Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.0) m####.h####.com:80
- TCP(HTTP/1.1) crash-r####.yy.com:80
- TCP(HTTP/1.1) norma-e####.m####.com:80
- TCP(HTTP/1.1) log####.ifl####.com:80
- TCP(HTTP/1.1) m####.h####.com:80
- UDP(TELNET) a####.yy.com:23
- UDP(TELNET) 61.1####.73.132:23
- UDP(TELNET) 1####.247.249.100:23
- UDP(TELNET) 2####.170.50.135:23
- UDP(TELNET) 2####.228.248.99:23
- UDP(TELNET) 1####.247.249.98:23
- UDP(TELNET) 61.1####.29.214:23
- UDP(TELNET) wta####.yy.com:23
- TCP(TLS/1.0) 1####.250.179.195:443
- TCP(TLS/1.0) log####.ifl####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) a####.a####.m.####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) 1####.250.179.174:443
- TCP(TLS/1.0) msg.umengc####.com:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) s####.yy.com:443
- TCP(TLS/1.2) 2####.58.208.99:443
- TCP(TLS/1.2) md####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.174:443
- UDP wta####.yy.com:80
- UDP a####.yy.com:6002
- UDP 61.1####.29.215:5002
- UDP 1####.20.84.154:6002
- UDP 14.2####.84.167:6002
- TCP 1####.239.232.9:82
- TCP 1####.205.7.74:89
- TCP 61.1####.199.194:8099
- UDP 1####.242.117.100:4002
- UDP 1####.90.175.157:4002
- TCP 36.2####.20.92:8121
- TCP a####.yy.com:6002
- UDP wta####.yy.com:4002
- UDP wta####.yy.com:6002
- UDP a####.yy.com:4002
- UDP 1####.247.249.98:4002
- UDP 61.1####.52.149:80
- UDP 1####.239.232.9:82
- TCP a####.yy.com:6888
- UDP 1####.247.249.100:80
- UDP 61.1####.52.149:5002
- UDP wta####.yy.com:5002
- UDP 61.1####.52.174:4002
- UDP 1####.231.141.196:4002
- UDP 2####.228.248.99:4002
- TCP zb-cent####.m.ta####.com:443
- TCP user-yi####.yy.com:443
- UDP 1####.20.84.154:80
- UDP a####.yy.com:5002
- UDP 61.1####.52.149:6002
- UDP a####.yy.com:80
- TCP 2####.91.199.19:112
- TCP data-yi####.yy.com:443
- UDP 60.2####.219.164:5002
- UDP 1####.90.175.157:6002
- UDP 2####.194.67.7:80
- TCP 1####.91.19.246:8080
- a####.m.ta####.com
- a####.yy.com
- a####.yy.com
- ap-mala####.yy.com
- ap-ru####.yy.com
- ap.liveme####.com
- crash-r####.yy.com
- d####.h####.com
- d####.opensp####.cn
- data-yi####.yy.com
- do.yy.du####.####.8
- do.yy.du####.com
- h####.h####.com
- instant####.google####.com
- log####.ifl####.com
- m####.h####.com
- md####.google####.com
- msg.umengc####.com
- norma-e####.m####.com
- p####.google####.com
- p####.hls.yy.com
- p####.liveme####.com
- s####.wta####.yy.com
- s####.yy.com
- umen####.m.ta####.com
- umengj####.m.ta####.com
- user-yi####.yy.com
- wta####.yy.com
- wta####.yy.com.####.8
- y####.h####.com
- m####.h####.com/c.gif?act=####&time=####&key=####&appid=####&scene=####&...
- m####.h####.com/c.gif?act=####&time=####&key=####&userIp=####&isAnonymou...
- norma-e####.m####.com/android/exchange/getpublickey.do
- s####.yy.com:443/MobileLoginFailReport3.html?isAnonymous=####&isFirstAno...
- a####.a####.m.####.com:443/amdc/mobileDispatch?platform=####&v=####&devi...
- crash-r####.yy.com/dau/reporting
- log####.ifl####.com/index.php/clientrequest/clientcollect/isCollect
- log####.ifl####.com:443/hotupdate
- m####.h####.com/c.gif?act=####&smkdata=####&EC=####&appkey=####&item=###...
- msg.umengc####.com:443/launch
- msg.umengc####.com:443/register
- norma-e####.m####.com/push/android/external/add.do
- /data/data/####/.hptc_kache_com.yy.onepiece
- /data/data/####/.jg.ic
- /data/data/####/ACCS_BINDumeng;59f1538c734be4767d0000a1.xml
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/AGOO_BIND.xml
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/CommonPref.xml
- /data/data/####/ContextData.xml
- /data/data/####/Cookies-journal
- /data/data/####/GuidPref.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/RuntimeKit.xml
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/accs.db-journal
- /data/data/####/agoo.pid
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/com.iflytek.id.xml
- /data/data/####/com.iflytek.msc.xml
- /data/data/####/com.x.y.1.xml
- /data/data/####/com.x.y.2.xml
- /data/data/####/com.yy.pushsvc.db-journal
- /data/data/####/data.mdb
- /data/data/####/geofencing.db
- /data/data/####/geofencing.db-journal
- /data/data/####/hd_default_pref.xml
- /data/data/####/hdcltid.xml
- /data/data/####/hdid.bck
- /data/data/####/hdid_v2
- /data/data/####/hdstatis_cache_4bcbabc0.db-journal
- /data/data/####/hdstatis_cache_b62623c4.db-journal
- /data/data/####/hdstatis_cache_b62623c4_88035825.db-journal
- /data/data/####/hdstatis_cache_f4df5118.db-journal
- /data/data/####/hduuid_v1
- /data/data/####/iflytek_collect_state.xml
- /data/data/####/iflytek_device_info.zip
- /data/data/####/iflytek_state_com.yy.onepiece.xml
- /data/data/####/lbscache.xml
- /data/data/####/libjiagu.so
- /data/data/####/lock.mdb
- /data/data/####/message_accs_db
- /data/data/####/message_accs_db-journal
- /data/data/####/mipush_extra.xml
- /data/data/####/proc_auxv
- /data/data/####/table.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/udbauthlooog-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/viewerConfig
- /data/data/####/yymobile_log_files.xml
- /data/media/####/.2F6E2C5B63F0F83B
- /data/media/####/.nomedia
- /data/media/####/2022-01-01.log.txt
- /data/media/####/30a2badcb9a2a3bb1978926aaeffa0d8.0.tmp
- /data/media/####/30a2badcb9a2a3bb1978926aaeffa0d8.1.tmp
- /data/media/####/4b71d97085954f1d9c0ef200dc79e3d2
- /data/media/####/791b38fae7cd455e91816e44c1ec80dd
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/Device
- /data/media/####/Device_v2
- /data/media/####/Global
- /data/media/####/LogPath.txt
- /data/media/####/config
- /data/media/####/deviceToken
- /data/media/####/hdcltid.ini
- /data/media/####/hdstatis_20220101.log
- /data/media/####/hduuid_v1
- /data/media/####/iflyworkdir_test (deleted)
- /data/media/####/inapp_20220101.log
- /data/media/####/info.txt
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/logs_2022_01_01_23.txt
- /data/media/####/mediaSdk-trans.txt
- /data/media/####/push_jni_log.txt
- /data/media/####/pushsvc_log.txt
- /data/media/####/uuid.dat
- /data/media/####/yysdk-yym101and.txt
- /data/misc/####/primary.prof
- AES
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES
- RSA-ECB-PKCS1Padding
- AES
- AES-CBC-PKCS7Padding
- DES