Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) a####.b####.qq.com:8011
- TCP(HTTP/1.1) sdk.o####.amp.####.com:80
- TCP(HTTP/1.1) a####.b####.qq.com:8012
- TCP(HTTP/1.1) b####.g####.com:80
- TCP(HTTP/1.1) a####.u####.com.####.com:80
- TCP(TLS/1.0) p####.5####.com.####.com:443
- TCP(TLS/1.0) api.j####.com.####.com:443
- TCP(TLS/1.0) report####.58.com:443
- TCP(TLS/1.0) 2####.58.208.110:443
- TCP(TLS/1.0) 1####.250.179.138:443
- TCP(TLS/1.0) richma####.j####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) 2####.58.214.10:443
- TCP(TLS/1.2) 1####.250.179.170:443
- TCP(TLS/1.2) 2####.58.214.10:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 1####.217.168.195:443
- TCP(TLS/1.2) 1####.250.179.138:443
- TCP sdk.o####.t####.####.com:5224
- TCP richma####.j####.com:443
- TCP cm-1####.g####.com:5226
- 4####.58.com
- a####.b####.qq.com
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- android####.go####.com
- api.j####.com
- api.map.b####.com
- b####.g####.com
- c####.g####.com
- cdn-sdk####.g####.com
- cm-1####.g####.com
- instant####.google####.com
- j1.5####.com.cn
- j2.5####.com.cn
- l####.58.com
- m.j####.com
- p####.5####.com.cn
- p####.5####.com.cn
- p####.5####.com.cn
- p####.5####.com.cn
- report####.58.com
- richma####.j####.com
- sdk.c####.g####.com
- sdk.o####.amp.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- vi####.j####.com
- api.j####.com.####.com:443/api/config/hotfix/1/5.9.4/2/?osver=####
- api.j####.com.####.com:443/vip/check?imei=####&userid=####
- api.j####.com.####.com:443/vip/imeicheck?imei=####&userid=####
- report####.58.com:443/baoxian/date/
- richma####.j####.com:443/api/ad/home/v2?packagename=####&osv=####&lon=##...
- sdk.o####.amp.####.com/api.htm?format=####&t=####
- a####.b####.qq.com:8011/rqd/async?aid=####
- a####.b####.qq.com:8012/rqd/async?aid=####
- a####.u####.com.####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- api.j####.com.####.com:443/vip/course/synch
- api.map.b####.com:443/sdkcs/verify
- b####.g####.com/api.php?format=####&t=####
- c####.g####.com/api.php?format=####&t=####
- report####.58.com:443/get_deviceid
- report####.58.com:443/v1/blood
- report####.58.com:443/v1/coke
- /data/data/####/-1077100814302649197
- /data/data/####/-1226205669302649197
- /data/data/####/-1878967553-1471121531
- /data/data/####/-2068142297-1746000248
- /data/data/####/-850196583302649197
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.old_file_converted
- /data/data/####/08404a2cec74e717_0
- /data/data/####/1004
- /data/data/####/1419075204-613584029
- /data/data/####/1480899311302649197
- /data/data/####/1710667238-36872461
- /data/data/####/1912683478302649197
- /data/data/####/1a3856b36aff00cc_0
- /data/data/####/1c029427cc7c4b6d_0
- /data/data/####/2cfc15b8e424e42a_0
- /data/data/####/323d89b3890955ae_0
- /data/data/####/33cbe6ad8722f165_0
- /data/data/####/3404bc48cf0f96b3_0
- /data/data/####/36cd3ef6e65cd7c9_0
- /data/data/####/413484de746f639b_0
- /data/data/####/4ab6cfa7f4ddeee0_0
- /data/data/####/4ca497c96bb46403_0
- /data/data/####/598697777302649197
- /data/data/####/7565533591d7a32d_0
- /data/data/####/77178a0d22f243ad_0
- /data/data/####/7dcde0d4077d7811_0
- /data/data/####/91c2277b5a835850_0
- /data/data/####/9506373c80a6183d_0
- /data/data/####/9d9f322db03fd266_0
- /data/data/####/9d9f322db03fd266_1
- /data/data/####/9ec7f35ecab392cf_0
- /data/data/####/Cookies-journal
- /data/data/####/WMDALITE.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/aba18fdc934cc758_0
- /data/data/####/aba18fdc934cc758_1
- /data/data/####/authStatus_com.jxedt.xml
- /data/data/####/authStatus_com.jxedt;remote.xml
- /data/data/####/b03845ff1288b964_0
- /data/data/####/bugly_db_-journal
- /data/data/####/c9d69a53dc251337_0
- /data/data/####/cbfca1279a940966_0
- /data/data/####/cbfca1279a940966_1
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/classes3.dex
- /data/data/####/com.jxedt_preferences.xml
- /data/data/####/crashrecord.xml
- /data/data/####/d562d44e6a1b5060_0
- /data/data/####/db_info.xml
- /data/data/####/dd49f94f2b07e75a_0
- /data/data/####/disk_entries_list_image_cache_532672399.xml
- /data/data/####/e0d37f85b6fb01fd_0
- /data/data/####/eb045a5332ef4153_0
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f29fbc78b77aab95_0
- /data/data/####/f3c70733b14efe7f_0
- /data/data/####/fd3c614a5d89250f_0
- /data/data/####/filedownloader.db-journal
- /data/data/####/gal.db
- /data/data/####/gal.db-journal
- /data/data/####/getui_sp.xml
- /data/data/####/gtc.db-journal
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/index
- /data/data/####/init_c1.pid
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/jxedt_user_11.db
- /data/data/####/jxedt_user_11.db (deleted)
- /data/data/####/jxedt_user_11.db-journal
- /data/data/####/lego_shared_name.xml
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/local_crash_lock
- /data/data/####/log.db-journal (deleted)
- /data/data/####/mac.xml
- /data/data/####/marking.txt
- /data/data/####/marking.zip
- /data/data/####/metrics_guid
- /data/data/####/openclient.txt
- /data/data/####/openclient.zip
- /data/data/####/proc_auxv
- /data/data/####/pushsdk.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/security_info
- /data/data/####/the-real-index
- /data/data/####/tmpd8.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/universal_info.db-journal (deleted)
- /data/data/####/user_info.xml
- /data/data/####/user_info.xml.bak
- /data/data/####/wmdalite
- /data/data/####/wmdalite-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/com.jxedt_.db
- /data/media/####/com.tencent.mobileqq_connectSdk.22.02.09.13.log
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/misc/####/primary.prof
- /system/bin/sh -c type su
- chmod 755 /data/user/0/<Package>/.jiagu/libjiagu.so
- getprop
- logcat -d -v threadtime
- AES
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding