Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) luna-im####.qq.com.####.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) www.w####.com:80
- TCP(HTTP/1.1) a####.u####.com.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) www.w####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) s####.e.qq.com:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) bgp.netarch####.l.####.net:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) securit####.sp####.mig.####.net:443
- TCP(TLS/1.0) is.sn####.com.####.com:443
- TCP(TLS/1.0) w####.xi####.com:443
- TCP(TLS/1.2) inte####.faceu####.com:6443
- TCP(TLS/1.2) 1####.217.168.195:443
- TCP(TLS/1.2) www.google####.com:443
- TCP(TLS/1.2) and####.cli####.go####.com:443
- a####.u####.com
- and####.b####.qq.com
- and####.cli####.go####.com
- android####.go####.com
- dig.b####.net
- dn####.d####.com
- down####.w####.com
- imgc####.qq.com
- inte####.faceu####.com
- is.sn####.com
- l####.tbs.qq.com
- m####.go####.com
- pla####.googleu####.com
- s####.e.qq.com
- sf3-fe####.pglstat####.com
- sf3-ttc####.ps####.com
- t####.m.qq.com
- to####.ctobsn####.com
- w####.xi####.com
- www.google####.com
- www.w####.com
- xiu.xi####.com
- bgp.netarch####.l.####.net:443/q?host=####&aid=####
- is.sn####.com.####.com:443/obj/ad-pattern/renderer/19602b/index.js
- is.sn####.com.####.com:443/obj/ad-pattern/renderer/package.json
- is.sn####.com.####.com:443/service/2/app_alert_check/?&os_api=####&devic...
- luna-im####.qq.com.####.com/qzone/biz/gdt/mod/android/AndroidAllInOne/pr...
- w####.xi####.com:443/vshow/streamname?get_url=####
- www.w####.com/activities/caidan/ip13/xxh1068x344.jpg
- www.w####.com/faxian/shouchongxxh.jpg
- www.w####.com/xiu/kanshipindeyangguang/xxh1068x344.jpg
- www.w####.com:443/upload/xiu/37/46/wx-qabutbntrm_3_550x410_211018193647....
- www.w####.com:443/upload/xiu/68/0/sj-sdmimvrcwn_3_550x410_191030161425.jpg
- www.w####.com:443/upload/xiu/72/22/sj-mtxtqbkpyd_3_550x410_220127235220....
- www.w####.com:443/upload/xiu/90/63/wx-wszlnrgddl_3_550x410_210925162605....
- www.w####.com:443/upload/xiu/98/85/litingxiu_3_550x410_211108154409.jpg
- a####.u####.com.####.com/app_logs
- and####.b####.qq.com/rqd/async
- is.sn####.com.####.com:443/api/ad/union/sdk/settings/
- is.sn####.com.####.com:443/api/ad/union/sdk/stats/
- is.sn####.com.####.com:443/api/ad/union/sdk/upload/app_info/
- is.sn####.com.####.com:443/service/2/app_log/?tt_data=####&&os_api=####&...
- is.sn####.com.####.com:443/service/2/device_register_only/?&os_api=####&...
- is.sn####.com.####.com:443/service/2/log_settings/?&os_api=####&device_t...
- l####.tbs.qq.com/ajax?c=####&k=####
- s####.e.qq.com/activate
- s####.e.qq.com:443/event
- securit####.sp####.mig.####.net:443/?mc=####
- www.w####.com:443/index.php?action=####&do=####
- /data/data/####/.cl
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/.turing.dat
- /data/data/####/07e2de851c27bd497ea4cea8cec3f22aff02e1ef1f1a936....0.tmp
- /data/data/####/1021689741840853517
- /data/data/####/23801e9069d8b145dc8734e75c685280ab375f338d31d73....0.tmp
- /data/data/####/2bb7130c3e420c69ec2d84389a8a68322b0614ab6baa14a...880e.0
- /data/data/####/2ee7acd3353cb716f45372768359e07f6ce7c711198de5e...4749.0
- /data/data/####/3408.yaqcookie
- /data/data/####/3c734150d245620787355a9bf3078e2022f7fd558e50c24....0.tmp
- /data/data/####/63dce1d0566053eeed5abe549b701dc3240cab2e2568b2e....0.tmp
- /data/data/####/6770804f674446e57d75e3f8ed4595aaef98baeb3f7774a....0.tmp
- /data/data/####/79c6e7d650f83b7c4946664560293f59e6e0e1443232d4b....0.tmp
- /data/data/####/907653126a69558dbb76f088b59df148bc0cae8a8994c46....0.tmp
- /data/data/####/936e86e98ee663ee69023432ac38bb93afc17164abc5f78....0.tmp
- /data/data/####/93ffe094bb78b8dc401c4441b9498bbb6ae0647dbca413e....0.tmp
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/TrineaAndroidCommon.xml
- /data/data/####/TrineaAndroidCommon.xml.bak
- /data/data/####/TrineaAndroidCommon.xml.bak (deleted)
- /data/data/####/ba5d586630cd533ff0d61058c810aadc5125ceb00b538f9...d783.0
- /data/data/####/bd_embed_tea_agent.db-journal
- /data/data/####/bugly_db_-journal
- /data/data/####/bytedance_downloader.db-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.oat
- /data/data/####/com.qq.e.sdkconfig.xml
- /data/data/####/core_info
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/download_upload
- /data/data/####/e40865aa0e549d3bb78792aef1fb1c9aa2fcc6965746130....0.tmp
- /data/data/####/ef759152e068d43df1f9f32fd5a722c0a61aeadc8c98209....0.tmp
- /data/data/####/embed_applog_stats.xml
- /data/data/####/embed_last_sp_session.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f09b04b78cd84176dc20f4bd1eca9d1d73b3eba06883bdd....0.tmp
- /data/data/####/gdt_config.cfg
- /data/data/####/gdt_plugin.dex
- /data/data/####/gdt_plugin.dex.flock (deleted)
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_stat.db
- /data/data/####/gdt_stat.db-journal
- /data/data/####/gdt_suid
- /data/data/####/journal
- /data/data/####/libMMANDKSignature.1023711b.so
- /data/data/####/libjiagu.so
- /data/data/####/libturingau.1023711b.so
- /data/data/####/libyaqbasic.1023711b.so
- /data/data/####/libyaqpro.1023711b.so
- /data/data/####/local_crash_lock
- /data/data/####/mpdc_105498_1
- /data/data/####/native_record_lock
- /data/data/####/proc_auxv
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/security_info
- /data/data/####/snssdk_openudid.xml
- /data/data/####/sp_push_time.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tt_dns_settings.xml
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/tt_sp_app_list.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/turingfd_conf_105498_auMini.xml
- /data/data/####/turingfd_conf_105498_auMini.xml.bak
- /data/data/####/turingfd_protect_105498_41_auMini.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_general_config.xml.bak (deleted)
- /data/data/####/umeng_it.cache
- /data/data/####/update_lc
- /data/data/####/yaq.1023711b.sec
- /data/data/####/yaq2.1023711b.sec
- /data/data/####/yaq3_0.1023711b.sec
- /data/data/####/yaqsdkcookie
- /system/bin/df
- /system/bin/getprop
- /system/bin/sh -c type su
- app_process /system/bin com.android.commands.pm.Pm list package -3
- chmod 777 /data/user/0/<Package>/cache/Download
- getprop androVM.vbox_dpi
- getprop gsm.sim.state
- getprop gsm.sim.state2
- getprop qemu.sf.fake_camera
- getprop ro.board.platform
- getprop ro.build.version.emui
- getprop ro.debuggable
- getprop ro.genymotion.version
- getprop ro.letv.release.version
- getprop ro.product.cpu.abi
- getprop ro.secure
- getprop ro.vivo.os.build.display.id
- sh
- libBugly
- libMMANDKSignature.1023711b
- libjiagu
- libnms
- libtobEmbedEncrypt
- libyaqbasic.1023711b
- libyaqpro.1023711b
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding