Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- UDP(DNS) 1####.29.29.29:53
- UDP(DNS) 1####.114.114.114:53
- UDP(DNS) 2####.5.5.5:53
- UDP(DNS) 2####.6.6.6:53
- TCP(HTTP/1.1) ngc.aliy####.com:80
- TCP(HTTP/1.1) 1####.37.132.16:80
- TCP(HTTP/1.1) l####.cuda####.com:80
- TCP(HTTP/1.1) adash####.man.aliy####.com:80
- TCP(HTTP/1.1) ad####.fa####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) h-adash####.ut.ta####.com:443
- TCP(TLS/1.0) def####.cn.zb.####.com:443
- TCP(TLS/1.0) 1####.250.179.174:443
- TCP(TLS/1.0) baichua####.al####.com:443
- TCP(TLS/1.0) secgw-d####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) hotfix####.aliy####.com:443
- TCP(TLS/1.0) l####.cmpass####.com:9443
- TCP(TLS/1.0) l####.tbs.qq.com:443
- TCP(TLS/1.0) plb####.u####.com:443
- TCP(TLS/1.0) 2####.58.214.14:443
- TCP(TLS/1.0) 1####.76.76.200:443
- TCP(TLS/1.0) user####.al####.com:443
- TCP(TLS/1.0) res####.a####.com:443
- TCP(TLS/1.0) ams-hot####.oss-cn-####.aliy####.com:443
- TCP(TLS/1.0) f####.253.com:443
- TCP(TLS/1.0) 2####.107.1.97:443
- TCP(TLS/1.0) secgw-n####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) al####.u####.com:443
- TCP(TLS/1.2) p####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) www.google####.com:443
- TCP(TLS/1.2) connect####.gst####.com:443
- UDP 2####.255.107.47:44449
- UDP 2####.255.107.47:44447
- UDP 2####.255.107.47:44453
- UDP 2####.255.107.47:44446
- UDP 2####.255.107.47:44451
- UDP 2####.255.107.47:44445
- UDP 2####.255.107.47:44444
- UDP 2####.255.107.47:44450
- UDP 2####.255.107.47:44448
- UDP 1####.0.16.1:137
- UDP 2####.255.107.47:44452
- a####.man.aliy####.com
- ad####.fa####.com
- adas####.ut.ta####.com
- ams-hot####.oss-cn-####.aliy####.com
- and####.b####.qq.com
- android####.go####.com
- baichua####.al####.com
- connect####.gst####.com
- f####.253.com
- hotfix####.aliy####.com
- i####.me
- l####.cmpass####.com
- l####.cuda####.com
- l####.tbs.qq.com
- log.u####.com
- ngc.aliy####.com
- p####.google####.com
- p####.ws####.com
- pla####.googleu####.com
- plb####.u####.com
- res####.a####.com
- u####.al####.org
- u####.u####.com
- umen####.m.ta####.com
- user####.al####.com
- www.google####.com
- y####.al####.org
- ams-hot####.oss-cn-####.aliy####.com:443/hotfix/30518088-1/patches/3.6.0...
- baichua####.al####.com:443/4.0.0.0/29467364/1.0.0/android/rule.htm
- def####.cn.zb.####.com:443/bar/get/5ba063b4f1f556882200012f/?pcv=####&de...
- hotfix####.aliy####.com:443/r/30518088/YhETQauC914DAGdzx1EEc380/100/3.6....
- hotfix####.aliy####.com:443/r/30518088/YhETQauC914DAGdzx1EEc380/181/3.6....
- hotfix####.aliy####.com:443/r/30518088/YhETQauC914DAGdzx1EEc380/200/3.6....
- hotfix####.aliy####.com:443/u/30518088/YhETQauC914DAGdzx1EEc380/3.6.0/0/
- hotfix####.aliy####.com:443/u/30518088/YhETQauC914DAGdzx1EEc380/3.6.0/80...
- l####.cuda####.com/dot/s.gif?ch=####&time=####&activityid=####&e=####&di...
- user####.al####.com:443/matrix_app/android/matrix_app_config.json
- user####.al####.com:443/matrix_app/android/safe_package_config.json
- user####.al####.com:443/smart_link/android/alsl_switch_config.json
- ad####.fa####.com/video-report/equipment
- adash####.man.aliy####.com/man/api?ak=####&s=####
- al####.u####.com:443/unify_logs
- and####.b####.qq.com/rqd/async?aid=####
- f####.253.com:443/flash/accountInit/v3
- l####.cmpass####.com:9443/log/logReport
- l####.tbs.qq.com:443/ajax?c=####&k=####
- ngc.aliy####.com/data/r?a=####&m=####&o=####&k=####&p=####&u=####&t=####...
- plb####.u####.com:443/umpx_internal
- plb####.u####.com:443/umpx_share
- res####.a####.com:443/v3/iasdkauth?key=####&ts=####&scode=####
- secgw-d####.wagbr####.ali####.####.com:443/saveWb.json?evt=####&pn=####&...
- secgw-n####.wagbr####.ali####.####.com:443/sg/data.json?evt=####&pn=####...
- /data/data/####/.imprint
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1004
- /data/data/####/66121141889190.0
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/Cookies-journal
- /data/data/####/JX0WDG83P1ZN.txt
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/S8NVBA1uP6xbjA_l1X4oH26lUHD6gN7Mgg2e4gbzNTld3n9...82.zip
- /data/data/####/SDK_config
- /data/data/####/SDK_config1
- /data/data/####/SGMANAGER_DATA2
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/SG_INNER_DATA
- /data/data/####/SP_AROUTER_CACHE.xml
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/UTCommon.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/accs.db-journal
- /data/data/####/agoo.pid
- /data/data/####/alsn20170807.db
- /data/data/####/alsn20170807.db-journal
- /data/data/####/ap.Lock
- /data/data/####/auth_sdk_device.xml
- /data/data/####/avmp_312757200.pkgInfo
- /data/data/####/avmp_312757200.pkgInfo.tmp
- /data/data/####/basic_params.xml
- /data/data/####/bc_config
- /data/data/####/bugly_db_-journal
- /data/data/####/c0586a10777146560765a69231d89beb.xml
- /data/data/####/chuanglan_report_2.2.1.db
- /data/data/####/chuanglan_report_2.2.1.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/classes.dex;classes5.dex
- /data/data/####/classes.dex;classes6.dex
- /data/data/####/classes.dex;classes7.dex
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/ct_account_api_sdk.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNjQ1Mjg2MjQxNzk4;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNjQ1Mjg2MjkyNjc1;
- /data/data/####/dW1weF9zaGFyZV8xNjQ1Mjg2MjQ1NDUx;
- /data/data/####/dW1weF9zaGFyZV8xNjQ1Mjg2MjQyMzAy;
- /data/data/####/dc81e4bf25e5f5448c
- /data/data/####/dcbffd35f4ffff1e12
- /data/data/####/dcf3f1c004f9ff3dd3
- /data/data/####/dcfffbfebbbfe0003d
- /data/data/####/dfba17c4d52138281c2597d63d6b225a.0
- /data/data/####/download_upload
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/httpdns_config_cache.xml
- /data/data/####/i==1.2.0&&3.6.0_1645286242088_envelope.log
- /data/data/####/i==1.2.0&&3.6.0_1645286295603_envelope.log
- /data/data/####/info.xml
- /data/data/####/journal
- /data/data/####/k.store
- /data/data/####/libjiagu.so
- /data/data/####/libjnilib.so
- /data/data/####/libsgavmpso-5.4.36.so
- /data/data/####/libsgmainso-5.4.171.so.tmp.3465
- /data/data/####/libsgsecuritybodyso-5.4.99.so
- /data/data/####/libsgsgmiddletierso-5.4.7.so.tmp.3465
- /data/data/####/local_crash_lock
- /data/data/####/locale.config.xml
- /data/data/####/lock.lock
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/main_312757200.pkgInfo
- /data/data/####/main_312757200.pkgInfo (deleted)
- /data/data/####/mipush_country_code
- /data/data/####/mipush_country_code.lock
- /data/data/####/mipush_region
- /data/data/####/mipush_region.lock
- /data/data/####/native_record_lock
- /data/data/####/pref.xml
- /data/data/####/proc_auxv
- /data/data/####/security_info
- /data/data/####/securitybody_312757200.pkgInfo
- /data/data/####/securitybody_312757200.pkgInfo.tmp
- /data/data/####/sgFile.lock
- /data/data/####/sgmiddletier_312757200.pkgInfo
- /data/data/####/sgmiddletier_312757200.pkgInfo.tmp
- /data/data/####/share.db-journal
- /data/data/####/share_data.xml
- /data/data/####/share_data.xml.bak
- /data/data/####/share_data.xml.bak (deleted)
- /data/data/####/smart_link_sp.xml
- /data/data/####/smart_link_sp.xml.bak (deleted)
- /data/data/####/sophix-patch.jar
- /data/data/####/sophix-patch.jar.odex
- /data/data/####/sophix-patch.jar.odex.flock (deleted)
- /data/data/####/sophix-patch.jar938292193.decrypt
- /data/data/####/sp.lock
- /data/data/####/sp_sophix.xml
- /data/data/####/t==8.1.3&&3.6.0_1645286242993_envelope.log
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/timestamp
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_message_state.xml
- /data/data/####/umeng_socialize.xml
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/yunceng.conf
- /data/misc/####/primary.prof
- /data/user/0/<Package>/files/dc81e4bf25e5f5448c
- /data/user/0/<Package>/files/dcbffd35f4ffff1e12
- /data/user/0/<Package>/files/dcf3f1c004f9ff3dd3
- /data/user/0/<Package>/files/dcfffbfebbbfe0003d
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- getprop
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- ls -l /system/xbin/su
- ls /sys/class/thermal
- libRongIMLib
- libjiagu
- libjnilib
- libsgavmpso-5.4.36
- libsgmainso-5.4.171
- libsgsecuritybodyso-5.4.99
- libsgsgmiddletierso-5.4.7
- libtnet-3.1.14
- libyunceng
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7PADDING
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding