Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) y0.ifen####.com:80
- TCP(HTTP/1.1) p0.ifen####.com:80
- TCP(HTTP/1.1) api.pus####.i####.com:80
- TCP(HTTP/1.1) p3.ifen####.com:80
- TCP(HTTP/1.1) s####.icl####.i####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) api.i####.i####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) m.i####.com:80
- TCP(HTTP/1.1) st####.i####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(TLS/1.0) st####.i####.com:443
- TCP(TLS/1.0) 2####.58.208.110:443
- TCP(TLS/1.0) y0.ifen####.com:443
- TCP(TLS/1.0) c0.ifen####.com.####.com:443
- TCP(TLS/1.0) p0.ifen####.com:443
- TCP(TLS/1.0) api.pus####.i####.com:443
- TCP(TLS/1.0) s####.icl####.i####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP 43.2####.145.6:5224
- TCP t####.nz4.ig####.com:5224
- 7j####.c####.z0.####.com
- api.i####.i####.com
- api.icl####.i####.com
- api.pus####.i####.com
- c-h####.g####.com
- c0.ifen####.com
- c1.m.i####.com
- c2.m.i####.com
- col####.ifengc####.i####.com
- com####.i####.com
- d.ifen####.com
- err.ifengc####.i####.com
- is####.i####.com
- m.i####.com
- p0.ifen####.com
- p1.ifen####.com
- p2.ifen####.com
- p3.ifen####.com
- re####.i####.com
- s####.icl####.i####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- shan####.i####.com
- st####.i####.com
- sta####.i####.com
- t####.nz4.g####.net
- t####.nz4.ge####.com
- t####.nz4.ig####.com
- y0.ifen####.com
- y2.ifen####.com
- api.i####.i####.com/ClientNews?id=####&gv=####&ad=####&av=####&proid=###...
- api.i####.i####.com/ClientNews?id=####&gv=####&os=####&vt=####&proid=###...
- api.i####.i####.com/news/upgrade.json?zip=####&firstOpenTime=####&openNu...
- api.i####.i####.com/totalProfile?&gv=####&av=####&uid=####&deviceid=####...
- api.i####.i####.com/weatherReport?city=####&callback=####&_=####
- api.i####.i####.com/weatherReport?gv=####&av=####&uid=####&deviceid=####...
- api.pus####.i####.com/get.php?orderby=####&docUrl=####&format=####&job=#...
- api.pus####.i####.com/newsh5sdk?ch=####&c_channel=####
- m.i####.com/newsh5sdk?ch=####
- m.i####.com/newsh5sdk?ch=####&c_channel=####
- p0.ifen####.com/a80c2beeeff78280/2017/50/news1121-bg6.png
- p0.ifen####.com/a80c2beeeff78280/2017/51/201707221503438679_iifeng.png
- p0.ifen####.com/ifengimcp/pic/20170309/65624297d9507791723f_size1_w18_h1...
- p0.ifen####.com/w138_h98_q75/e0.ifengimg.com/03/2019/0119/CCF6363A75B31E...
- p0.ifen####.com/w138_h98_q75/img1.ugc.ifeng.com/newugc/20190402/10/wemed...
- p0.ifen####.com/w138_h98_q75/p0.ifengimg.com/2019_11/551324427F8A0FBE8BC...
- p0.ifen####.com/w201_h144_q100/e0.ifengimg.com/05/2019/0530/248AF5E61F59...
- p0.ifen####.com/w201_h144_q100/e0.ifengimg.com/05/2019/0601/E327C23490B7...
- p0.ifen####.com/w201_h144_q100/e0.ifengimg.com/06/2019/0512/38CA10D05586...
- p0.ifen####.com/w201_h144_q100/e0.ifengimg.com/07/2019/0509/888AAECE911A...
- p0.ifen####.com/w201_h144_q100/p0.ifengimg.com/cmpp/2019/04/27/8bc7110c4...
- p0.ifen####.com/w201_h144_q100/p1.ifengimg.com/2019_22/2177230A0E86BF548...
- p0.ifen####.com/w201_h144_q100/p3.ifengimg.com/2019_22/44A7CD5D05D9216D5...
- p0.ifen####.com/w201_h144_q100/p3.ifengimg.com/2019_22/A186D6BE38C49493D...
- p0.ifen####.com/w201_h144_q100/p3.ifengimg.com/2019_22/E8C4E6F92D4C1DCD9...
- p0.ifen####.com/w201_h144_q100_aix0_aiy23_aiw600_aih396/e0.ifengimg.com/...
- p0.ifen####.com/w576_h324_q100/p2.ifengimg.com/2019_22/ABAF501D4790AA204...
- p0.ifen####.com/w576_h324_q100/p3.ifengimg.com/2019_22/2BFA00F47F883A82E...
- p0.ifen####.com/w576_h324_q100/p3.ifengimg.com/2019_22/36FE7DCFB7C91AFBC...
- p0.ifen####.com/w576_h324_q100/p3.ifengimg.com/2019_22/CDA8826CC2F4BC638...
- p0.ifen####.com/w698_h392_q100/img1.ugc.ifeng.com/newugc/20190601/13/wem...
- p0.ifen####.com/w698_h392_q100_aix0_aiy261_aiw4052_aih2268/e0.ifengimg.c...
- p3.ifen####.com/29b92e35b2b20708/2016/47/ifengnews_focus.png
- p3.ifen####.com/29b92e35b2b20708/2016/47/swiper.min.css
- p3.ifen####.com/29b92e35b2b20708/2016/47/swiper.min.js
- p3.ifen####.com/29b92e35b2b20708/2017/9/topd.png
- p3.ifen####.com/a/2016/0809/sta_collection_common_iifeng_v4.js
- p3.ifen####.com/a/2016/1128/jquery.lazyload.js
- p3.ifen####.com/a/2016/1128/underscore-min.js
- p3.ifen####.com/a/2017/0105/ifengnews1122_v3.3.css
- p3.ifen####.com/a/2017/0329/sta_collection_iifeng_pv_v8.js
- p3.ifen####.com/ifengimcp/pic/20161013/50d3e7dc4028ebf273bd_size7_w200_h...
- p3.ifen####.com/ifengimcp/pic/20170228/451d8f3c0cf1e03c9adc_size13_w750_...
- p3.ifen####.com/ifengimcp/pic/20170309/4ffe7c299fc06042d9ae_size2_w48_h4...
- p3.ifen####.com/ifengimcp/pic/20170310/8515f88aefcb75e86b48_size18_w750_...
- p3.ifen####.com/ifengimcp/pic/20170317/105c28f6ba8dc7bd3937_size2_w640_h...
- p3.ifen####.com/ifengimcp/pic/20180829/dbb2b26e3af9a85e6c57_size83_w540_...
- s####.icl####.i####.com/ClientNews?id=####&ad=####&gv=####&os=####&proid...
- s####.icl####.i####.com/ClientNews?id=####&os=####&ad=####&gv=####&proid...
- s####.icl####.i####.com/shareNews?ch=####&aid=####&proid=####&channelId=...
- s####.icl####.i####.com/weatherReport?city=####&callback=####&_=####
- st####.i####.com/appsta.js?datatype=####&mos=####&softversion=####&publi...
- st####.i####.com/wapsta?url=http://m.ifeng.com/newsh5sdk?ch=####&c_chann...
- st####.i####.com/wapsta?url=http://m.ifeng.com/newsh5sdk?ch=####&ref=###...
- t####.c####.q####.####.com/config/bj-bjv7.conf
- t####.c####.q####.####.com/config/hz-bjv8.conf
- t####.c####.q####.####.com/tdata_imh016
- y0.ifen####.com/base/jQuery/jquery-1.9.1.min.js
- y0.ifen####.com/ifengimcp/pic/20151102/b4dd6ce70aac8fd6cb79_size63_w170_...
- y0.ifen####.com/ifengimcp/pic/20151225/026d4fb6998b09e80c96_size52_w170_...
- api.pus####.i####.com/appsta.js
- c-h####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/FirstLogin.xml
- /data/data/####/com.ifext.news_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/f_000016
- /data/data/####/f_000017
- /data/data/####/f_000018
- /data/data/####/f_000019
- /data/data/####/f_00001a
- /data/data/####/f_00001b
- /data/data/####/f_00001c
- /data/data/####/f_00001d
- /data/data/####/f_00001e
- /data/data/####/f_00001f
- /data/data/####/f_000020
- /data/data/####/f_000021
- /data/data/####/f_000022
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu.so
- /data/data/####/lock_dm
- /data/data/####/lock_gt
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tdata_imh016
- /data/data/####/tdata_imh016.jar
- /data/data/####/tmpd8.db-journal
- /data/data/####/use_info.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/685b5b67c61461dc
- /data/media/####/app.db
- /data/media/####/c827352928163291
- /data/media/####/channel_info
- /data/media/####/channel_server_info
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.ifext.news.bin
- /data/media/####/com.ifext.news.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/tdata_imh016
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.ifeng.lite.getui.GetuiPushService 24400 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.ifeng.lite.getui.GetuiPushService 24400 300 0
- getuiext2
- libjiagu
- RSA-NONE-OAEPWithSHA1AndMGF1Padding