Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) oss.lanlan####.com:80
- TCP(HTTP/1.1) a####.b####.qq.com:8011
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) ada####.m.ta####.com:80
- TCP(HTTP/1.1) a####.b####.qq.com:8012
- TCP(HTTP/1.1) hk.wagbr####.non####.####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) ad####.m.ta####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) gd2.al####.com:80
- TCP(HTTP/1.1) wild####.al####.com.####.net:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) o####.lanlan####.com:80
- TCP(HTTP/1.1) api.xiao####.com:8808
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) 1####.217.20.78:443
- TCP(TLS/1.0) nbsdk-b####.al####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5227
- 7j####.c####.z0.####.com
- a####.b####.qq.com
- a####.u####.com
- ad####.m.ta####.com
- ada####.m.ta####.com
- aexcep####.b####.qq.com
- and####.b####.qq.com
- api.xiao####.com
- banner####.xiao####.com
- c####.g####.ig####.com
- c-h####.g####.com
- gd2.al####.com
- img.al####.com
- log.u####.com
- mt####.go####.com
- nbsdk-b####.al####.com
- o####.lanlan####.com
- oss.lanlan####.com
- pub-####.qin####.com
- s####.u####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- y####.al####.com
- ad####.m.ta####.com/rest/gc2?ak=####&av=####&c=####&d=####&sv=####&t=###...
- gd2.al####.com/imgextra/i2/726980090/O1CN01TVAw741CXGArhaSgz_!!726980090...
- o####.lanlan####.com/e7f8d2af26a91d6a487a40db98fb9fe0_800x800.jpg@!1-500...
- oss.lanlan####.com/668886dbb035424ee1842b3488df09fd_800x800.png@!1-500-8...
- oss.lanlan####.com/b0a3c87fee0a79e4dce9bf412be808a8_800x800.jpg@!1-500-8...
- qin####.com.www.####.com/tdata_EDT369
- t####.c####.q####.####.com/config/hz-hzv6.conf
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_ilz707
- t####.c####.q####.####.com/tdata_zbA366
- ti####.c####.l####.####.com/1546582023765.png
- ti####.c####.l####.####.com/1546582059861.png
- ti####.c####.l####.####.com/1546582072323.png
- ti####.c####.l####.####.com/1547630781555.png
- ti####.c####.l####.####.com/1547630849173.png
- ti####.c####.l####.####.com/1547631104016.png
- ti####.c####.l####.####.com/1547631146071.png
- ti####.c####.l####.####.com/1547631171397.png
- ti####.c####.l####.####.com/1547631239276.png
- ti####.c####.l####.####.com/1547631267192.png
- ti####.c####.l####.####.com/1547631319560.png
- ti####.c####.l####.####.com/FhcsqHRrUSJqcLyzhLQM5LLOqFce
- ti####.c####.l####.####.com/Fl9tYN0Vo-yHuyoNUnBg9Mm5_T8q
- ti####.c####.l####.####.com/FnPCk-rW5i1PzsqHvVzn_Xj56au5
- wild####.al####.com.####.net/imgextra/i1/2457813340/O1CN01MnMwPm1aXlLSdr...
- wild####.al####.com.####.net/imgextra/i2/3108401389/O1CN016umb3v1M8CdT3Z...
- wild####.al####.com.####.net/imgextra/i2/4130420528/O1CN014LJzuU1FlrbAq6...
- wild####.al####.com.####.net/imgextra/i3/3082268483/O1CN01XxJVzd2CXGKmP7...
- a####.b####.qq.com:8011/rqd/async
- a####.b####.qq.com:8012/rqd/async
- a####.u####.com/app_logs
- ada####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=###...
- and####.b####.qq.com/rqd/async
- api.xiao####.com:8808/banner/getBanneNoticeV1
- api.xiao####.com:8808/banner/getBannerByKeyV2
- api.xiao####.com:8808/banner/getMenuBanner
- api.xiao####.com:8808/banner/getModelBannerV3
- api.xiao####.com:8808/banner/getSlideBanner
- api.xiao####.com:8808/category/getCategory
- api.xiao####.com:8808/category/getCategoryItemForIndex
- api.xiao####.com:8808/product/getHotProductListByCid
- api.xiao####.com:8808/product/getProductList
- api.xiao####.com:8808/system/checkVersion
- c-h####.g####.com/api.php?format=####&t=####
- hk.wagbr####.non####.####.com/saveWb.json
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.imprint
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/0e71a4e9547e
- /data/data/####/0f7ff7b04da469a08ac413fb9729cf16421dba65e473940....0.tmp
- /data/data/####/1558080245038.log
- /data/data/####/1558080245038.log.bak
- /data/data/####/189af9cfa6cfba5e186c64a727c2b31eb9bf89dc6e8e4de....0.tmp
- /data/data/####/18da7c4fef54679e5e33834d895cf30c9f289c6c4523c8c....0.tmp
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/2d289409048ca366d9758a98f1b1caa6df85bef660fa8ac....0.tmp
- /data/data/####/316fe31d63423b2c5e5f0a84d4a375a7d4227bbe73023ed....0.tmp
- /data/data/####/3264295cae5fbdf4ebcafd1924ec64ebd78f3cbd61de261....0.tmp
- /data/data/####/4ca0d15bd424f663bb2a081a045b71040e13eaae9988e3c....0.tmp
- /data/data/####/509d63a7175a7529a76166626a1cbf977d48d61efc70953....0.tmp
- /data/data/####/52eb5b461b06ddbbd3b37c136ec25a13997b99c6570b4e2....0.tmp
- /data/data/####/56fdf515ab7e2e9d95a2c684e4c115a2eaa07a25788d1a1....0.tmp
- /data/data/####/5987e3d706a94c0e8d376021906fac305001e16c13f7448....0.tmp
- /data/data/####/746936702
- /data/data/####/79d5a8302d9070decfc30a114ad7fa37898d6eb5eabff26....0.tmp
- /data/data/####/7dee7d66074d4dfe411d6d6907e7cf0d2535a9e91c3335e....0.tmp
- /data/data/####/81debfced1a14f6f15b956350ca5b4ccc12b688c839ada3....0.tmp
- /data/data/####/83b2e98c110bd4855465b1e8a4784b09544735c1c1864c9....0.tmp
- /data/data/####/8b98441c22df4702b02177bc7a7cb2a5f69c5b468bce9b5....0.tmp
- /data/data/####/8e1092747932fd828ec59ac42309344287376f6ab15c359....0.tmp
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/AlibcLinkPartner.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/MEMBER_IM.xml
- /data/data/####/Q0VSVC5SU0EK.txt908
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/UTCommon.xml
- /data/data/####/ad574fbc152363ee72859100b2598a011f4818b7e66db5c....0.tmp
- /data/data/####/aliTradeConfigSP.xml
- /data/data/####/ap.Lock
- /data/data/####/auth_sdk_device.xml
- /data/data/####/bugly_db_legu-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cdd22a9c693cc6e7e86e05654c1086f7fbec65a4b4a421b....0.tmp
- /data/data/####/com.fzh.xylm_preferences.xml
- /data/data/####/d4c213cbea23f2af6df7bf36c02fb8f34d1a22415f73bfd....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fb0144c55a890a31a3d2811865de688de7dcb1ca5c3de12....0.tmp
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal.tmp
- /data/data/####/libsgmainso-5.1.96.so.tmp
- /data/data/####/libsgsecuritybodyso-5.1.25.so.tmp
- /data/data/####/libshella-2.9.1.2.so
- /data/data/####/libufix.so
- /data/data/####/local_crash_lock
- /data/data/####/lock.lock
- /data/data/####/mix.dex
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/sp.lock
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_ilz707
- /data/data/####/tdata_ilz707.jar
- /data/data/####/tdata_zbA366
- /data/data/####/tdata_zbA366.jar
- /data/data/####/timestamp
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/media/####/.nomedia
- /data/media/####/6c709c11d2d46a7b
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/app.db
- /data/media/####/com.fzh.xylm.bin
- /data/media/####/com.fzh.xylm.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/dd7893586a493dc3
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/hid.dat
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_ilz707
- /data/media/####/tdata_zbA366
- /data/media/####/test.log
- /system/bin/cat /proc/cpuinfo
- /system/bin/sh -c getprop ro.aa.romver
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c getprop ro.build.fingerprint
- /system/bin/sh -c getprop ro.build.nubia.rom.name
- /system/bin/sh -c getprop ro.build.rom.id
- /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
- /system/bin/sh -c getprop ro.build.version.emui
- /system/bin/sh -c getprop ro.build.version.opporom
- /system/bin/sh -c getprop ro.gn.gnromvernumber
- /system/bin/sh -c getprop ro.lenovo.series
- /system/bin/sh -c getprop ro.lewa.version
- /system/bin/sh -c getprop ro.meizu.product.model
- /system/bin/sh -c getprop ro.miui.ui.version.name
- /system/bin/sh -c getprop ro.vivo.os.build.display.id
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GeTuiPushService 24197 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 700 <Package Folder>/tx_shell/libnfix.so
- chmod 700 <Package Folder>/tx_shell/libshella-2.9.1.2.so
- chmod 700 <Package Folder>/tx_shell/libufix.so
- getprop ro.aa.romver
- getprop ro.board.platform
- getprop ro.build.fingerprint
- getprop ro.build.nubia.rom.name
- getprop ro.build.rom.id
- getprop ro.build.tyd.kbstyle_version
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.gn.gnromvernumber
- getprop ro.lenovo.series
- getprop ro.lewa.version
- getprop ro.meizu.product.model
- getprop ro.miui.ui.version.name
- getprop ro.vivo.os.build.display.id
- getprop ro.yunos.version
- logcat -d -v threadtime
- mount
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.service.GeTuiPushService 24197 300 0
- Bugly
- getuiext2
- libnfix
- libshella-2.9.1.2
- libufix
- nfix
- sgmainso-5.1
- sgsecuritybodyso-5.1
- ufix
- ut_c_api
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding