Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) d####.d####.mob.com:80
- TCP(HTTP/1.1) app.21ji####.com:80
- TCP(HTTP/1.1) r####.uu.qq.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) api.s####.mob.com:80
- TCP(HTTP/1.1) h####.b####.com:80
- TCP(HTTP/1.1) app.2####.org:80
- TCP(TLS/1.0) qq.i####.com:443
- a####.21ji####.com
- a####.exc.mob.com
- api.s####.mob.com
- app.2####.org
- app.21ji####.com
- d####.d####.mob.com
- h####.b####.com
- m.d####.mob.com
- m.i####.com
- r####.uu.qq.com
- app.2####.org/json/ipadPaper/paperList_mobile.json
- app.21ji####.com/epaper/json/Android_v4.1.0.json
- app.21ji####.com/epaper/json/reddot.json
- m.d####.mob.com/cconf?appkey=####&plat=####&apppkg=####&appver=####&netw...
- a####.exc.mob.com/errconf
- api.s####.mob.com/conn
- d####.d####.mob.com/dinfo
- d####.d####.mob.com/dsign
- h####.b####.com/app.gif
- r####.uu.qq.com/rqd/sync
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.log.lock
- /data/data/####/.log.ls
- /data/data/####/.mrecord
- /data/data/####/.mrecord (deleted)
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/21epaper.db
- /data/data/####/21epaper.db-journal
- /data/data/####/21epaperPreference.xml
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/__local_ap_info_cache.json
- /data/data/####/__local_stat_cache.json
- /data/data/####/__send_data_1558956197164
- /data/data/####/bugly_db_-journal
- /data/data/####/buglylog_com.twentyfirstcbh.epaper_.txt
- /data/data/####/core_info
- /data/data/####/hmt_agent_commonutill_com.twentyfirstcbh.epaper.xml
- /data/data/####/hmt_agent_commonutill_device_id.xml
- /data/data/####/hmt_agent_online_setting_com.twentyfirstcbh.epaper.xml
- /data/data/####/hmt_analytics
- /data/data/####/hmt_analytics-journal
- /data/data/####/hmt_init_savetime.xml
- /data/data/####/hmt_irsuid.xml
- /data/data/####/hmt_session_id.xml
- /data/data/####/hmt_session_id_savetime.xml
- /data/data/####/libcuid.so
- /data/data/####/libjiagu.so
- /data/data/####/multidex.version.xml
- /data/data/####/openudid_prefs.xml
- /data/data/####/share_sdk_1.xml
- /data/data/####/skin_plugin_pref.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/media/####/.ccLock
- /data/media/####/.ccc
- /data/media/####/.confd
- /data/media/####/.confd-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.dk
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.timestamp
- /data/media/####/1258478763
- /data/media/####/3347807
- /system/bin/sh -c getprop ro.board.platform
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop ro.board.platform
- getprop ro.product.cpu.abi
- Bugly
- libjiagu
- neh
- xyz
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- DES-CBC-PKCS5Padding