Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(TLS/1.0) www.a.sh####.com:443
- TCP(TLS/1.0) 1####.217.19.202:443
- TCP(TLS/1.0) he####.b####.com:443
- TCP(TLS/1.0) mbd.n.sh####.com:443
- TCP(TLS/1.0) ssls####.jom####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) b.bdst####.com:443
- TCP(TLS/1.0) wap.n.sh####.com:443
- TCP(TLS/1.0) hpd.b####.com:443
- TCP(TLS/1.0) 2####.58.208.110:443
- TCP(TLS/1.0) search-####.cdn.bc####.####.com:443
- TCP(TLS/1.0) sslb####.jom####.com:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) www.6####.com:443
- TCP(TLS/1.0) sslbdst####.jom####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) hectors####.b####.com.####.com:443
- TCP(TLS/1.0) box.jom####.com:443
- TCP(TLS/1.2) 1####.217.19.202:443
- TCP(TLS/1.2) 1####.250.179.195:443
- TCP sdk.o####.t####.####.com:5224
- android####.go####.com
- b.bdst####.com
- c.appj####.com
- cm-1####.g####.com
- cm-1####.g####.com
- cm-1####.g####.com
- ext.b####.com
- f####.b####.com
- g####.bdst####.com
- he####.b####.com
- hectors####.b####.com
- hpd.b####.com
- instant####.google####.com
- m.b####.com
- md####.google####.com
- p####.google####.com
- s.bdst####.com
- sdk.c####.g####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- search-####.cdn.bc####.com
- sm.b####.com
- ss0.b####.com
- ss0.bdst####.com
- ss1.b####.com
- ss2.b####.com
- www.6####.com
- www.b####.com
- www.gst####.com
- d####.c####.l####.####.com/config/hzv9.conf
- c.appj####.com/ad/splash/stats.html
- /data/data/####/.imei.txt
- /data/data/####/.jg.ic
- /data/data/####/061099884dd7467a_0
- /data/data/####/0c533dbadc5aa9f4_0
- /data/data/####/12e5b247935e91a9_0
- /data/data/####/2aaaa86467c8e1e3_0
- /data/data/####/2b20c720998808ca_0
- /data/data/####/3627a65d17c6e73f_0
- /data/data/####/37a258a443e27053_0
- /data/data/####/4227b067d21b618f_0 (deleted)
- /data/data/####/43843144742e4529_0
- /data/data/####/4c5e8e9dbb6044d9_0
- /data/data/####/4c5e8e9dbb6044d9_1
- /data/data/####/4fc420446759f95b_0
- /data/data/####/61e3ade5547f4ab8_0
- /data/data/####/61f7934b4ba46a23_0 (deleted)
- /data/data/####/7165195293c7cd3e_0
- /data/data/####/7165195293c7cd3e_1
- /data/data/####/7ff81ffc7052df9b_0
- /data/data/####/8250956803d3936a_0 (deleted)
- /data/data/####/885e1c0239f2652c_0
- /data/data/####/8d390d5873e34bee_0
- /data/data/####/8d390d5873e34bee_1
- /data/data/####/9273fccdd9dfc9bf_0
- /data/data/####/9581ffe3be5ca05c_0
- /data/data/####/9db62d11b0d38071_0
- /data/data/####/9f173a0408b4825d_0
- /data/data/####/Cookies-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/ad_show_time.xml
- /data/data/####/c00ef146f6168104_0
- /data/data/####/cb2aca8945142569_0
- /data/data/####/classes.dex
- /data/data/####/classes.oat
- /data/data/####/classes2.dex
- /data/data/####/d50aaf8baa771a62_0
- /data/data/####/de139ee3b5823ddb_0
- /data/data/####/e5684875303dc004_0
- /data/data/####/ee56169dc10e0c21_0
- /data/data/####/ee56169dc10e0c21_1
- /data/data/####/efde40db238add33_0
- /data/data/####/f32c69d77a2b772e_0
- /data/data/####/fa4ee938b5bf2db6_0
- /data/data/####/fa4ee938b5bf2db6_1
- /data/data/####/ffb1774397c09b2b_0
- /data/data/####/getui_sp.xml
- /data/data/####/https_www.6006.com_0.localstorage-journal
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/io.dcloud.com.yxwaipanv.xml
- /data/data/####/io.dcloud.com.yxwaipanv_preferences.xml
- /data/data/####/jg_app_update_settings_random.xml
- /data/data/####/libjiagu.so
- /data/data/####/metrics_guid
- /data/data/####/pdr.xml
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/pushsdk.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/run.pid
- /data/data/####/stream_permission.xml
- /data/data/####/the-real-index
- /data/data/####/tmpd8.db-journal
- /data/media/####/.imei.txt
- /data/media/####/crash_1619871442592_2021-05-01-15-17-22.log
- /data/media/####/io.dcloud.com.yxwaipanv.bin
- /data/media/####/temp.arm
- /data/misc/####/primary.prof
- /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes2.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- chmod 755 /data/user/0/<Package>/.jiagu/libjiagu.so
- AES-CBC-PKCS5Padding
- RSA
- RSA-NONE-OAEPWithSHA1AndMGF1Padding