Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) api.icaipia####.com:80
- TCP(TLS/1.0) api.icaipia####.com:443
- TCP(TLS/1.0) res####.a####.com:443
- a####.u####.com
- a.appj####.com
- amap####.cn-hang####.oss####.####.com
- api.icaipia####.com
- p.wangca####.com
- p.zhangko####.cn
- res####.a####.com
- s0.icaipia####.com
- so####.icaipia####.com
- api.icaipia####.com/api/v1/c/p?p=####
- api.icaipia####.com/api/v2/rank/landing?lottery_key=####
- api.icaipia####.com/api/v5/server/timestamp
- api.icaipia####.com/api/v6/lotterynums/latest/all
- api.icaipia####.com/api/v7/social/hitlist?count=####&max_id=####
- api.icaipia####.com/api/v7/social/hotlist?count=####&page=####
- api.icaipia####.com/api/v7/social/newlist?count=####&max_id=####
- api.icaipia####.com/api/v7/social/topandnoticelist
- api.icaipia####.com/static/icon/avatar.jpg?imageVi####
- sh.wagbr####.aliyun####.com/sdkcoor/android/x86/libJni_wgs2gcj.so
- t####.c####.q####.####.com/20181203/CD62A3D4E2A139F96092AE0455548DF6.jpg...
- t####.c####.q####.####.com/20181213/719D647F095A82F82D73EFDCF755B7BD.jpg...
- t####.c####.q####.####.com/20190111/74979fdade1a3c4c5b0daf099e817f70.jpe...
- t####.c####.q####.####.com/20190112/738fdc077c447205ea197a065dd9d7ae.jpg...
- t####.c####.q####.####.com/20190113/2a106bfc906eb8b0bbcfe0cd091e644f.jpe...
- t####.c####.q####.####.com/avatar/171212/d4af8a0415f38004df920f27277227e...
- t####.c####.q####.####.com/avatar/180513/2773d2bafc6b2560a4178b7b59f5186...
- t####.c####.q####.####.com/avatar/180911/86208cea5de704b6bab50911709ba9b...
- t####.c####.q####.####.com/avatar/181112/edbf45b66555c5e8b3efefe5c997988...
- t####.c####.q####.####.com/avatar/181220/f46cc5d3d33d6d6501a0da7d38c50fa...
- t####.c####.q####.####.com/avatar/181229/d0580903adbcdd80505f970f162b56f...
- t####.c####.q####.####.com/avatar/190112/e41b29f8e67c74b792fe1871e950365...
- a####.u####.com/app_logs
- a.appj####.com/ad-service/ad/mark
- api.icaipia####.com/api/v5/server/activate
- api.icaipia####.com/api/v5/server/config
- /data/data/####/-10741751651846406854
- /data/data/####/-1114569695936591400
- /data/data/####/-11788933491545824674
- /data/data/####/-1446001841-1381790411
- /data/data/####/-1493252944-1869695066
- /data/data/####/-157045110-1743029638
- /data/data/####/-158973068707598428
- /data/data/####/-17893987121944668222
- /data/data/####/-2728054731602105740
- /data/data/####/-355694590-1074117528
- /data/data/####/-645535823626820934
- /data/data/####/-680318743652665607
- /data/data/####/-762244661-218193634
- /data/data/####/-8338230672108209449
- /data/data/####/-941616519-977889342
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/13052df36bd622b623500213fe0905bb519962a66a9732a....0.tmp
- /data/data/####/1381688239849376004
- /data/data/####/1393356888-234303881
- /data/data/####/1410228562228996501
- /data/data/####/1c6c882dc67eb19f7cfaffa64e43ce0652eda0c7785518a....0.tmp
- /data/data/####/1d13a2dfa91ec7614416af802b10dfa51419d723ad04d73....0.tmp
- /data/data/####/21090119561046727059
- /data/data/####/253193064-1619705854
- /data/data/####/253193064-2039568853
- /data/data/####/363214831-101004511
- /data/data/####/36321483127994478
- /data/data/####/367472543467560806
- /data/data/####/3750184290565.0
- /data/data/####/6250182850545.0
- /data/data/####/681183270-119718588
- /data/data/####/815e472c4c27e134596e941391a0e2b23792e3b4c1029cb....0.tmp
- /data/data/####/953799101-1361430384
- /data/data/####/9cd009e2478ab3d7ee388f43f22270320fb04b8ae07c39e....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/__cfg_lk_1312
- /data/data/####/a75cce37438e7039446014f8ea9a4add39effecaa9a134b....0.tmp
- /data/data/####/b7fe75cb4bafb843baaf814bfca1fc435d90d76223f134d....0.tmp
- /data/data/####/ba66c9efd8d5b6d31f0a82f25c621c424a56e38fb5e0b4d....0.tmp
- /data/data/####/c1538d493e3754f353907b220d24eeccc1023bb8b98eab7....0.tmp
- /data/data/####/cache.xml
- /data/data/####/cache_int.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.mango.kaijiangdaquan_preferences.xml
- /data/data/####/d0111634da3f6bab6fcf85980804cf6d5fc82f29d564e2f....0.tmp
- /data/data/####/e58fb610429db05203f7618b8e72dec4776a49b2efa74ee....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f9477ea54704047d150f5bc93055d0aec96b6d4b58c2c8a....0.tmp
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/journal
- /data/data/####/journal.tmp
- /data/data/####/libjiagu.so
- /data/data/####/loctemp.so
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/multidex.version.xml
- /data/data/####/pref.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/media/####/1ugitk6q9v1r6fpw5pgrlagv
- /data/media/####/2htxx2uxydy3f37wdxirb65f0
- /data/media/####/2k21vfy2cvwj5p3cgh90dewr1
- /data/media/####/5vgspxpwsz6c1i7yf31m7kfrl
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/als.db
- /data/media/####/als.db-journal
- /data/media/####/kyhzd4i0r0lz38wookmp7mgi
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- libjiagu
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES