Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) res####.bx####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) s29.9####.cn:80
- TCP(HTTP/1.1) et2-na6####.wagbr####.ali####.####.com:80
- TCP(HTTP/1.1) s28.9####.cn:80
- TCP(TLS/1.0) s29.9####.cn:443
- TCP(TLS/1.0) ti####.bx####.com:443
- a####.u####.com
- apm-col####.qte####.com
- log.u####.com
- res####.bx####.com
- s####.u####.com
- s28.9####.cn
- s29.9####.cn
- ti####.bx####.com
- et2-na6####.wagbr####.ali####.####.com/bar/get/54ab977dfd98c51d120006bf/...
- s28.9####.cn/static/upload/a/181108143124-481_m.png
- s28.9####.cn/static/upload/a/181109115153-735_m.png
- s28.9####.cn/static/upload/a/181109115649-378_m.png
- s29.9####.cn/attach/download/app/pic/1e/1d753fd7effa3ba483cbe944e9dcf7bf...
- s29.9####.cn/attach/download/app/pic/54/d23d2b080a69efb6dfe4b0f833f84740...
- s29.9####.cn/attach/download/app/pic/b5/8847656116c565449bf9db55b388ec46...
- s29.9####.cn/attach/download/app/pic/bc/71295c1b8972b87eda831cc05168cd86...
- s29.9####.cn/attach/product/9d/1c/9d1c574ed3d615ff6146f42063086b5c_L.jpg
- s29.9####.cn/attach/product/c9/09/c909f47f35f0257f5f4dfada5f140b34_L.jpg
- s29.9####.cn/attach/product/f2/ec/f2ec482c8724ea9cd2a2de38f00edd85_L.jpg
- s29.9####.cn/attach/product/f7/b5/f7b50d1c75dbddaa90cbf060465d1edf_L.jpg
- s29.9####.cn/attach/wenwen/ef/03/ef0366bb90db458736d709385fa9f02d_IMGINF...
- a####.u####.com/app_logs
- res####.bx####.com/api/article/lists
- res####.bx####.com/api/common/ads
- res####.bx####.com/api/common/checkversion
- res####.bx####.com/api/common/launchstat
- res####.bx####.com/api/common/popads
- res####.bx####.com/api/planner/lists
- res####.bx####.com/api/product/airecommend
- res####.bx####.com/api/solution/lists
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/102aeaf37947a8c992b2d7bef402c1bcb4f032d22c2ef86....0.tmp
- /data/data/####/1542236577695.log
- /data/data/####/1542236577695.log.bak (deleted)
- /data/data/####/1c2abf7617c8edf8104afd725d84cbca6121e9ae5718cb6....0.tmp
- /data/data/####/39b564e1bda5174ef9adb5016be02f59d3621d49d8b1dfe....0.tmp
- /data/data/####/5c386baf2a4338639bffe18cb684ae892639486826d4e69....0.tmp
- /data/data/####/879d5103aa6b2256c9dfa05bf8386c4d115717fc89a32db....0.tmp
- /data/data/####/97dd3bda7c406bebb459019fadcb10e08b9c7ec8246414e....0.tmp
- /data/data/####/9bbed1087e6846d5ab547408c1d7c6126d0e1edff50e5cf....0.tmp
- /data/data/####/QALConfigStore.dat
- /data/data/####/TLS_DEVICE_INFO.xml
- /data/data/####/TestinAgent.db
- /data/data/####/TestinAgent.db-journal
- /data/data/####/TestinCrash.xml
- /data/data/####/WLOGIN_DEVICE_INFO.xml
- /data/data/####/b2457ec57f4fd1065e3c87d3b402adc09c3f0a225313f1d....0.tmp
- /data/data/####/bafaac226fa2109bb742c659d2c91060ef3020e70caff60....0.tmp
- /data/data/####/c61f3dfbf31eeb5602a1fb7d7ff0a6cce4216784d08f42e....0.tmp
- /data/data/####/com.jiuyang.baoxian_preferences.xml
- /data/data/####/db1b079e5574924e45d815eecb05195f88e6a0732e5384b....0.tmp
- /data/data/####/dbd0b350b47f2eeec1154baf0115df0eff0e5c068e0d48c....0.tmp
- /data/data/####/e1140a0e91ea932eb6a74f7385354a46d0fb284969142cc....0.tmp
- /data/data/####/e52c98dce2d8a7e341e01ad4526468be97a2ba86a183265....0.tmp
- /data/data/####/eae060d9a187284a49935af638efa5b0b370c1ae3113f4c....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/f130e4294750b004c85b5145c04ad0c5657ae73b847d2a7....0.tmp
- /data/data/####/imei
- /data/data/####/insure.db-journal
- /data/data/####/journal.tmp
- /data/data/####/libjiagu-214755050.so
- /data/data/####/multidex.version.xml
- /data/data/####/report_v5.msgstore-journal
- /data/data/####/tls_device.dat
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/data/####/wlogin_device.dat
- /data/media/####/app.18.11.14.23.log
- /data/media/####/sdk.18.11.14.23.log
- chmod 755 <Package Folder>/.jiagu/libjiagu-214755050.so
- NativeCrash
- _imcore_jni_gyp
- libjiagu-214755050
- libwtcrypto
- qalcodecwrapper
- qalmsfboot
- AES
- AES-CBC-NoPadding
- AES-CBC-NoPadding