Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) 1####.199.224.209:8001
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) 47.1####.140.194:80
- TCP(HTTP/1.1) q####.a####.com:80
- TCP(TLS/1.0) d####.fl####.com:443
- TCP(TLS/1.0) sett####.crashly####.com:443
- TCP(TLS/1.0) api.face####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- 7j####.c####.z0.####.com
- c####.g####.ig####.com
- c-h####.g####.com
- d####.fl####.com
- g####.face####.com
- googl####.g.doublec####.net
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sett####.crashly####.com
- x####.bj####.cn
- z####.bj####.cn
- q####.a####.com/otherdz/otherdzver.txt
- q####.a####.com/otherdz/zxotherdzrhe74
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/tdata_IKl114
- t####.c####.q####.####.com/tdata_qHR433
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_T87KX79Q...TX_216
- /data/data/####/.YFlurrySenderIndex.info.AnalyticsMain
- /data/data/####/.jg.ic
- /data/data/####/.yflurrydatasenderblock.337d007e-0fcc-4a63-898a...1e147f
- /data/data/####/1459442732877.jar
- /data/data/####/1459442732877.tmp
- /data/data/####/5C6B07810134-0001-08F9-5539F0ADA551BeginSession.cls_temp
- /data/data/####/5C6B07810134-0001-08F9-5539F0ADA551SessionApp.cls_temp
- /data/data/####/5C6B07810134-0001-08F9-5539F0ADA551SessionDevice.cls_temp
- /data/data/####/5C6B07810134-0001-08F9-5539F0ADA551SessionOS.cls_temp
- /data/data/####/5C6B078202CF-0001-0924-5539F0ADA551BeginSession.cls_temp
- /data/data/####/5C6B078202CF-0001-0924-5539F0ADA551SessionApp.cls_temp
- /data/data/####/5C6B078202CF-0001-0924-5539F0ADA551SessionDevice.cls_temp
- /data/data/####/5C6B078202CF-0001-0924-5539F0ADA551SessionOS.cls_temp
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/DtdzRhe.xml
- /data/data/####/DtdzRhe_config.xml
- /data/data/####/FBAdPrefs.xml
- /data/data/####/SDKIDFA.xml
- /data/data/####/STICKER.xml
- /data/data/####/TwitterAdvertisingInfoPreferences.xml
- /data/data/####/XZFOtherDz.xml
- /data/data/####/XZFOther_conf.xml
- /data/data/####/a86e70777b30
- /data/data/####/com.crashlytics.prefs.xml
- /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
- /data/data/####/com.crashlytics.settings.json
- /data/data/####/com.facebook.ads.FEATURE_CONFIG.xml
- /data/data/####/com.google.android.gms.measurement.prefs.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dtdzrhesms.db
- /data/data/####/dtdzrhesms.db-journal
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/gdaemon_20161017
- /data/data/####/gx_sp.xml
- /data/data/####/https_googleads.g.doubleclick.net_0.localstorage-journal
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c.pid
- /data/data/####/initialization_marker
- /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.andr...ng.xml
- /data/data/####/libjiagu1097821727.so
- /data/data/####/multidex.version.xml
- /data/data/####/otherdzdx.db
- /data/data/####/otherdzdx.db-journal
- /data/data/####/otherdzzx.apkdata
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/sa_f41030e3-5c59-4fa3-a606-3bfbb1e866ef_1550518146841.tap
- /data/data/####/session_analytics.tap
- /data/data/####/session_analytics.tap (deleted)
- /data/data/####/session_analytics.tap.tmp
- /data/data/####/tdata_IKl114
- /data/data/####/tdata_IKl114.jar
- /data/data/####/tdata_qHR433
- /data/data/####/tdata_qHR433.jar
- /data/data/####/webview.db-journal
- /data/data/####/webviewCache.db
- /data/data/####/webviewCache.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.zalo.cm.db
- /data/media/####/tdata_IKl114
- /data/media/####/tdata_qHR433
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24057 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24057 300 0
- getuiext2
- libjiagu1097821727
- AES-CBC-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding