Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) img.newairc####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) h5.newairc####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(TLS/1.0) oss.newairc####.com:443
- TCP(TLS/1.0) 1####.217.168.238:443
- TCP(TLS/1.0) s####.ml####.cc:443
- TCP(TLS/1.0) h5.newairc####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- 7j####.c####.z0.####.com
- a####.u####.com
- a.appj####.com
- c####.g####.ig####.com
- c-h####.g####.com
- h5.newairc####.com
- img.newairc####.com
- l####.tbs.qq.com
- oss.newairc####.com
- pub-####.qin####.com
- s####.ml####.cc
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- h5.newairc####.com/api/getArticleAdv?sid=####&cid=####&v=####
- h5.newairc####.com/api/getComments?sid=####&rootID=####&sourceType=####&...
- img.newairc####.com/xarb/pic/201809/17/00c0628b-b265-4dbb-a2b7-a0551ba09...
- img.newairc####.com/xarb/pic/201809/17/3147a03c-d0a1-4c17-9687-94ca6ef9d...
- img.newairc####.com/xarb/pic/201809/17/98c4a7c2-4734-42ef-a7c0-16f6b8774...
- img.newairc####.com/xarb/pic/201809/17/b154c0a3-22df-473a-b098-34d1f53a5...
- img.newairc####.com/xarb/pic/201809/17/d88c1325-be42-4621-ae79-f9eb41580...
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/config/hz-hzv6.conf
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_ilz707
- t####.c####.q####.####.com/tdata_siA393
- a####.u####.com/app_logs
- a.appj####.com/ad-service/ad/mark
- c-h####.g####.com/api.php?format=####&t=####
- h5.newairc####.com/api/event
- l####.tbs.qq.com/ajax?c=####&k=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/-1312716470
- /data/data/####/-1383162662
- /data/data/####/-1384058372
- /data/data/####/-1384085252
- /data/data/####/-1384087295
- /data/data/####/-1384089129
- /data/data/####/-1384089152
- /data/data/####/-1384089153
- /data/data/####/-1392773489
- /data/data/####/-1397480940
- /data/data/####/-196126607
- /data/data/####/-2110936501
- /data/data/####/-2141956308
- /data/data/####/-341729750
- /data/data/####/-763553208
- /data/data/####/-804016753
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/05abed5b5804a975b67c4b849c59b97f7f7d108fb9425f6....0.tmp
- /data/data/####/0a41b75f73dfa0e90dcd23258df13afc9ff15c94608b8aa....0.tmp
- /data/data/####/0db8116c919e5cb12e4c1c6ff055d96619775e586088b5b....0.tmp
- /data/data/####/1389023919
- /data/data/####/144eeee8b043aa59eb2eac7d287b42e429a1dcb52129c35....0.tmp
- /data/data/####/1526646622
- /data/data/####/1695857311
- /data/data/####/1b918b05bfc8d8f950e18d74a74b84c9b6b3f87eed3cfa5....0.tmp
- /data/data/####/1f45aa6deffc1d44a36cc1fc38dfe2a97ca28c041388280....0.tmp
- /data/data/####/2014087981
- /data/data/####/22db522e3ff6e1138e24936540820fe55c74eae0fce6873....0.tmp
- /data/data/####/250dfd9c99acb7c46d402df68a8d65af68e3c8fe40df014....0.tmp
- /data/data/####/29c23e86b232bbf6b404778912dcc51102e650b4dfff1db....0.tmp
- /data/data/####/2f256593aa6b8b194bc3ec51ddd6a505796eb57c6387fb4....0.tmp
- /data/data/####/2f7688cea7fb4a62ba14c839cf0ed5d6d067a88c656b226....0.tmp
- /data/data/####/337525857
- /data/data/####/33f1b5d946c1d541397e361f75ac1971af97446034ccc48....0.tmp
- /data/data/####/3482d4176ed7cbcc02b05ecfea896c3126f4dba03ffa2e3....0.tmp
- /data/data/####/3692c992899b247f28c180916ddb5b2fb7dd89dcddc8063....0.tmp
- /data/data/####/36efca9baa7f5cdccda7c32e4b5a58cb58a7e7ff04a7158....0.tmp
- /data/data/####/37ca285b12e471d92e12fee8270e216a16f35a534a72884....0.tmp
- /data/data/####/386967948
- /data/data/####/3d649717480a841d8f1e1f704e7649fc5e7cab2b9e17697....0.tmp
- /data/data/####/3dfd018c7e1896bab5fb649a1fb7f89793fa6772d46c1ba....0.tmp
- /data/data/####/3f1c9486ab162f8e461497a4549940d351063c914191aaf....0.tmp
- /data/data/####/47e51d0cd987a257380de14418b5e18a43bf5b45aad8170....0.tmp
- /data/data/####/48c5306294108e8b64ddec54a429b408575456a606d0e01....0.tmp
- /data/data/####/49
- /data/data/####/492026243
- /data/data/####/4ee946f9409127379ee6bfc064e2a7eb50529a7331d1efb....0.tmp
- /data/data/####/51375ddc58f0b537eb7408033b05526c42aff36916515df....0.tmp
- /data/data/####/51f6d0add14c74b697e90bd269bea7e0c816cc71ec5f1d7....0.tmp
- /data/data/####/520ed917f9ef331f5f389e72022734b8845f1bdd2b07fa1....0.tmp
- /data/data/####/53c2edb25b56dce7e86b55c34e46ea9b38aac8b918490f1....0.tmp
- /data/data/####/59b9b016602fc0b37a8efe74de87461cefccf4defaeee22....0.tmp
- /data/data/####/5d74d9511906f485fd87953f8b9dccd7f48d9eaca7a612c....0.tmp
- /data/data/####/5f2b7c20241c2ca3c7b3a62e5ccb63fd99fcce915e9a6bd....0.tmp
- /data/data/####/611cbe458849c6b1a35362bfe5383c0e9dbc87d833d1b9a....0.tmp
- /data/data/####/65094070f865c86bd655b01db5c7e5623b1ad23013862a1....0.tmp
- /data/data/####/682dcac121bac42d662cbd6ec952de50db12793eb4482fa....0.tmp
- /data/data/####/685374e95601119ccd382a6ac6589c0e6908cde0e6740dd....0.tmp
- /data/data/####/6a4b06f23d3057bd6738e9a72b430907d0c39352b05daca....0.tmp
- /data/data/####/707118423c442d417438df83aecc0b728fd66cc0073f097....0.tmp
- /data/data/####/7211773_article.js
- /data/data/####/722433770
- /data/data/####/7264b735e660868c7da69e6de792d89463e4e6e76e97ecb....0.tmp
- /data/data/####/768ffef7ed30c642c27be7b454c99949db4da0a229a9a0a....0.tmp
- /data/data/####/80dea552cc2050072dec69784459a2a1c87d85c6a82d33b....0.tmp
- /data/data/####/82cdc889dcbe4ff76479ca2e17e88e5c3b1a4476f0a52a5....0.tmp
- /data/data/####/97277987dc370699c8b8bbf52c919331b5b292d655208f1....0.tmp
- /data/data/####/97c6a9a8553db757f86882a643d4f2241458649077f753f....0.tmp
- /data/data/####/9950f7c20529994fa7cf14dd0063d8d8ee1a65ee32bc7f2....0.tmp
- /data/data/####/FZLTXHK-GBK_YS.ttf
- /data/data/####/QQ_3x.png
- /data/data/####/a525cf9064829270d15230c524353022b025ed0d8feeca9....0.tmp
- /data/data/####/aac3e98a97bcf807545894c7273a3bc349a99ffa7cc42db....0.tmp
- /data/data/####/abf8d6321aa68ca5544e9b9e52c7089cd58915737d23e83....0.tmp
- /data/data/####/ae12ead33bb9be14b593f78af06020a4dab41e0940c58ef....0.tmp
- /data/data/####/amazeui.min.css
- /data/data/####/amazeui.min.js
- /data/data/####/angular1.4.6.min.js
- /data/data/####/article.js
- /data/data/####/b18285cbdeb41f5ab00b4bc559b1a86fd0c674610b3e77f....0.tmp
- /data/data/####/b4c3db7a1f606170257eebee6409f7e86eaaf565c44c5ee....0.tmp
- /data/data/####/b8eaba33c75703dd4f311e9ecba2657745eead51813c0cc....0.tmp
- /data/data/####/base.css
- /data/data/####/c7708847c0a8b5f3b6532aa5c29d9ce2be2e39008528e32....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cc4118102b742889ed027ee611c15b1f4587c3f89f71913....0.tmp
- /data/data/####/cc6f95882cfdd7bb9e7f793547eb5c5bfd79924c1cb042c....0.tmp
- /data/data/####/cc80dbe1277d18fd1a14b429f2589d7567c63efca5575bc....0.tmp
- /data/data/####/columnId.xml
- /data/data/####/core_info
- /data/data/####/d453635ef39dd9088b55192eb2f1d3947392cf7f2be57ec....0.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/db_founder0-journal
- /data/data/####/debug.conf
- /data/data/####/device_id.xml.xml
- /data/data/####/e4719ee5e88b6156e21cd7810a8219e3cd0cbebb5a9e9b1....0.tmp
- /data/data/####/e4905e7b51264931c030a28b128e928c850ff45116c0f4d....0.tmp
- /data/data/####/e8eee857d62b2bc2314ad430d14eea3ec90279d2e4abd8e....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f06d5afc5bf91391b0fd773ec2d271eec80369e4fffa282....0.tmp
- /data/data/####/f0754015f1602bd3ea1863a1b225e1a0e0c984796f18afe....0.tmp
- /data/data/####/f2d553a9b2c7d5c7a7eedb73bf42fa97756498b3e3caac1....0.tmp
- /data/data/####/f967e7fa46f4b9f1690f216e6e8efc18a0806aaf65a5dfd....0.tmp
- /data/data/####/f9da53ca915171a242230937f067035687c65434640c236....0.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/fb2e267b24a75319f815782fc29c1954b45e05895640795....0.tmp
- /data/data/####/fce251d49f2444c53cd5fb825b637a2f94fad133d61c8ae....0.tmp
- /data/data/####/ff9c29004fde746357122790ea11cebfa297921ffeab210....0.tmp
- /data/data/####/file__0.localstorage-journal
- /data/data/####/fontawesome-webfont.ttf
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/great_button.png
- /data/data/####/great_cancel_button.png
- /data/data/####/gx_sp.xml
- /data/data/####/helpMsg.xml
- /data/data/####/icon-images.png
- /data/data/####/icon_audio_play.png
- /data/data/####/icon_file.png
- /data/data/####/icon_file_down.png
- /data/data/####/icon_meta_voice.png
- /data/data/####/icon_praise.png
- /data/data/####/icon_praiseStar.png
- /data/data/####/icon_selector_normal.png
- /data/data/####/icon_selector_press.png
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/journal.tmp
- /data/data/####/jquery.min2.2.0.js
- /data/data/####/js.combine.min.js
- /data/data/####/libjiagu.so
- /data/data/####/loading.png
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/news_detail.html
- /data/data/####/persistent_data.xml
- /data/data/####/play.png
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/reader.db-journal
- /data/data/####/run.pid
- /data/data/####/sanjiaoxing.png
- /data/data/####/shareTimeline_3x.png
- /data/data/####/sina_3x.png
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_ilz707
- /data/data/####/tdata_ilz707.jar
- /data/data/####/tdata_siA393
- /data/data/####/tdata_siA393.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/video.png
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/wx_3x.png
- /data/media/####/.nomedia
- /data/media/####/app.db
- /data/media/####/com.founder.meixian.bin
- /data/media/####/com.founder.meixian.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/journal.tmp
- /data/media/####/localTemplate.zip
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_ilz707
- /data/media/####/tdata_siA393
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.push.GeTuiPushService 24913 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop ro.product.cpu.abi
- mount
- getuiext2
- libjiagu
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding