Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) luna-im####.qq.com.####.com:80
- TCP(HTTP/1.1) down####.w####.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(TLS/1.0) securit####.sp####.mig.####.net:443
- TCP(TLS/1.0) down####.w####.com:443
- TCP(TLS/1.0) w####.xi####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) dm.tou####.com.####.com:443
- TCP(TLS/1.0) safebro####.google####.com:443
- TCP(TLS/1.0) s####.e.qq.com:443
- TCP(TLS/1.2) 2####.58.208.110:443
- TCP(TLS/1.2) inte####.faceu####.com:6443
- TCP(TLS/1.2) 1####.217.168.195:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 1####.250.179.138:443
- TCP dm.tou####.com.####.com:443
- a####.u####.com
- and####.b####.qq.com
- and####.google####.com
- api-ac####.pangoli####.com
- dm.tou####.com
- dn####.d####.com
- down####.w####.com
- imgc####.qq.com
- inte####.faceu####.com
- pang####.sn####.com
- s####.e.qq.com
- safebro####.google####.com
- sf3-fe####.pglstat####.com
- sf3-ttc####.ps####.com
- t####.m.qq.com
- to####.ctobsn####.com
- w####.xi####.com
- www.w####.com
- xiu.xi####.com
- dm.tou####.com.####.com:443/service/2/app_alert_check/?aid=####&tt_info#...
- down####.w####.com/activities/caidan/ip13/xxh1068x344.jpg
- down####.w####.com/faxian/shouchongxxh.jpg
- down####.w####.com/xiu/kanshipindeyangguang/xxh1068x344.jpg
- down####.w####.com:443/upload/xiu/0/60/gygxh94_union_b_171002075656_2427...
- down####.w####.com:443/upload/xiu/0/64/sj-ohppysareo_3_550x550_220217010...
- down####.w####.com:443/upload/xiu/13/82/sj-kzbfdupklu_3_550x550_21070721...
- down####.w####.com:443/upload/xiu/13/88/gygxh87_union_b_171002074147_828...
- down####.w####.com:443/upload/xiu/18/12/qq-txkpthdpdv_3_550x550_20061720...
- down####.w####.com:443/upload/xiu/23/1/qq-zpmkklasej_3_550x550_211128204...
- down####.w####.com:443/upload/xiu/23/80/wx-bfpdavvbbm_3_550x550_21010316...
- down####.w####.com:443/upload/xiu/24/6/ice121ice_pixel_56.com_1909082149...
- down####.w####.com:443/upload/xiu/29/91/sj-gebfvcratw_3_550x550_21101222...
- down####.w####.com:443/upload/xiu/4/5/qq-qtvsexltmn_3_550x550_2003041819...
- down####.w####.com:443/upload/xiu/45/35/sj-hjjwxkmdhh_3_550x550_20110516...
- down####.w####.com:443/upload/xiu/47/15/qq-xyezlhvyuv_3_550x550_20071413...
- down####.w####.com:443/upload/xiu/61/78/qq-sgwkgzifjg_3_550x550_20041000...
- down####.w####.com:443/upload/xiu/64/10/wx-iezpungekx_3_550x550_21080122...
- down####.w####.com:443/upload/xiu/73/1/sj-utfuoepbgp_3_550x550_210508165...
- down####.w####.com:443/upload/xiu/75/9/qq-ijrlnnwcdu_3_550x550_220120004...
- down####.w####.com:443/upload/xiu/80/34/qq-ompljwaxwf_3_550x550_22020818...
- down####.w####.com:443/upload/xiu/82/21/gygxh91_union_b_171002074846_155...
- down####.w####.com:443/upload/xiu/87/47/qq-kseymoaozl_3_550x550_19120916...
- down####.w####.com:443/upload/xiu/88/34/gygxh92_union_b_171002075055_161...
- down####.w####.com:443/upload/xiu/96/53/sj-bwentblumw_3_550x550_20101520...
- down####.w####.com:443/upload/xiu/97/93/qq-bprhzlszoz_3_550x550_21020123...
- down####.w####.com:443/upload/xiu/98/85/litingxiu_3_550x550_211108154409...
- down####.w####.com:443/upload/xiu/99/69/qq-erezdsurio_3_550x550_21052700...
- luna-im####.qq.com.####.com/qzone/biz/gdt/mod/android/AndroidAllInOne/pr...
- w####.xi####.com:443/vshow/streamname?get_url=####
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async
- dm.tou####.com.####.com:443/service/2/app_log/?device_platform=####&vers...
- dm.tou####.com.####.com:443/service/2/device_register_only/?aid=####&tt_...
- dm.tou####.com.####.com:443/service/2/log_settings/?device_platform=####
- down####.w####.com:443/index.php?action=####&do=####
- s####.e.qq.com/activate
- s####.e.qq.com:443/event
- securit####.sp####.mig.####.net:443/?mc=####
- /data/data/####/-1025052814979690616
- /data/data/####/-1561220934775701699
- /data/data/####/.bak
- /data/data/####/.cl
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.turing.dat
- /data/data/####/012ef73172d6d5a3445311b6b5f05dac436d783a8223d3e....0.tmp
- /data/data/####/08d1eb4d7b794f29fa44161f36d46f040e97dd5b880a750...d0f1.0
- /data/data/####/0a63ab1aa20c4f6514537070a1985e0267008536dc754e6....0.tmp
- /data/data/####/0bf1835049fce713b781bda75673732c89505aa7a02689e....0.tmp
- /data/data/####/1028bb52a4d3fe9f91b4fcb12c7f5a189204d54bf4968de....0.tmp
- /data/data/####/1495915e020b1dde314d29b7144c34789cd1f96a144c57b....0.tmp
- /data/data/####/17f5e5b812baece18e19c2bdcdf758dbe7a338392637dac....0.tmp
- /data/data/####/193f9c7c476b55b7d40e4efccaa32aeade03c5bdd5a4ce0....0.tmp
- /data/data/####/21567cf09fa86d1bab5d7c7e0959d819b9a8500ab557815....0.tmp
- /data/data/####/22e1acc1844887e3f190f575e28e0bb7fbd988875140157...9e1f.0
- /data/data/####/2377463b2ca7d6c322ce200bab79cca1fdb9e925d040a26....0.tmp
- /data/data/####/23801e9069d8b145dc8734e75c685280ab375f338d31d73....0.tmp
- /data/data/####/30dd98fcf9b0d6cd00d7142caa2b28c57e0ec525e3c20e7....0.tmp
- /data/data/####/3379.yaqcookie
- /data/data/####/39b424d18f0904a74222720a284fc756795cde40e1f53cc....0.tmp
- /data/data/####/3c734150d245620787355a9bf3078e2022f7fd558e50c24....0.tmp
- /data/data/####/4266f9491872af1a2f4d0bef68d22aec990eb5ebb7ac022....0.tmp
- /data/data/####/429f68bbcc79982d414c6f4faf2bf4efd0b6a4408649ed6....0.tmp
- /data/data/####/45a8d247fa87f011f6dea416d16fa2090a826c2554ef295....0.tmp
- /data/data/####/46f019c514c026041c87e3e4b527d4b19472b431d5f7b24....0.tmp
- /data/data/####/4e3987f291869f24077dc22ddf4955a274d09d1c14dcf69...a9f0.0
- /data/data/####/508bf2daefece05fce150adbb515c8ea3f60e9d294dfdd6....0.tmp
- /data/data/####/55cc65c40ceef66b0f01652a480f9b08d63dcb9adbf35a0....0.tmp
- /data/data/####/5d93939cfd0c8a503990b799d36454a83c6c593c43d05f4....0.tmp
- /data/data/####/63a4f503d63b004a8908004a729d993ce500857e7c562f2....0.tmp
- /data/data/####/7467e292b6c6f37243d7649cb529ffaa0573c3ade20d457...4943.0
- /data/data/####/7766dd2ee3dce9f3f4061511436ef9dff468bcfda365150....0.tmp
- /data/data/####/79aaa5431263590ccebe4e089f257c83b24c30491cfb631....0.tmp
- /data/data/####/87e3cbade64c41232e6bf777b0184769839692e4e2627b9....0.tmp
- /data/data/####/89cb25b8a0f2440ba20269537d467fbf77f431d4f1ba8ae...237b.0
- /data/data/####/907653126a69558dbb76f088b59df148bc0cae8a8994c46....0.tmp
- /data/data/####/93ffe094bb78b8dc401c4441b9498bbb6ae0647dbca413e....0.tmp
- /data/data/####/9badadb77df5c2b7b8925e217b8bfd3863f75319fa24b80....0.tmp
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/TrineaAndroidCommon.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/a8f6c8fcede2a0330f38282c168bad96c39a5297ec35b10....0.tmp
- /data/data/####/aa0eb2649ebcb93bfdcc35ca811b1d872268422c0e4b420....0.tmp
- /data/data/####/aee3d54046c623d2b1ddff793e1923acc3b909209ceecbb....0.tmp
- /data/data/####/afdb00f20b3c6e7680b408cc8cdc7fb6b3f759571fb94cb...8b06.0
- /data/data/####/b9089d46642d78dfac1c3c22717acf28930b639c9a72936....0.tmp
- /data/data/####/bc8ce914675054aa97d76df4df21fbdc0652f7313ae7671....0.tmp
- /data/data/####/bd_embed_tea_agent.db-journal
- /data/data/####/bugly_db_-journal
- /data/data/####/c1dcf06ee2d1a7789186b86f41436869f0c6ab1d0e8b955....0.tmp
- /data/data/####/c2c5e0a2f5217f1a02d05442eaa04ed2f2d780d1eddbc01...c301.0
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/com.wole56.ishow_preferences.xml
- /data/data/####/core_info
- /data/data/####/dbfccd7721eff6c73415ce9be8d11ab71d92edf848b8980....0.tmp
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/download_upload
- /data/data/####/downloader.db-journal
- /data/data/####/ea843b0d7e57c8b0ec9b0225de01de63cd36af1b328043b....0.tmp
- /data/data/####/ed74d74bb0f2db5d3caee0912517ea0b88ca6fd81234544....0.tmp
- /data/data/####/ef759152e068d43df1f9f32fd5a722c0a61aeadc8c98209....0.tmp
- /data/data/####/embed_applog_stats.xml
- /data/data/####/embed_header_custom.xml
- /data/data/####/embed_last_sp_session.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f09b04b78cd84176dc20f4bd1eca9d1d73b3eba06883bdd....0.tmp
- /data/data/####/f5198e9904f062c82490e37a0c9ec84135d79587ce423ed....0.tmp
- /data/data/####/f5872227138eb38302a04aa2e589581953ff26e8c009b61....0.tmp
- /data/data/####/f61214db748954e8f8996c075a4087b6d89b73b4b45a48e....0.tmp
- /data/data/####/f6f2ae8ddcd3d64ed679a56027837f8936289107ccaaa76...ff6d.0
- /data/data/####/fb5b050f3d09bf417d9968357ca629e9cae394270f5438e....0.tmp
- /data/data/####/fc9f92dbe294c3778ae246986886ec676cf8e77edcc3c6f...807c.0
- /data/data/####/fced07abe083c26a356aed5965f6d83648dcc0f85e07725....0.tmp
- /data/data/####/gdt_config.cfg
- /data/data/####/gdt_plugin.dex
- /data/data/####/gdt_plugin.dex.flock (deleted)
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_stat.db
- /data/data/####/gdt_stat.db-journal
- /data/data/####/gdt_suid
- /data/data/####/journal
- /data/data/####/libMMANDKSignature.1023711b.so
- /data/data/####/libjiagu.so
- /data/data/####/libturingau.1023711b.so
- /data/data/####/libyaqbasic.1023711b.so
- /data/data/####/libyaqpro.1023711b.so
- /data/data/####/local_crash_lock
- /data/data/####/metrics_guid
- /data/data/####/mpdc_105498_1
- /data/data/####/native_record_lock
- /data/data/####/npth.xml
- /data/data/####/npth_log.db-journal
- /data/data/####/proc_auxv
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/security_info
- /data/data/####/snssdk_openudid.xml
- /data/data/####/sp_multi_ttadnet_config.xml
- /data/data/####/sp_push_time.xml
- /data/data/####/ss_app_config.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tt_sdk_settings.xml
- /data/data/####/tt_sdk_settings.xml.bak
- /data/data/####/ttnet_tnc_config.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/turingfd_conf_105498_auMini.xml
- /data/data/####/turingfd_conf_105498_auMini.xml.bak
- /data/data/####/turingfd_protect_105498_41_auMini.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/update_lc
- /data/data/####/yaq.1023711b.sec
- /data/data/####/yaq2.1023711b.sec
- /data/data/####/yaq3_0.1023711b.sec
- /data/data/####/yaqsdkcookie
- /system/bin/df
- /system/bin/getprop
- /system/bin/sh -c getprop ro.genymotion.version
- /system/bin/sh -c type su
- app_process /system/bin com.android.commands.pm.Pm list package -3
- chmod 777 /data/user/0/<Package>/cache/Download
- getprop androVM.vbox_dpi
- getprop gsm.sim.state
- getprop gsm.sim.state2
- getprop qemu.sf.fake_camera
- getprop ro.board.platform
- getprop ro.build.version.emui
- getprop ro.debuggable
- getprop ro.genymotion.version
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.secure
- sh
- libBugly
- libMMANDKSignature.1023711b
- libjiagu
- libnama
- libnms
- libtobEmbedEncrypt
- libturingau.1023711b
- libyaqbasic.1023711b
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding