Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) api.icaipia####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) p####.tc.qq.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) api.icaipia####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) res####.a####.com:443
- a####.u####.com
- amap####.cn-hang####.oss####.####.com
- api.icaipia####.com
- imgc####.qq.com
- mi.g####.qq.com
- p.wangca####.com
- p.zhangko####.cn
- res####.a####.com
- s####.e.qq.com
- s0.icaipia####.com
- so####.icaipia####.com
- ssl.gst####.com
- www.go####.com
- www.gst####.com
- api.icaipia####.com/api/v1/c/p?p=####
- api.icaipia####.com/api/v2/rank/landing?lottery_key=####
- api.icaipia####.com/api/v5/server/timestamp
- api.icaipia####.com/api/v6/lotterynums/latest/all
- api.icaipia####.com/api/v7/social/hotlist?count=####&page=####
- api.icaipia####.com/api/v7/social/topandnoticelist
- api.icaipia####.com/static/icon/avatar.jpg?imageVi####
- mi.g####.qq.com/gdt_mview.fcg?datatype=####&posid=####&count=####&r=####...
- p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
- sh.wagbr####.aliyun####.com/sdkcoor/android/x86/libJni_wgs2gcj.so
- t####.c####.q####.####.com/avatar/190124/ad8e5f58e31d7ff85ff41ddbfc4204b...
- ti####.c####.l####.####.com/avatar/190225/99df19092bf77f247827ff11818c4c...
- ti####.c####.l####.####.com/avatar/190225/d423b68815854cd3a3ed6b345519b9...
- ti####.c####.l####.####.com/avatar/190225/e6eacb84df3399c550ad8f47ec4bed...
- ti####.c####.l####.####.com/avatar/190226/30dcf199973ddb194faace2e720ae4...
- a####.u####.com/app_logs
- api.icaipia####.com/api/v5/server/activate
- api.icaipia####.com/api/v5/server/config
- s####.e.qq.com/activate
- /data/data/####/-1067956839-346359608
- /data/data/####/-117889334996384371
- /data/data/####/-14932529442085446822
- /data/data/####/-149325294475075523
- /data/data/####/-157045110-1743029638
- /data/data/####/-1743051465758344189
- /data/data/####/-17893987121944668222
- /data/data/####/-2020606643-932857568
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/040e816d7adcdbfe3ca7e198cd71d7e69aacfe83a7f8eed....0.tmp
- /data/data/####/040e816d7adcdbfe3ca7e198cd71d7e69aacfe83a7f8eed...91f5.0
- /data/data/####/1271118148-138790719
- /data/data/####/1463226077-1722291537
- /data/data/####/1552736352544.0
- /data/data/####/1672293057-357459473
- /data/data/####/1785704582-119718588
- /data/data/####/1887414811080.0
- /data/data/####/21090119561046727059
- /data/data/####/24148dc6a833f8773130366a096b02f3e82c66646d8d400....0.tmp
- /data/data/####/253193064-1619705854
- /data/data/####/253193064-2039568853
- /data/data/####/367472543943249124
- /data/data/####/4687417197258.0
- /data/data/####/583066204-1457457844
- /data/data/####/6252727428303.0
- /data/data/####/68acffb91cb2c8c4755a415307cf2afc.0
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/__cfg_lk_1312
- /data/data/####/b7fe75cb4bafb843baaf814bfca1fc435d90d76223f134d....0.tmp
- /data/data/####/bf421905a40eb5f90b1297c5e62e47c9aac5ec3153b07b9....0.tmp
- /data/data/####/c6351d4de2d21ce39b1a6d41dcfb36f31c886fde7a7f330....0.tmp
- /data/data/####/cache.xml
- /data/data/####/cache_int.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.mango.kaijiangqixingcai_preferences.xml
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fcde9fbd86e1df9482954d2f8808de22d56cade3c01a5a8....0.tmp
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_suid
- /data/data/####/getui_sp.xml
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/init_c1.pid
- /data/data/####/journal
- /data/data/####/journal.tmp
- /data/data/####/libjiagu.so
- /data/data/####/loctemp.so
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/multidex.version.xml
- /data/data/####/pref.xml
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/update_lc
- /data/data/####/webview.db-journal
- /data/media/####/.nomedia
- /data/media/####/2k21vfy2cvwj5p3cgh90dewr1
- /data/media/####/6ps7ytm0q9suaubk4e5vxux7p
- /data/media/####/als.db
- /data/media/####/als.db-journal
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getuiext2
- libjiagu
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- DES
- RSA-ECB-PKCS1Padding