Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) q####.c####.l####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(HTTP/1.1) cdn.xg####.com:80
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(TLS/1.0) s####.xg####.com:443
- TCP(TLS/1.0) in-prod####.traffic####.net:443
- TCP(TLS/1.0) www.3####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP cm-1####.ig####.com:5226
- TCP cm-1####.ig####.com:5225
- 7j####.c####.z0.####.com
- c-h####.g####.com
- cdn-sdk####.g####.com
- cdn.xg####.com
- cm-1####.ig####.com
- cm-1####.ig####.com
- in.appce####.ms
- s####.xg####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- www.3####.com
- cdn-sdk####.g####.com.####.com/tdata_EDB102
- cdn-sdk####.g####.com.####.com/tdata_cpZ817
- cdn-sdk####.g####.com.####.com/tdata_jbc429
- cdn-sdk####.g####.com.####.com/tdata_ngI479
- cdn.xg####.com/api/getinfo.ashx
- q####.c####.l####.####.com/config/hz-hzv6.conf
- q####.c####.l####.####.com/tdata_RTc910
- sdk.o####.p####.####.com/api/addr.htm
- c-h####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- sdk-ope####.g####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.jg.ic
- /data/data/####/09a22d18-079a-4651-87b9-7ac384141914.json
- /data/data/####/09a22d18-079a-4651-87b9-7ac384141914.throwable
- /data/data/####/1cbef6a0-bb65-45e5-a6b4-66c1094aa808.json
- /data/data/####/1cbef6a0-bb65-45e5-a6b4-66c1094aa808.throwable
- /data/data/####/3221d4d0-f8c6-4f7b-a527-c1997554ed33.json
- /data/data/####/3221d4d0-f8c6-4f7b-a527-c1997554ed33.throwable
- /data/data/####/3ed9154f-cf2c-4d94-b65c-38736a92c4b8.json
- /data/data/####/3ed9154f-cf2c-4d94-b65c-38736a92c4b8.throwable
- /data/data/####/511bc421-9afd-4a9e-bb10-d464bbcc0173.json
- /data/data/####/511bc421-9afd-4a9e-bb10-d464bbcc0173.throwable
- /data/data/####/5b4936bd-6f82-4aa0-9db8-20ecf1340640.json
- /data/data/####/5b4936bd-6f82-4aa0-9db8-20ecf1340640.throwable
- /data/data/####/5f6165ff-1b3e-4985-a9d1-018fca651586.json
- /data/data/####/5f6165ff-1b3e-4985-a9d1-018fca651586.throwable
- /data/data/####/76cdd79f-1bc0-4a31-9d01-f8165177bb6b.json
- /data/data/####/76cdd79f-1bc0-4a31-9d01-f8165177bb6b.throwable
- /data/data/####/7ebbe625f2d2
- /data/data/####/8452b541-d852-4850-83f9-2304c40171d6.json
- /data/data/####/8452b541-d852-4850-83f9-2304c40171d6.throwable
- /data/data/####/99a27a84-fae6-4935-8c3a-3acdf1270b87.json
- /data/data/####/99a27a84-fae6-4935-8c3a-3acdf1270b87.throwable
- /data/data/####/AppCenter.xml
- /data/data/####/COUNTLY_STORE.xml
- /data/data/####/Push.xml
- /data/data/####/b5155bfe-57d8-4dff-b9e3-7d4627c43948.json
- /data/data/####/b5155bfe-57d8-4dff-b9e3-7d4627c43948.throwable
- /data/data/####/bff63ddc-8d34-4b66-9b47-ed4de22dde78.json
- /data/data/####/bff63ddc-8d34-4b66-9b47-ed4de22dde78.throwable
- /data/data/####/ce3896f4-1845-4940-bcae-b19ca6013191.json
- /data/data/####/ce3896f4-1845-4940-bcae-b19ca6013191.throwable
- /data/data/####/com.microsoft.appcenter.persistence-journal
- /data/data/####/d5c69736-6cd0-45d1-8814-f29ead214aae.json
- /data/data/####/d5c69736-6cd0-45d1-8814-f29ead214aae.throwable
- /data/data/####/ee8cbe98-6e40-4bf5-af71-72695d587bc6.json
- /data/data/####/ee8cbe98-6e40-4bf5-af71-72695d587bc6.throwable
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/hosts.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu834782669.so
- /data/data/####/openudid_prefs.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/run.pid
- /data/data/####/tdata_cpZ817
- /data/data/####/tdata_cpZ817.jar
- /data/data/####/tdata_jbc429
- /data/data/####/tdata_jbc429.jar
- /data/data/####/tdata_ngI479
- /data/data/####/tdata_ngI479.jar
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.hongyue.android.ope.bin
- /data/media/####/com.hongyue.android.ope.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_cpZ817
- /data/media/####/tdata_jbc429
- /data/media/####/tdata_ngI479
- /data/media/####/test.log
- /system/bin/cat /proc/cpuinfo
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui.OPEPushService 25285 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- mount
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.getui.OPEPushService 25285 300 0
- getuiext2
- libjiagu834782669
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding