Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) oa-####.d####.al####.com:80
- TCP(HTTP/1.1) img.y####.tv:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) up####.sdk.jig####.cn:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) p####.tc.qq.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) b####.g####.com:80
- TCP(HTTP/1.1) d####.y####.tv:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) c####.y####.tv:443
- TCP(TLS/1.0) frontr####.y####.tv:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) img.y####.tv:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5226
- UDP s.j####.cn:19000
- TCP 1####.248.241.219:7007
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a####.u####.com
- adser####.go####.com
- and####.b####.qq.com
- api.s####.mob.com
- b####.g####.com
- c####.g####.com
- c####.g####.ig####.com
- c####.y####.tv
- c-h####.g####.com
- d####.y####.tv
- fron####.y####.tv
- frontr####.y####.tv
- img.y####.tv
- imgc####.qq.com
- mi.g####.qq.com
- oa-####.d####.al####.com
- s####.e.qq.com
- s.j####.cn
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- ssl.gst####.com
- up####.sdk.jig####.cn
- v####.y####.tv
- www.go####.com
- www.go####.nl
- www.gst####.com
- d####.y####.tv/event/action?action=####&app=####&loadid=####&m=####&mac=...
- d####.y####.tv/event/heartbeat?app=####&beatid=####&interval=####&loadid...
- d####.y####.tv/event/session?action=####&app=####¤tpage=####&loadi...
- d####.y####.tv/system/bootstrap?app=####&brand=####&btype=####&idfa=####...
- d####.y####.tv/video/videoplay?app=####&loadid=####&logid=####&m=####&ma...
- d####.y####.tv/video/videoshow?app=####&loadid=####&m=####&mac=####&mode...
- img.y####.tv//00000001/u6006500.jpg
- img.y####.tv/20160908/v_13176376.jpg?x-oss-process=####
- img.y####.tv/20170516/v_13188460.jpg
- img.y####.tv/20170523/v_13399187.jpg
- img.y####.tv/20170627/v_15253892.jpg
- img.y####.tv/20171108/v_18238016.jpg
- img.y####.tv/20180209/v_20158153.jpg?x-oss-process=####
- img.y####.tv/20180319/643cd1b1d7daed0d254cd646523d0636.jpg
- img.y####.tv/20180328/v_20685555.jpg?x-oss-process=####
- img.y####.tv/20180610/cc3451faccd3c18dba35a932c000399e.jpg?x-oss-process...
- mi.g####.qq.com/gdt_mview.fcg?datatype=####&posid=####&count=####&r=####...
- mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
- oa-####.d####.al####.com/fetch_creative?bidrequ####
- p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
- t####.c####.q####.####.com/tdata_MkX219
- t####.c####.q####.####.com/tdata_iGj879
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a####.exc.mob.com/errconf
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- api.s####.mob.com/conf5
- api.s####.mob.com/conn
- api.s####.mob.com/snsconf
- b####.g####.com/api.php?format=####&t=####
- c####.g####.com/api.php?format=####&t=####
- s####.e.qq.com/activate
- s####.e.qq.com/msg
- sdk.o####.p####.####.com/api.php?format=####&t=####
- up####.sdk.jig####.cn/v1/push/sdk/postlist
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/.vpl_lock
- /data/data/####/0a97254aceda88bfd9b9009cc48e6702b73dedc896bd566....0.tmp
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/1f489c22b1de57f2a8f6a0a3982d90825ee8f6877c2622e....0.tmp
- /data/data/####/2265ef538cae6b201fc9db0ac308c79208edca4d383fce9....0.tmp
- /data/data/####/28dd4f86316d0ff39f5e36ceff8e435cfd5129ae3e5d3fa....0.tmp
- /data/data/####/68a38e13199027fb90d8e691ee044b0de21fe9ac791ee2f....0.tmp
- /data/data/####/7ee1ad1f45f956be6775925aac4584581711c7f1da5dccd....0.tmp
- /data/data/####/83014bf5-bf5f-4dde-a711-c448fe2b037f
- /data/data/####/89452d54cc0a0e71d764a60f7056fcc228144de5a1a0a3b....0.tmp
- /data/data/####/8c6d8e306386942bf4cfee7206b83b9daa8fa3354db2efd....0.tmp
- /data/data/####/91fb9e1fb4030b6ea88c9d7f67555520d2a65068367ab32....0.tmp
- /data/data/####/92b1d00b-20b8-46c9-b4b2-66c3d09669fb
- /data/data/####/937d9420545eacd4189bd9abdf56a396041ed3bca1bd659....0.tmp
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/JPushSA_Config.xml
- /data/data/####/MultiDex.lock
- /data/data/####/SP_AROUTER_CACHE.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/aebc5d7133df41121428d4c6870387404528217aef83b0a....0.tmp
- /data/data/####/b5740e8a87d4ab29ff1b9fa7be50df35f5d530afcbbc1bb....0.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cfec2c05dcd244788497909c6332a479c9673b90eb6f7c5....0.tmp
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/crashrecord.xml
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f2743d59a62b7d0d5783d9e417d9ff87c83125684f8064f....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_suid
- /data/data/####/getui_sp.xml
- /data/data/####/gtc.db-journal
- /data/data/####/hudid.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/libjiagu557181570.so
- /data/data/####/local_crash_lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/security_info
- /data/data/####/share_sdk_1
- /data/data/####/sharesdk.db-journal
- /data/data/####/tdata_MkX219
- /data/data/####/tdata_MkX219.jar
- /data/data/####/tdata_iGj879
- /data/data/####/tdata_iGj879.jar
- /data/data/####/tv.yilan.bobo.app.BETA_VALUES.xml
- /data/data/####/tv.yilan.bobo.app_preferences.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/update_lc
- /data/data/####/yilan.db-journal
- /data/media/####/.artc_lock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.hudid
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.mn_-1464060969
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.push_deviceid
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/logs_0.csv
- /data/media/####/tdata_MkX219
- /data/media/####/tdata_iGj879
- /data/media/####/test.log
- /data/media/####/tv.yilan.bobo.app.db
- /data/media/####/tv.yilan.bobo.app_.db
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24652 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu557181570.so
- getprop
- Bugly
- getuiext2
- ijkffmpeg
- ijkplayer
- ijksdl
- jcore120
- libjiagu557181570
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding