Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) p.s.3####.cn:80
- TCP(HTTP/1.1) sh####.360t####.com.####.com:80
- TCP(HTTP/1.1) sdk.s.360.####.com:80
- TCP(HTTP/1.1) s####.l####.360.####.com:80
- TCP(HTTP/1.1) up####.sdk.jig####.cn:80
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(HTTP/1.1) app.v.k.####.com:80
- TCP(HTTP/1.1) sdk.l####.360.cn:80
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) mdm.ope####.360.cn:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) cc.p####.dc.####.cn:443
- TCP(TLS/1.0) 1####.177.14.95:443
- TCP(TLS/1.0) sdkc####.e.360.cn:443
- TCP(TLS/1.0) 1####.250.179.174:443
- TCP(TLS/1.0) s####.j####.cn:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) 1####.194.73.95:443
- TCP(TLS/1.0) sdk.l####.360.cn:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 1####.177.14.95:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP sdk.o####.t####.####.com:5224
- TCP 2####.167.166.38:443
- UDP s.j####.cn:19000
- TCP 1####.163.235.100:80
- TCP 43.2####.88.95:7003
- android####.go####.com
- api####.me####.com
- app.k.36####.####.8
- app.k.36####.com
- app.v.k.####.com
- cc.p####.dc.####.cn
- cm-1####.g####.com
- instant####.google####.com
- k####.36####.com
- k####.36####.com
- k####.36####.com.####.8
- k####.36####.com.####.8
- m####.go####.com
- md####.google####.com
- mdm.ope####.360.cn
- p####.google####.com
- p.s.3####.cn
- s####.j####.cn
- s####.l####.360.cn
- s####.s.360.cn
- s.j####.cn
- sdk.c####.g####.com
- sdk.l####.360.cn
- sdk.l####.360.cn
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sdkc####.e.360.cn
- sh####.360t####.com
- up####.sdk.jig####.cn
- app.v.k.####.com/crossdomain.xml?time=####&sign=####
- d####.c####.l####.####.com/config/hzv9.conf
- s####.l####.360.####.com/Object.getFile/livecloudsdk/YW5kcm9pZF9wbHVnaW5...
- s####.l####.360.####.com/Object.getFile/livecloudsdk/cGx1Z2luX2xvY2Fsc2V...
- s####.l####.360.####.com/Object.getFile/livecloudsdk/cGx1Z2luX3BsYXllcl8...
- s####.l####.360.####.com/Object.getFile/livecloudsdk/cGx1Z2luX3Rvb2xzXzI...
- sdk.l####.360.cn/codec?sdkver=####&bid=####&pid=####&mid=####&ver=####&m...
- sdk.l####.360.cn/rtc?model=####
- sdk.l####.360.cn/sdkconf/videoplace?sign=####&u=####&version=####&sdk_ve...
- sdk.l####.360.cn/xinxiliu_tv_android_10169.conf
- sdk.s.360.####.com/ak/42998cf32d552343bc8e460416382dca.html?m2=####
- sdk.s.360.####.com/ak/6766aa2750c19aad2fa1b32f36ed4aee.html?m2=####
- sh####.360t####.com.####.com/171122/c867c6e2f627a813302a3a0d0d891203/FZL...
- p.s.3####.cn/update/update.php?p=####
- up####.sdk.jig####.cn/v1/push/sdk/postlist
- /data/data/####/.jg.ic
- /data/data/####/2033145970-602345128
- /data/data/####/Alliance.xml
- /data/data/####/JPushSA_Config.xml
- /data/data/####/JPushSA_Config.xml.bak
- /data/data/####/QHA_JSON_PERSISTER_42998cf32d552343bc8e460416382dca
- /data/data/####/QH_DeviceSDK.xml
- /data/data/####/QH_DeviceSDK.xml (deleted)
- /data/data/####/QH_SDK_M2.xml
- /data/data/####/QH_SDK_UserData42998cf32d552343bc8e460416382dca.xml
- /data/data/####/QH_SDK_UserData42998cf32d552343bc8e460416382dca.xml.bak
- /data/data/####/QH_SDK_UserData6766aa2750c19aad2fa1b32f36ed4aee.xml
- /data/data/####/QH_SDK_UserData6766aa2750c19aad2fa1b32f36ed4aee.xml.bak
- /data/data/####/QH_SDK_sessionID42998cf32d552343bc8e460416382dca.xml
- /data/data/####/Web Data
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/Y29tLmxpZ2h0c2t5LnZpZGVv.tick.lock
- /data/data/####/ad_config_file.xml
- /data/data/####/ad_config_file.xml.bak
- /data/data/####/appPackageNames
- /data/data/####/app_globel_config_file.xml
- /data/data/####/app_globel_config_file.xml.bak
- /data/data/####/auth_guide_config_sdk.xml
- /data/data/####/auth_guide_config_sdk.xml.bak
- /data/data/####/cacerts.crt
- /data/data/####/cache.ttf
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/cloud_switch_cache
- /data/data/####/cloud_switch_cache (deleted)
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/com.lightsky.video_preferences.xml
- /data/data/####/critical_service_config.xml
- /data/data/####/dbfocus-journal
- /data/data/####/download-journal
- /data/data/####/dso_deps
- /data/data/####/dso_lock
- /data/data/####/dso_manifest
- /data/data/####/dso_state
- /data/data/####/finalcore.dex
- /data/data/####/finalcore.dex.flock (deleted)
- /data/data/####/finalcore.jar
- /data/data/####/getui_sp.xml
- /data/data/####/hotrizon_sharepref.xml
- /data/data/####/hotrizon_sharepref.xml.bak
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/jg_so_upgrade_setting.xml.bak
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_local_notification.db-wal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/jpush_statistics.db-shm (deleted)
- /data/data/####/jpush_statistics.db-wal
- /data/data/####/jpush_statistics.db-wal (deleted)
- /data/data/####/libdvrender.so.tmp
- /data/data/####/libjiagu.so
- /data/data/####/libjplayer.so.tmp
- /data/data/####/liblocalserver.so.tmp
- /data/data/####/libmyssl.so.1.1.tmp
- /data/data/####/libtranscore.so.tmp
- /data/data/####/libviewer.so.tmp
- /data/data/####/light_sky_avast.xml
- /data/data/####/localserver.zip
- /data/data/####/locker
- /data/data/####/metrics_guid
- /data/data/####/p.l
- /data/data/####/player.zip
- /data/data/####/proc_auxv
- /data/data/####/push.db-journal
- /data/data/####/push.pid
- /data/data/####/push_share.xml
- /data/data/####/push_share.xml.bak
- /data/data/####/pushsdk.db-journal
- /data/data/####/qhvc_plugin.xml
- /data/data/####/qhvc_plugin.xml.bak
- /data/data/####/run.pid
- /data/data/####/share_data.xml
- /data/data/####/share_data.xml (deleted)
- /data/data/####/single_process_core_update
- /data/data/####/single_process_core_update_locker
- /data/data/####/single_process_device_collector
- /data/data/####/single_process_device_collector_locker
- /data/data/####/single_process_profile_task
- /data/data/####/single_process_profile_task_locker
- /data/data/####/single_process_uninstall_apk
- /data/data/####/single_process_uninstall_apk_locker
- /data/data/####/sp.livecloud.database.xml
- /data/data/####/sp_file_recommend_upload.xml
- /data/data/####/the-real-index
- /data/data/####/tools.zip
- /data/data/####/torch_sdk_config.xml
- /data/data/####/torch_sdk_config.xml.bak
- /data/data/####/videolist.db-journal
- /data/data/####/webview_data.lock
- /data/media/####/.deviceId
- /data/media/####/.iddata
- /data/media/####/.nomedia
- /data/media/####/.push_deviceid
- /data/media/####/.sfp
- /data/media/####/.testf (deleted)
- /data/media/####/1614917860699
- /data/media/####/1614917860999
- /data/media/####/42998cf32d552343bc8e460416382dca
- /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee
- /data/media/####/6766aa2750c19aad2fa1b32f36ed4aee (deleted)
- /data/media/####/GZy
- /data/media/####/GZy (deleted)
- /data/media/####/Ode
- /data/media/####/Ode (deleted)
- /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv
- /data/media/####/Y29tLmxpZ2h0c2t5LnZpZGVv (deleted)
- /data/media/####/__VERSION__
- /data/media/####/avast_done
- /data/media/####/b05ce39c1fe9e72dc1df70989e7e6d14
- /data/media/####/com.lightsky.video.bin
- /data/media/####/data.lock
- /data/media/####/px0
- /data/media/####/px0 (deleted)
- /data/media/####/report.lock
- /data/media/####/tlL (deleted)
- /data/media/####/uninstall_apk_list
- /data/media/####/uninstall_apk_list (deleted)
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes2.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/torch/core/finalcore.jar --oat-fd=75 --oat-location=/data/user/0/<Package>/files/torch/opt/finalcore.dex --compiler-filter=speed
- cat /sys/class/net/wlan0/address
- chmod 755 /data/user/0/<Package>/.jiagu/libjiagu.so
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- DES
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- RSA-None-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding