Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) i4.b####.com.####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) gu####.ovo.top:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) thi####.q####.cn:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) i1.f####.com.####.com:80
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP 1####.24.80.208:9090
- TCP c####.g####.ig####.com:5225
- 7j####.c####.z0.####.com
- a####.u####.com
- a.appj####.com
- c####.g####.ig####.com
- c-h####.g####.com
- gu####.ovo.top
- i1.f####.com
- i2.t####.com
- i4.b####.com
- i4.f####.com
- log.u####.com
- pub-####.qin####.com
- s####.u####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- st####.fun####.top
- thi####.q####.cn
- gu####.ovo.top/api/comment/ScanComment.php?uid=####&cert=####&cmt2=####&...
- gu####.ovo.top/api/getNextArticlesById.php?aid=####&ict=####
- gu####.ovo.top/api/newEvents.php
- gu####.ovo.top/api/scanTagsForApp.php
- i1.f####.com.####.com/565547/08155badceffc95as.jpg
- i1.f####.com.####.com/565547/74957d1427bd77f9s.jpg
- i1.f####.com.####.com/565547/8a2e6ebe0434466cs.jpg
- i1.f####.com.####.com/565547/a1f2a3f6ec09f31ds.jpg
- i1.f####.com.####.com/565547/c16034dd6c0cd50cs.jpg
- i1.f####.com.####.com/565547/f2e9ea9d7303b864s.jpg
- i4.b####.com.####.com/565547/ce8d9260910bf89as.png
- i4.b####.com.####.com/565547/e4ca8487378ac411s.png
- t####.c####.q####.####.com/tdata_Rnl693
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_siA393
- thi####.q####.cn/mmopen/vi_32/CEWufvUZXsVKn15xiaXvbs7XRu5gYGDKkibpoHMiaw...
- ti####.c####.l####.####.com/Fiq6tKmvVEdEPZkmoNpaqli9AG9D-show748
- ti####.c####.l####.####.com/FmRW70PrKqd21XbEITcdkn6SF6vU-show748
- ti####.c####.l####.####.com/Fnqk3SS9iWNBoE8WrXZ7pewL6uM5-show748
- ti####.c####.l####.####.com/FqKS2x9dM4c0hvMHiTJMWAOsEuX3-show748
- ti####.c####.l####.####.com/FvWohIP93iEt7d9_6HCz8wHcBJEm-show748
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- ti####.c####.l####.####.com/li8VVWiI1sip7ZsBCHEn0nbfRvVW-show748
- ti####.c####.l####.####.com/lnP7X3YaPZbn8rQB5j745JCUOrSq-show748
- ti####.c####.l####.####.com/luFs-crCiwxt3JfUfqLjeQwjYmoh-show748
- ti####.c####.l####.####.com/lv38F2jZXe3A6XOpm8EoBOz7TDZg-show748
- ti####.c####.l####.####.com/tdata_EDT369
- a####.u####.com/app_logs
- a.appj####.com/ad-service/ad/mark
- c-h####.g####.com/api.php?format=####&t=####
- gu####.ovo.top/api/getLatestVersionInfo.php
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/15352b25de576a8aa45d82359841a2120bd1a470070a159....0.tmp
- /data/data/####/1552768834268.log
- /data/data/####/2ce10639e370
- /data/data/####/4Smygum9TubRn_88I2f8bz_LDK8.1116874286.tmp
- /data/data/####/4a4a41e43fffda618086db9d1a135304dec72fcae6fbc0c....0.tmp
- /data/data/####/4f6812f9e78c16872d92a7d78546ea853a9cd765b072903....0.tmp
- /data/data/####/643fefb4228703e8bb7ae98627d4b4fb514477f2a2ef9cb....0.tmp
- /data/data/####/6c06561c66e5ecce080b45541fe2317229483b38bc589aa....0.tmp
- /data/data/####/6ff9008b65b27057f8b7b50c3d2494a67534d2f30f3c28a....0.tmp
- /data/data/####/8107f2ef5fde7c88e5e3ed0e15f38122fed61755cef2a7e....0.tmp
- /data/data/####/9061239c748b04d3611fe7c3c82ab15aacad50fec3fc016....0.tmp
- /data/data/####/93d1df64c3a24ad33434bc5ab6c7a2134c853c6cd419db4....0.tmp
- /data/data/####/99880c546c1860f45da13045a7884fc249c14aa5741b7ff....0.tmp
- /data/data/####/9b97bb12f629a49e631b78049341cc247bccb8f69e6ee2a....0.tmp
- /data/data/####/EcV0SP-1zhChISTPk3-5Kz6nMUs.-2017458611.tmp
- /data/data/####/Sn9dNfuOaJQ3CjQoUDuj6Rcw6Ds.1245869289.tmp
- /data/data/####/ZAokpPq63ELzGeniO0OhvUw8S2c.-2027106677.tmp
- /data/data/####/_jpQUlnZj2XinaDGgY-Y8HRLii0.1971447509.tmp
- /data/data/####/ab056e6f0a740c1b5774588c390b3fea1f77c529c1db2ca....0.tmp
- /data/data/####/bdfc5095cb7abda7fc002917073870c22d65806ee0e111f....0.tmp
- /data/data/####/c179009a260f89e9d8ba74dcccc74300d16b519fd64ce47....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cc4d22fdbdda777646ea4409c9698a23f9e0623d6814dc9....0.tmp
- /data/data/####/d8347debe0877a3061504872ca8515c1db01f56db814dc4....0.tmp
- /data/data/####/default.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/journal.tmp
- /data/data/####/libjiagu.so
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tdata_Rnl693
- /data/data/####/tdata_Rnl693.jar
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_siA393
- /data/data/####/tdata_siA393.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_Rnl693
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_siA393
- /data/media/####/test.log
- /data/media/####/top.ovo.gundam.bin
- /data/media/####/top.ovo.gundam.db
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.receiver.push.GundamPushService 24407 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- mount
- fb_jpegturbo
- getuiext2
- imagepipeline
- libjiagu
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding