Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) reso####.msg.xi####.net:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) p####.tc.qq.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) c.g####.qq.com:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(HTTP/1.1) d.g####.qq.com:80
- TCP(HTTP/1.1) oth.up####.mdt.####.com:8080
- TCP(HTTP/1.1) s####.tc.qq.com:80
- TCP(TLS/1.0) h####.b####.com:443
- TCP(TLS/1.0) www.opendre####.cn:443
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP 47.74.1####.158:5222
- TCP 4####.62.94.2:443
- 7x####.c####.z0.####.com
- a####.exc.mob.com
- c.g####.qq.com
- d.g####.qq.com
- h####.b####.com
- imgc####.qq.com
- mi.g####.qq.com
- oth.up####.mdt.####.com
- p####.ugd####.com
- qzones####.g####.cn
- regi####.xm####.xi####.com
- reso####.msg.xi####.net
- s####.e.qq.com
- www.opendre####.cn
- c.g####.qq.com/gdt_mclick.fcg?viewid=####&jtype=####&i=####&os=####&asi=...
- d.g####.qq.com/fcg-bin/gdt_appdetail.fcg?ico=####&op_appid=####
- mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
- p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
- p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
- reso####.msg.xi####.net/gslb/?ver=####&type=####&conpt=####&uuid=####&li...
- s####.tc.qq.com/gdt/0/transformer_1741552844700747622_1532628756_80.jpg/...
- t####.c####.q####.####.com/day7.jpg
- a####.exc.mob.com/errconf
- oth.up####.mdt.####.com:8080/beacon/vercheck
- s####.e.qq.com/activate
- s####.e.qq.com/click
- s####.e.qq.com/msg
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
- /data/data/####/6112c8c448e9f55c8cc6aa763f2ef0b1436b6718ba655c3....0.tmp
- /data/data/####/876eb81b37851c55653d3914013f8e41.temp
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/XMPushServiceConfig.xml
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_last_session.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1532992456959
- /data/data/####/account_config.xml
- /data/data/####/baidu_mtj_sdk_record.xml
- /data/data/####/beacontsa_cover.xml
- /data/data/####/beacontsa_cover_check.lock
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.onlybeyond.QRcode;pushservice
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/error.txt
- /data/data/####/f_000001
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_suid
- /data/data/####/index
- /data/data/####/journal.tmp
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/mipush.xml
- /data/data/####/mipush_account.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/qrCode.db-journal
- /data/data/####/recordIndexFile.txt
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/umeng_general_config.xml
- /data/data/####/update_lc
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.dic_lock
- /data/media/####/.nomedia
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.rcTag
- /data/media/####/.rc_lock
- /data/media/####/.timestamp
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop ro.build.display.id
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- sh
- crash_analysis
- libjiagu
- neh
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding