Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) i####.app.jme.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(TLS/1.0) wg.a####.jme.com:8083
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5224
- 7j####.c####.z0.####.com
- a####.u####.com
- c####.g####.ig####.com
- c-h####.g####.com
- i####.app.jme.com
- pub-####.qin####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- wg.a####.jme.com
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170421/1492772686684.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170608/1496888201054.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170609/1496989371485.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170609/1496992100009.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170609/1496993635961.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497234130078.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497234288620.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497234502898.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497234626145.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497234883267.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170612/1497235015598.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170621/1498006778239.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170629/1498724060845.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20170630/1498810078971.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180823/1535001902516.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180823/1535003427666.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180823/1535004558672.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180824/1535072435674.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180827/1535332533298.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180828/1535418414258.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180904/1536023440434.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180905/1536109054343.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180905/1536111665693.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180906/1536199998180.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180907/1536284734015.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180910/1536547714716.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180911/1536632500348.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180914/1536903253210.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180917/1537151897241.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20180926/1537922918693.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190201/1549005170771.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190213/1550044561051.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190214/1550130686343.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190215/1550217090528.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190218/1550476433187.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190221/1550736278041.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190222/1550820201166.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190225/1551080295119.png
- i####.app.jme.com/ad/newjmeimage/imgUp/temp/20190226/1551169066482.png
- i####.app.jme.com/apks/jme_trade_v4.0.9_website_409_jiagu_sign.apk
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/tdata_RSQ274
- t####.c####.q####.####.com/tdata_RbW195
- t####.c####.q####.####.com/tdata_qHR433
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/05163825479aaeb99142e3d5826d61b6.0.tmp
- /data/data/####/05163825479aaeb99142e3d5826d61b6.1.tmp
- /data/data/####/05a26f2a9c4384faa75310ebb9b0db64.0.tmp
- /data/data/####/05a26f2a9c4384faa75310ebb9b0db64.1.tmp
- /data/data/####/0793aeafa31f08fa9c8dbf3886798682.0.tmp
- /data/data/####/0793aeafa31f08fa9c8dbf3886798682.1.tmp
- /data/data/####/0c8bd3845492014d012d0e44e87724bd.0.tmp
- /data/data/####/0c8bd3845492014d012d0e44e87724bd.1.tmp
- /data/data/####/0d2c5fc64c131130fca77ea2043b1083.0.tmp
- /data/data/####/0d2c5fc64c131130fca77ea2043b1083.1.tmp
- /data/data/####/10167792d0a735cf998e90a9759f254d.0.tmp
- /data/data/####/10167792d0a735cf998e90a9759f254d.1.tmp
- /data/data/####/18df3582cd660403c9435582e79733f9.0.tmp
- /data/data/####/18df3582cd660403c9435582e79733f9.1.tmp
- /data/data/####/23ccdebce5b5632b10df9743b5b57038.0.tmp
- /data/data/####/23ccdebce5b5632b10df9743b5b57038.1.tmp
- /data/data/####/2893ecba031dfd8942d8feba7b811a0f.0.tmp
- /data/data/####/2893ecba031dfd8942d8feba7b811a0f.1.tmp
- /data/data/####/2b4deac8a312f86567bc336458342d28.0.tmp
- /data/data/####/2b4deac8a312f86567bc336458342d28.1.tmp
- /data/data/####/2c2272ad8cfa9572926f8ee8954df512.0.tmp
- /data/data/####/2c2272ad8cfa9572926f8ee8954df512.1.tmp
- /data/data/####/2df918cfec110eb6a479bb03f3a76b62.0.tmp
- /data/data/####/2df918cfec110eb6a479bb03f3a76b62.1
- /data/data/####/2df918cfec110eb6a479bb03f3a76b62.1.tmp
- /data/data/####/3f7d3f808b9e4314de9846d169d3dd51.0.tmp
- /data/data/####/3f7d3f808b9e4314de9846d169d3dd51.1
- /data/data/####/3f7d3f808b9e4314de9846d169d3dd51.1.tmp
- /data/data/####/53e0e705efc3
- /data/data/####/5d5b7ddf01508210574e218e22150e9e.0.tmp
- /data/data/####/5d5b7ddf01508210574e218e22150e9e.1.tmp
- /data/data/####/61b0fd4a1098b69bbf97d9671077515e.0.tmp
- /data/data/####/61b0fd4a1098b69bbf97d9671077515e.1.tmp
- /data/data/####/66d28ef3ef2767c614b83ebc0df1ccea.0.tmp
- /data/data/####/66d28ef3ef2767c614b83ebc0df1ccea.1.tmp
- /data/data/####/6fc94a4757d010306a895c2cd85fb917.0.tmp
- /data/data/####/6fc94a4757d010306a895c2cd85fb917.1.tmp
- /data/data/####/73b987038b2226da00445d3e51fae92f.0.tmp
- /data/data/####/73b987038b2226da00445d3e51fae92f.1.tmp
- /data/data/####/76d2cb52d1eb373d622e66678f888ed6.0.tmp
- /data/data/####/76d2cb52d1eb373d622e66678f888ed6.1.tmp
- /data/data/####/77555d16f71ab89c233180a1a757fbdb.0.tmp
- /data/data/####/77555d16f71ab89c233180a1a757fbdb.1.tmp
- /data/data/####/8986910a59a34ca68204c89d0b509577.0.tmp
- /data/data/####/8986910a59a34ca68204c89d0b509577.1.tmp
- /data/data/####/8f7b7ac7a96b8306b42f42230b0ef788.0.tmp
- /data/data/####/8f7b7ac7a96b8306b42f42230b0ef788.1.tmp
- /data/data/####/92d8f2c21abb62cc2271a90adc51b660.0.tmp
- /data/data/####/92d8f2c21abb62cc2271a90adc51b660.1.tmp
- /data/data/####/9f6d1e86044a3f1120f4537d775b38bc.0.tmp
- /data/data/####/9f6d1e86044a3f1120f4537d775b38bc.1.tmp
- /data/data/####/JMETrade.db-journal
- /data/data/####/aa74a707e6e5addb4b2d6568285a7645.0.tmp
- /data/data/####/aa74a707e6e5addb4b2d6568285a7645.1.tmp
- /data/data/####/ac821cfc6fa92fd8289b993eff8b9591.0.tmp
- /data/data/####/ac821cfc6fa92fd8289b993eff8b9591.1.tmp
- /data/data/####/ad11995bf344a32a94c47894a3db97f8.0.tmp
- /data/data/####/ad11995bf344a32a94c47894a3db97f8.1.tmp
- /data/data/####/b13307c38ffdc6556d1de0746ca8f092.0.tmp
- /data/data/####/b13307c38ffdc6556d1de0746ca8f092.1.tmp
- /data/data/####/b4123a0b1e0f9422bcbf0b2eec7371a9.0.tmp
- /data/data/####/b4123a0b1e0f9422bcbf0b2eec7371a9.1.tmp
- /data/data/####/c719b8d6edcb7929af4c98525ade9c80.0.tmp
- /data/data/####/c719b8d6edcb7929af4c98525ade9c80.1.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cd13ef5150baa6bb4ab1f927443e8bdf.0.tmp
- /data/data/####/cd13ef5150baa6bb4ab1f927443e8bdf.1.tmp
- /data/data/####/cde381a918038772999f92614c15512f.0.tmp
- /data/data/####/cde381a918038772999f92614c15512f.1.tmp
- /data/data/####/cf98d6ca2f9aa0e5590357a87b6bd5bd.0.tmp
- /data/data/####/cf98d6ca2f9aa0e5590357a87b6bd5bd.1.tmp
- /data/data/####/com.jme.trade_preferences.xml
- /data/data/####/d3f912572b5b4362eaec63a8135121bb.0.tmp
- /data/data/####/d3f912572b5b4362eaec63a8135121bb.1.tmp
- /data/data/####/e3ba7eff86f038676af0a75f9f1cc94d.0.tmp
- /data/data/####/e3ba7eff86f038676af0a75f9f1cc94d.1.tmp
- /data/data/####/ec20beb8f5f528075c7d2c15963bf00a.0.tmp
- /data/data/####/ec20beb8f5f528075c7d2c15963bf00a.1.tmp
- /data/data/####/ef41a18c2647a26893a028ecac8b86fb.0.tmp
- /data/data/####/ef41a18c2647a26893a028ecac8b86fb.1.tmp
- /data/data/####/ef712ec460f64d156280b04e14cfa31c.0.tmp
- /data/data/####/ef712ec460f64d156280b04e14cfa31c.1.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f41605fdf49808ce39dbf3399d7cb9c6.0.tmp
- /data/data/####/f41605fdf49808ce39dbf3399d7cb9c6.1.tmp
- /data/data/####/f7ae8fc534af80e2c593d180ba01ca99.0.tmp
- /data/data/####/f7ae8fc534af80e2c593d180ba01ca99.1.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu.so
- /data/data/####/multidex.version.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tdata_RSQ274
- /data/data/####/tdata_RSQ274.jar
- /data/data/####/tdata_RbW195
- /data/data/####/tdata_RbW195.jar
- /data/data/####/tdata_qHR433
- /data/data/####/tdata_qHR433.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/media/####/JMEApp4.0.9
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.jme.trade.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_RSQ274
- /data/media/####/tdata_RbW195
- /data/media/####/tdata_qHR433
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24255 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- mount
- getuiext2
- libjiagu
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding