Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(DNS) <Google DNS>
- TCP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(HTTP/1.1) pi####.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) 1####.254.116.117:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) tinychi####.q####.com.####.com:80
- TCP(HTTP/1.1) a####.xtoolsr####.com:80
- TCP(HTTP/1.1) sdk-ope####.g####.com:80
- TCP(TLS/1.0) 2####.107.1.97:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) ali-s####.j####.cn:443
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) gd-s####.j####.cn:443
- TCP(TLS/1.0) o####.e.kuai####.com:443
- TCP(TLS/1.0) ti####.c####.l####.####.com:443
- TCP(TLS/1.0) ce3e####.j####.cn:443
- TCP(TLS/1.0) 1####.217.17.106:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) t####.j####.cn:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) bj####.j####.cn:443
- TCP(TLS/1.2) 1####.217.17.106:443
- TCP(TLS/1.2) and####.cli####.go####.com:443
- TCP(TLS/1.2) 1####.217.19.195:443
- TCP(TLS/1.2) 1####.217.168.202:443
- TCP i####.j####.cn:7005
- TCP sdk.o####.t####.####.com:5224
- UDP s.j####.cn:19000
- UDP 1####.121.49.100:19000
- UDP 1####.229.215.60:19000
- TCP 2####.205.254.117:80
- UDP 1####.196.118.23:19000
- TCP cm-1####.g####.com:5225
- a####.xtoolsr####.com
- ali-s####.j####.cn
- and####.cli####.go####.com
- android####.go####.com
- bj####.j####.cn
- c-h####.g####.com
- cdn-sdk####.g####.com
- ce3e####.j####.cn
- cm-1####.g####.com
- cm-1####.g####.com
- cm-1####.g####.com
- easytom####.com
- gd-s####.j####.cn
- i####.j####.cn
- instant####.google####.com
- m####.go####.com
- md####.google####.com
- o####.e.kuai####.com
- p####.google####.com
- pi####.qq.com
- s####.j####.cn
- s.j####.cn
- sdk-ope####.g####.com
- sdk.c####.g####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sdkfi####.jig####.cn
- sis.j####.io
- t####.j####.cn
- cdn-sdk####.g####.com.####.com/tdata_SrK505
- cdn-sdk####.g####.com.####.com/tdata_WSq872
- cdn-sdk####.g####.com.####.com/tdata_YLc027
- cdn-sdk####.g####.com.####.com/tdata_fKw278
- sdk.o####.p####.####.com/api/addr.htm
- tinychi####.q####.com.####.com/config/hzv9.conf
- a####.xtoolsr####.com/api/v7/config/<Package>
- a####.xtoolsr####.com/api/v7/country/<Package>
- a####.xtoolsr####.com/api/v7/log/<Package>
- a####.xtoolsr####.com/api/v7/toutiao/postload/<Package>
- a####.xtoolsr####.com/api/v7/toutiao/postload_retention/<Package>
- c-h####.g####.com/api.php?format=####&t=####
- pi####.qq.com/mstat/report/?index=####
- sdk-ope####.g####.com/api.php?format=####&t=####
- /data/data/####/.259ae0b248cd62abc70bea1070bb31b6
- /data/data/####/.cl
- /data/data/####/.extConfig.xml
- /data/data/####/.jg.ic
- /data/data/####/.tpns.service.xml.xml
- /data/data/####/.tpns.settings.xml.xml
- /data/data/####/.tpush_mta.xml
- /data/data/####/.tpush_mta.xml.bak
- /data/data/####/09c0036e-7a76-4b18-aedd-6fed13581b04
- /data/data/####/1d3d1299-3ac9-45b3-bd2b-2ccd4af670bf
- /data/data/####/39285EFA.dex
- /data/data/####/39285EFA.dex.flock (deleted)
- /data/data/####/703821e4
- /data/data/####/721a43c8-bb8a-46bf-a9f3-16089291634f
- /data/data/####/74de46b9-0bab-4ed1-abb8-a93927d33c9f
- /data/data/####/74de46b9-0bab-4ed1-abb8-a93927d33c9f (deleted)
- /data/data/####/IpInfos.xml
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/Push_Page_Config.xml
- /data/data/####/ad.dat
- /data/data/####/ad001b8c-0850-415d-a2a7-125dec559c0b
- /data/data/####/ad_rule.db
- /data/data/####/ad_rule.db-journal
- /data/data/####/androidx.work.util.id.xml
- /data/data/####/androidx.work.util.preferences.xml
- /data/data/####/androidx.work.workdb-journal (deleted)
- /data/data/####/b14cc5ec-39bd-4741-9a87-3f0fd62b8438
- /data/data/####/bal.catch
- /data/data/####/bwc.catch
- /data/data/####/cache_rule.db
- /data/data/####/cache_rule.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/clean_db-journal
- /data/data/####/clean_db.xml
- /data/data/####/cn.jiguang.common.xml
- /data/data/####/cn.jiguang.prefs.xml
- /data/data/####/cn.jiguang.sdk.address.xml
- /data/data/####/cn.jiguang.sdk.report.xml
- /data/data/####/cn.jiguang.sdk.share.profile.xml
- /data/data/####/cn.jiguang.sdk.user.profile.xml
- /data/data/####/cn.jiguang.sdk.user.profile.xml.bak
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.config.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml.bak
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/com.phone.booster.app.cleaner.lite.log.dat
- /data/data/####/com.phone.booster.app.cleaner.lite.mta.cloudctr...leted)
- /data/data/####/com.phone.booster.app.cleaner.lite.mta.cloudctr.xml
- /data/data/####/com.phone.booster.app.cleaner.lite;pushservice.log.dat
- /data/data/####/com.phone.booster.app.cleaner.lite;remote.work.log.dat
- /data/data/####/com.phone.booster.app.cleaner.lite;watch.log.dat
- /data/data/####/com.phone.booster.app.cleaner.lite;xg_service_v4.log.dat
- /data/data/####/com.phone.booster.app.cleaner.lite_preferences....leted)
- /data/data/####/com.phone.booster.app.cleaner.lite_preferences.xml
- /data/data/####/com.phone.booster.app.cleaner.lite_preferences.xml.bak
- /data/data/####/com.tencent.tpush.RD.xml
- /data/data/####/com.tencent.tpush.RFHD.xml
- /data/data/####/config.dat
- /data/data/####/device_id.xml
- /data/data/####/getui_sp.xml
- /data/data/####/head_line_active.xml
- /data/data/####/httpdns_config_cache.xml
- /data/data/####/httpdns_config_cache.xml.bak
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/ksadsdk_config.xml
- /data/data/####/ksadsdk_seq.xml
- /data/data/####/libjiagu.so
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/push_stat_cache.json
- /data/data/####/pushext.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/pushservice_umeng_common_config.xml
- /data/data/####/remote.work_umeng_common_config.xml
- /data/data/####/residue.db
- /data/data/####/residue.db-journal
- /data/data/####/rl.catch
- /data/data/####/run.pid
- /data/data/####/scene.xml
- /data/data/####/tdata_SrK505
- /data/data/####/tdata_SrK505.dex
- /data/data/####/tdata_SrK505.dex.flock (deleted)
- /data/data/####/tdata_SrK505.jar
- /data/data/####/tdata_WSq872
- /data/data/####/tdata_YLc027
- /data/data/####/tdata_YLc027.jar
- /data/data/####/tdata_fKw278
- /data/data/####/tdata_fKw278.dex.flock (deleted)
- /data/data/####/tdata_fKw278.jar
- /data/data/####/tpush.shareprefs.xml
- /data/data/####/tpush.shareprefs.xml.bak
- /data/data/####/umeng_common_config.xml
- /data/data/####/update.xml
- /data/data/####/watch_process.xml
- /data/data/####/watch_umeng_common_config.xml
- /data/data/####/xg_message.db
- /data/data/####/xg_message.db-journal
- /data/data/####/xg_service_v4_umeng_common_config.xml
- /data/misc/####/primary.prof
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/.00000000000/39285EFA.dex --oat-fd=49 --oat-location=/data/user/0/<Package>/.11111111111/39285EFA.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_SrK505.jar --oat-fd=58 --oat-location=/data/user/0/<Package>/files/tdata_SrK505.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_YLc027.jar --oat-fd=84 --oat-location=/data/user/0/<Package>/files/tdata_YLc027.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_fKw278.jar --oat-fd=58 --oat-location=/data/user/0/<Package>/files/tdata_fKw278.dex --compiler-filter=speed
- app_process /system/bin com.android.commands.pm.Pm list package -3
- cat /sys/class/net/wlan0/address
- ps
- sh
- AES-CBC-PKCS5Padding
- AES-CFB8-NoPadding
- AES-ECB-PKCS5Padding
- BlowFish-ECB-PKCS5Padding
- RSA-ECB-PKCS1PADDING
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CFB8-NoPadding
- BlowFish-ECB-PKCS5Padding
- DES-ECB-PKCS5Padding
- RSA-ECB-PKCS1Padding