Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) f####.1x####.com:80
- TCP(HTTP/1.1) sc####.1x####.com:80
- TCP(HTTP/1.1) api.map.b####.com:80
- TCP(HTTP/1.1) o####.5####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(TLS/1.0) sc####.1x####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) api.w####.com:443
- TCP c####.g####.ig####.com:5224
- TCP sdk.o####.t####.####.com:5224
- api.map.b####.com
- api.w####.com
- c####.g####.ig####.com
- c.sz.gt.####.com
- f####.1x####.com
- f####.1x####.com
- hm.b####.com
- loc.map.b####.com
- o####.5####.com
- sc####.1x####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- api.map.b####.com/geocoder/v2/?ak=####&callback=####&location=####&outpu...
- f####.1x####.com/upload/201603251606274076661.jpg
- f####.1x####.com/upload/201603251608576097746.jpg
- f####.1x####.com/upload/201603251618242777353.jpg
- f####.1x####.com/upload/201604022009053249434.jpg
- f####.1x####.com/upload/201604260920023041443.jpg
- f####.1x####.com/upload/201604261800343941468.jpg
- f####.1x####.com/upload/201604261800536189176.jpg
- f####.1x####.com/upload/201604261803566608141.jpg
- f####.1x####.com/upload/201604261804377935944.jpg
- f####.1x####.com/upload/201604261804580301040.jpg
- f####.1x####.com/upload/201604261805161851488.jpg
- f####.1x####.com/upload/201604261805301998707.jpg
- f####.1x####.com/upload/201604261805433406226.jpg
- f####.1x####.com/upload/201604261806025183548.jpg
- f####.1x####.com/upload/201604261806156232817.jpg
- f####.1x####.com/upload/20160426180628242812.jpg
- f####.1x####.com/upload/201604261806426988266.jpg
- f####.1x####.com/upload/201604261806560209956.jpg
- f####.1x####.com/upload/20160426180726640623.jpg
- f####.1x####.com/upload/201604261807444631542.jpg
- f####.1x####.com/upload/201604261808074246546.jpg
- f####.1x####.com/upload/201604261808360237879.jpg
- f####.1x####.com/upload/201604261808493593692.jpg
- f####.1x####.com/upload/201604261810076714573.jpg
- f####.1x####.com/upload/201604261810234822708.jpg
- f####.1x####.com/upload/201604261810527207226.jpg
- f####.1x####.com/upload/201604270858211834749.jpg
- f####.1x####.com/upload/201604270858427413455.jpg
- f####.1x####.com/upload/201605241723179343834.jpg
- f####.1x####.com/upload/201607061903470168160.png
- f####.1x####.com/upload/201607061904143559751.png
- f####.1x####.com/upload/201607061904473531012.png
- f####.1x####.com/upload/201607061905250396546.png
- f####.1x####.com/upload/20160706190552746109.png
- f####.1x####.com/upload/201607061911556643108.png
- f####.1x####.com/upload/2018-11/2018-11-12/201811121028194251998.gif
- f####.1x####.com/upload/2018-12/2018-12-18/201812181145337973252.jpg
- f####.1x####.com/upload/2018-12/2018-12-18/201812181641314909147.jpg
- o####.5####.com/Public/img/hezuo/hz_10_32.jpg
- o####.5####.com/user/myscript/1574d0153bb719.html
- sc####.1x####.com/phone/index.html?fromSource=####&deviceType=####&appNa...
- sc####.1x####.com/upload/201603251611505751899.jpg
- sc####.1x####.com/upload/201603251615125163843.jpg
- sc####.1x####.com/phoneLoginReg/updatePushInfoForAndroid.html
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.jg.ic
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/f_000016
- /data/data/####/f_000017
- /data/data/####/f_000018
- /data/data/####/f_000019
- /data/data/####/f_00001a
- /data/data/####/f_00001b
- /data/data/####/f_00001c
- /data/data/####/f_00001d
- /data/data/####/f_00001e
- /data/data/####/f_00001f
- /data/data/####/f_000020
- /data/data/####/f_000021
- /data/data/####/f_000022
- /data/data/####/f_000023
- /data/data/####/f_000024
- /data/data/####/f_000025
- /data/data/####/f_000026
- /data/data/####/f_000027
- /data/data/####/f_000028
- /data/data/####/f_000029
- /data/data/####/f_00002a
- /data/data/####/f_00002b
- /data/data/####/f_00002c
- /data/data/####/f_00002d
- /data/data/####/f_00002e
- /data/data/####/f_00002f
- /data/data/####/f_000030
- /data/data/####/f_000031
- /data/data/####/f_000032
- /data/data/####/f_000033
- /data/data/####/f_000034
- /data/data/####/f_000035
- /data/data/####/f_000036
- /data/data/####/f_000037
- /data/data/####/firll.dat
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c.pid
- /data/data/####/libjiagu.so
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/push.pid
- /data/data/####/push.xml
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.cuid
- /data/media/####/app.db
- /data/media/####/com.ehxz.demo.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/ller.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/test.0
- /data/media/####/yoh.dat
- /data/media/####/yol.dat
- /data/media/####/yom.dat
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getuiext2
- libjiagu
- locSDK6a
- weibosdkcore
- AES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding