Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) wb.110.ta####.com:80
- TCP(HTTP/1.1) t####.dmp.y####.net:80
- TCP(HTTP/1.1) l####.c####.q####.####.net:80
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) ada####.m.ta####.com:80
- TCP(HTTP/1.1) zhg.ali####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) ad####.m.ta####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) 1####.205.160.63:80
- TCP(HTTP/1.1) 1####.205.163.87:80
- TCP(HTTP/1.1) www.dianm####.com:80
- TCP(HTTP/1.1) api.q####.com:80
- TCP(HTTP/1.1) au.y####.net:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) s.y####.net:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) sh.wagbr####.ta####.com:443
- TCP(TLS/1.0) msg.umengc####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) adser####.go####.com:443
- UDP 2####.0.0.1:9998
- TCP c####.g####.ig####.com:5226
- TCP 1####.205.160.76:443
- TCP umengj####.m.ta####.com:80
- TCP sdk.o####.t####.####.com:5224
- 1####.nd####.y####.com
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a.appj####.com
- ad####.m.ta####.com
- ada####.m.ta####.com
- adser####.go####.com
- ag####.m.ta####.com
- aos.w####.y####.net
- api.q####.com
- au.y####.net
- bcfeed####.ta####.com
- c####.g####.ig####.com
- c-h####.g####.com
- log.u####.com
- m.d####.mob.com
- msg.umengc####.com
- s####.gw.y####.net
- s####.u####.com
- s.y####.net
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sdk.st####.y####.com
- ssl.gst####.com
- t####.dmp.y####.net
- umengj####.m.ta####.com
- wb.110.ta####.com
- www.dianm####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- y####.al####.com
- ad####.m.ta####.com/rest/gc2?ak=####&av=####&c=####&d=####&sv=####&t=###...
- api.q####.com/api/android/verify3?key=####&ver=2vP####
- api.q####.com/api/android/verify3?key=####&ver=3ds####
- api.q####.com/api/android/verify3?key=####&ver=4L3####
- api.q####.com/api/android/verify3?key=####&ver=5T8####
- api.q####.com/api/android/verify3?key=####&ver=9Xe####
- api.q####.com/api/android/verify3?key=####&ver=GCH####
- api.q####.com/api/android/verify3?key=####&ver=Il7####
- api.q####.com/api/android/verify3?key=####&ver=K6T####
- api.q####.com/api/android/verify3?key=####&ver=W1a####
- api.q####.com/api/android/verify3?key=####&ver=cxm####
- api.q####.com/api/android/verify3?key=####&ver=dPu####
- api.q####.com/api/android/verify3?key=####&ver=jjj####
- api.q####.com/api/android/verify3?key=####&ver=oCh####
- api.q####.com/api/android/verify3?key=####&ver=tUE####
- api.q####.com/api/android/verify3?key=####&ver=uoc####
- api.q####.com/jar/jfq3.2.5.jar
- au.y####.net/offer/dist/aos/pkg/3.2.2/offers_3.2.2.zip
- l####.c####.q####.####.net/config/hz-hzv3.conf
- l####.c####.q####.####.net/tdata_BAI450
- l####.c####.q####.####.net/tdata_YJA893
- m.d####.mob.com/v2/cconf?appkey=####&plat=####&apppkg=####&appver=####&n...
- s.y####.net/aos/v3/initf?s=####
- s.y####.net/stat/aos/v3/pkc?s=####
- s.y####.net/stat/aos/v3/pku?s=####
- s.y####.net/stat/v3/udt2?appid=####&s=####
- s.y####.net/v3/zip_upd?s=####
- www.dianm####.com/sdk/DianCaiWall.zip
- a####.exc.mob.com/errconf
- a.appj####.com/ad-service/ad/mark
- ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- t####.dmp.y####.net/v1/android/packages?rt=####&sign=####
- t####.dmp.y####.net/v2/android/pkgtime?rt=####&sign=####
- wb.110.ta####.com/api/update.do
- www.dianm####.com/diancai/getConfig.json
- www.dianm####.com/diancai/init.json
- www.dianm####.com/diancai/wall.do
- zhg.ali####.com/saveWb.json
- /data/data/####/-1542147482.xml
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1532319902781.log
- /data/data/####/1d77ea041509fe06.lock
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/50c56e13d82d11ba17aeb5e3764c4d4f
- /data/data/####/50c56e13d82d11ba17aeb5e3764c4d4f-journal
- /data/data/####/766907729
- /data/data/####/766907729.jar
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/937446895.xml
- /data/data/####/937446895.xml (deleted)
- /data/data/####/ACCS_BIND.xml
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/AGOO_BIND.xml
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
- /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
- /data/data/####/ContextData.xml
- /data/data/####/DaemonServer
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/OFFERSCONFIG1.xml
- /data/data/####/OxgHkj2lz09F
- /data/data/####/OxgHkj2lz09F-journal
- /data/data/####/P15pKIjsm64m
- /data/data/####/P15pKIjsm64m-journal
- /data/data/####/SGMANAGER_DATA2
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/SMSSDK_2.xml
- /data/data/####/SMSSDK_VCODE_1.xml
- /data/data/####/T1oX0rhhuXWt
- /data/data/####/T1oX0rhhuXWt-journal
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UTCommon.xml
- /data/data/####/UTCommon.xml.bak (deleted)
- /data/data/####/XKwVoK0huy3R
- /data/data/####/XKwVoK0huy3R-journal
- /data/data/####/accs.db-journal
- /data/data/####/agoo.pid
- /data/data/####/ap.Lock
- /data/data/####/arrow-left-pink.png
- /data/data/####/arrow-left.png
- /data/data/####/arrow-right-pink.png
- /data/data/####/arrow-right.png
- /data/data/####/b3174b7a6d3bea51202ab7a342495ddf-journal
- /data/data/####/blank.gif
- /data/data/####/c6fa56a26a6b87108dee2c3cb0393e5a.zip
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/close-icon.png
- /data/data/####/com.anroid.mylockscreen_preferences.xml
- /data/data/####/default.png
- /data/data/####/detail-wx-miniprogram.html
- /data/data/####/detail-wx-miniprogram.js
- /data/data/####/detail-wx.html
- /data/data/####/detail-wx.js
- /data/data/####/detail.html
- /data/data/####/detail.js
- /data/data/####/e22c534f482a6f9f0867c77fa2c670d2
- /data/data/####/e22c534f482a6f9f0867c77fa2c670d2-journal
- /data/data/####/feedback.html
- /data/data/####/feedback.js
- /data/data/####/form.css
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/global.js
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jfq.jar
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/jqIqJYOT3JpT
- /data/data/####/jqIqJYOT3JpT-journal
- /data/data/####/libjiagu.so
- /data/data/####/libsgmainso-5.1.81.so.tmp
- /data/data/####/lists.css
- /data/data/####/lists.html
- /data/data/####/lists.js
- /data/data/####/lock.lock
- /data/data/####/md5.js
- /data/data/####/message_accs_db
- /data/data/####/message_accs_db-journal
- /data/data/####/mob_commons_1.xml
- /data/data/####/mob_sdk_exception_1.xml
- /data/data/####/multidex.version.xml
- /data/data/####/nointernet.png
- /data/data/####/out_system.xml
- /data/data/####/pic_friend_step1.jpg
- /data/data/####/pic_friend_step2.jpg
- /data/data/####/pic_friend_step3.jpg
- /data/data/####/pic_friend_step4.jpg
- /data/data/####/pic_friend_step5.jpg
- /data/data/####/pic_m.png
- /data/data/####/pic_tips_01.png
- /data/data/####/pic_tips_02.png
- /data/data/####/pic_xiaochengxu_kefu_step1.png
- /data/data/####/pic_xiaochengxu_kefu_step2.png
- /data/data/####/pic_xiaochengxu_kefu_step3.png
- /data/data/####/pic_xiaochengxu_kefu_step4.png
- /data/data/####/pic_xiaochengxu_kefu_step5.png
- /data/data/####/pic_xiaochengxu_kefu_step6.png
- /data/data/####/pic_xiaochengxu_step1.png
- /data/data/####/pic_xiaochengxu_step2.png
- /data/data/####/pic_xiaochengxu_step3.png
- /data/data/####/pic_xiaochengxu_step4.png
- /data/data/####/pic_xiaochengxu_step5.png
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/result.png
- /data/data/####/rule.html
- /data/data/####/run.pid
- /data/data/####/sdetail.html
- /data/data/####/share.css
- /data/data/####/share.html
- /data/data/####/share.js
- /data/data/####/sp.lock
- /data/data/####/sprite-face.png
- /data/data/####/sprite-icons.png
- /data/data/####/sprite-icons2.png
- /data/data/####/tdata_BAI450
- /data/data/####/tdata_BAI450.jar
- /data/data/####/tdata_YJA893
- /data/data/####/tdata_YJA893.jar
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_socialize.xml
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/wIU6pTyUBYWX
- /data/data/####/wIU6pTyUBYWX-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/data/####/wsUL1uCdKvjD
- /data/data/####/wsUL1uCdKvjD-journal
- /data/data/####/wx-qr-step1.jpg
- /data/data/####/wx-qr-step2.jpg
- /data/data/####/wx-qr-step3.jpg
- /data/data/####/wx-qr-step4.jpg
- /data/data/####/wx-qr-step5.jpg
- /data/data/####/wx-step1.jpg
- /data/data/####/wx-step2.jpg
- /data/data/####/wx-step3.jpg
- /data/data/####/wx-step4.jpg
- /data/data/####/wx-step5.jpg
- /data/data/####/wx-wifi-step1.jpg
- /data/data/####/wx-wifi-step2.jpg
- /data/data/####/wx-wifi-step3.jpg
- /data/data/####/wx-wifi-step4.jpg
- /data/data/####/wx-wifi-step5.jpg
- /data/data/####/ymdex.jar
- /data/data/####/ywPrefsTools.xml
- /data/data/####/zy_init.xml
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.nomedia
- /data/media/####/.nulplt
- /data/media/####/.org
- /data/media/####/.pkg_lock
- /data/media/####/.rcTag
- /data/media/####/.rc_lock
- /data/media/####/.slock
- /data/media/####/13205b1733134068bc68f03d41312755
- /data/media/####/3a355bf0c3fc44cfa7f2f6d064b38035
- /data/media/####/6c709c11d2d46a7b
- /data/media/####/761ebf817ec056095fad98e32cf851a0
- /data/media/####/761ebf817ec056095fad98e32cf851a0.ymtf
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/accs_election
- /data/media/####/app.db
- /data/media/####/com.anroid.mylockscreen.bin
- /data/media/####/com.anroid.mylockscreen.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/dd7893586a493dc3
- /data/media/####/deviceToken
- /data/media/####/fbf45d5ab755435896843231b26a37bd
- /data/media/####/hid.dat
- /data/media/####/i42d45df023jnkdd93la483f9xGFKXI
- /data/media/####/inapp_20180723.log
- /data/media/####/lock.dat
- /data/media/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
- /data/media/####/tdata_BAI450
- /data/media/####/tdata_YJA893
- /data/media/####/test.log
- /data/media/####/zhaocaisuo.txt
- /system/bin/cat /sys/devices/system/cpu/kernel_max
- <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:55652c7967e58ed6fa001afd","utdid":"W1VYmNY4xdwDAGdzx1G2C6Zn","sdkVersion":"212"} -I agoodm.m.taobao.com -O 80 -T -Z
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.presenter.service.GeTuiService 25343 300 0
- chmod 500 <Package Folder>/files/DaemonServer
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.presenter.service.GeTuiService 25343 300 0
- abcdefgh
- getuiext2
- libjiagu
- neh
- sgmainso-5.1
- tnet-3.1
- ut_c_api
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES
- PBEWITHMD5andDES
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- DES
- PBEWITHMD5andDES