Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) a####.u####.com.####.com:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) 2####.58.208.106:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) 2####.58.214.14:443
- TCP(TLS/1.0) st0.d####.com:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) api.xs####.com:443
- TCP(TLS/1.2) 2####.58.208.106:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 2####.58.208.99:443
- TCP api.xs####.com:443
- TCP st0.d####.com:443
- a####.exc.mob.com
- a####.u####.com
- and####.b####.qq.com
- and####.google####.com
- android####.go####.com
- api.growi####.com
- api.s####.mob.com
- api.xs####.com
- instant####.google####.com
- m.d####.mob.com
- st0.d####.com
- t####.growi####.com
- t.growi####.com
- www.gst####.com
- api.s####.mob.com/v4/cconf?appkey=####&plat=####&apppkg=####&appver=####...
- st0.d####.com:443/xsb/3/templets/0/20210803-221253-bee9.gif
- t####.growi####.com:443/products/9f0d781f62086c68/android/<Package>/sett...
- t.growi####.com:443/app/9f0d781f62086c68/android/devices?u=####&dm=####&...
- a####.u####.com.####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- api.growi####.com:443/v2/9f0d781f62086c68/android/action?stm=####
- api.growi####.com:443/v2/9f0d781f62086c68/android/pv?stm=####
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/snsconf
- /data/data/####/.dic_lock
- /data/data/####/.globalLock
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/.lock
- /data/data/####/.mps
- /data/data/####/.mrecord
- /data/data/####/.mrecord (deleted)
- /data/data/####/.mrlock
- /data/data/####/.pkg_lock
- /data/data/####/.slw
- /data/data/####/.statistics
- /data/data/####/1004
- /data/data/####/32c5ea26b3e992c3b0ce82a464fc8589001d92e222db921...2181.0
- /data/data/####/5ba392b62d3c7f108c7277b52f5b303d7423ec920e9c818....0.tmp
- /data/data/####/956db59beff51fa887a45588efe6e2f6613ef45478b7779....0.tmp
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/bc49e2e78d5028aa4ca32f0903334e58b66f213e2ec78d6...5fec.0
- /data/data/####/bugly_db_
- /data/data/####/bugly_db_-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.oat
- /data/data/####/classes.oat.flock (deleted)
- /data/data/####/com.hlg.xsbapp;pushservice.growing.db
- /data/data/####/com.hlg.xsbapp;pushservice.growing.db-journal
- /data/data/####/com.hlg.xsbapp;videoedit.growing.db
- /data/data/####/com.hlg.xsbapp;videoedit.growing.db-journal
- /data/data/####/com.hlg.xsbapp_preferences.xml
- /data/data/####/crashrecord.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/getui_sp.xml
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid.xml
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/hlg_xsb.db-journal
- /data/data/####/init_c1.pid
- /data/data/####/journal
- /data/data/####/libjiagu.so
- /data/data/####/local_crash_lock
- /data/data/####/metrics_guid
- /data/data/####/mob_commons_1
- /data/data/####/native_record_lock
- /data/data/####/proc_auxv
- /data/data/####/security_info
- /data/data/####/share_sdk_1
- /data/data/####/sharesdk.db-journal
- /data/data/####/sys_log_1641165043752540.txt
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/user.info
- /data/data/####/xiaoshibing_video.xml
- /data/media/####/.artc_lock
- /data/media/####/.dic_lock
- /data/media/####/.globalLock
- /data/media/####/.mps
- /data/media/####/.pkg_lock
- /data/media/####/.slw
- /data/media/####/030495691e3c6cd9cce31d4f076de4af.0.tmp
- /data/media/####/030495691e3c6cd9cce31d4f076de4af.1.tmp
- /data/media/####/0414c2f5af5eaf699fdabab87914a1ab.0.tmp
- /data/media/####/0414c2f5af5eaf699fdabab87914a1ab.1.tmp
- /data/media/####/171
- /data/media/####/172
- /data/media/####/173
- /data/media/####/174
- /data/media/####/175
- /data/media/####/176
- /data/media/####/177
- /data/media/####/178
- /data/media/####/179
- /data/media/####/180
- /data/media/####/181
- /data/media/####/182
- /data/media/####/183
- /data/media/####/184
- /data/media/####/185
- /data/media/####/186
- /data/media/####/187
- /data/media/####/188
- /data/media/####/189
- /data/media/####/190
- /data/media/####/191
- /data/media/####/192
- /data/media/####/193
- /data/media/####/194
- /data/media/####/195
- /data/media/####/196
- /data/media/####/197
- /data/media/####/198
- /data/media/####/199
- /data/media/####/200
- /data/media/####/201
- /data/media/####/202
- /data/media/####/203
- /data/media/####/204
- /data/media/####/205
- /data/media/####/206
- /data/media/####/207
- /data/media/####/208
- /data/media/####/209
- /data/media/####/210
- /data/media/####/211
- /data/media/####/212
- /data/media/####/213
- /data/media/####/214
- /data/media/####/215
- /data/media/####/216
- /data/media/####/217
- /data/media/####/389d7b4e641e09db3077c006c9bae4d7.0.tmp
- /data/media/####/389d7b4e641e09db3077c006c9bae4d7.1.tmp
- /data/media/####/6f416a95002f5421bb8662db0b130016.0.tmp
- /data/media/####/6f416a95002f5421bb8662db0b130016.1
- /data/media/####/6f416a95002f5421bb8662db0b130016.1.tmp
- /data/media/####/782e4ffd21472768c087585c0c5afb02.0.tmp
- /data/media/####/782e4ffd21472768c087585c0c5afb02.1.tmp
- /data/media/####/827eadc8aa3ba7ce133430fd0814fc82.0.tmp
- /data/media/####/827eadc8aa3ba7ce133430fd0814fc82.1.tmp
- /data/media/####/8ff3a8a7483129426bbf66c8a9c0a5a7.0.tmp
- /data/media/####/8ff3a8a7483129426bbf66c8a9c0a5a7.1.tmp
- /data/media/####/DINPro-Regular.a69258.woff
- /data/media/####/a753e06b58b699d83d6c87ce7ab04b52.0.tmp
- /data/media/####/a753e06b58b699d83d6c87ce7ab04b52.1.tmp
- /data/media/####/a80eb1ef25163dbfb33bcd8985490804.0.tmp
- /data/media/####/a80eb1ef25163dbfb33bcd8985490804.1.tmp
- /data/media/####/about.48bff3.js
- /data/media/####/about.html
- /data/media/####/app-debug.1eb5ee.js
- /data/media/####/app-debug.html
- /data/media/####/chunk-commons.2966a3.js
- /data/media/####/chunk-vendor.823220.js
- /data/media/####/common-problem-detail.9f7f72.js
- /data/media/####/common-problem-detail.html
- /data/media/####/common-problems.5a5d38.js
- /data/media/####/common-problems.html
- /data/media/####/commons.723e1e.css
- /data/media/####/d2dba02d65ebb4421cce7896d59b294d.0.tmp
- /data/media/####/d2dba02d65ebb4421cce7896d59b294d.1.tmp
- /data/media/####/defa340ec074f299caa82a11645d1362.0
- /data/media/####/defa340ec074f299caa82a11645d1362.0.tmp
- /data/media/####/defa340ec074f299caa82a11645d1362.1
- /data/media/####/defa340ec074f299caa82a11645d1362.1.tmp
- /data/media/####/detail.56411a.js
- /data/media/####/detail.html
- /data/media/####/dist.zip
- /data/media/####/e9ba7efedb937a2d36f516888ada14dc.0.tmp
- /data/media/####/e9ba7efedb937a2d36f516888ada14dc.1.tmp
- /data/media/####/f05329621a748a6ff17364767e7f6fc8.0.tmp
- /data/media/####/f05329621a748a6ff17364767e7f6fc8.1.tmp
- /data/media/####/f4eb0891e2e22f73785ee57840a2beb5.0.tmp
- /data/media/####/f4eb0891e2e22f73785ee57840a2beb5.1.tmp
- /data/media/####/f5877f651137f84fec3990901df683f5.0.tmp
- /data/media/####/f5877f651137f84fec3990901df683f5.1.tmp
- /data/media/####/f6a12770f8e7cae6d4b4d442a8493d8e.0.tmp
- /data/media/####/f6a12770f8e7cae6d4b4d442a8493d8e.1
- /data/media/####/feedback.18f6cc.js
- /data/media/####/feedback.html
- /data/media/####/font_config
- /data/media/####/help-register-vertification-code.0ae9eb.js
- /data/media/####/help-register-vertification-code.html
- /data/media/####/hotcss_lib.bc8065.js
- /data/media/####/index.953102.js
- /data/media/####/index.html
- /data/media/####/jigsaw_templets.zip
- /data/media/####/journal
- /data/media/####/jump.dd09f6.js
- /data/media/####/jump.html
- /data/media/####/loading.d259b7.gif
- /data/media/####/logo-about.212206.png
- /data/media/####/personal_vip.877f44.png
- /data/media/####/personal_vip_newmember.095b00.png
- /data/media/####/personal_vip_visitor.a8f038.png
- /data/media/####/posts-detail.575d84.js
- /data/media/####/posts-detail.html
- /data/media/####/posts-editor.e04d1a.js
- /data/media/####/posts-editor.html
- /data/media/####/posts.e6f4fb.js
- /data/media/####/posts.html
- /data/media/####/protocol-private.8d0ec1.js
- /data/media/####/protocol-private.html
- /data/media/####/protocol-user.f774d6.js
- /data/media/####/protocol-user.html
- /data/media/####/protocol-vip.ba8f59.js
- /data/media/####/protocol-vip.html
- /data/media/####/templet-keyword.b28b36.js
- /data/media/####/templet-keyword.html
- /data/media/####/templet_content.json
- /data/media/####/user-personal-center.b0e661.js
- /data/media/####/user-personal-center.html
- /data/media/####/user-recharge-history.00d3f6.js
- /data/media/####/user-recharge-history.html
- /data/media/####/user-templets-collection.e7b035.js
- /data/media/####/user-templets-collection.html
- /data/misc/####/primary.prof
- /system/bin/sh -c type su
- cat /sys/class/net/wlan0/address
- getprop
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding