Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) idu####.qini####.com:80
- TCP(HTTP/1.1) 1####.254.116.117:80
- TCP(HTTP/1.1) loc.map.b####.com:80
- TCP(HTTP/1.1) t####.qq.com:8080
- TCP(HTTP/1.1) 3####.tc.qq.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) s1.m####.com:80
- TCP(HTTP/1.1) a.a####.qq.com:80
- TCP(TLS/1.0) idu####.qini####.com:443
- TCP(TLS/1.0) z.c####.com:443
- TCP(TLS/1.0) m####.y####.com:443
- TCP(TLS/1.0) c####.y####.com:443
- TCP(TLS/1.0) fp.fraudme####.cn:443
- TCP(TLS/1.0) s1.m####.com:443
- TCP(TLS/1.0) m####.data####.sensors####.cn:443
- TCP(TLS/1.0) gm.mm####.com:443
- TCP(TLS/1.0) redi####.network####.com:443
- TCP(TLS/1.0) dc1.network####.com:443
- TCP(TLS/1.0) be####.tin####.com:443
- TCP(TLS/1.0) c.c####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) v1-auth####.visionc####.com:443
- TCP t####.qq.com:80
- TCP t####.qq.com:14000
- a####.u####.com
- a.a####.qq.com
- api.map.b####.com
- be####.tin####.com
- c####.mm####.com
- c####.y####.com
- c.c####.com
- dc1.network####.com
- dd.m####.com
- fp.fraudme####.cn
- hm.b####.com
- i####.y####.com
- loc.map.b####.com
- m####.data####.sensors####.cn
- m####.y####.com
- pi####.qq.com
- redi####.network####.com
- s1.m####.com
- s1.y####.com
- s13.c####.com
- t####.qq.com
- v1-auth####.visionc####.com
- xdy.y####.com
- z7.c####.com
- 3####.tc.qq.com/16891/98629B38364D73301DDF4DB2AA99CE7D.apk?fsname=####
- 3####.tc.qq.com/dd.myapp.com/16891/98629B38364D73301DDF4DB2AA99CE7D.apk?...
- a.a####.qq.com/o/down/<Package>
- idu####.qini####.com/340448551211843584.jpeg?imageVi####
- idu####.qini####.com/347054146492776448.jpeg?imageVi####
- idu####.qini####.com/350083882341056512.jpeg?imageVi####
- idu####.qini####.com/350954532777705472.jpeg?imageVi####
- idu####.qini####.com/351408251822616576.jpeg?imageVi####
- idu####.qini####.com/351408646041055232.jpeg?imageVi####
- idu####.qini####.com/353506220717850624.jpg?imageVi####
- idu####.qini####.com/353506437592727552.jpg?imageVi####
- idu####.qini####.com/353506679964778496.jpg?imageVi####
- idu####.qini####.com/353507089186242560.jpg?imageVi####
- idu####.qini####.com/356069398656004096.jpeg?imageVi####
- idu####.qini####.com/356830534548533248.jpeg?imageVi####
- idu####.qini####.com/358683632397139968.png
- idu####.qini####.com/360454916554567680.jpeg?imageVi####
- idu####.qini####.com/362630045766201344.png?imageVi####
- idu####.qini####.com/362631864865206272.png?imageVi####
- idu####.qini####.com/365880576605368320.jpeg?imageVi####
- idu####.qini####.com/366213468984389632.jpeg?imageVi####
- idu####.qini####.com/368797344743243776.jpeg?imageVi####
- idu####.qini####.com/369653207628460032.jpeg?imageVi####
- idu####.qini####.com/369664607134363648.jpeg?imageVi####
- idu####.qini####.com/372895063116038144.png?imageVi####
- idu####.qini####.com/373786686263865344.jpg?imageVi####
- idu####.qini####.com/381491771706126336.jpeg?imageVi####
- idu####.qini####.com/383646080715665408.jpeg?imageVi####
- idu####.qini####.com/384029919900286976.jpeg?imageVi####
- idu####.qini####.com/388121467982131200.jpeg?imageVi####
- idu####.qini####.com/495299450852679680.jpg?imageVi####
- idu####.qini####.com/495301866624983040.jpg?imageVi####
- idu####.qini####.com/499249813247041536.png?imageVi####
- idu####.qini####.com/499250075802083328.png?imageVi####
- idu####.qini####.com/499250126330863616.png?imageVi####
- idu####.qini####.com/499250174930264064.png?imageVi####
- idu####.qini####.com/561269780922560512.png?imageVi####
- idu####.qini####.com/57d66dd98ee8c83f57d66dda-bg
- idu####.qini####.com/584382323387854848.png?imageVi####
- idu####.qini####.com/58dc7b1445ce817e58dc7b15?imageVi####
- idu####.qini####.com/58dc7b1445ce817e58dc7b17?imageVi####
- idu####.qini####.com/58dc7b1845ce817e58dc7b26?imageVi####
- idu####.qini####.com/58dc7b1845ce817e58dc7b27?imageVi####
- idu####.qini####.com/5911f71145ceab145912e64a?imageVi####
- idu####.qini####.com/5911f71145ceab145912e64e?imageVi####
- idu####.qini####.com/5911f71145ceab145912e64f?imageVi####
- idu####.qini####.com/5911f73345ceab145912e6ef?imageVi####
- idu####.qini####.com/5911f7e245ceab145912ea40?imageVi####
- idu####.qini####.com/5911f7e345ceab145912ea4b?imageVi####
- idu####.qini####.com/5911f82e45ceab145912ebee?imageVi####
- idu####.qini####.com/5916a93b45ce143c5914455c?imageVi####
- idu####.qini####.com/592544a945cedf4b59254dc8?imageVi####
- idu####.qini####.com/5925566345ce3b2d59253b01?imageVi####
- idu####.qini####.com/592c24f745cefde659281208?imageVi####
- idu####.qini####.com/592d46c945cefde65928160d?imageVi####
- idu####.qini####.com/593e34ec45ceea3a593aa070?imageVi####
- idu####.qini####.com/5940eb6e45cef9465940e170?imageVi####
- idu####.qini####.com/594684e545ced6c65944f8f4?imageVi####
- idu####.qini####.com/594b48e545ceb336594aa86a?imageVi####
- idu####.qini####.com/5958617b45ce1ddb5957cb01?imageVi####
- idu####.qini####.com/5962c06e45ce6f9c595faa29?imageVi####
- idu####.qini####.com/596eef1345ce0400596e2c5c?imageVi####
- idu####.qini####.com/59769c8745ce7c015971507b?imageVi####
- idu####.qini####.com/597d412645ce3f3d597b2be4?imageVi####
- idu####.qini####.com/598ffd0645ce385e598890f5?imageVi####
- idu####.qini####.com/599e38ea45cee253599d949f?imageVi####
- idu####.qini####.com/59aad87245cefefc59a8902a?imageVi####
- idu####.qini####.com/59aad8a445cefefc59a892d9?imageVi####
- idu####.qini####.com/59aad8ab45cefefc59a89347?imageVi####
- s1.m####.com/cms/asset/2017-04/06/2bf7/44e2/dc4655f4c7303ca6e628561a.png
- s1.m####.com/cms/asset/2017-04/06/53e3/842f/dd0c9da0f25b10567b459a50.png
- s1.m####.com/cms/asset/2017-04/06/6d75/d55b/d66740430283bcc11b7b1aee.png
- s1.m####.com/cms/asset/2017-04/06/ae39/495d/63869796433747687d81f2b4.png
- s1.m####.com/cms/asset/2017-04/06/c981/6720/1a0a4769347cfe1305e3b2b8.png
- s1.m####.com/cms/asset/2017-04/06/cbfa/cca2/9bd8c48c6e0189cc5c8c93e0.png
- s1.m####.com/cms/asset/2017-04/06/d11d/2872/2354fa39d7c460b3a98028ec.png
- s1.m####.com/cms/asset/2017-04/06/f2a6/ca37/31a54f7d2602300625cbec31.png
- a####.u####.com/app_logs
- loc.map.b####.com/sdk.php
- pi####.qq.com/mstat/report/?index=####
- t####.qq.com:8080/203.205.146.122:8080/
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/.tpns.service.xml.xml
- /data/data/####/.tpns.settings.xml.xml
- /data/data/####/.tpush_mta.xml
- /data/data/####/01f4h0cx25Jx4weXaWwPcnVt-hk.-1902021110.tmp
- /data/data/####/0HZZSJnROMCPDvxDM3cvPg03kUs.450094080.tmp
- /data/data/####/0uHcHO7lXeyQdBzJ9up5joTZnlc.415883105.tmp
- /data/data/####/31106c310c4ff5a832eeca806399d947.0.tmp
- /data/data/####/31106c310c4ff5a832eeca806399d947.1.tmp
- /data/data/####/33ceb5eeecf5647cefb52ed6923b8793.0.tmp
- /data/data/####/33ceb5eeecf5647cefb52ed6923b8793.1.tmp
- /data/data/####/4BZz4Qll_tyUAvVX7YnMZjok9Xk.1524729283.tmp
- /data/data/####/4EgUQfmxNUsTif1jGyVipEDcUzk.2142843927.tmp
- /data/data/####/4PIIwW-ra2CMXWNR7NuI1G1mUaE.1887614999.tmp
- /data/data/####/4be74a0d03b5129e050b08c67cd799ad.0.tmp
- /data/data/####/4be74a0d03b5129e050b08c67cd799ad.1.tmp
- /data/data/####/4lWsGu9r_KJLOSpl_LP6wfBpzvQ.-504828729.tmp
- /data/data/####/65bc59795ffdac87c16204617bab95c3.0.tmp
- /data/data/####/65bc59795ffdac87c16204617bab95c3.1.tmp
- /data/data/####/746d656f62b11e397b431f9add0b5d69.0.tmp
- /data/data/####/746d656f62b11e397b431f9add0b5d69.1.tmp
- /data/data/####/76b98513370819d481b9f0cefc9da323.data-journal
- /data/data/####/78_hLVyrHXJ4EuzsRS54Y5wAIOo.-675413220.tmp
- /data/data/####/7fBL0gJ95tTazlIIzXn-y4p2kpc.525894330.tmp
- /data/data/####/7hX7PBqcvCC3S4oN57iNXf44PkA.1966035482.tmp
- /data/data/####/849037c3c4f618c9eb5767bbe29f2bc1.0.tmp
- /data/data/####/849037c3c4f618c9eb5767bbe29f2bc1.1.tmp
- /data/data/####/8yRiL9Ud8P5SxUG3tuKj8KfE3-0.-1920023707.tmp
- /data/data/####/A1xmLiB-KXAAT4gleWQtEDgDaas.-684344341.tmp
- /data/data/####/AM6YEpn4SvY5ok8RnIY_yAVm5eE.130242079.tmp
- /data/data/####/AexryV-UUpQTQ4vu0ayNi8119mg.730189659.tmp
- /data/data/####/Bm0RD18dqmIY3WOFfWUmJ9P_iaI.2042149746.tmp
- /data/data/####/DRMUwTmybB892__XOBfba_RLOC4.-1030421956.tmp
- /data/data/####/Dewr2NvPkdNavjzjV6mPtX-fZUM.240939928.tmp
- /data/data/####/GQKMkqNDHOQmA3G9ZT3yGMHkmrc.1860646302.tmp
- /data/data/####/I9HTyTZjcxAO57bDSH8YnR76qvk.1669684639.tmp
- /data/data/####/K0dnDKp0bVjXphVGx5bdu4NKiGk.-1586358256.tmp
- /data/data/####/KQAlIoPpknKJHlb4iExxF_zDkUk.2092173688.tmp
- /data/data/####/KxN_xAeoio493ZWqWWyhEIttCVQ.-487107775.tmp
- /data/data/####/MHxWcJ9QkJwjSNL3oO6uN031mBY.364138904.tmp
- /data/data/####/McZ-1AIwkCT6E43oCBD19H05LXc.-2009321650.tmp
- /data/data/####/NBSUserAction
- /data/data/####/PNXlGoQu02kqoH8TuPtXw9SWaXI.155114077.tmp
- /data/data/####/Pu4S8jcoscoyyq7f64z2i_tG-Xk.1075792774.tmp
- /data/data/####/R7jJtmWmI6cFDeZUmMYvPAxlgGk.-1770421745.tmp
- /data/data/####/SW1HtpMK_JSptXy9qyszgvGt0RI.-1262591243.tmp
- /data/data/####/Uy9Mj9i7W8LjOJMeX7zCY_6pMWw.1635544765.tmp
- /data/data/####/WZXOQuVQIv9aBa02lGSvVPBILVo.-1799099812.tmp
- /data/data/####/WdB_epC25sp6QQ4mTqUrhuzt4TU.-878102597.tmp
- /data/data/####/X5P913rqjVuxAymPmo30Cg1lcTk.-910413077.tmp
- /data/data/####/YIDhVOeg3K_fDfWFYbHTz1gr36I.640530110.tmp
- /data/data/####/YchiLe9n13nHt3LR-01H2P3jvqs.-317278683.tmp
- /data/data/####/_S1yWz3V9p2cx8KLrPEzHgB5d74.2103348171.tmp
- /data/data/####/_gD3LHe1eyLX0eh4kmec5HAL8Rw.-413955674.tmp
- /data/data/####/authStatus_com.meili.yyfenqi;remote.xml
- /data/data/####/b8fe460beb1a8952c60b33074a0535b8.0.tmp
- /data/data/####/b8fe460beb1a8952c60b33074a0535b8.1.tmp
- /data/data/####/bpy9U-ydbeg0ZEjhsQUdy2kfCnc.517168639.tmp
- /data/data/####/com.meili.yyfenqi_preferences.xml
- /data/data/####/com.networkbench.agent.impl.v2_com.meili.yyfenqi.xml
- /data/data/####/config.xml
- /data/data/####/dTTgMmtmEULkmGP6AOPMR_Y0kmA.-554629924.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/device_id.xml
- /data/data/####/disk_entries_list_image_cache_1565976845.xml
- /data/data/####/disk_entries_list_image_small_cache_322317205.xml
- /data/data/####/dmAgt2qCCVhNSUQVWyDeYGmXM0c.-1657944335.tmp
- /data/data/####/eXN36UWCROJ_C81lazcAcgbBV-s.-569560037.tmp
- /data/data/####/efdbbfb45365f340adaa80c20d3cef07.0.tmp
- /data/data/####/efdbbfb45365f340adaa80c20d3cef07.1.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/f7f68e26218f98d2ab896d6ac9725bb8.0.tmp
- /data/data/####/f7f68e26218f98d2ab896d6ac9725bb8.1.tmp
- /data/data/####/fRaZVLhZK-eA_pkB0JvFzIcyz_w.1975004480.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/fimkYPCf7Xd1bJuW2VDyeLjGho4.1652578041.tmp
- /data/data/####/firll.dat
- /data/data/####/fm_shared.xml
- /data/data/####/gWQtg-HNa4wudq60jZVkNYwBXaA.-583318334.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/gvAgpBSxhxOrBr3rWwmwEISN5bQ.248059789.tmp
- /data/data/####/iNLBgv0CxIpujy0N92GXXPO5oKw.-1612927025.tmp
- /data/data/####/index
- /data/data/####/jOVlByQuCS73p-M_mbZonqzISW0.-594846620.tmp
- /data/data/####/journal.tmp
- /data/data/####/kWzx-GzAI1CWz4DGRJ__ddTPptA.10095582.tmp
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/mLicjpWFnsK_0bvNG2eB6O0At6o.1942320337.tmp
- /data/data/####/mianqian_bt.xml
- /data/data/####/multidex.version.xml
- /data/data/####/nNyq5zY1rPjJYhXb07DUiC0cZ34.408271106.tmp
- /data/data/####/oFiROUPG_GLwVfe0isVTvQYptKg.1115445940.tmp
- /data/data/####/oKxuYaU0PV_Frvy0PRxky0DJdVc.1188879227.tmp
- /data/data/####/pg5yG3uguXddnrE8UET9O6d7poc.-1427700535.tmp
- /data/data/####/qzp0HRSDThkloovS9_kOp3R0YSc.1030276889.tmp
- /data/data/####/sSSvxSzhtD6O7oi-T2IX1PLrgPo.-252293183.tmp
- /data/data/####/sZGyRzVuVdwUsZLFpBjFJPNYmhg.1482145140.tmp
- /data/data/####/shVcYYa0Q6kP-81QiftKJ0UHTFo.-1644108131.tmp
- /data/data/####/sx1e_4nFwJgk2hSRzkFgp9fzHzk.874906801.tmp
- /data/data/####/td_fm.jar
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/u6PDjc2-F2tTZ2S5NYv_D8vc-9M.-1230198375.tmp
- /data/data/####/uboE43E_16P0xqRI1--6IitHCyQ.-313836070.tmp
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/upq_dOvw3ABxxmxuZC5vBj9Q4DE.-1999813417.tmp
- /data/data/####/wL2KIWp8u47ha0kkCHVSGMrYRlw.-815675709.tmp
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/x95zH5zZZD4DmhNJLm-68xadaZo.-2003301655.tmp
- /data/data/####/xg_message.db
- /data/data/####/xg_message.db-journal
- /data/data/####/yejJI7JoFVG3jH-OFRWW4u6bdpY.1023881944.tmp
- /data/data/####/zJ3wU6PdK73Pdt-df772FLI5-us.1814722471.tmp
- /data/data/####/zOZbxZzwFSb0Dawl7ULdrPZtdAg.-1119207579.tmp
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.mid.txt
- /data/media/####/.mid.txt1000001
- /data/media/####/.nomedia
- /data/media/####/_0ServerSendToService.txt
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/log-20190308_1508_1.txt
- /data/media/####/log-20190308_1509_1.txt
- /data/media/####/test.0
- /data/media/####/yyfq_2.6.1.apk
- <Package Folder>/lib/libxguardian.so <Package>,2100258429; 55421 203.205.128.130 [{ idx :0, ts :%d, et :2000, si :0, ui : <IMEI> , ky : Axg%lu , mid : 0 , ev :{ ov : 18 , sr : 600*752 , md : <System Property> , lg : en , sv : 3.0 , mf : unknown , apn : %s }}] 1 18
- <Package Folder>/lib/libxguardian.so <Package>,2100258429; 55421 203.205.128.130 [{"idx":0,"ts":%d,"et":2000,"si":0,"ui":"<IMEI>","ky":"Axg%lu","mid":"0","ev":{"ov":"18","sr":"600*752","md":"<System Property>","lg":"en","sv":"3.0","mf":"unknown","apn":"%s"}}] 1 18
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop net.dns1
- ls -l /system/xbin/su
- imagepipeline
- libjiagu
- locSDK7
- tongdun
- tpnsSecurity
- AES-CBC-PKCS5Padding
- AES-CFB8-NoPadding
- AES-ECB-PKCS5Padding
- RSA-ECB-PKCS1PADDING
- AES-CBC-PKCS5Padding
- AES-CFB8-NoPadding
- DES-ECB-PKCS5Padding