Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) m.yangla####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) l####.tbs.qq.com:443
- TCP(TLS/1.0) 1####.217.17.142:443
- TCP(TLS/1.0) as####.growi####.com.####.net:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP(TLS/1.0) m.yangla####.com:443
- TCP(TLS/1.0) oss.yangla####.com:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- 7j####.c####.z0.####.com
- and####.b####.qq.com
- api.growi####.com
- as####.growi####.com
- c####.g####.ig####.com
- c-h####.g####.com
- l####.tbs.qq.com
- log.u####.com
- m.yangla####.com
- oss.yangla####.com
- pub-####.qin####.com
- s####.u####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t####.growi####.com
- t.growi####.com
- m.yangla####.com/pages/user/login.html
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/config/hz-hzv6.conf
- t####.c####.q####.####.com/tdata_Jga153
- t####.c####.q####.####.com/tdata_WOW230
- t####.c####.q####.####.com/tdata_bca864
- t####.c####.q####.####.com/tdata_mSr887
- and####.b####.qq.com/rqd/async?aid=####
- c-h####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.jg.ic
- /data/data/####/0a99e1ab36c68947b0dc315c5510211f2448b52d14bebdc....0.tmp
- /data/data/####/0e872351f3c0bc6be3c4a1dc90ccdc28293ca2d47fc19eb....0.tmp
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/12336fcfbf056990adefc8b7d57c15159415ab396b894af....0.tmp
- /data/data/####/1315c75f61e572816d1d252179983c6d80dcb28acad42ee....0.tmp
- /data/data/####/1559501537637.log
- /data/data/####/1660cbe64a211a468cb67e75a77993c7f39505ac24eff21....0.tmp
- /data/data/####/1f50d99d41a823ae17c780b9044f8650300e4fe9f2ea3ed....0.tmp
- /data/data/####/212bb631f2080a4976875629fa5ecc7982727faf6168b2b....0.tmp
- /data/data/####/3e7dfaf9b9bc1bdcb936d82db77b1aee16c0ea1871c0fcd....0.tmp
- /data/data/####/48beb36dab02dc340caba3e5a7e987c407b05f73937a74f....0.tmp
- /data/data/####/4abb5ef6bf418be61bf0ee736b50f14805b1443a9d70e12....0.tmp
- /data/data/####/4ad7efc2c177de1b551944531bcee0b3a8184861c4a2e84....0.tmp
- /data/data/####/63c5045b75cbdf613117fb3b7dc709e2c5dbbd32a7de93a....0.tmp
- /data/data/####/6cc4563487e3
- /data/data/####/77417202184cb808511a330b51f7630ee0c6e979c5135ae....0.tmp
- /data/data/####/79bd4f06f0b3dfba44aa0c10ba3f6112a28db0d34838bd7....0.tmp
- /data/data/####/8df95425ed74ded3e19f35159b969d8726f6033444b54d8....0.tmp
- /data/data/####/93ca12f2324a5b19309fb4210262809443927205d4f9e1d....0.tmp
- /data/data/####/96399af51bdd5dfc8d5e1af7a69f032f11f2d3ba6534ffc....0.tmp
- /data/data/####/BUGLY_COMMON_VALUES.xml
- /data/data/####/COMMON_APP_CACHE.xml
- /data/data/####/IBALIFE.xml
- /data/data/####/MultiDex.lock
- /data/data/####/Upgrade_activity_count.xml
- /data/data/####/a847c945a6e5c24964800bbcf17858323cbde368cf4ccdd....0.tmp
- /data/data/####/b4685e570e4689c5b114f127a2dcf20540a3fab848f3504....0.tmp
- /data/data/####/ba2d47f59aa9ef241f4d2361f17a7d97ec6d57f9afd7588....0.tmp
- /data/data/####/bf809c20c105b95c6cb560c6f613564ca1ddbbeec6e072e....0.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/c1bb55bee2f885a7666f6b02eaa74473b1948077606468b....0.tmp
- /data/data/####/c5007243cabf08b40c1c675a666a715293141153db04228....0.tmp
- /data/data/####/c6fe0bdbebc115cbc872916fca5f2a583dc547c1b6b1402....0.tmp
- /data/data/####/ca2043edf43e2a366b9edaf3697d538d8b194b6ade4e61d....0.tmp
- /data/data/####/cc1de20bbe03e7977cb251b26b8fb27b7e7179ef301b53a....0.tmp
- /data/data/####/cf3f72193669aeca015d68a928bac786d518947eb0eb525....0.tmp
- /data/data/####/com.ibalife.ibaboss.BETA_VALUES.xml
- /data/data/####/com.ibalife.ibaboss;PushService.growing.db
- /data/data/####/com.ibalife.ibaboss;PushService.growing.db-journal
- /data/data/####/com.ibalife.ibaboss;X5WebView.growing.db
- /data/data/####/com.ibalife.ibaboss;X5WebView.growing.db-journal
- /data/data/####/com.ibalife.ibaboss;recover.growing.db-journal
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/d051441ff8c9a69d76334d3eda6287694e2c822a3a82ee8....0.tmp
- /data/data/####/d21594c81ce6a227585f811e4df726bbdf199689cea4a99....0.tmp
- /data/data/####/d2e8d92b7fde37cf16bac13c9b3b18110957369e44e48a4....0.tmp
- /data/data/####/d4c4593e6763613258e8728d71c171c16baa402754ad0dd....0.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/debug.conf
- /data/data/####/dec88d349232c2b45685683a77d658cd3a010c1476c6c8c....0.tmp
- /data/data/####/download_upload
- /data/data/####/f2d8cf570a387edfd94a2e4f7c47ba4e2e3a3b29b6b330e....0.tmp
- /data/data/####/f532ae9bde36d7b1e37824ef4dee53ec4a56d6de05c89c0....0.tmp
- /data/data/####/f801cd2bc7ccc47eccff6bbf4d5af11911f6c4ed6a5ec08....0.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/fbbdecdb88b569110678d60429658d3c0f81f640c286998....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/growingio.lock-journal
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu2020789794.so
- /data/data/####/local_crash_lock
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/newVersion201.xml
- /data/data/####/playAdvertise.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/recovery_silent_info.xml
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_Jga153
- /data/data/####/tdata_Jga153.jar
- /data/data/####/tdata_WOW230
- /data/data/####/tdata_WOW230.jar
- /data/data/####/tdata_bca864
- /data/data/####/tdata_bca864.jar
- /data/data/####/tdata_mSr887
- /data/data/####/tdata_mSr887.jar
- /data/data/####/umeng_socialize.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.nomedia
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.ibalife.ibaboss.bin
- /data/media/####/com.ibalife.ibaboss.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tbslog.txt
- /data/media/####/tdata_Jga153
- /data/media/####/tdata_WOW230
- /data/media/####/tdata_bca864
- /data/media/####/tdata_mSr887
- /data/media/####/test.log
- /system/bin/sh -c getprop
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.IBAPushService 24866 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- getprop
- getprop ro.product.cpu.abi
- logcat -d -v threadtime
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.IBAPushService 24866 300 0
- Bugly
- getuiext3
- libjiagu2020789794
- AES-CBC-NoPadding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding