Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) s.a.longy####.com:80
- TCP(HTTP/1.1) ad.nowyin####.com:80
- TCP(HTTP/1.1) htt####.mm####.com:80
- TCP(HTTP/1.1) antil####.nowsh####.com:80
- TCP(HTTP/1.1) ip.ta####.com:80
- TCP(TLS/1.0) ro####.nowyin####.com:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) ad.nowyin####.com:443
- TCP(TLS/1.0) sdk.me####.com:443
- TCP(TLS/1.0) sh####.me####.com:443
- ad.nowyin####.com
- antil####.nowsh####.com
- htt####.mm####.com
- ip.ta####.com
- is.sn####.com
- log.u####.com
- mo####.b####.com
- plb####.u####.com
- po####.nowsh####.com
- ro####.nowyin####.com
- s.a.longy####.com
- sdk.me####.com
- sh####.me####.com
- u####.u####.com
- ad.nowyin####.com/heibes/ad?model=####&ts=####&density=####&root=####&gd...
- antil####.nowsh####.com/request/cde
- antil####.nowsh####.com/time?timestamp=####
- htt####.mm####.com/dns?domain=####
- ip.ta####.com/service/getIpInfo.php?ip=####
- s.a.longy####.com/
- /data/anr/traces.txt
- /data/data/####/.imprint
- /data/data/####/1d2b904cbeadfb72ed9546111a231c85.0
- /data/data/####/MultiDex.lock
- /data/data/####/__x_adsdk_agent_header__.xml
- /data/data/####/__xadsdk__remote__final__builtin__.jar
- /data/data/####/__xadsdk__remote__final__builtinversion__.jar
- /data/data/####/__xadsdk__remote__final__running__.jar
- /data/data/####/a==7.5.3&&1.4.5_1568417401025_envelope.log
- /data/data/####/com.baidu.mobads.loader.xml
- /data/data/####/commonsp.xml
- /data/data/####/conf.dat
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDA0MTM4;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDA4NTEz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDAwMTM2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDE2NzMw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDEyNjI0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDI2NDEx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDIyNDU2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDM0NDk5;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDMwNjAx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDQ2MDAw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDQ5OTkz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDQxOTUw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDU0Mjg3;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDU4MzI0;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDY2MTg4;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDYyMTcx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDc2NDA2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTY4NDE3NDcwMjc2;
- /data/data/####/downloader.db-journal
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/i==1.2.0&&1.4.5_1568417400230_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417404158_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417412655_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417416732_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417422486_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417426443_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417430575_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417446054_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417454334_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417458342_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417462203_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417470313_envelope.log
- /data/data/####/i==1.2.0&&1.4.5_1568417476433_envelope.log
- /data/data/####/infinitemovie.db
- /data/data/####/infinitemovie.db-journal
- /data/data/####/info.xml
- /data/data/####/journal
- /data/data/####/journal.tmp
- /data/data/####/k.store
- /data/data/####/libp2p-native.so
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/longyun_sdk.xml
- /data/data/####/p2p_config.xml
- /data/data/####/p2p_down_config.xml
- /data/data/####/pref.xml
- /data/data/####/setting_relative_sharepreference.xml
- /data/data/####/ttopenadsdk.xml
- /data/data/####/ttopensdk.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak (deleted)
- /data/data/####/umeng_it.cache
- /data/media/####/.a.dat
- /data/media/####/.adfwe.dat
- /data/media/####/.cca.dat
- /data/media/####/.sfp
- /data/media/####/.testf
- /data/media/####/.umm.dat
- /data/media/####/1568417405587 (deleted)
- /data/media/####/1568417405589 (deleted)
- /data/media/####/1568417405711 (deleted)
- /data/media/####/1568417405729 (deleted)
- /data/media/####/1568417406368.db
- /data/media/####/1568417406738 (deleted)
- /data/media/####/1568417406739 (deleted)
- /data/media/####/1568417408768 (deleted)
- /data/media/####/1568417408770 (deleted)
- /data/media/####/1568417408857 (deleted)
- /data/media/####/1568417408915 (deleted)
- /data/media/####/1568417408916 (deleted)
- /data/media/####/1568417446140 (deleted)
- /data/media/####/1568417450189 (deleted)
- /data/media/####/1568417450190 (deleted)
- /data/media/####/1568417450267 (deleted)
- /data/media/####/1568417450274 (deleted)
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/alsn20170807.db
- /data/media/####/alsn20170807.db-journal
- /data/media/####/crash1568417395453.txt
- /data/media/####/crash1568417396034.txt
- /data/media/####/crash1568417399946.txt
- /data/media/####/crash1568417404042.txt
- /data/media/####/crash1568417408425.txt
- /data/media/####/crash1568417412490.txt
- /data/media/####/crash1568417412842.txt
- /data/media/####/crash1568417416578.txt
- /data/media/####/crash1568417422188.txt
- /data/media/####/crash1568417426275.txt
- /data/media/####/crash1568417430411.txt
- /data/media/####/crash1568417430711.txt
- /data/media/####/crash1568417434355.txt
- /data/media/####/crash1568417434639.txt
- /data/media/####/crash1568417441975.txt
- /data/media/####/crash1568417445858.txt
- /data/media/####/crash1568417449931.txt
- /data/media/####/crash1568417454250.txt
- /data/media/####/crash1568417458176.txt
- /data/media/####/crash1568417462136.txt
- /data/media/####/crash1568417466115.txt
- /data/media/####/crash1568417470194.txt
- /data/media/####/crash1568417474330.txt
- /data/media/####/crash1568417476327.txt
- /data/media/####/crash1568417477335.txt
- /data/media/####/sysid.dat
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- getprop ro.build.version.emui
- ls /sys/class/thermal
- libdown-native
- libjiagu1104429066
- libp2p-native
- wencrypt
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding
- 1
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding