Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) p.s.3####.cn:80
- TCP(HTTP/1.1) sdk.s.360.####.com:80
- TCP(TLS/1.0) dp.p####.dc.####.cn:443
- TCP(TLS/1.0) e.crashly####.com:443
- TCP(TLS/1.0) api.s####.com:443
- TCP(TLS/1.0) s.3####.cn:443
- TCP(TLS/1.0) lbs.net####.im:443
- TCP(TLS/1.0) p6.nic####.com:443
- TCP(TLS/1.0) p4.nic####.com:443
- TCP(TLS/1.0) sett####.crashly####.com:443
- TCP(TLS/1.0) api.nic####.com:443
- TCP(TLS/1.0) f####.fengkon####.com:443
- TCP(TLS/1.0) wa####.127.net:443
- TCP(TLS/1.0) s####.nic####.com:443
- TCP(TLS/1.0) s2.nic####.com:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) m.nic####.com:443
- TCP 2####.167.166.46:80
- a####.u####.com
- and####.cli####.go####.com
- api.nic####.com
- api.s####.com
- cloud####.fengkon####.com
- dp.p####.dc.####.cn
- e.crashly####.com
- f####.fengkon####.com
- i####.uc.cn
- lbs.net####.im
- m.nic####.com
- p.s.3####.cn
- p1.nic####.com
- p2.nic####.com
- p4.nic####.com
- p5.nic####.com
- p6.nic####.com
- s####.nic####.com
- s####.s.360.cn
- s.3####.cn
- s1.nic####.com
- s2.nic####.com
- s3.nic####.com
- sdk.o####.p####.####.com
- sett####.crashly####.com
- wa####.127.net
- sdk.s.360.####.com/ak/6cfe0e6127fa25df2a0ef2ae1067d915.html?m2=####
- a####.u####.com/app_logs
- p.s.3####.cn/update/update.php?p=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/58de82c0ce0ff326475e833719a16922.0.tmp
- /data/data/####/58de82c0ce0ff326475e833719a16922.1.tmp
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901BeginSession.cls_temp
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901BeginSession.json
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionApp.cls_temp
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionApp.json
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionDevice.cls_temp
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionDevice.json
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionOS.cls_temp
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionOS.json
- /data/data/####/5D7AA4B80301-0001-082C-4081EE73F901SessionUser.cls_temp
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901BeginSession.cls_temp
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901BeginSession.json
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionApp.cls_temp
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionApp.json
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionDevice.cls_temp
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionDevice.json
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionOS.cls_temp
- /data/data/####/5D7AA4BD02A8-0001-0945-4081EE73F901SessionOS.json
- /data/data/####/693f523992895df98c74b39de68b7ca1.0.tmp
- /data/data/####/693f523992895df98c74b39de68b7ca1.1.tmp
- /data/data/####/82CFE0C35829BE9D67E08925EC816654.xml
- /data/data/####/8ec976d411a6db7864ccbc346f6b67b5.0.tmp
- /data/data/####/8ec976d411a6db7864ccbc346f6b67b5.1.tmp
- /data/data/####/MultiDex.lock
- /data/data/####/NIMSDK_Config_37b3efac645e38895674dee7dfea546b.xml
- /data/data/####/QH_DeviceSDK.xml
- /data/data/####/QH_SDK_M2.xml
- /data/data/####/QH_SDK_UserData6766aa2750c19aad2fa1b32f36ed4aee.xml
- /data/data/####/QH_SDK_UserData6cfe0e6127fa25df2a0ef2ae1067d915.xml
- /data/data/####/QH_SDK_sessionID6cfe0e6127fa25df2a0ef2ae1067d915.xml
- /data/data/####/TwitterAdvertisingInfoPreferences.xml
- /data/data/####/Y29tLmZpbmFuY2lhbDM2MC5uaWNhaWZ1.tick.lock
- /data/data/####/a56572d43c844fc9fe021e48c66c90f8.0.tmp
- /data/data/####/a56572d43c844fc9fe021e48c66c90f8.1.tmp
- /data/data/####/aaa3cc057163f7160347624d6635813a.0.tmp
- /data/data/####/aaa3cc057163f7160347624d6635813a.1.tmp
- /data/data/####/bad6d1c1f51a65846d315570608e7c31.0.tmp
- /data/data/####/bad6d1c1f51a65846d315570608e7c31.1.tmp
- /data/data/####/c4761dc610cc7c50e9454721a5425bb2.0.tmp
- /data/data/####/c4761dc610cc7c50e9454721a5425bb2.1.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.crashlytics.prefs.xml
- /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
- /data/data/####/com.crashlytics.settings.json
- /data/data/####/com.financial360.nicaifu_preferences.xml
- /data/data/####/com.shumei.xml
- /data/data/####/cube_ptr_classic_last_update.xml
- /data/data/####/d37f2e2c840e11a6245e740c853c0e11.0.tmp
- /data/data/####/d37f2e2c840e11a6245e740c853c0e11.1.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/dd5251c81aa746fb02fd3a71b16e272e.0.tmp
- /data/data/####/dd5251c81aa746fb02fd3a71b16e272e.1.tmp
- /data/data/####/ddfbf66d4fff0efd5e9576b573f39d0f.0.tmp
- /data/data/####/ddfbf66d4fff0efd5e9576b573f39d0f.1.tmp
- /data/data/####/device_id.xml.xml
- /data/data/####/ee688635804422d50c0bb399dd651a86.0.tmp
- /data/data/####/ee688635804422d50c0bb399dd651a86.1.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/fea95a7a6d270475e0d401270a9d0475.0.tmp
- /data/data/####/fea95a7a6d270475e0d401270a9d0475.1.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/index
- /data/data/####/init_c1.pid
- /data/data/####/init_er.pid
- /data/data/####/initialization_marker
- /data/data/####/io.fabric.sdk.android;fabric;cek.xml
- /data/data/####/journal.tmp
- /data/data/####/libjiagu104569824.so
- /data/data/####/multidex.version.xml
- /data/data/####/push_share.xml
- /data/data/####/sa_24060bb9-58d4-4279-a5d1-9e6e6706e24a_1568318650501.tap
- /data/data/####/sa_806fd208-36ce-4516-ac0f-73562a6fe05d_1568318660269.tap
- /data/data/####/seq.xml
- /data/data/####/session_analytics.tap
- /data/data/####/session_analytics.tap.tmp
- /data/data/####/sobot_config.xml
- /data/data/####/tracker.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/.deviceId
- /data/media/####/.iddata
- /data/media/####/.nomedia
- /data/media/####/.thumbcache_idx0
- /data/media/####/009a3b20d01a0861ce9b727107025030.gif
- /data/media/####/0cfac10607d74f5a138c5469f4643d8af4cfe79db242df....0.tmp
- /data/media/####/0e2c6d7afd5367d8e080fde575f9d08bf3e5ee9f3b8604....0.tmp
- /data/media/####/315b2fda3c9027828e8ebb9e5f0f3951edfe90ef2e37eb....0.tmp
- /data/media/####/3cc22f86e99df839e26237c8103099e0.jpg
- /data/media/####/3fc9a76e28ea9c654bc7c875126f9e8f.png
- /data/media/####/41be865af86fd4547b5a329b4d4fa13090992b22c76a86....0.tmp
- /data/media/####/52f25785d08782aaba57205ee0c31b877db8a782c17293....0.tmp
- /data/media/####/5744d66a1422dcbbf82e49ce103b2e390662500ddfea3d....0.tmp
- /data/media/####/6cfe0e6127fa25df2a0ef2ae1067d915
- /data/media/####/6cfe0e6127fa25df2a0ef2ae1067d915 (deleted)
- /data/media/####/7121321c0565bcd0b6af1e9cf2897b03.gif
- /data/media/####/81e9b4af0d6dfe5e07f5543d0c1164b2ff9648821c4cb1....0.tmp
- /data/media/####/85740a8c688767897f31c22301e97b9783ddb1642e38c1....0.tmp
- /data/media/####/875f9d2a089dada6cc9cebddb7cda60f.jpg
- /data/media/####/92639969f29cab45fe48c395bbc99446173a7450bacaac....0.tmp
- /data/media/####/98fa6ba0589e9e862c3bdec49346062b.gif
- /data/media/####/Ab7
- /data/media/####/Ab7 (deleted)
- /data/media/####/a13c3691f82cf699beeb2e6b04ffc9db.png
- /data/media/####/ak6
- /data/media/####/ak6 (deleted)
- /data/media/####/b29ab51bb7b42f9c333423e3dc812108e3f341aa9f82f5....0.tmp
- /data/media/####/bfb25fd55513a2d0f39b16bf7a1ae71aa33c1f73c54439....0.tmp
- /data/media/####/d070a823529d3e3a741d676ef12f0eee6df56939c2b60b....0.tmp
- /data/media/####/d71a10fe9da84236e0f5120a7cc2882a39ccfa0e904838....0.tmp
- /data/media/####/d71ecc4eff8e1dc6da3b6f34aa86d7c8.png
- /data/media/####/dd149e12cb0651bb39bd02f8679bde0f.gif
- /data/media/####/e4d1032a0515fa9032b453aff6e265038c0059e063f942....0.tmp
- /data/media/####/eb71d974bb8d2451de40e6cf1509a2d0.png
- /data/media/####/ef03380c653d774aab90dd83c6a31284.gif
- /data/media/####/f8a3a30b18557cd70ef94fdefc48d2e442a3a4eaa9aeae....0.tmp
- /data/media/####/journal.tmp
- /data/media/####/nim_sdk.log
- /data/media/####/official_config
- /data/media/####/rga
- /data/media/####/rga (deleted)
- /data/media/####/shumei.txt
- cat /proc/self/cgroup
- ps
- getuiext2
- libjiagu104569824
- smsdk
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- DES-ECB-NoPadding