Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) aserver####.m.ta####.com:80
- TCP(HTTP/1.1) gd.a.s####.com:80
- TCP(HTTP/1.1) a####.wagbr####.t####.####.com:80
- TCP(HTTP/1.1) idm.bce.b####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) c####.e.qq.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) ckm.i####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) cm.g.doublec####.net:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) bs####.opt####.cn:80
- TCP(HTTP/1.1) ic####.cm.adma####.####.cn:80
- TCP(HTTP/1.1) st####.bs####.cn.####.com:80
- TCP(HTTP/1.1) m.reac####.cn:80
- TCP(HTTP/1.1) its.fuge####.com:80
- TCP(HTTP/1.1) bx.opt####.asia:80
- TCP(HTTP/1.1) cm.fas####.net:80
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5225
- 7j####.c####.z0.####.com
- a.appj####.com
- b####.opt####.asia
- b####.opt####.cn
- bs####.opt####.cn
- bx.opt####.asia
- c####.e.qq.com
- c####.g####.ig####.com
- c-h####.g####.com
- c.appj####.com
- c.yes.y####.com
- ckm.i####.com
- cm.fas####.net
- cm.g.doublec####.net
- cm.op####.com
- cm.qt####.com
- cm.vam####.com
- cms.t####.com
- ic####.cm.adma####.####.cn
- idm.bce.b####.com
- its.fuge####.com
- m####.com
- m.reac####.cn
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- st####.bs####.cn
- t.go.s####.com
- a####.wagbr####.t####.####.com/t.gif?id=####&extendata=####
- aserver####.m.ta####.com/cm.gif?dspid=####
- bs####.opt####.cn/bshare_view?Callback=####&url=####&h=####&uuid=####&sc...
- bx.opt####.asia/cms.gif?a=####&c=####
- bx.opt####.asia/cms.gif?a=####&mzid=####
- bx.opt####.asia/cms.gif?a=####&origin=####&google_error=####
- bx.opt####.asia/cms.gif?a=####&suid=####&ver=####
- bx.opt####.asia/cms.gif?a=####&uid=####
- bx.opt####.asia/cms.gif?a=####&xxid=####
- bx.opt####.asia/cms.gif?tid=####&ver=####&extendata=####&a=####
- bx.opt####.asia/gdt/cms.gif?status=####&id=####&name=####&time=####&j=##...
- c####.e.qq.com/cm.fcg?a=####&j=####&time=####
- ckm.i####.com/pixel?qiyi_nid=####&qiyi_n####
- cm.fas####.net/?dspid=####&hparam=####&gethuid=####&dspuid=####
- cm.g.doublec####.net/pixel?google_nid=####&googl####&origin=####
- cm.g.doublec####.net/pixel?google_nid=####&google_cm=####&origin=####&go...
- gd.a.s####.com/cm.gif?ver=####&mid=####&uid=####
- ic####.cm.adma####.####.cn/?tid=####&type=####&uid=####&redir=h####
- idm.bce.b####.com/t/ping.gif?dm=####&ac=####&v=####&rnd=####&ext_bce_tid...
- its.fuge####.com/bg.gif?p=####&g=####
- m.reac####.cn/rm.gif?ext=####
- st####.bs####.cn.####.com/b/bshareC0.js
- st####.bs####.cn.####.com/b/buttonLite.js
- st####.bs####.cn.####.com/b/components/bsMore.js?v=####
- st####.bs####.cn.####.com/b/components/bsStatic.js?v=####
- st####.bs####.cn.####.com/b/engines/bs-engine.js?v=####
- st####.bs####.cn.####.com/b/styles/bshareS887.js?v=####
- st####.bs####.cn.####.com/cm.html?cid=####&m=####
- st####.bs####.cn.####.com/frame/images//background-opaque-dark.gif
- st####.bs####.cn.####.com/frame/images/background-opaque-dark.png
- t####.c####.q####.####.com/tdata_Rnl693
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_siA393
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a.appj####.com/jiagu/check/upgrade
- c-h####.g####.com/api.php?format=####&t=####
- c.appj####.com/ad/splash/stats.html
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.jg.ic
- /data/data/####/ad_show_time.xml
- /data/data/####/clientid_igexin.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/file__0.localstorage-journal
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/io.dcloud.felix.xml
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/libjiagu.so
- /data/data/####/pdr.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/stream_permission.xml
- /data/data/####/tdata_Rnl693
- /data/data/####/tdata_Rnl693.jar
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_siA393
- /data/data/####/tdata_siA393.jar
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/io.dcloud.felix.bin
- /data/media/####/io.dcloud.felix.db
- /data/media/####/tdata_Rnl693
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_siA393
- /data/media/####/temp.arm
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/io.dcloud.feature.apsGt.GTNormalPushService 24479 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/io.dcloud.feature.apsGt.GTNormalPushService 24479 300 0
- getuiext2
- libjiagu
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA
- RSA-ECB-NoPadding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-ECB-PKCS5Padding