Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) h####.opensp####.cn:80
- TCP(HTTP/1.1) oss.newairc####.com:80
- TCP(HTTP/1.1) onl####.map.b####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
- TCP(HTTP/1.1) a####.map.b####.com:80
- TCP(HTTP/1.1) www.scsy####.cn:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) api.map.b####.com:80
- TCP(HTTP/1.1) d####.opensp####.cn:80
- TCP(TLS/1.0) s####.ml####.cc:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) oss.newairc####.com:443
- TCP(TLS/1.0) h5.newairc####.com:443
- TCP c####.g####.ig####.com:5226
- TCP sdk.o####.t####.####.com:5224
- 7j####.c####.z0.####.com
- a####.b####.qq.com
- a####.map.b####.com
- a####.u####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- and####.cli####.go####.com
- api.map.b####.com
- c####.g####.ig####.com
- c-h####.g####.com
- d####.opensp####.cn
- h####.opensp####.cn
- h5.newairc####.com
- img.newairc####.com
- l####.tbs.qq.com
- onl####.map.b####.com
- oss.newairc####.com
- s####.ml####.cc
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- www.scsy####.cn
- a####.map.b####.com/getmodules?v=####&t=####&mod=####
- a####.map.b####.com/images/copyright_logo_s.png
- api.map.b####.com/?qt=####&ak=####&callback=####
- api.map.b####.com/?qt=####&b=####&l=####&ie=####&oue=####&fromproduct=##...
- api.map.b####.com/api?v=####&ak=####
- api.map.b####.com/getscript?v=####&ak=####&services=####&t=####
- api.map.b####.com/images/blank.gif?product=####&sub_product=####&v=####&...
- api.map.b####.com/location/ip?qt=####&coor=####&ak=####&timeout=####&cal...
- h####.opensp####.cn/launchconfig?t=####&p=####
- onl####.map.b####.com/tile/?qt=####&x=####&y=####&z=####&styles=####&sca...
- oss.newairc####.com/jrsq/pic/201710/31/3b8b4387-4408-46f1-ab7e-ec79ff671...
- oss.newairc####.com/jrsq/pic/201710/31/849a14c5-739f-48f0-be88-bc798c35e...
- oss.newairc####.com/jrsq/pic/201710/31/8b620abc-7e97-4de0-aee5-028c93e25...
- oss.newairc####.com/jrsq/pic/201710/31/bce25de9-6d49-4b1a-981f-d21cbe763...
- oss.newairc####.com/jrsq/pic/201809/27/ff5ec03d-eb53-40fe-b2d1-a5f487493...
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_ntt510
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- www.scsy####.cn//index.php/app/yycurrency/ad.html?type=####
- www.scsy####.cn//index.php/app/yycurrency/home_cat.html?type=####
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20171225/15141914...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20171225/15141915...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20171225/15141916...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20171225/15141917...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180224/15194571...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180224/15194662...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180306/15203404...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180320/15215359...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180322/15217099...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180402/15226655...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180402/15226664...
- www.scsy####.cn//public/ueditor/php/upload/com/qls/img/20180704/15306677...
- www.scsy####.cn/jrsq_html/
- www.scsy####.cn/jrsq_html/css/index.css
- www.scsy####.cn/jrsq_html/css/mui.min.css
- www.scsy####.cn/jrsq_html/css/public.css
- www.scsy####.cn/jrsq_html/css/swiper.min.css
- www.scsy####.cn/jrsq_html/js/common.js
- www.scsy####.cn/jrsq_html/js/core.js
- www.scsy####.cn/jrsq_html/js/jquery-1.10.2.js
- www.scsy####.cn/jrsq_html/js/swiper.min.js
- a####.u####.com/app_logs
- aexcep####.b####.qq.com:8011/rqd/async
- aexcep####.b####.qq.com:8012/rqd/async
- and####.b####.qq.com/rqd/async
- c-h####.g####.com/api.php?format=####&t=####
- d####.opensp####.cn/index.php/clientrequest/clientcollect/isCollect
- l####.tbs.qq.com/ajax?c=####&k=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/-1015298293
- /data/data/####/-1124754041
- /data/data/####/-1262609044
- /data/data/####/-1293628851
- /data/data/####/-1312716470
- /data/data/####/-1383137677
- /data/data/####/-1383881486
- /data/data/####/-1383881487
- /data/data/####/-1383881578
- /data/data/####/-1383910281
- /data/data/####/-1383911436
- /data/data/####/-1383911437
- /data/data/####/-1383911459
- /data/data/####/-1383911461
- /data/data/####/.imprint
- /data/data/####/04f262c5f7eff238a0a9307262dcd29cae0e93bb393a7b0....0.tmp
- /data/data/####/0dbca9a424affb5d126a2b7ea1d8aecfa8bce9b67781027....0.tmp
- /data/data/####/11510d6aa37c0aae64b3f5f1c54a692c96547df5c104d27....0.tmp
- /data/data/####/12ab59dedb850a7d142ac27403c064a158aad2af2806336....0.tmp
- /data/data/####/1389023919
- /data/data/####/1526646622
- /data/data/####/155637c7e2cc4ea23704ddf5c61b99947971acb8e1aaf7d....0.tmp
- /data/data/####/1671054731
- /data/data/####/1695857311
- /data/data/####/1702074538
- /data/data/####/178536008
- /data/data/####/1864066650
- /data/data/####/1c280173a1e4cc8c435d7bb34452162a5f348c682ef8617....0.tmp
- /data/data/####/1eb7eb583a59c02a2fb9091889b9f20fdf9b01b9a39e450....0.tmp
- /data/data/####/2014265674
- /data/data/####/211c3c76ee224ca70afad4db3830f03c94f650c2df8b4c8....0.tmp
- /data/data/####/23e04b573e0da83e2813ad91be280fd9e36463ec54aaaee....0.tmp
- /data/data/####/2b2f1710074a2bac5e059d0abaf86034ba64a85b38c02e2....0.tmp
- /data/data/####/2efb6e0540f4e37d6f6026c29a91f8d48051fc20c0db01b....0.tmp
- /data/data/####/2f89070bd5069555a77e9de0c37d23f19b3cdc53a61699e....0.tmp
- /data/data/####/2ffa2f0139c9e436fc62f4827e68a8ded27839bfcf4a834....0.tmp
- /data/data/####/386967948
- /data/data/####/409bd4503e3e07af592370f75284e56fd93d769d616c76a....0.tmp
- /data/data/####/4199cbedfc097430199962c667f5e4e65ec1a33689f947a....0.tmp
- /data/data/####/4360b92cf6f9f62c2236a5b11c9139762e4a44039428fd3....0.tmp
- /data/data/####/438cd4ee5509d5aef090324a0dd6f9eb744ecacbfd8c9fd....0.tmp
- /data/data/####/46d9b4346d032e7d03ec245def29a0a5180d0c668febfca....0.tmp
- /data/data/####/492203936
- /data/data/####/4f041101519099e78e66bf0fe753b81948db8859630a39c....0.tmp
- /data/data/####/4ffec881d9719b512e10059c0610e7dee081432cb91fad0....0.tmp
- /data/data/####/51586bed990bfe13f5490ad4f26940a0e61a61fcbf23f28....0.tmp
- /data/data/####/519e6b9e3072e0f34517799fc24aa124a184754321a98eb....0.tmp
- /data/data/####/5316c9c62fa72815770df1572a84e3936ec02c4b1fcca90....0.tmp
- /data/data/####/5ee69b7be1e9e4e99c0279cef12391d04ffffe091d2856d....0.tmp
- /data/data/####/6b3f84ce7c68974ba74dc998d7a05781ca686b2fff9a249....0.tmp
- /data/data/####/6c5650241d671f8b293e321df1edfa574456ed4ab3aac64....0.tmp
- /data/data/####/722611463
- /data/data/####/7c4c22d0c35794434d667122387d037b65c15909bd7661a....0.tmp
- /data/data/####/7c91c2d9e39e7e399d07de5ec65e3fc36dc64c58f1f5a4d....0.tmp
- /data/data/####/83a08d29ce3c5acdfbe39be337c7bb7bd800ca7e3f4af16....0.tmp
- /data/data/####/866b32f28ad32df4cbab2a15a4167180d89adee346ae223....0.tmp
- /data/data/####/8d20d77a6ed0d50856757ea798280a8ac14882cb00716b3....0.tmp
- /data/data/####/926579363
- /data/data/####/988618977
- /data/data/####/9c01fc0e0975a8277febca21d048326f8a038bfee040c76....0.tmp
- /data/data/####/FZLTXHK-GBK_YS.ttf
- /data/data/####/QQ_3x.png
- /data/data/####/ae635be8144924a1fe6aa81ab2950561065f1d618e2debe....0.tmp
- /data/data/####/af8ed8c0864d156864c493b1c2a47c5578070147d87f7c8....0.tmp
- /data/data/####/amazeui.min.css
- /data/data/####/amazeui.min.js
- /data/data/####/angular1.4.6.min.js
- /data/data/####/b0c6b91d62401577ff61e0a408a0fdbf431a268c83d9fa0....0.tmp
- /data/data/####/b420c471de65d6c82a863eb14aa0e03ddc52fb9699b20c2....0.tmp
- /data/data/####/b93a50bddd36ccd22c89599fe3029dab325fdbc80520c14....0.tmp
- /data/data/####/base.css
- /data/data/####/bf55ed02b1cd0fda88d9ebaf14371570d9adb93949a471e....0.tmp
- /data/data/####/bugly_db_legu
- /data/data/####/bugly_db_legu-journal
- /data/data/####/caea2ded7c0a6ff414d226ebad274d510e05c65e4b8c4b7....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cfd75a77a757c2f947bcbda61d0dcd20740b56062e23333....0.tmp
- /data/data/####/columnId.xml
- /data/data/####/com.founder.shunqing-1.apk.classes-1048470369.zip
- /data/data/####/com.iflytek.id.xml
- /data/data/####/com.iflytek.msc.xml
- /data/data/####/core_info
- /data/data/####/d6f56f488a7c2fc5e3bab400922598e2db98ab31b020023....0.tmp
- /data/data/####/d81806d546726f23761a7da5d3ac521f0109e9e81281845....0.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/db_founder0-journal
- /data/data/####/dd8670e4ba4a1e3c32f88e4a1a81d37c174c3505f504cb4....0.tmp
- /data/data/####/ddd8c47d0432ce80f84fbd3329f7219305164281121e79d....0.tmp
- /data/data/####/ddd8c47d0432ce80f84fbd3329f7219305164281121e79d...7ec1.0
- /data/data/####/debug.conf
- /data/data/####/device_id.xml.xml
- /data/data/####/e12ab6e0fc14aa9aac553a57052f980f335dc29f7b23770....0.tmp
- /data/data/####/e69f30b61b59e44b07e4c4c8514fd72b5b12ddf7e105463....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f01c12d156b05fadfd9ecd9b6a39725a4815461c72510d0....0.tmp
- /data/data/####/f0b6486021f95e8f8a1d8a0a52422017ab78c2f3b267906....0.tmp
- /data/data/####/f379ec7a874efef53513ddb0b777104f2eb8aa09659c06a....0.tmp
- /data/data/####/f44b4ad794ea273df9a8f1d424a08693062dfa1f6a21a56....0.tmp
- /data/data/####/f677fde6e35d0129b30117ee36a1cf69f7be7d6670ae979....0.tmp
- /data/data/####/f755819328f09625c2307ee1ee39dba5423b09dc96bb1f6....0.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/fe99c81460fb06172a0415410c51e847cb35fd9c4a25c30....0.tmp
- /data/data/####/fontawesome-webfont.ttf
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/great_button.png
- /data/data/####/great_cancel_button.png
- /data/data/####/gx_sp.xml
- /data/data/####/helpMsg.xml
- /data/data/####/icon-images.png
- /data/data/####/icon_audio_play.png
- /data/data/####/icon_file.png
- /data/data/####/icon_file_down.png
- /data/data/####/icon_meta_voice.png
- /data/data/####/icon_praise.png
- /data/data/####/icon_praiseStar.png
- /data/data/####/icon_selector_normal.png
- /data/data/####/icon_selector_press.png
- /data/data/####/ifly_launch_lib.xml
- /data/data/####/ifly_launch_lib.xml.bak (deleted)
- /data/data/####/iflytek_state_com.founder.shunqing.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/jquery.min2.2.0.js
- /data/data/####/js.combine.min.js
- /data/data/####/libnfix.so
- /data/data/####/libshella-2.10.2.3.so
- /data/data/####/libufix.so
- /data/data/####/loading.png
- /data/data/####/local_crash_lock
- /data/data/####/mix.dex
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/native_record_lock
- /data/data/####/news_detail.html
- /data/data/####/persistent_data.xml
- /data/data/####/play.png
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/reader.db-journal
- /data/data/####/run.pid
- /data/data/####/sanjiaoxing.png
- /data/data/####/security_info
- /data/data/####/shareTimeline_3x.png
- /data/data/####/sina_3x.png
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_ntt510
- /data/data/####/tdata_ntt510.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/video.png
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/wx_3x.png
- /data/media/####/.nomedia
- /data/media/####/app.db
- /data/media/####/com.founder.shunqing.bin
- /data/media/####/com.founder.shunqing.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/iflyworkdir_test
- /data/media/####/journal.tmp
- /data/media/####/localTemplate.zip
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_ntt510
- /data/media/####/test.log
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.GeTuiPushService 25043 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.10.2.3.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.GeTuiPushService 25043 300 0
- Bugly
- getuiext2
- libnfix
- libshella-2.10.2.3
- libufix
- msc
- nfix
- ufix
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding