Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) wild####.al####.com.####.net:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) gd4.al####.com:80
- TCP(HTTP/1.1) gd3.al####.com:80
- TCP(HTTP/1.1) thi####.q####.cn:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) io####.tiantia####.com:80
- TCP(HTTP/1.1) idv####.qini####.com:80
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) thi####.q####.cn:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP(TLS/1.0) s####.ml####.cc:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP c####.g####.ig####.com:5227
- TCP sdk.o####.t####.####.com:5224
- 7j####.c####.z0.####.com
- api.growi####.com
- c####.g####.ig####.com
- c-h####.g####.com
- gd1.al####.com
- gd2.al####.com
- gd3.al####.com
- gd4.al####.com
- img.al####.com
- io####.tiantia####.com
- log.u####.com
- p37h4####.bkt.clo####.com
- plb####.u####.com
- s####.ml####.cc
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t####.growi####.com
- t.growi####.com
- thi####.q####.cn
- wx.q####.cn
- gd3.al####.com/imgextra/i2/810563441/TB2G6TsIACWBuNjy0FaXXXUlXXa_!!81056...
- gd3.al####.com/imgextra/i4/23042700/O1CN011Vodq6hZC5R0e6L_!!23042700.jpg...
- gd4.al####.com/imgextra/i1/1100610487/O1CN011FT5LmzGXCcZjn7_!!1100610487...
- gd4.al####.com/imgextra/i2/490330476/O1CN011FO2zbkSnaGbQoS_!!490330476.j...
- gd4.al####.com/imgextra/i3/0/TB1jcMeKVXXXXa8XpXXXXXXXXXX_!!0-item_pic.jp...
- gd4.al####.com/imgextra/i3/1821666267/TB2wB41rJknBKNjSZKPXXX6OFXa_!!1821...
- gd4.al####.com/imgextra/i4/179917267/O1CN0123YKfc1bjuMassL_!!179917267.j...
- gd4.al####.com/imgextra/i4/697826229/O1CN011vsvYlRaoQhdC9L_!!697826229.j...
- gd4.al####.com/imgextra/i4/697826229/TB2rAErpsj_B1NjSZFHXXaDWpXa_!!69782...
- idv####.qini####.com/20181016173605-4551.png
- idv####.qini####.com/icon_handpick_default.png
- idv####.qini####.com/icon_invite_prize_default.png
- idv####.qini####.com/icon_quickest_winning_default.png
- idv####.qini####.com/product_1539756723822.jpg
- idv####.qini####.com/product_1540179721029.jpg
- idv####.qini####.com/product_1540260856014.jpg
- idv####.qini####.com/product_1540435352216.jpg
- idv####.qini####.com/product_1541319903967.jpg
- idv####.qini####.com/spec_1540807591741.jpg
- idv####.qini####.com/spec_1541470689385.jpg
- io####.tiantia####.com/orderSeller/category.do
- io####.tiantia####.com/orderSeller/sort.do
- io####.tiantia####.com/special/getAppSpecialRecomList.do?pageIndex=####&...
- io####.tiantia####.com/special/getHeadPageInfo.do?reqtype=####
- io####.tiantia####.com/special/getHotRecomList.do?pageIndex=####&pageSiz...
- io####.tiantia####.com/version/update.do?client=####
- t####.c####.q####.####.com/config/hz-hzv3.conf
- t####.c####.q####.####.com/tdata_BAI450
- t####.c####.q####.####.com/tdata_YJA893
- thi####.q####.cn/mmopen/vi_32/8m96uYNX9WeRVgDeWV15FtNStZa9jR6jLicW5PfcUi...
- thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTI5jr1KfpLoXYu9VKPLx8XdPNjv3dkP7x...
- thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTK5Y16h6Irib2Yr1iclYUPVP9KAcRcicI...
- thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTK6IxCxniax4vSxwnCq8G7Feib9C2gGKu...
- thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTKmj2hibqrMD5aR9RtMhy8jeT9Qkm3C9o...
- thi####.q####.cn/mmopen/vi_32/Q0j4TwGTfTKntHcwSqMiaVuDicojmfVksvIsibDgPD...
- wild####.al####.com.####.net/imgextra///img.alicdn.com/imgextra/i2/22195...
- wild####.al####.com.####.net/imgextra///img.alicdn.com/imgextra/i4/30513...
- wild####.al####.com.####.net/imgextra/i2/1916094987/O1CN01HxWA1S1mi5eb5M...
- wild####.al####.com.####.net/imgextra/i2/1964136194/O1CN011vcth61KQgsUxp...
- wild####.al####.com.####.net/imgextra/i2/1964136194/O1CN01L9ycmx1vctho3f...
- wild####.al####.com.####.net/imgextra/i2/2081314055/O1CN01U913MC1fpEWFpT...
- wild####.al####.com.####.net/imgextra/i2/TB119YhQpXXXXaLaFXXXXXXXXXX_!!0...
- wild####.al####.com.####.net/imgextra/i3/1964136194/TB1hxsHX8bM8KJjSZFFX...
- wild####.al####.com.####.net/imgextra/i4/2177203318/O1CN011aNgcWqFG1aDRi...
- c-h####.g####.com/api.php?format=####&t=####
- io####.tiantia####.com/search/getCategoryList.do
- io####.tiantia####.com/search/list.do
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.jg.ic
- /data/data/####/082808d8932f615a21504dfa122edebd33b843ab8cbb09a....0.tmp
- /data/data/####/15e7b6ca3634a65071f1411913f98b11e2c9a75bac3cb36....0.tmp
- /data/data/####/34348f556c6f9db89d1a67ac01e5ed8316067ed07a99a64....0.tmp
- /data/data/####/49455ea802b1da99a6d77eeac9e368c8b3f89396d1b5938....0.tmp
- /data/data/####/4e48e82b1d799f783d2cfcb3f2c5a0e2c39f8a472ad742d....0.tmp
- /data/data/####/53e90b1b0b081bd151bee28cf1ecd230d690638542a53b7....0.tmp
- /data/data/####/5e4f71a03a3d802b16e724817e78ccc14bbf84cf318a07f....0.tmp
- /data/data/####/845222cef9f45186a1b31c9b897328698ecbad380c73d87....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MultiDex.lock
- /data/data/####/a0405869d7e49439175b192f94423a060ab63ad45b04174....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.biaoqi.tiantianling;pushservice.growing.db-journal
- /data/data/####/com.biaoqi.tiantianling_preferences.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTQxNzg2ODQ4ODA5;
- /data/data/####/dW1weF9zaGFyZV8xNTQxNzg2ODQ5OTY0;
- /data/data/####/dW1weF9zaGFyZV8xNTQxNzg2ODUwMDkw;
- /data/data/####/e23441acac713a374de785823dbc65dd9771fead6df1377....0.tmp
- /data/data/####/f4b8289ae9914bc39701bc66452259930990338f1ca7033....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid.xml
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/info.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu1515902194.so
- /data/data/####/mobclick_agent_cached_com.biaoqi.tiantianling2031
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/persistent_data.xml
- /data/data/####/persistent_data.xml.bak
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/share.db-journal
- /data/data/####/tdata_BAI450
- /data/data/####/tdata_BAI450.jar
- /data/data/####/tdata_YJA893
- /data/data/####/tdata_YJA893.jar
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/app.db
- /data/media/####/com.biaoqi.tiantianling.bin
- /data/media/####/com.biaoqi.tiantianling.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/tdata_BAI450
- /data/media/####/tdata_YJA893
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GeTuiPushService 25322 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- ls /sys/class/thermal
- getuiext2
- libjiagu1515902194
- securityenv
- AES-CBC-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding