Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) q####.c####.l####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(HTTP/1.1) www.hufen####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) 2####.205.239.188:80
- TCP(TLS/1.0) www.hufen####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP cm-1####.ig####.com:5226
- TCP 1####.168.107.254:52108
- 7j####.c####.z0.####.com
- c-h####.g####.com
- cm-1####.ig####.com
- pub-####.qin####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- www.hufen####.com
- q####.c####.l####.####.com/config/hz-hzv6.conf
- q####.c####.l####.####.com/tdata_EDT369
- q####.c####.l####.####.com/tdata_Soq141
- q####.c####.l####.####.com/tdata_eTB810
- q####.c####.l####.####.com/tdata_ris804
- q####.c####.l####.####.com/tdata_tQZ349
- sdk.o####.p####.####.com/api/addr.htm
- www.hufen####.com/data/afficheimg/1568682231842088832.jpg
- www.hufen####.com/data/afficheimg/1569300004018762234.jpg
- www.hufen####.com/data/afficheimg/1569573637217517413.jpg
- www.hufen####.com/data/afficheimg/1569798195382170410.jpg
- www.hufen####.com/images/201704/goods_img/747_P_1491958019344.jpg
- www.hufen####.com/images/201704/goods_img/747_P_1491958019739.jpg
- www.hufen####.com/images/201704/goods_img/747_P_1491958019981.jpg
- www.hufen####.com/images/201708/goods_img/747_P_1503019260554.jpg
- www.hufen####.com/images/201708/thumb_img/1960_thumb_G_1503009806718.jpg
- www.hufen####.com/images/201708/thumb_img/747_thumb_G_1503019260172.jpg
- www.hufen####.com/images/201709/thumb_img/618_thumb_G_1505943783559.jpg
- www.hufen####.com/images/201710/thumb_img/1958_thumb_G_1509297209138.jpg
- www.hufen####.com/images/201712/thumb_img/2256_thumb_G_1513795924468.jpg
- www.hufen####.com/images/201904/thumb_img/714_thumb_G_1554248472387.jpg
- www.hufen####.com/images/201907/thumb_img/865_thumb_G_1564009602616.jpg
- www.hufen####.com/images/201908/thumb_img/813_thumb_G_1564680331170.jpg
- www.hufen####.com/images/201909/thumb_img/2102_thumb_G_1567908422781.jpg
- www.hufen####.com/images/201909/thumb_img/575_thumb_G_1569543531888.jpg
- www.hufen####.com/images/201909/thumb_img/848_thumb_G_1568602832750.jpg
- www.hufen####.com/images/upload/Image/阳光金果.jpg
- www.hufen####.com/images/upload/Image/龙快递说明最新.jpg
- c-h####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.jg.ic
- /data/data/####/3XVTjKVCqgjS1xaoE6zwPdB0XvM.615311366.tmp
- /data/data/####/4ShNWkWD9uiFRc_9xYhJqkdo-AE.736848625.tmp
- /data/data/####/5p3vyHS6hddXVSD77jXe92rCew8.-418312337.tmp
- /data/data/####/78db8ee70e96
- /data/data/####/78sDRxyeZYDPNV5SalAWj14Tf-w.1415411579.tmp
- /data/data/####/FmfJQIiPf6OOVMKhu-6sIAehOdM.2123313367.tmp
- /data/data/####/FydTsM9lnOWUA1dgI3dnZuh1pBw.-113032800.tmp
- /data/data/####/Ien5nvJ5yLAouIXnOkt0-g9tPjw.2038862458.tmp
- /data/data/####/KUZK7nCc7EuBHwgsnG8Z17np_SA.-975119667.tmp
- /data/data/####/MultiDex.lock
- /data/data/####/SAh5ptiy6JyVM8YjKF5Ebg_spAI.17026892.tmp
- /data/data/####/VV0TjRl9omjkWjte-kPP7wMwRFI.-1899638210.tmp
- /data/data/####/VfTYt4OeoWwYxu-2Thk4nQkks90.197849649.tmp
- /data/data/####/X8pn6yD18OZteL_p7oVi9fYlHig.2024446121.tmp
- /data/data/####/_Qprz55Qsc1gCxaWXP1mNX3t6rQ.1540463809.tmp
- /data/data/####/_t_yPgaFCldJ3u1yEvMdY81k6EQ.433065613.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/gdaZoceuYIoCyDES28Jxz-HLz2A.-350941666.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/hfd_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu946464725.so
- /data/data/####/local_crash_lock
- /data/data/####/multidex.version.xml
- /data/data/####/oyG4F01sLapu3X6vGjS1GywQqBo.1408802816.tmp
- /data/data/####/pKrRT5_JwqVBZbhkFico5nLM5iE.2099150938.tmp
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_eTB810
- /data/data/####/tdata_eTB810.jar
- /data/data/####/tdata_ris804
- /data/data/####/tdata_ris804.jar
- /data/data/####/tdata_tQZ349
- /data/data/####/tdata_tQZ349.jar
- /data/data/####/utT5Yk0uyQUrKBLrd5gLi6PjJKc.1461533081.tmp
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/zivDtY9XggItCXeu45PS_FLuy9U.-1011701707.tmp
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.winhands.hfd.bin
- /data/media/####/com.winhands.hfd.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_eTB810
- /data/media/####/tdata_ris804
- /data/media/####/tdata_tQZ349
- /data/media/####/test.log
- /system/bin/cat /proc/cpuinfo
- /system/bin/sh -c getprop androVM.vbox_dpi
- /system/bin/sh -c getprop gsm.sim.state
- /system/bin/sh -c getprop gsm.sim.state2
- /system/bin/sh -c getprop qemu.sf.fake_camera
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.debuggable
- /system/bin/sh -c getprop ro.genymotion.version
- /system/bin/sh -c getprop ro.secure
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.receiver.getuipush.DemoPushService 24577 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu946464725.so
- getprop androVM.vbox_dpi
- getprop gsm.sim.state
- getprop gsm.sim.state2
- getprop qemu.sf.fake_camera
- getprop ro.board.platform
- getprop ro.debuggable
- getprop ro.genymotion.version
- getprop ro.secure
- mount
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.receiver.getuipush.DemoPushService 24577 300 0
- Bugly
- getuiext2
- imagepipeline
- libjiagu946464725
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding