Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.w####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) xiu.xi####.com:80
- TCP(HTTP/1.1) down####.w####.com.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) w####.xi####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) dn####.fas####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(SSL/3.0) 9ec8524####.bug####.com:443
- TCP(TLS/1.0) 1####.217.17.142:443
- TCP(TLS/1.0) 9ec8524####.bug####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5224
- 7j####.c####.z0.####.com
- 9ec8524####.bug####.com
- a####.u####.com
- c####.g####.ig####.com
- c-h####.g####.com
- dn####.fas####.com
- down####.w####.com
- l####.tbs.qq.com
- mt####.go####.com
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- w####.xi####.com
- www.w####.com
- x1.xi####.com
- xiu.xi####.com
- dn####.fas####.com//dnionget
- down####.w####.com.####.com/activities/sanyue/chunri-xxh1068x344.jpg
- down####.w####.com.####.com/ad/jifenzadannew7/xxh.jpg
- down####.w####.com.####.com/ad/xunbao/xunbao-xxh.jpg
- down####.w####.com.####.com/faxian/shouchongxxh.jpg
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/tdata_AXX896
- t####.c####.q####.####.com/tdata_BAI450
- t####.c####.q####.####.com/tdata_Fus136
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- w####.xi####.com/vshow/streamname?get_url=####
- xiu.xi####.com/style/wxstyle/release/project/jpxz/banner/ios.jpg
- xiu.xi####.com/upload/xiu/1/75/qq-kvnkmmbltx_pixel_56.com_190309155034.jpg
- xiu.xi####.com/upload/xiu/12/78/sj-kjnxduwkdf_pixel_56.com_190314192514....
- xiu.xi####.com/upload/xiu/15/4/sj-lkdybpygtz_pixel_56.com_181226130218.jpg
- xiu.xi####.com/upload/xiu/16/20/qq-xbhvrqwdpw_pixel_56.com_180918145846....
- xiu.xi####.com/upload/xiu/17/7/sj-wxjrtjbdlx_pixel_56.com_190211103746.jpg
- xiu.xi####.com/upload/xiu/17/99/xihuanni121212_pixel_56.com_181224214523...
- xiu.xi####.com/upload/xiu/21/59/qq-owziqvfvxv_pixel_56.com_190201162611....
- xiu.xi####.com/upload/xiu/24/40/wx-dyviqsmehz_pixel_56.com_181216194804....
- xiu.xi####.com/upload/xiu/24/6/ice121ice_pixel_56.com_170810203804.jpg
- xiu.xi####.com/upload/xiu/28/2/sj-tmznaddawn_pixel_56.com_181005193635.jpg
- xiu.xi####.com/upload/xiu/29/4/wang5299_pixel_56.com_180706131609.jpg
- xiu.xi####.com/upload/xiu/29/91/sj-gebfvcratw_pixel_56.com_180725220304....
- xiu.xi####.com/upload/xiu/30/27/qq-swllnrdphj_pixel_56.com_170724195021....
- xiu.xi####.com/upload/xiu/32/27/xswm04_pixel_56.com_180522210142.jpg
- xiu.xi####.com/upload/xiu/37/76/qq-naegbscddl_pixel_56.com_180311181045....
- xiu.xi####.com/upload/xiu/38/23/sj-qnfwsbfrhh_pixel_56.com_190124145241....
- xiu.xi####.com/upload/xiu/40/71/oqq-hqjfvxtpsg_pixel_56.com_170503175637...
- xiu.xi####.com/upload/xiu/41/8/fjm123456_pixel_56.com_180517170331.jpg
- xiu.xi####.com/upload/xiu/41/89/wx-mskydzykhu_pixel_56.com_190223212959....
- xiu.xi####.com/upload/xiu/41/90/sj-ynqsoursrp_pixel_56.com_190301193017....
- xiu.xi####.com/upload/xiu/47/18/ss000222_pixel_56.com_190210185001.jpg
- xiu.xi####.com/upload/xiu/49/32/sj-sfhykahiqd_pixel_56.com_180621110933....
- xiu.xi####.com/upload/xiu/58/89/qq-hfknqwmsnq_pixel_56.com_1810<Network ...
- xiu.xi####.com/upload/xiu/6/12/wj77777_pixel_56.com_170217130607.jpg
- xiu.xi####.com/upload/xiu/6/9/baiqingmei520_pixel_56.com_190130135742.jpg
- xiu.xi####.com/upload/xiu/61/60/qq-nacflxjqoe_pixel_56.com_171123180950....
- xiu.xi####.com/upload/xiu/64/82/wx-basiuvcxcf_pixel_56.com_181026072512....
- xiu.xi####.com/upload/xiu/65/23/ww8701003_pixel_56.com_190104121620.jpg
- xiu.xi####.com/upload/xiu/72/21/qq-poxmfqmqbw_pixel_56.com_180611225206....
- xiu.xi####.com/upload/xiu/8/86/wx-yfxsdrrecd_pixel_56.com_190302005250.jpg
- xiu.xi####.com/upload/xiu/80/4/sj-vboacvwpck_pixel_56.com_190108154955.jpg
- xiu.xi####.com/upload/xiu/81/0/taobao117452_pixel_56.com_170702211335.jpg
- xiu.xi####.com/upload/xiu/82/24/qq-wbqpcctmrn_pixel_56.com_190227163242....
- xiu.xi####.com/upload/xiu/82/29/wx-oijwpgbqqe_pixel_56.com_190304220802....
- xiu.xi####.com/upload/xiu/85/39/qq-jxdzoixkcl_pixel_56.com_181229121551....
- xiu.xi####.com/upload/xiu/86/68/yanziliyan_pixel_56.com_190117150723.jpg
- xiu.xi####.com/upload/xiu/88/80/wx-svrwmwnkjg_pixel_56.com_190227203600....
- xiu.xi####.com/upload/xiu/90/79/qq-ovwopmztqa_pixel_56.com_180616230256....
- xiu.xi####.com/upload/xiu/92/10/qq-dcsygmdbem_pixel_56.com_181229183312....
- xiu.xi####.com/upload/xiu/92/84/qq-ohnypxymon_pixel_56.com_190206171403....
- xiu.xi####.com/upload/xiu/95/42/qq-yirkliwadi_pixel_56.com_171006215436....
- xiu.xi####.com/upload/xiu/98/35/qq-jrbdlyuadk_pixel_56.com_190123213815....
- xiu.xi####.com/upload/xiu/98/79/sj-cysvnlmfuv_pixel_56.com_190125180243....
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- l####.tbs.qq.com/ajax?c=####&k=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- www.w####.com/index.php?action=####&do=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/01ecb1773015bc8f318f1b969c3b738c6ef95c1f3cde0fd....0.tmp
- /data/data/####/052a38f8065ce95bd1929240b1ca4b51b44ce1ec0a2694b....0.tmp
- /data/data/####/056ddab1dcfa53bfaf54ddf4134454fba621ab4b9f149b3....0.tmp
- /data/data/####/0dcef0f5c462afda98b9da44c0e3e0e5f4289f3595db52c....0.tmp
- /data/data/####/121cabc1c3ff
- /data/data/####/15e452c78fa7b5fbe565b4ecb0472293.0.tmp
- /data/data/####/15e452c78fa7b5fbe565b4ecb0472293.1.tmp
- /data/data/####/1cfd1a71c41db06d6bda8ad458a96d5232b4142cb32cbd9....0.tmp
- /data/data/####/1cfd1a71c41db06d6bda8ad458a96d5232b4142cb32cbd9...46d6.0
- /data/data/####/1e88f9d8fe1afe9679b9273be0b271e91e18eb36245c2a2....0.tmp
- /data/data/####/1f35b6c21e8369ad0fc1d7f0f69950f6c7e7893e7ae0250....0.tmp
- /data/data/####/2b4da5293af8933331194c05b929ac9155eb85d62a6a08c....0.tmp
- /data/data/####/372836c2344323ed6493e20ca2eddacceae46858832c461....0.tmp
- /data/data/####/40de4c4622c2c8cacc88473536373586fe31318182f0119....0.tmp
- /data/data/####/4142e4ae127d78e864ff4c60dbe9f9d13921fb28f776d8e....0.tmp
- /data/data/####/4acf08d683e045d625e5f9945dd1f4d9be2cfd25d81c6a4....0.tmp
- /data/data/####/4d69b774ab234c32b6c2af0e3aece37926d5133a54f21cb....0.tmp
- /data/data/####/522e2e8eca9f163921f1b031026da3cbfef694b6a339a00....0.tmp
- /data/data/####/567dbbf9c18e741cf8d1376202a041d44adca1572376cbe....0.tmp
- /data/data/####/58323f270c8143a3fc5b331378c20d9ba80c8cb2134c6d6....0.tmp
- /data/data/####/58a9e2b23d59780367eb533904f63e1bf7c32e3785a8ef4....0.tmp
- /data/data/####/5e4978a70a61f7d89392d9cc9245cac9eeb6a7c701c7736....0.tmp
- /data/data/####/60c67d5ee9aa6afb865a72b821d4c7380915f4d28274034....0.tmp
- /data/data/####/60e29a0595a1115d382284a780c0fc7e1943c679bd36143....0.tmp
- /data/data/####/67e94a3d3261bf9be1c45e8a12d06ab8ade922d7d662743....0.tmp
- /data/data/####/69bc3f00db3fe0f8998a7851f7703e03125678407fa20eb....0.tmp
- /data/data/####/6b022a2f48735f26e38dd39e59f992d5000517343e7371a....0.tmp
- /data/data/####/6b10ad4cda08144fb863c5a67bec3c181894c95f67972ab....0.tmp
- /data/data/####/71e896f0683a6710637bb5db4cb84857e7151d2c346b4ea....0.tmp
- /data/data/####/722a1039de0c481bc5e1686de8ffbd0ade140f9a13b24e3....0.tmp
- /data/data/####/749e4e80a84f11d7218cb0b5902a417abe4914840e358f4....0.tmp
- /data/data/####/74e7ba219ff0e9947ba606c099c38bd864df0cd71e3c7fa....0.tmp
- /data/data/####/78f1f06b04f44931d891707510c22ee9e6db844a0189c4b....0.tmp
- /data/data/####/8477ac1b3f25fd5a4fdd7ff15e8a3ab3dbd0fb04b4d3259....0.tmp
- /data/data/####/8fbff1323b7130843dd946cd8ffd736c41a36d3f2455e46....0.tmp
- /data/data/####/TrineaAndroidCommon.xml
- /data/data/####/a2e0be0aef2f4f0a1caddf9d52b20315370680a7362b13f....0.tmp
- /data/data/####/a31e2095fba8d9f2cdb0a2d89374a2a4c331939809b5879....0.tmp
- /data/data/####/a34fa2f60d131e596eca43581e3c8fc3f28fcde145911b4....0.tmp
- /data/data/####/a773dd3e8f68abbf62bb900f7443fd1d18f2b961b9c0628....0.tmp
- /data/data/####/a9a421d5a38d9e4f6f7be448bcdd89c762669ff42daad51....0.tmp
- /data/data/####/b2a08c8c04c5c75517ab1f661097bb68622162982af1134....0.tmp
- /data/data/####/b36cb6a0a6e0df36be94f618f42604141d408a73df9b710....0.tmp
- /data/data/####/b4cde0e85faa6ce9bac7bf2f7ccd335f0bf768066f82986....0.tmp
- /data/data/####/b7df2116c9826b897eec7b5e97598c1518706a76606eca6....0.tmp
- /data/data/####/be56022791054108e4ba315cc366a96176740f21b10d4e4....0.tmp
- /data/data/####/bfa6464ccff6858388e91bdae356dbec891e4a4145f4572....0.tmp
- /data/data/####/c04915768f75c22baf3a7a8ebc8cb59d2a0c6bebc3c83bb....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/ce1a847bcb0c8e7bb8c5672edfe80d581da24239a7c7c72....0.tmp
- /data/data/####/core_info
- /data/data/####/d61cfa3b846d70c9c483535a64e269dc81670c3127bfe18....0.tmp
- /data/data/####/ec3472683a3e0578bc6ecaee386ade043e872472c9f8284....0.tmp
- /data/data/####/ed23337b4fd8d51b00a62c3acb8d42f46051eeb73b20044....0.tmp
- /data/data/####/ee72be0f7d0d9ebed45d3047cf12dc02419728baa527ab1....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fc5a5a7b1de15ee1fcf582c09fec0e83b2af474dd9159a3....0.tmp
- /data/data/####/ff408e110089e1af3bf5562843b5bcb079e6bf18dbd5b03....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu616568235.so
- /data/data/####/multidex.version.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_AXX896
- /data/data/####/tdata_AXX896.jar
- /data/data/####/tdata_BAI450
- /data/data/####/tdata_BAI450.jar
- /data/data/####/tdata_Fus136
- /data/data/####/tdata_Fus136.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.wole56.ishow.bin
- /data/media/####/com.wole56.ishow.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_AXX896
- /data/media/####/tdata_BAI450
- /data/media/####/tdata_Fus136
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.DemoPushService 24511 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- getprop ro.product.cpu.abi
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.DemoPushService 24511 300 0
- Bugtags
- getuiext2
- libjiagu616568235
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding