Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) q####.c####.l####.####.com:80
- TCP(HTTP/1.1) api.380####.com.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) api.380####.com.####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP cm-1####.ig####.com:5226
- and####.b####.qq.com
- api.380####.com
- c-h####.g####.com
- cdn-sdk####.g####.com
- cm-1####.ig####.com
- l####.tbs.qq.com
- pi####.qq.com
- plb####.u####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- u####.u####.com
- yd-####.380####.com
- cdn-sdk####.g####.com.####.com/tdata_CoH340
- cdn-sdk####.g####.com.####.com/tdata_EDB102
- cdn-sdk####.g####.com.####.com/tdata_JmH262
- cdn-sdk####.g####.com.####.com/tdata_pKX830
- q####.c####.l####.####.com/config/hz-hzv6.conf
- sdk.o####.p####.####.com/api/addr.htm
- and####.b####.qq.com/rqd/async?aid=####
- api.380####.com.####.com/friendshop/36/home/adinfo.do
- api.380####.com.####.com/friendshop/36/home/navigationlist.do
- api.380####.com.####.com/yd/buyer/client/upgrade.do
- c-h####.g####.com/api.php?format=####&t=####
- l####.tbs.qq.com/ajax?c=####&k=####
- pi####.qq.com/mstat/report/?index=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/1004
- /data/data/####/202001210008318.v1.crash
- /data/data/####/202001210008396.v1.crash
- /data/data/####/202001210008529.v1.crash
- /data/data/####/202001210008547.v1.crash
- /data/data/####/202001210008740.v1.crash
- /data/data/####/202001210008773.v1.crash
- /data/data/####/202001210008841.v1.crash
- /data/data/####/202001210008998.v1.crash
- /data/data/####/202001210009513.v1.crash
- /data/data/####/202001210009819.v1.crash
- /data/data/####/4736bd5d6dd60f0c2abe62c5b448a4f34e5670dc8bbcfe6....0.tmp
- /data/data/####/523072fee8e974d45bb47b92404ded53a823c1c877782d4....0.tmp
- /data/data/####/66748cb32d3d8f66dc5fb44ac18afadf683fe46d957694c....0.tmp
- /data/data/####/71db1fef3c4fdc8df611d2a615691e4a7b048151f71ed29....0.tmp
- /data/data/####/7a8be20e851aa76222d0ca1d64a8c637fea23c63be21413....0.tmp
- /data/data/####/925b93ab93efe8d7aed150466f0fad96d0a2be971c2729d....0.tmp
- /data/data/####/9667f1f49567
- /data/data/####/9867050eb4fd7d9636102c37794187862a004d2f888afff....0.tmp
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/FriendShipShop.xml
- /data/data/####/MultiDex.lock
- /data/data/####/QALConfigStore.dat
- /data/data/####/SP_AROUTER_CACHE.xml
- /data/data/####/TLS_DEVICE_INFO.xml
- /data/data/####/WLOGIN_DEVICE_INFO.xml
- /data/data/####/a==7.5.0&&3.3.0_1579554490894_envelope.log
- /data/data/####/aad772b5aca5aa26a73e79c937d9aefbdae31ed75d23d22....0.tmp
- /data/data/####/bc2b746bfc56942696ad333d941f8499bd5c216b6421724....0.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/c0dec36a202db28867f6bd8aaa6db69755b7eced0d7713e....0.tmp
- /data/data/####/com.eascs.friendshipshop.mid.world.ro.xml
- /data/data/####/com.eascs.friendshipshop_preferences.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NDkwNDEx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTE0Njgz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTE4ODAw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTI0ODYw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTI4MTMz;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTM2MzAw;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTM5MDIx;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTMyMzYy;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTQ0MzI3;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTQ4NjI2;
- /data/data/####/dW1weF9pbnRlcm5hbF8xNTc5NTU0NTU0MDQw;
- /data/data/####/dbece627e269bc75e3d4bcaf9a32f3f076ca9a9ebae8388....0.tmp
- /data/data/####/e2929a1389165ed52fb4cf3b757dacfb9aa8404e24bdd8f....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fb4e6aee3da4ea41d82de4e2130f039e4f0e0e93028b49e....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/i==1.2.0&&3.3.0_1579554490414_envelope.log
- /data/data/####/i==1.2.0&&3.3.0_1579554514805_envelope.log
- /data/data/####/info.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libjiagu-1772264162.so
- /data/data/####/local_crash_lock
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/native_record_lock (deleted)
- /data/data/####/pri_tencent_analysis.db_com.eascs.friendshipshop-journal
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/qalimid_v2
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/report_v5.msgstore-journal
- /data/data/####/run.pid
- /data/data/####/runlife.config.xml
- /data/data/####/security_info
- /data/data/####/sp_sophix.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak (deleted)
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbslock.txt
- /data/data/####/tdata_CoH340
- /data/data/####/tdata_CoH340.jar
- /data/data/####/tdata_JmH262
- /data/data/####/tdata_JmH262.jar
- /data/data/####/tdata_pKX830
- /data/data/####/tdata_pKX830.jar
- /data/data/####/tencent_analysis.db_com.eascs.friendshipshop-journal
- /data/data/####/tls_device.dat
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/udesk_sdk.xml
- /data/data/####/um_pri.xml
- /data/data/####/umdat.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/wlogin_device.dat
- /data/media/####/.a.dat
- /data/media/####/.adfwe.dat
- /data/media/####/.cca.dat
- /data/media/####/.nomedia
- /data/media/####/.umm.dat
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/app.20.01.21.00.log
- /data/media/####/app.db
- /data/media/####/com.eascs.friendshipshop.bin
- /data/media/####/com.eascs.friendshipshop.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/imsdk_20200120.log
- /data/media/####/imsdk_20200121.log
- /data/media/####/sdk.20.01.21.00.log
- /data/media/####/sysid.dat
- /data/media/####/tbslog.txt
- /data/media/####/tdata_CoH340
- /data/media/####/tdata_JmH262
- /data/media/####/tdata_pKX830
- /data/media/####/test.log
- /system/bin/cat /proc/cpuinfo
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.eascs.base.push.EaPushService 25448 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu-1772264162.so
- getprop
- getprop ro.product.cpu.abi
- logcat -c
- logcat -d -v threadtime
- logcat -d -v time
- ls /sys/class/thermal
- mount
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.eascs.base.push.EaPushService 25448 300 0
- Bugly
- MtaNativeCrash_v2
- _imcore_group_ext_gyp
- _imcore_jni_gyp
- _imcore_msg_ext_gyp
- _imcore_sns_ext_gyp
- _imcore_ugc_ext_gyp
- getuiext2
- gnustl_shared
- libjiagu-1772264162
- libwtcrypto
- qalcodecwrapper
- qalmsfboot
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-GCM-NoPadding
- DES-CBC-PKCS5Padding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding