Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) ymaccel####.oss-cn-####.aliy####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) cgi.con####.qq.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(TLS/1.0) cdn.boo####.com.####.net:443
- TCP(TLS/1.0) api.w####.com:443
- TCP(TLS/1.0) qi####.com:443
- TCP(TLS/1.0) 1####.217.17.46:443
- TCP(TLS/1.0) r####.unip####.com:443
- TCP(TLS/1.0) da.qi####.com:443
- TCP(TLS/1.0) z.c####.com:443
- TCP(TLS/1.0) qy-swa####.qi####.com:443
- TCP(TLS/1.0) c.c####.com:443
- TCP c####.g####.ig####.com:5225
- TCP sdk.o####.t####.####.com:5224
- 7j####.c####.z0.####.com
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- api.w####.com
- c####.g####.ig####.com
- c-h####.g####.com
- c.c####.com
- cdn.boo####.com
- cgi.con####.qq.com
- da.qi####.com
- m.unip####.com
- pub-####.qin####.com
- qi####.com
- qy-swa####.qi####.com
- r####.unip####.com
- s22.c####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- ymaccel####.oss-cn-####.aliy####.com
- z1.c####.com
- cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?sdkv=####&appid=###...
- t####.c####.q####.####.com/config/hz-hzv3.conf
- t####.c####.q####.####.com/tdata_EDT356
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_vxj811
- ymaccel####.oss-cn-####.aliy####.com/Upload/152332957478835593.png?x-oss...
- ymaccel####.oss-cn-####.aliy####.com/Upload/152332961527431257.png?x-oss...
- ymaccel####.oss-cn-####.aliy####.com/Upload/152332979361923492.png?x-oss...
- ymaccel####.oss-cn-####.aliy####.com/Upload/152846244875730620.png?x-oss...
- ymaccel####.oss-cn-####.aliy####.com/Upload/152846274478240698.png?x-oss...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15344891208672690...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15395688766393157...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15395693350099896...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15401687277553628...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15401687578762554...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15401688146113295...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15401732639292977...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15404292608748982...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15404309666607838...
- ymaccel####.oss-cn-####.aliy####.com/Upload/ad/manager/15405174410644906...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/11437/15359696967794497...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/11576/15361107453904016...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/12286/15373509248542803...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/12317/15373570269665316...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/12946/15390734034429424...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/12998/15391354675531181...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/1300/150224188744439222...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/15391598979769333...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/15391598984967568...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/15391598989696447...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/15391598994875038...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/15391599000756350...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/Content/153915996...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13066/Content/153915997...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13448/15397482438102789...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13513/15399175008462236...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/13568/15398584576068180...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/5320/151799505733438375...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/6794/152489846962130226...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/6878/152548992441312702...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7177/152807730265165355...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7518/152913044323292392...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7708/153077693940436440...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7915/152956629936328574...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7931/152956825419468823...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/7935/152956863790064503...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8015/152963161932510356...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8016/153490419620011156...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8406/153032677278734451...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8416/153032853686270991...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8444/153035152495316434...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8445/153035182500010483...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8471/153050068490592801...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/153050174813310522...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/153050174821687853...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/153050174833112106...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/153050174834079477...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/153050174845315138...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501781...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501782...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501783...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501784...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501785...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501786...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501787...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501831...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501832...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8473/Content/1530501833...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8483/153051163381215388...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8485/153051198891797119...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8486/153051223293795602...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8500/153051841584411993...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/8578/153066849097111902...
- ymaccel####.oss-cn-####.aliy####.com/Upload/good/9247/153242154567314240...
- ymaccel####.oss-cn-####.aliy####.com/Upload/goodContentTemp/ContentTemp/...
- a####.u####.com/app_logs
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/-1031207439-1370472930
- /data/data/####/-1031207439-428098366
- /data/data/####/-1031207439-725255108
- /data/data/####/-1037137441-1354437764
- /data/data/####/-10371374411278574476
- /data/data/####/-1037137441555778633
- /data/data/####/-1037137441710522008
- /data/data/####/-1180040146-1148887651
- /data/data/####/-1180040146-1803239610
- /data/data/####/-1180040146-1891745021
- /data/data/####/-1180040146-1913015574
- /data/data/####/-11800401461365505964
- /data/data/####/-131843301-1854029610
- /data/data/####/-1510195332-1444804764
- /data/data/####/-15101953321764841428
- /data/data/####/-1528492239-1976498891
- /data/data/####/-15284922391076292496
- /data/data/####/-446599915-238670946
- /data/data/####/-4465999151774861231
- /data/data/####/-4489067541150212833
- /data/data/####/.imprint
- /data/data/####/10a0686d1d416b7e63d1dcb99ebdeb7d8269c9b9b2f8730....0.tmp
- /data/data/####/12431268741587225174
- /data/data/####/1625034afe0a20cec9e26136c714204e29c8a044bb01fe2....0.tmp
- /data/data/####/178e810eba2dfc283c06cbb3c746a0ebc07e5dd60161993....0.tmp
- /data/data/####/1ccd42293b3476631b9caea8f38ea75d3d73650d58e072c....0.tmp
- /data/data/####/283b5e9a630976f65813479c3ecaeea9c39e70d7f757a07....0.tmp
- /data/data/####/42aa13962ec36e3a6d401b15d4492dab9eb5dcd0b1327f8....0.tmp
- /data/data/####/50824915e26dd8a5c28cb7b564d9a95a804c404f97cc7c6....0.tmp
- /data/data/####/57543b41fa1f60f34b7d100b302b4277c402f4605e48c41....0.tmp
- /data/data/####/588421972e6b
- /data/data/####/6440206791584350601
- /data/data/####/644020679630052200
- /data/data/####/792a29b37be9389a5c7b4c53cfbabbea723f270b6bcb0f0....0.tmp
- /data/data/####/8f74dea3052abe44ac984299f1598b0f6c0f1782e4ba9b8....0.tmp
- /data/data/####/9d27a42a65fd8d96f3be4c7faa096fd9906ef2e51260f7d....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MultiDex.lock
- /data/data/####/bc8db9858b9e6862f53d922dc770d88ebcb00bc4689513f....0.tmp
- /data/data/####/bugly_db_legu-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.qiyukf.analytics.xml
- /data/data/####/com.tencent.open.config.json.1106343314
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_1 (deleted)
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/f_000016
- /data/data/####/f_000017
- /data/data/####/f_000018
- /data/data/####/f_000019
- /data/data/####/f_00001a
- /data/data/####/f_00001b
- /data/data/####/f_00001c
- /data/data/####/f_00001d
- /data/data/####/f_00001e
- /data/data/####/f_00001f
- /data/data/####/f_000020
- /data/data/####/f_000021
- /data/data/####/f_000022
- /data/data/####/f_000023
- /data/data/####/f_000024
- /data/data/####/f_000025
- /data/data/####/f_000026
- /data/data/####/f_000027
- /data/data/####/f_000028
- /data/data/####/f_000029
- /data/data/####/f_00002a
- /data/data/####/f_00002b
- /data/data/####/f_00002c
- /data/data/####/f_00002d
- /data/data/####/f_00002e
- /data/data/####/f_00002f
- /data/data/####/f_000030
- /data/data/####/f_000031
- /data/data/####/f_000032
- /data/data/####/f_000033
- /data/data/####/f_000034
- /data/data/####/f_000035
- /data/data/####/f_000036
- /data/data/####/f_000037
- /data/data/####/f_000038
- /data/data/####/f_000039
- /data/data/####/f_00003a
- /data/data/####/f_00003b
- /data/data/####/f_00003c
- /data/data/####/f_00003d
- /data/data/####/f_00003e
- /data/data/####/f_00003f
- /data/data/####/f_000040
- /data/data/####/f_000041
- /data/data/####/f_000042
- /data/data/####/f_000043
- /data/data/####/f_000044
- /data/data/####/f_000045
- /data/data/####/f_000046
- /data/data/####/f_000047
- /data/data/####/f_000048
- /data/data/####/f_000049
- /data/data/####/f_00004a
- /data/data/####/f_00004b
- /data/data/####/f_00004c
- /data/data/####/f_00004d
- /data/data/####/f_00004e
- /data/data/####/f_00004f
- /data/data/####/f_000050
- /data/data/####/f_000051
- /data/data/####/f_000052
- /data/data/####/f_000053
- /data/data/####/f_000054
- /data/data/####/f_000055
- /data/data/####/fenxiao.xml
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.9.0.2.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_vxj811
- /data/data/####/tdata_vxj811.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/unicorn#cheese#
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/weibo_sdk_aid1
- /data/media/####/.nomedia
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.uniplaza.fenx.bin
- /data/media/####/com.uniplaza.fenx.db
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_vxj811
- /data/media/####/test.log
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui.GetuiPushService 24712 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.0.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui.GetuiPushService 24712 300 0
- Bugly
- getuiext2
- libnfix
- libshella-2.9.0.2
- libufix
- nfix
- ufix
- weibosdkcore
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding