
- getuiext2
- libjiagu1036419398
- pl_droidsonroids_gif
- tongdun
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding