Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 2####.119.206.97:80
- TCP(HTTP/1.1) gm.mm####.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) c.c####.com:80
- TCP(HTTP/1.1) pco####.ta####.com:80
- TCP(HTTP/1.1) gw.al####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) z.c####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) appinte####.5####.com:80
- TCP(HTTP/1.1) wwc.taoba####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
- TCP(TLS/1.0) loc.map.b####.com:443
- TCP(TLS/1.0) o####.map.b####.com:443
- TCP(TLS/1.0) hotfix####.aliy####.com:443
- TCP(TLS/1.0) appinte####.5####.com:443
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) s####.5####.com:443
- TCP(TLS/1.0) wild####.al####.com.####.net:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a####.man.aliy####.com
- a####.u####.com
- api.map.b####.com
- appinte####.5####.com
- c####.g####.ig####.com
- c####.mm####.com
- c-h####.g####.com
- c.c####.com
- gw.al####.com
- h####.c####.com
- hm.b####.com
- hotfix####.aliy####.com
- img.al####.com
- loc.map.b####.com
- m.5####.com
- o####.map.b####.com
- pco####.c####.com
- s####.5####.com
- s19.c####.com
- s6.c####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- wwc.taoba####.com
- www.5####.com
- z8.c####.com
- appinte####.5####.com/monitor/in_page.htm?shopId=&referer=&connectKey=&u...
- c.c####.com/core.php?web_id=####&t=####
- c.c####.com/stat.php?id=####&web_id=####
- c.c####.com/z_stat.php?id=####&web_id=####
- gm.mm####.com/9.gif?abc=####&rnd=####
- gw.al####.com/tps/i3/TB1yeWeIFXXXXX5XFXXuAZJYXXX-210-210.png_100x100.jpg
- pco####.ta####.com/app.gif?&cna=####
- t####.c####.q####.####.com/config/hz-hzv3.conf
- t####.c####.q####.####.com/tdata_MkX219
- t####.c####.q####.####.com/tdata_iGj879
- wwc.taoba####.com/avatar/getAvatar.do?userNick=####&width=####&height=##...
- z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/1667874a4877b83d2ea5eb46792ca51abcdb655f38f6ca0....0.tmp
- /data/data/####/175c1765709bcd81a3d64f4f048ad60c47ffb2ac9a6e30f....0.tmp
- /data/data/####/310457a2c749de9e9f95e6c26fc3c05726f548d631b546b....0.tmp
- /data/data/####/3e6640be8b66df8bef2b0a79cdb4c96139a1e1119cc33e2....0.tmp
- /data/data/####/5a157ed81c113d20103aa82d9ae0647c44392204a6959b0....0.tmp
- /data/data/####/5e1af848d710ad55fb3aa69fd051f96da9175f52a8cffcb....0.tmp
- /data/data/####/668c7ef3763adf95f83e46d2d95cb06bb422e4a41dc53ca....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MultiDex.lock
- /data/data/####/P4j7qa6hBksY_7nmsqPPcnYR6M8.1024533474.tmp
- /data/data/####/PXZBUMsr0d9jR7iwtqwuZ1vDVO4.-806554896.tmp
- /data/data/####/PageInfo.db-journal
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/authStatus_com.alidao.sjxz;remote.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dd96659c7613b4ce74e998db91e01963503310734f59101....0.tmp
- /data/data/####/df9e23c153a7b30cc947e38767dd57e69c592de510e907f....0.tmp
- /data/data/####/disk_entries_list_image_cache_-1702915271.xml
- /data/data/####/dkT6QNVWEDGiVeP5ydSzGm1zmfQ.-36217261.tmp
- /data/data/####/domain_1
- /data/data/####/e849343673971a6433d2234955d27f6cc1855c15268f50e....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f9ec75e47cb50b53b4fbd4904773e9801d71e1dd3fe0888....0.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/firll.dat
- /data/data/####/gal.db
- /data/data/####/gal.db-journal
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jK8Bq7iZCPadHnX8Yid1YfZxM1c.2016959409.tmp
- /data/data/####/journal.tmp
- /data/data/####/libcuid.so
- /data/data/####/libjiagu658884186.so
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/ofl.config
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/sp_sophix.xml
- /data/data/####/tdata_MkX219
- /data/data/####/tdata_MkX219.jar
- /data/data/####/tdata_iGj879
- /data/data/####/tdata_iGj879.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.artc_lock
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.mn_-1464060969
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/app.db
- /data/media/####/com.alidao.sjxz.bin
- /data/media/####/com.alidao.sjxz.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/conlts.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/tdata_MkX219
- /data/media/####/tdata_iGj879
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui_service.DemoPushService 24492 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui_service.DemoPushService 24492 300 0
- getuiext2
- imagepipeline
- libjiagu658884186
- locSDK7b
- static-webp
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding