Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(DNS) <Google DNS>
- TCP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) a####.hdg####.com:9090
- TCP(HTTP/1.1) a####.31####.com:9090
- TCP(HTTP/1.1) t####.1####.com:80
- TCP(HTTP/1.1) a####.ytxi####.com:9090
- TCP(HTTP/1.1) ln-te####.1####.com:80
- TCP(HTTP/1.1) t####.0####.com.####.net:80
- TCP(HTTP/1.1) a####.07####.com:9090
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) avpp1vx####.edges####.net:80
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) l####.tbs.qq.com:443
- TCP(TLS/1.0) 1####.194.73.95:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) 2####.85.233.95:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) ipg.716####.com:10443
- TCP(TLS/1.0) o4n2d2####.v1cchkl####.com:443
- TCP(TLS/1.0) 64.2####.163.138:443
- TCP(TLS/1.0) o4n2d2####.v1cchkl####.com:11443
- TCP(TLS/1.0) yu####.1####.com:11443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.2) 2####.85.233.95:443
- TCP(TLS/1.2) 64.2####.161.94:443
- TCP(TLS/1.2) 1####.194.73.95:443
- TCP(TLS/1.2) 64.2####.163.138:443
- TCP 1####.232.25.186:7002
- UDP sis.j####.io:19000
- UDP s.j####.cn:19000
- 4n2d2####.1####.com
- a####.07####.com
- a####.31####.com
- a####.hdg####.com
- a####.ytxi####.com
- and####.b####.qq.com
- android####.go####.com
- api.map.b####.com
- instant####.google####.com
- ipg.716####.com
- l####.tbs.qq.com
- l4n2d2####.1####.com
- ln-te####.1####.com
- md####.google####.com
- p####.google####.com
- s.j####.cn
- sis.j####.io
- t####.0####.com
- t####.1####.com
- yu####.1####.com
- yu####.1####.com
- yu####.891####.com
- avpp1vx####.edges####.net/m/app
- ln-te####.1####.com/tl01.html
- t####.0####.com.####.net/tl01.html
- t####.1####.com/tl01.html
- a####.07####.com:9090/?appName=####&os=####&version=####
- a####.31####.com:9090/?appName=####&os=####&version=####
- a####.hdg####.com:9090/?appName=####&os=####&version=####
- a####.ytxi####.com:9090/?appName=####&os=####&version=####
- and####.b####.qq.com/rqd/async?aid=####
- /data/data/####/.cl
- /data/data/####/.jg.ic
- /data/data/####/049ac051955dd93c_0
- /data/data/####/049ac051955dd93c_1
- /data/data/####/04ce205df174581e_0
- /data/data/####/052f69f491698a3a_0
- /data/data/####/09a2d529e0cecd4b_0
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/10e76d5dc2f85579_0
- /data/data/####/1c682a2f9b9779f7_0
- /data/data/####/1f5d7084512ba41f_0
- /data/data/####/23266efed04081c4_0
- /data/data/####/2651f25fd5ddac4f_0
- /data/data/####/2651f25fd5ddac4f_0 (deleted)
- /data/data/####/27404f3942a796e1_0
- /data/data/####/4593e34daca5aa36_0
- /data/data/####/46d2ebf541eee09d_0
- /data/data/####/46d2ebf541eee09d_1
- /data/data/####/4b3fb9c52ae9bfd7_0
- /data/data/####/4c9504c04e2828fb_0
- /data/data/####/4e730f2cf7ad4b93_0
- /data/data/####/4eed0f88d9606564_0
- /data/data/####/51e06022d12dfd7d_0
- /data/data/####/599d43000d51e311_0
- /data/data/####/5c53f36aef34aea9_0
- /data/data/####/617d11fc7f2fa6f4_0
- /data/data/####/61c6f7e4bd1743b7_0
- /data/data/####/61c6f7e4bd1743b7_0 (deleted)
- /data/data/####/64c47dd5f24b86b3_0
- /data/data/####/651d71f5e2c55bf9_0
- /data/data/####/69f0e5ff4a9b0316_0
- /data/data/####/78e21cb07d1fbb5d_0
- /data/data/####/7b5bf122d33e7578_0
- /data/data/####/7f813cb3-6550-4c75-9f2a-901b28908f2f
- /data/data/####/8394a663eeb0dd9c_0
- /data/data/####/8ed14ea3394ce14b_0
- /data/data/####/9325194d6df1c6af_0
- /data/data/####/965a8686a9c66ede_0
- /data/data/####/9663e25877cfce46_0
- /data/data/####/Cookies-journal
- /data/data/####/JPushSA_Config.xml
- /data/data/####/JPushSA_Config.xml.bak
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/ad_auth.xml
- /data/data/####/af27defe71879ab1_0
- /data/data/####/authStatus_com.enyu.huanbao.guanjia.xml
- /data/data/####/b1eb1942ba9c6d14_0
- /data/data/####/b56a3fe876be9aac_0
- /data/data/####/b58e28a97a732da1_0
- /data/data/####/ba69beded98c3b43_0
- /data/data/####/baeaaf1140264f06_0
- /data/data/####/bugly_db_-journal
- /data/data/####/c089c2ee56f41d81_0
- /data/data/####/c852df8140de3c67_0
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/cn.jpush.preferences.v2.xml.bak
- /data/data/####/com.enyu.huanbao.guanjia.BETA_VALUES.xml
- /data/data/####/com.enyu.huanbao.guanjia_preferences.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/d5012690b2cdace4_0
- /data/data/####/da414ffd53b5ea34_0
- /data/data/####/da414ffd53b5ea34_1
- /data/data/####/debug.conf
- /data/data/####/download_upload
- /data/data/####/e79eea5001595940_0
- /data/data/####/e876a23c1d8ed61f_0
- /data/data/####/ec4c532a34a511ad_0
- /data/data/####/eda57984-a4df-496b-99fa-4aca2b241db7
- /data/data/####/eefad47fd70ea6ab_0
- /data/data/####/f5c92ae6c34fdc45_0
- /data/data/####/f8a2ee3962250b2b_0
- /data/data/####/fa28eb234dd8f550_0
- /data/data/####/https_yuvqem.1201o.com_11443.localstorage-journal
- /data/data/####/index
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/mac.xml
- /data/data/####/metrics_guid
- /data/data/####/native_record_lock (deleted)
- /data/data/####/proc_auxv
- /data/data/####/security_info
- /data/data/####/sharePreName.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/the-real-index
- /data/media/####/tbslog.txt
- /data/misc/####/primary.prof
- getprop
- getprop ro.product.cpu.abi
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-ECB-NoPadding
- AES-GCM-NoPadding