Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) na61-####.wagbr####.ali####.####.com:80
- TCP(HTTP/1.1) ada####.m.ta####.com:80
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) hk.wagbr####.non####.####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) img1-mi####.b0.a####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) o####.jd.com:80
- TCP(HTTP/1.1) gs.g####.com:80
- TCP(HTTP/1.1) ad####.m.ta####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) hbk.shu####.cn:80
- TCP(HTTP/1.1) po####.jd.com:80
- TCP(HTTP/1.1) norma-e####.m####.com:80
- TCP(HTTP/1.1) b####.g####.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) ope####.m.ta####.com:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) www.henza####.com:443
- TCP(TLS/1.0) dai.shu####.cn:443
- TCP(TLS/1.0) api.shu####.cn:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP(TLS/1.0) nbsdk-b####.al####.com:443
- TCP(TLS/1.0) img1-mi####.b0.a####.com:443
- TCP(TLS/1.0) ke####.jd.com:443
- TCP(TLS/1.0) d####.k.jd.com:443
- TCP(TLS/1.0) dcc.shu####.cn:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) a####.m.jd.com:443
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) www.j####.com:443
- TCP(TLS/1.0) m####.m.jd.com:443
- TCP(TLS/1.0) d####.shu####.cn:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP(TLS/1.0) daa.shu####.cn:443
- TCP(TLS/1.0) www.go####.com:443
- TCP c####.g####.ig####.com:5224
- TCP sdk.o####.t####.####.com:5224
- 7j####.c####.z0.####.com
- a####.exc.mob.com
- a####.m.jd.com
- acs4bai####.m.ta####.com
- ad####.m.ta####.com
- ada####.m.ta####.com
- and####.b####.qq.com
- api.growi####.com
- api.shu####.cn
- b####.g####.com
- c####.g####.com
- c####.g####.com
- c####.g####.ig####.com
- c-h####.g####.com
- d####.k.jd.com
- d####.shu####.cn
- daa.shu####.cn
- dai.shu####.cn
- dcc.shu####.cn
- dgst####.jd.com
- gs.g####.com
- hbk.shu####.cn
- i####.miaom####.com
- ke####.jd.com
- m####.m.jd.com
- nbsdk-b####.al####.com
- norma-e####.m####.com
- o####.jd.com
- po####.jd.com
- s####.ml####.cc
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- ssl.gst####.com
- t####.growi####.com
- t.growi####.com
- wb.110.ta####.com
- www.go####.com
- www.gst####.com
- www.henza####.com
- y####.al####.com
- ad####.m.ta####.com/rest/gc2?ak=####&av=####&c=####&d=####&sv=####&t=###...
- img1-mi####.b0.a####.com/image/ba76ea70cd1955bc2e13afbfc0391f1f.png
- norma-e####.m####.com/android/exchange/getpublickey.do
- ope####.m.ta####.com/gw-open/mtop.taobao.tbk.sdk.config/1.0/?data=####
- t####.c####.q####.####.com/tdata_QGQ361
- t####.c####.q####.####.com/tdata_XNg805
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- a####.exc.mob.com/errconf
- ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
- and####.b####.qq.com/rqd/async?aid=####
- b####.g####.com/api.php?format=####&t=####
- c####.g####.com/api.php?format=####&t=####
- gs.g####.com/encryption/key/fetch
- gs.g####.com/geshu/sdkStatistics/bd
- gs.g####.com/geshu/sdkStatistics/ubi
- hbk.shu####.cn/report?v=####&c=####&e=####&t=####
- hk.wagbr####.non####.####.com/saveWb.json
- na61-####.wagbr####.ali####.####.com/api/update.do
- norma-e####.m####.com/push/android/external/add.do
- o####.jd.com/upload
- po####.jd.com/m/log/v1
- po####.jd.com/m/sys/v1
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.duid
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/043dde54025853c412f118205c1e835106bc7b7f4a6a1c8....0.tmp
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1004
- /data/data/####/10f4bf88c1a05e9c04726687c99a18b6b97575b33e9e04b....0.tmp
- /data/data/####/15c587a93a7d0439b17891417b241f6d5f89fd2c517015b....0.tmp
- /data/data/####/1b031113e7694f465cf30e4d0424a87b003693d70d28b40....0.tmp
- /data/data/####/1d77ea041509fe06.lock
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/3f60145f17f78ee4562cf957ddfb7bc32cbf8592fae1e49....0.tmp
- /data/data/####/3f60145f17f78ee4562cf957ddfb7bc32cbf8592fae1e49...5fa1.0
- /data/data/####/4ff8cc1d3473e674b5622561f9017765062cd357c74aec6....0.tmp
- /data/data/####/4ff8cc1d3473e674b5622561f9017765062cd357c74aec6...94aa.0
- /data/data/####/5d0323fbb1dbd3f03076a83d0d4435c6048dc47d8827c2f....0.tmp
- /data/data/####/66d5d681eafca4ca4a5e176f7474c3540b8da3925013846....0.tmp
- /data/data/####/74dbb81ce98cf289d0b89c1581abbda3912bb8ca64e2f79....0.tmp
- /data/data/####/755c73f0851c23f81f54eb8505429141208e50b5868bc5b....0.tmp
- /data/data/####/861e3aea84e5bf6304db916f30ce61b459011e1d3b7ad05....0.tmp
- /data/data/####/8654e0cd2d506f8be80de3cf4bd02af73dabd2115a0a7e0....0.tmp
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/AlibcLinkPartner.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MultiDex.lock
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UTCommon.xml
- /data/data/####/access_control.control.mx
- /data/data/####/access_control.write.mx
- /data/data/####/aliTradeConfigSP.xml
- /data/data/####/ap.Lock
- /data/data/####/auth_sdk_device.xml
- /data/data/####/auth_shared.xml
- /data/data/####/b4276069b68664a726356cabc5f1982eba2bf65e1d7ae56....0.tmp
- /data/data/####/b4276069b68664a726356cabc5f1982eba2bf65e1d7ae56...642a.0
- /data/data/####/bugly_db_-journal
- /data/data/####/cf349fabddb95535649c2e3988c6ffd6d9d4624a6abda50....0.tmp
- /data/data/####/com.henzanapp.miaomiaozhe;du.growing.db
- /data/data/####/com.henzanapp.miaomiaozhe;du.growing.db-journal
- /data/data/####/com.henzanapp.miaomiaozhe;pushservice.growing.db
- /data/data/####/com.henzanapp.miaomiaozhe;pushservice.growing.db-journal
- /data/data/####/com.henzanapp.miaomiaozhe_dna.xml
- /data/data/####/com.henzanapp.miaomiaozhe_preferences.xml
- /data/data/####/com.henzanapp.miaomiaozhe_prefs.xml
- /data/data/####/com.henzanapp.miaomiaozhe_prefs.xml.bak (deleted)
- /data/data/####/com.x.y.1.xml
- /data/data/####/com.x.y.2.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/device_id.xml.xml
- /data/data/####/deviceid_prefs.xml
- /data/data/####/domain_1
- /data/data/####/du.lock
- /data/data/####/f16b03c73422b27ed6a78b30ae1fff9e182cb438f05c715....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/growing.db
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid.xml
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/gtc.db-journal
- /data/data/####/gx_sp.xml
- /data/data/####/henzan.xml
- /data/data/####/ias.db-journal
- /data/data/####/ias_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/kepler_public.xml
- /data/data/####/libjiagu-1968675475.so
- /data/data/####/libsgmainso-5.1.81.so.tmp
- /data/data/####/libsgsecuritybodyso-5.1.25.so.tmp
- /data/data/####/local_crash_lock
- /data/data/####/lock.lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/myRealm.realm
- /data/data/####/myRealm.realm.lock
- /data/data/####/mz_push_preference.xml
- /data/data/####/native_record_lock
- /data/data/####/persistent_data.xml
- /data/data/####/persistent_data.xml (deleted)
- /data/data/####/persistent_data.xml.bak
- /data/data/####/persistent_data.xml.bak (deleted)
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/save_ma_init_commoninfo.xml
- /data/data/####/security_info
- /data/data/####/silent.preferences.xml
- /data/data/####/sp.lock
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbslock.txt
- /data/data/####/tdata_QGQ361
- /data/data/####/tdata_QGQ361.jar
- /data/data/####/tdata_XNg805
- /data/data/####/tdata_XNg805.jar
- /data/data/####/timestamp
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/..ccdid
- /data/media/####/..ccvid
- /data/media/####/..cvtid
- /data/media/####/._android.dat
- /data/media/####/._system.dat
- /data/media/####/.artc_lock
- /data/media/####/.ccdid
- /data/media/####/.ccvid
- /data/media/####/.cvtid
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.mn_-1464060969
- /data/media/####/.n_a
- /data/media/####/.n_b
- /data/media/####/.n_c
- /data/media/####/.n_d
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/.wkl
- /data/media/####/18d2ed21a6e7170c48de5438de9b9d8e
- /data/media/####/18d2ed21a6e7170c48de5438de9b9d8e (deleted)
- /data/media/####/2019-03-14.log.txt
- /data/media/####/6c709c11d2d46a7b
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/_android.dat
- /data/media/####/_system.dat
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.henzanapp.miaomiaozhe.bin
- /data/media/####/com.henzanapp.miaomiaozhe.db
- /data/media/####/com.henzanapp.miaomiaozhe_.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/d41d8cd98f00b204e9800998ecf8427e
- /data/media/####/dd7893586a493dc3
- /data/media/####/dfe55732e3ae9e6e6f3a4348457e1ba7
- /data/media/####/dfe55732e3ae9e6e6f3a4348457e1ba7 (deleted)
- /data/media/####/duid
- /data/media/####/hid.dat
- /data/media/####/n_a
- /data/media/####/n_b
- /data/media/####/n_c
- /data/media/####/n_d
- /data/media/####/tbslog.txt
- /data/media/####/tdata_QGQ361
- /data/media/####/tdata_XNg805
- /data/media/####/test.log
- /system/bin/sh -c getprop
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 25547 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- date
- df
- getprop
- getprop ro.product.cpu.abi
- id
- ip link
- ls /dev/socket
- ls /system/fonts
- mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
- ps
- sh -c cat /proc/meminfo
- sh -c cat /sys/class/net/eth0/address
- sh -c cd /proc/;cat cpuinfo
- sh -c cd /proc/net/ && cat arp
- sh -c cd /proc/self/;cat status
- sh -c echo MENGOUJGODkyRDk4MzhCNkEzQjJGMjgwODU1MDAxNzUwNTkwMDcwQw== > <SD-Card>/../../../../../..<SD-Card>/.n_a
- sh -c echo MENGOUJGODkyRDk4MzhCNkEzQjJGMjgwODU1MDAxNzUwNTkwMDcwQw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_a
- sh -c echo MjRDNjhCRjJGRTcwRDZBMjdBMzM2RjUwMjIwRjNFRTRjOGZ2NXhDVjUrMllMaEtrSGRjWjQ2NGp3aGlwbGFNMTV4R3gydjFBVUIxUXMzVUNHMGN5OC9qNFJUK3E5N0xkbGYxdkF6WE5udSsxTDV0MnF6dSt5QnphWHRvODdJUmNxTjAvenE2bDBMeWpza3Zva0Z1UnFxMTdOMW9iWWFSZlArVkZJOE5oS0MvUmcvaWVtYkFyVG1jQlRJZWlJSGlJb3NNaDhZNFNRdFlVUGhBM2pFb3V4TEpJeHozSDdPN25wdEhrRTNqYXVMS1NndFlWY3Y4NXljSzE4YU5IaS9zSHBvWnF4S2FEMWgxVXRjd01wSmlFWlZRaHcvcnM5bmp4SUQvNEpCekE2SHJPS0syK2ljQXBpejJwUWc5Y09Pd3ovWWk2YXFoY3Q4NnJwb0g3Tk4vbTZqYjQzcTZvZ3pzK1lPQ2JRY1ZQRkd4NG1EdGZTKzJVbDYwTzRURlJNdWd5azVjSG43UnVjZ1VnOHM1RStxWUM1eEQ2YUdrZUNFc29vOHAzajNjbjJSWT0= > <SD-Card>/../../../../../..<SD-Card>/..ccdid
- sh -c echo MjRDNjhCRjJGRTcwRDZBMjdBMzM2RjUwMjIwRjNFRTRjOGZ2NXhDVjUrMllMaEtrSGRjWjQ2NGp3aGlwbGFNMTV4R3gydjFBVUIxUXMzVUNHMGN5OC9qNFJUK3E5N0xkbGYxdkF6WE5udSsxTDV0MnF6dSt5QnphWHRvODdJUmNxTjAvenE2bDBMeWpza3Zva0Z1UnFxMTdOMW9iWWFSZlArVkZJOE5oS0MvUmcvaWVtYkFyVG1jQlRJZWlJSGlJb3NNaDhZNFNRdFlVUGhBM2pFb3V4TEpJeHozSDdPN25wdEhrRTNqYXVMS1NndFlWY3Y4NXljSzE4YU5IaS9zSHBvWnF4S2FEMWgxVXRjd01wSmlFWlZRaHcvcnM5bmp4SUQvNEpCekE2SHJPS0syK2ljQXBpejJwUWc5Y09Pd3ovWWk2YXFoY3Q4NnJwb0g3Tk4vbTZqYjQzcTZvZ3pzK1lPQ2JRY1ZQRkd4NG1EdGZTKzJVbDYwTzRURlJNdWd5azVjSG43UnVjZ1VnOHM1RStxWUM1eEQ2YUdrZUNFc29vOHAzajNjbjJSWT0= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccdid
- sh -c echo NDcxNjRDODQ4RjdFNjA1MDBFNDQ1NDlDQzQzMzkxNTFlMWJiYmI1NGJjYzU0Njg4YTA0ZWQ2MTExOTc0YmRjZwo= > <SD-Card>/../../../../../..<SD-Card>/.duid
- sh -c echo NDcxNjRDODQ4RjdFNjA1MDBFNDQ1NDlDQzQzMzkxNTFlMWJiYmI1NGJjYzU0Njg4YTA0ZWQ2MTExOTc0YmRjZwo= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/duid
- sh -c echo NEVCNTUyQzg5NjY2RTU3OTBBQTQwQTQ0Qzc4Qzk1ODMwMDAyMDA= > <SD-Card>/../../../../../..<SD-Card>/.n_b
- sh -c echo NEVCNTUyQzg5NjY2RTU3OTBBQTQwQTQ0Qzc4Qzk1ODMwMDAyMDA= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_b
- sh -c echo NUMwNURGNDY0NTg0OUY4Qjk1Q0FDREE1NTQ2MTg4NEE4MUVFRkU6ODREMTc3OjUxMzc4OA== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c echo NUMwNURGNDY0NTg0OUY4Qjk1Q0FDREE1NTQ2MTg4NEE4MUVFRkU6ODREMTc3OjUxMzc4OA== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/..ccvid
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccvid
- sh -c echo ODYzNDEzQjk3NkI1MzUzRDg4ODJGMTQxOTQ2RUQxNjk5QjAx > <SD-Card>/../../../../../..<SD-Card>/.n_d
- sh -c echo ODYzNDEzQjk3NkI1MzUzRDg4ODJGMTQxOTQ2RUQxNjk5QjAx > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_d
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c echo RUE1RDRENEFFRjkxMzRENDYwRDk3MzMxRjJERUEzQTUxNTUyNTgyMjI1 > <SD-Card>/../../../../../..<SD-Card>/..cvtid
- sh -c echo RUE1RDRENEFFRjkxMzRENDYwRDk3MzMxRjJERUEzQTUxNTUyNTgyMjI1 > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.cvtid
- sh -c echo RkQxODlGOEE4RTk3MjE2MkQ3MTI3RTJENUVEM0RENDUwMDBB > <SD-Card>/../../../../../..<SD-Card>/.n_c
- sh -c echo RkQxODlGOEE4RTk3MjE2MkQ3MTI3RTJENUVEM0RENDUwMDBB > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_c
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GTPushService 25547 300 0
- Bugly
- du
- getuiext3
- libjiagu-1968675475
- realm-jni
- sgmainso-5.1
- sgsecuritybodyso-5.1
- ut_c_api
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- desede-CBC-NoPadding