Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) d####.c####.l####.####.com:80
- TCP(HTTP/1.1) www.qchann####.cn:80
- TCP(HTTP/1.1) 2####.107.1.1:80
- TCP(HTTP/1.1) a.s.lm####.com:80
- TCP(HTTP/1.1) api.xima####.com.####.com:80
- TCP(HTTP/1.1) adash####.man.aliy####.com:80
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) schedul####.yo####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) 1####.217.168.206:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) safebro####.google####.com:443
- TCP(TLS/1.2) safebro####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.174:443
- TCP(TLS/1.2) 2####.58.208.99:443
- TCP sdk.o####.t####.####.com:5224
- a####.man.aliy####.com
- and####.google####.com
- api.g####.lm####.com
- api.xima####.com
- cm-1####.g####.com
- cm-1####.g####.com
- instant####.google####.com
- m####.go####.com
- m####.lm####.com
- o####.lm####.com
- s####.lm####.com
- safebro####.google####.com
- sdk.c####.g####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- tj.youza####.com
- www.gst####.com
- www.qchann####.cn
- a.s.lm####.com/ad-lmb/adshow?v=####&mvc=####&pid=####&os_ver=####&jingdu...
- a.s.lm####.com/ad/user/v2?v=####&uid=####&jingdu=####&weidu=####&encrypt...
- a.s.lm####.com/api-user-address/getregion?v=####&vendor=####&osver=####&...
- a.s.lm####.com/diary/timeline?v=####&uid=####&p=####&vendor=####&osver=#...
- a.s.lm####.com/lmbang/config?check_flag=####
- a.s.lm####.com/lmbang/config?v=####&last_modify=####&vendor=####&osver=#...
- a.s.lm####.com/preg-baby/recoveryWeightDoyen?v=####&mvc=####&bid=####&ve...
- a.s.lm####.com/preg-baby/recoveryWeightRecord?v=####&mvc=####&vendor=###...
- a.s.lm####.com/preg-healthy/reportdetail?v=####&mvc=####&week=####&vendo...
- a.s.lm####.com/preg-template/getSubjectInfoById?v=####&subject_id=####&s...
- a.s.lm####.com/preg/statistics/report?v=####&log_type=####&vendor=####&o...
- a.s.lm####.com/tool-aboutlmbang/default?v=####&mvc=####&vendor=####&osve...
- a.s.lm####.com/tool-cnf/afterLoginConf?v=####&mvc=####&vendor=####&osver...
- a.s.lm####.com/tool-cnf/app?v=####&mvc=####&vendor=####&osver=####&clien...
- a.s.lm####.com/tool-cnf/getPublicData?v=####&mvc=####&vendor=####&osver=...
- a.s.lm####.com/tool-cnf/whitelist?v=####&mvc=####&vendor=####&osver=####...
- a.s.lm####.com/tool-facepackage/update?v=####&mvc=####&vendor=####&osver...
- a.s.lm####.com/tool-monitor/check?mvc=####&check_flag=####&fs=####
- a.s.lm####.com/topic/content/index?check_flag=####
- a.s.lm####.com/topic/info/index?check_flag=####
- a.s.lm####.com/user-identify/mobilebind?v=####&mvc=####&source_from=####...
- a.s.lm####.com/user-main/getnewskin?v=####&vendor=####&osver=####&client...
- a.s.lm####.com/user/member/update?v=####&postype=####&is_hdhead=####&ven...
- a.s.lm####.com/user/score/config?v=####&vendor=####&osver=####&client_fl...
- d####.c####.l####.####.com/config/hzv9.conf
- a.s.lm####.com/diary/picture/comment_list
- a.s.lm####.com/preg-slog/index
- adash####.man.aliy####.com/man/api?ak=####&s=####
- api.xima####.com.####.com/oauth2/secure_access_token
- schedul####.yo####.com:443/v3/log
- www.qchann####.cn/center/adj
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/.lock
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/QT.xml
- /data/data/####/Qcache1641070642
- /data/data/####/Qcache1641070652
- /data/data/####/arch.xml
- /data/data/####/arch.xml.bak
- /data/data/####/bids.xml
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes2.dex
- /data/data/####/classes3.dex
- /data/data/####/classes4.dex
- /data/data/####/classes5.dex
- /data/data/####/classes6.dex
- /data/data/####/com.wangzhi.MaMaHelp_preferences.xml
- /data/data/####/com.youzan.mobile.AnalyticsPrefs.xml
- /data/data/####/events
- /data/data/####/events (deleted)
- /data/data/####/events-journal
- /data/data/####/events-journal (deleted)
- /data/data/####/getui_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu.so
- /data/data/####/mamahelp.db
- /data/data/####/mamahelp.db-journal
- /data/data/####/mamahelpdatacollect.db
- /data/data/####/mamahelpdatacollect.db-journal
- /data/data/####/okgo_cookie.xml
- /data/data/####/pili_qos_index.json
- /data/data/####/pili_qos_log.0
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/pushsdk.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/qos.xml
- /data/data/####/qtsession.xml
- /data/data/####/run.pid
- /data/data/####/ting_data.xml
- /data/data/####/tmpd8.db-journal
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/xmplayer_config.xml
- /data/data/####/xmplayer_config.xml.bak
- /data/media/####/.nomedia
- /data/media/####/007b843cf53af32f4c5a7e995776fa8b
- /data/media/####/213aec8994865b6d07ff0efd6f2d0b19
- /data/media/####/515c5eaae1596ba1d7c7c7da3142a730
- /data/media/####/881930b9f522b7b41ee4d8a249368816
- /data/media/####/AN.csv-20220101235757
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/TruthInfo.csv-1641070681289
- /data/media/####/UA.csv-20220101235759
- /data/media/####/apion.csv-20220101235834
- /data/media/####/apion.csv-20220101235837
- /data/media/####/apion.csv-20220101235841
- /data/media/####/apion.csv-20220101235844
- /data/media/####/apion.csv-20220101235848
- /data/media/####/apion.csv-20220101235851
- /data/media/####/com.tencent.mobileqq_connectSdk.22.01.01.23.log
- /data/media/####/com.wangzhi.MaMaHelp.bin
- /data/media/####/d37f8c0e828efe44ac255f803fdfafdd
- /data/media/####/f7dcad9a83f4664bc75cafce18327242
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/nim_sdk.log
- /data/media/####/qt.csv.1641070643648.txt
- /data/media/####/uuid
- /data/misc/####/primary.prof
- cat /proc/cpuinfo
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- ps
- ps -P
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding