Technical information
- Adware.Gexin.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) msg.umengc####.com:80
- TCP(HTTP/1.1) 1####.205.203.104:8007
- TCP(HTTP/1.1) api.m.ta####.com:80
- TCP(TLS/1.0) m1.pinzh####.com:443
- TCP(TLS/1.0) img.pinzh####.com:443
- a####.m.ta####.com
- a####.u####.com
- ag####.m.ta####.com
- api.m.ta####.com
- img.pinzh####.com
- m1.pinzh####.com
- msg.umengc####.com
- api.m.ta####.com/activeip/?appkey=####&ttid=####&deviceId=####&imei=####...
- api.m.ta####.com/rest/api3.do?t=####&deviceId=####&imei=####&appKey=####...
- api.m.ta####.com/rest/api3.do?ttid=####&t=####&deviceId=####&imei=####&a...
- api.m.ta####.com/rest/api3.do?ttid=####&t=####&imei=####&appKey=####&v=#...
- api.m.ta####.com/spdyip/?appkey=####&ttid=####&deviceId=####&imei=####&n...
- a####.u####.com/app_logs
- msg.umengc####.com/v2/register
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/cache/####/00703ffdd7e3a4ed644065fabd8491bc88a....0.tmp
- <Package Folder>/cache/####/05a68c468df136bdffe62873e1b31cfd401....0.tmp
- <Package Folder>/cache/####/09102b26428c2083d730c99deab5c8d0c03....0.tmp
- <Package Folder>/cache/####/1a98f81d1b7a112e5dd47ea8db683b63796....0.tmp
- <Package Folder>/cache/####/1cbee61effd4132b6ff64d15beaca02215e....0.tmp
- <Package Folder>/cache/####/1e805dd04350e59bcb7cd10c4eb3f16f22b....0.tmp
- <Package Folder>/cache/####/28fe66b086cac94c8abadd8a60b0d08f21d....0.tmp
- <Package Folder>/cache/####/486f0cb2acab0ebcc324320900e2d010128....0.tmp
- <Package Folder>/cache/####/48b1e833f8d5de3b57e8b4fb78e63cb9c74....0.tmp
- <Package Folder>/cache/####/5797f59a5459ff9a02e32f43e82ca06b055....0.tmp
- <Package Folder>/cache/####/645bb40b0af07820533fad4b334bcdad073....0.tmp
- <Package Folder>/cache/####/6f5e6244e29652cf25ea68cfa3f10d2d05e....0.tmp
- <Package Folder>/cache/####/722314148635f4c0b3f1493f9c7dd60e744....0.tmp
- <Package Folder>/cache/####/75bfb0653ea3344eeda16f092465e290916....0.tmp
- <Package Folder>/cache/####/7a3279ef11c3029b764863139ab68a1db99....0.tmp
- <Package Folder>/cache/####/89022303fd8ecce9c9ccb233619e6997942....0.tmp
- <Package Folder>/cache/####/904fca1124dd801d71379d8871f113d59e3....0.tmp
- <Package Folder>/cache/####/91f28d5ecf53cacb9dae6100d425f452d7c....0.tmp
- <Package Folder>/cache/####/9226dc9ad217814168c58de21a17043aa6e....0.tmp
- <Package Folder>/cache/####/9346bd1fb0b7142186667342d815f142fd8....0.tmp
- <Package Folder>/cache/####/b1317c07ec9193c43886ed6e04101135e3b....0.tmp
- <Package Folder>/cache/####/c463b60fdc56923b8c8d0b4e37205b6a8a1....0.tmp
- <Package Folder>/cache/####/c4c8b93546518306e8cb56472779fe49fce....0.tmp
- <Package Folder>/cache/####/c5b24d17e0dbb42e5fce91624a039318720....0.tmp
- <Package Folder>/cache/####/cefb4cd366a2cddbe1d73645bc72de6a3c1....0.tmp
- <Package Folder>/cache/####/dbc5d2f95eb1fa8888d87ef66c8383fae15....0.tmp
- <Package Folder>/cache/####/e2383a3130abbded2c2575d9f61d4566dc4....0.tmp
- <Package Folder>/cache/####/f0599220dd232e4e3c2eb49cd171d772060....0.tmp
- <Package Folder>/cache/####/f1381f5b425953b3ce7b7eb7a820dbcaabf....0.tmp
- <Package Folder>/cache/####/journal.tmp
- <Package Folder>/databases/MsgLogStore.db-journal
- <Package Folder>/databases/UmengLocalNotificationStore.db-journal
- <Package Folder>/databases/cc.db
- <Package Folder>/databases/cc.db-journal
- <Package Folder>/databases/ua.db
- <Package Folder>/databases/ua.db-journal
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/####/exchangeIdentity.json
- <Package Folder>/files/.imprint
- <Package Folder>/files/DaemonServer
- <Package Folder>/files/agoo.pid
- <Package Folder>/files/exid.dat
- <Package Folder>/files/umeng_it.cache
- <Package Folder>/shared_prefs/<Package>_preferences.xml
- <Package Folder>/shared_prefs/AGOO_CONNECT.xml
- <Package Folder>/shared_prefs/AGOO_HOST.xml
- <Package Folder>/shared_prefs/Alvin2.xml
- <Package Folder>/shared_prefs/AppStore.xml
- <Package Folder>/shared_prefs/ContextData.xml
- <Package Folder>/shared_prefs/PhoneUtil.xml
- <Package Folder>/shared_prefs/jg_so_upgrade_setting.xml
- <Package Folder>/shared_prefs/umeng_general_config.xml
- <Package Folder>/shared_prefs/umeng_message_state.xml
- <SD-Card>/.DataStorage/ContextData.xml
- <SD-Card>/.UTSystemConfig/####/Alvin2.xml
- <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.umeng.message.UmengService --es cockroach cockroach-PPreotect --es pack <Package> --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_android_daemon_1.1.0 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:5279b36856240bf5740885c0","utdid":"Wg2HdK1YoiwDAGdzx1HUn9dq","sdkVersion":"20160215"} -I agoodm.m.taobao.com -O 80 -T -Z
- chmod 500 <Package Folder>/files/DaemonServer
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- sh
- libjiagu
- tnet-2.1.20
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding