Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) na61-####.wagbr####.ali####.####.com:80
- TCP(HTTP/1.1) ada####.m.ta####.com:80
- TCP(HTTP/1.1) c####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) hk.wagbr####.non####.####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) img1-mi####.b0.a####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) o####.jd.com:80
- TCP(HTTP/1.1) gs.g####.com:80
- TCP(HTTP/1.1) ad####.m.ta####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) hbk.shu####.cn:80
- TCP(HTTP/1.1) po####.jd.com:80
- TCP(HTTP/1.1) norma-e####.m####.com:80
- TCP(HTTP/1.1) wild####.al####.com.####.net:80
- TCP(HTTP/1.1) b####.g####.com:80
- TCP(HTTP/1.1) ope####.m.ta####.com:80
- TCP(TLS/1.0) www.henza####.com:443
- TCP(TLS/1.0) ke####.jd.com:443
- TCP(TLS/1.0) dai.shu####.cn:443
- TCP(TLS/1.0) s####.ml####.cc:443
- TCP(TLS/1.0) t.growi####.com:443
- TCP(TLS/1.0) nbsdk-b####.al####.com:443
- TCP(TLS/1.0) img1-mi####.b0.a####.com:443
- TCP(TLS/1.0) d####.k.jd.com:443
- TCP(TLS/1.0) dcc.shu####.cn:443
- TCP(TLS/1.0) a####.m.jd.com:443
- TCP(TLS/1.0) api.growi####.com:443
- TCP(TLS/1.0) www.j####.com:443
- TCP(TLS/1.0) m####.m.jd.com:443
- TCP(TLS/1.0) d####.shu####.cn:443
- TCP(TLS/1.0) a####.shu####.cn:443
- TCP(TLS/1.0) t####.growi####.com:443
- TCP(TLS/1.0) daa.shu####.cn:443
- TCP(TLS/1.0) wild####.al####.com.####.net:443
- TCP sdk.o####.t####.####.com:5224
- a####.exc.mob.com
- a####.m.jd.com
- a####.shu####.cn
- acs4bai####.m.ta####.com
- ad####.m.ta####.com
- ada####.m.ta####.com
- and####.b####.qq.com
- api.growi####.com
- b####.g####.com
- c####.g####.com
- c####.g####.com
- d####.k.jd.com
- d####.shu####.cn
- daa.shu####.cn
- dai.shu####.cn
- dcc.shu####.cn
- dgst####.jd.com
- gs.g####.com
- hbk.shu####.cn
- i####.miaom####.com
- img.al####.com
- ke####.jd.com
- l####.tbs.qq.com
- m####.m.jd.com
- nbsdk-b####.al####.com
- norma-e####.m####.com
- o####.jd.com
- po####.jd.com
- s####.ml####.cc
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- t####.growi####.com
- t.growi####.com
- wb.110.ta####.com
- www.henza####.com
- y####.al####.com
- ad####.m.ta####.com/rest/gc2?ak=####&av=####&c=####&d=####&sv=####&t=###...
- img1-mi####.b0.a####.com/image/ba76ea70cd1955bc2e13afbfc0391f1f.png
- norma-e####.m####.com/android/exchange/getpublickey.do
- ope####.m.ta####.com/gw-open/mtop.taobao.tbk.sdk.config/1.0/?data=####
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- wild####.al####.com.####.net/bao/uploaded/i2/2931078658/O1CN012DpPbOOUOZ...
- a####.exc.mob.com/errconf
- ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
- and####.b####.qq.com/rqd/async?aid=####
- b####.g####.com/api.php?format=####&t=####
- c####.g####.com/api.php?format=####&t=####
- gs.g####.com/encryption/key/fetch
- gs.g####.com/geshu/sdkStatistics/bd
- gs.g####.com/geshu/sdkStatistics/ubi
- hbk.shu####.cn/report?v=####&c=####&e=####&t=####
- hk.wagbr####.non####.####.com/saveWb.json
- l####.tbs.qq.com/ajax?c=####&k=####
- na61-####.wagbr####.ali####.####.com/api/update.do
- norma-e####.m####.com/push/android/external/add.do
- o####.jd.com/upload
- po####.jd.com/m/log/v1
- po####.jd.com/m/sys/v1
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.duid
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/04306f7d47f7c38ff26e08eaaee922cf7936a51772af7fc....0.tmp
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1004
- /data/data/####/13ce17e86565266ca961ca9d664944b15671cdee76e2def....0.tmp
- /data/data/####/14e4814e414eece5fdf90f4181bb109df556292f5657f12....0.tmp
- /data/data/####/1d77ea041509fe06.lock
- /data/data/####/1dd7eef7a90440b0016e15fac04f8b7a8be530bed16b006....0.tmp
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/36a92c0f4c1306f74b0c8e85fa4d44c2d225abfbcd554cc....0.tmp
- /data/data/####/3bb8779c66265a10a8d3e16d80eba8239e9da1fac5a47db....0.tmp
- /data/data/####/47b1fdc817c304f340967a1fb8ad047b0c0c7b8b0a24964....0.tmp
- /data/data/####/52167390501a54f606d01edda3b53df555c85c04a7b3fd8....0.tmp
- /data/data/####/54ac53a198e3d4a558eaec2c46599494ab2fefff774ff76....0.tmp
- /data/data/####/6515f35759351bf72a48dd4c6e8d05666e434d6f6f891b9....0.tmp
- /data/data/####/66498d6393691d01a5df5f0afc16a18ce45271552abd69a....0.tmp
- /data/data/####/707e2f05f0b5458cfed8b6ddcb9ba58727606b66fd37e4f....0.tmp
- /data/data/####/7e3e1f9085c851a031c8646aa4725b19db842b3862c5ee9....0.tmp
- /data/data/####/8b0d667e75fae95716aac3c9356a4ee72959df92f45e75f....0.tmp
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/92cb6b53420fee34b6254dce4de23c1f1d081ecf6e1dbe8....0.tmp
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/AlibcLinkPartner.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MultiDex.lock
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UTCommon.xml
- /data/data/####/access_control.control.mx
- /data/data/####/access_control.write.mx
- /data/data/####/aliTradeConfigSP.xml
- /data/data/####/ap.Lock
- /data/data/####/auth_sdk_device.xml
- /data/data/####/auth_shared.xml
- /data/data/####/b327f543073ba8e8459084ff7d5ec7daed9784bbd3297e2....0.tmp
- /data/data/####/b4276069b68664a726356cabc5f1982eba2bf65e1d7ae56....0.tmp
- /data/data/####/b7614a9b7335eb30aeffaa0a4935d1183287db6559f390e....0.tmp
- /data/data/####/bugly_db_-journal
- /data/data/####/c1d17b5956f13db28c8cff5dbcf2515eb5324fca7445ea2....0.tmp
- /data/data/####/c7c16c4d9ec118b2fb8fa95758dddf51c0662e907079e00....0.tmp
- /data/data/####/cc20abfc1c6cbb56ae9f6dc0583fafec9cf3cba457d0db9....0.tmp
- /data/data/####/com.henzanapp.miaomiaozhe;pushservice.growing.db
- /data/data/####/com.henzanapp.miaomiaozhe;pushservice.growing.db-journal
- /data/data/####/com.henzanapp.miaomiaozhe_dna.xml
- /data/data/####/com.henzanapp.miaomiaozhe_preferences.xml
- /data/data/####/com.henzanapp.miaomiaozhe_prefs.xml
- /data/data/####/com.x.y.1.xml
- /data/data/####/com.x.y.2.xml
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/d96342e80e88ced24cfae195a4e1dbb2347f56fccde8197....0.tmp
- /data/data/####/d96342e80e88ced24cfae195a4e1dbb2347f56fccde8197...b52f.0
- /data/data/####/device_id.xml.xml
- /data/data/####/deviceid_prefs.xml
- /data/data/####/domain_1
- /data/data/####/du.lock
- /data/data/####/e0d80be2c5ad366b55fec55f87aa9aa887647903214f26b....0.tmp
- /data/data/####/e5b38103c1cbf6c7551ea75e4d9bd74964a8921aa1ef541....0.tmp
- /data/data/####/e5ebc0bc8f6fe279c0bff5c010df1990d38b30d4220762b....0.tmp
- /data/data/####/ec5c8d49ae0de5e5eda690314ef365380d51326fcb45e20....0.tmp
- /data/data/####/getui_sp.xml
- /data/data/####/growing.db-journal
- /data/data/####/growing_ecsid.xml
- /data/data/####/growing_persist_data.xml
- /data/data/####/growing_profile.xml
- /data/data/####/growing_server_pref.xml
- /data/data/####/gtc.db-journal
- /data/data/####/henzan.xml
- /data/data/####/ias.db-journal
- /data/data/####/ias_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/kepler_public.xml
- /data/data/####/libjiagu-1968675475.so
- /data/data/####/libsgmainso-5.1.81.so.tmp
- /data/data/####/libsgsecuritybodyso-5.1.25.so.tmp
- /data/data/####/local_crash_lock
- /data/data/####/lock.lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/multidex.version.xml
- /data/data/####/mwsdk_analytics.db-journal
- /data/data/####/myRealm.realm
- /data/data/####/myRealm.realm.lock
- /data/data/####/mz_push_preference.xml
- /data/data/####/native_record_lock
- /data/data/####/persistent_data.xml
- /data/data/####/persistent_data.xml.bak (deleted)
- /data/data/####/push.pid
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/save_ma_init_commoninfo.xml
- /data/data/####/security_info
- /data/data/####/silent.preferences.xml
- /data/data/####/sp.lock
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/timestamp
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/..ccdid
- /data/media/####/..ccvid
- /data/media/####/..cvtid
- /data/media/####/._android.dat
- /data/media/####/._system.dat
- /data/media/####/.artc_lock
- /data/media/####/.ccdid
- /data/media/####/.ccvid
- /data/media/####/.cvtid
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.mn_-1464060969
- /data/media/####/.n_a
- /data/media/####/.n_b
- /data/media/####/.n_c
- /data/media/####/.n_d
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/.wkl
- /data/media/####/18d2ed21a6e7170c48de5438de9b9d8e
- /data/media/####/2019-03-25.log.txt
- /data/media/####/6c709c11d2d46a7b
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/_android.dat
- /data/media/####/_system.dat
- /data/media/####/com.henzanapp.miaomiaozhe.bin
- /data/media/####/com.henzanapp.miaomiaozhe_.db
- /data/media/####/d41d8cd98f00b204e9800998ecf8427e
- /data/media/####/d41d8cd98f00b204e9800998ecf8427e (deleted)
- /data/media/####/dd7893586a493dc3
- /data/media/####/dfe55732e3ae9e6e6f3a4348457e1ba7
- /data/media/####/duid
- /data/media/####/hid.dat
- /data/media/####/n_a
- /data/media/####/n_b
- /data/media/####/n_c
- /data/media/####/n_d
- /system/bin/sh -c getprop
- cat /sys/class/net/wlan0/address
- date
- df
- getprop
- getprop ro.product.cpu.abi
- id
- ip link
- ls /system/fonts
- mkdir -p <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/
- ps
- service call iphonesubinfo 1
- sh -c cat /proc/meminfo
- sh -c cd /proc/;cat cpuinfo
- sh -c cd /proc/net/ && cat arp
- sh -c cd /proc/self/;cat status
- sh -c echo MENGOUJGODkyRDk4MzhCNkEzQjJGMjgwODU1MDAxNzUwNTkwMDcwQw== > <SD-Card>/../../../../../..<SD-Card>/.n_a
- sh -c echo MENGOUJGODkyRDk4MzhCNkEzQjJGMjgwODU1MDAxNzUwNTkwMDcwQw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_a
- sh -c echo MTgzRDlFOEFGQTY4QUYzRjdENUVBQjkwREFBMjhCRjJhNzI4NGUzZjk3NmY0NmU1OWU0MWE5ZTVjNjVkOWVjNwo= > <SD-Card>/../../../../../..<SD-Card>/.duid
- sh -c echo MTgzRDlFOEFGQTY4QUYzRjdENUVBQjkwREFBMjhCRjJhNzI4NGUzZjk3NmY0NmU1OWU0MWE5ZTVjNjVkOWVjNwo= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/duid
- sh -c echo MjRDNjhCRjJGRTcwRDZBMjdBMzM2RjUwMjIwRjNFRTRjOGZ2NXhDVjUrMllMaEtrSGRjWjQ2NGp3aGlwbGFNMTV4R3gydjFBVUIxUXMzVUNHMGN5OC9qNFJUK3E5N0xkbGYxdkF6WE5udSsxTDV0MnF6dSt5QnphWHRvODdJUmNxTjAvenE2bDBMeWpza3Zva0Z1UnFxMTdOMW9iWWFSZlArVkZJOE5oS0MvUmcvaWVtYkFyVG1jQlRJZWlJSGlJb3NNaDhZNFNRdFlVUGhBM2pFb3V4TEpJeHozSDdPN25wdEhrRTNqYXVMS1NndFlWY3Y4NXljSzE4YU5IaS9zSHBvWnF4S2FEMWgxVXRjd01wSmlFWlZRaHcvcnM5bmp4SUQvNEpCekE2SHJPS0syK2ljQXBpejJwUWc5Y09Pd3ovWWk2YXFoY3Q4NnJwb0g3Tk4vbTZqYjQzcTZvZ3pzK1lPQ2JRY1ZQRkd4NG1EdGZTKzJVbDYwTzRURlJNdWd5azVjSG43UnVjZ1VnOHM1RStxWUM1eEQ2YUdrZUNFc29vOHAzajNjbjJSWT0= > <SD-Card>/../../../../../..<SD-Card>/..ccdid
- sh -c echo MjRDNjhCRjJGRTcwRDZBMjdBMzM2RjUwMjIwRjNFRTRjOGZ2NXhDVjUrMllMaEtrSGRjWjQ2NGp3aGlwbGFNMTV4R3gydjFBVUIxUXMzVUNHMGN5OC9qNFJUK3E5N0xkbGYxdkF6WE5udSsxTDV0MnF6dSt5QnphWHRvODdJUmNxTjAvenE2bDBMeWpza3Zva0Z1UnFxMTdOMW9iWWFSZlArVkZJOE5oS0MvUmcvaWVtYkFyVG1jQlRJZWlJSGlJb3NNaDhZNFNRdFlVUGhBM2pFb3V4TEpJeHozSDdPN25wdEhrRTNqYXVMS1NndFlWY3Y4NXljSzE4YU5IaS9zSHBvWnF4S2FEMWgxVXRjd01wSmlFWlZRaHcvcnM5bmp4SUQvNEpCekE2SHJPS0syK2ljQXBpejJwUWc5Y09Pd3ovWWk2YXFoY3Q4NnJwb0g3Tk4vbTZqYjQzcTZvZ3pzK1lPQ2JRY1ZQRkd4NG1EdGZTKzJVbDYwTzRURlJNdWd5azVjSG43UnVjZ1VnOHM1RStxWUM1eEQ2YUdrZUNFc29vOHAzajNjbjJSWT0= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccdid
- sh -c echo MjhCMjhEMDQzMERFNjdGQ0QyQjA5N0E5QjgwNEI0NjExNTUzNTM0Nzg3 > <SD-Card>/../../../../../..<SD-Card>/..cvtid
- sh -c echo MjhCMjhEMDQzMERFNjdGQ0QyQjA5N0E5QjgwNEI0NjExNTUzNTM0Nzg3 > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.cvtid
- sh -c echo NEVCNTUyQzg5NjY2RTU3OTBBQTQwQTQ0Qzc4Qzk1ODMwMDAyMDA= > <SD-Card>/../../../../../..<SD-Card>/.n_b
- sh -c echo NEVCNTUyQzg5NjY2RTU3OTBBQTQwQTQ0Qzc4Qzk1ODMwMDAyMDA= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_b
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/..ccvid
- sh -c echo NkRGMTFDMTFGMTFBODA1M0MwMjQ1QTZCQTVDNkU4MzIyMDE4MDIwOTAwMDM= > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/.ccvid
- sh -c echo ODYzNDEzQjk3NkI1MzUzRDg4ODJGMTQxOTQ2RUQxNjk5QjAx > <SD-Card>/../../../../../..<SD-Card>/.n_d
- sh -c echo ODYzNDEzQjk3NkI1MzUzRDg4ODJGMTQxOTQ2RUQxNjk5QjAx > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_d
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/._system.dat
- sh -c echo QjU4NUVFQTBCMEQ3MkI1Mzg5QjM5ODQ1MzQ1NUNFMDMzQzdBQjU6ODg2Qzc4OjI3RERDMw== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_system.dat
- sh -c echo RTIyREY1QUU4RDE1N0JEMjE3MjlERDY4M0ExNzc2NzVBNkYwQTM6OEJDOTRDOkMyMzA3QQ== > <SD-Card>/../../../../../..<SD-Card>/._android.dat
- sh -c echo RTIyREY1QUU4RDE1N0JEMjE3MjlERDY4M0ExNzc2NzVBNkYwQTM6OEJDOTRDOkMyMzA3QQ== > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/_android.dat
- sh -c echo RkQxODlGOEE4RTk3MjE2MkQ3MTI3RTJENUVEM0RENDUwMDBB > <SD-Card>/../../../../../..<SD-Card>/.n_c
- sh -c echo RkQxODlGOEE4RTk3MjE2MkQ3MTI3RTJENUVEM0RENDUwMDBB > <SD-Card>/../../../../../..<SD-Card>/Android/Data/System/local/n_c
- Bugly
- du
- getuiext3
- libjiagu-1968675475
- realm-jni
- sgmainso-5.1
- sgsecuritybodyso-5.1
- ut_c_api
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- desede-CBC-NoPadding