Техническая информация
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sni.c####.q####.####.net:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) c####.t####.cn:80
- TCP(TLS/1.0) s3.ps####.com:443
- TCP(TLS/1.0) adt.x####.com:443
- TCP(TLS/1.0) c####.t####.cn:443
- TCP(TLS/1.0) www.s####.com:443
- TCP(TLS/1.0) sta####.t####.cn:443
- TCP(TLS/1.0) zz.bdst####.com:443
- TCP(TLS/1.0) s####.tc.qq.com:443
- TCP(TLS/1.0) acti####.moretic####.com:443
- TCP(TLS/1.0) www.a.sh####.com:443
- TCP(TLS/1.0) h5.talking####.com:443
- TCP(TLS/1.0) hm.b####.com:443
- TCP(TLS/1.0) i####.t####.cn:443
- TCP(TLS/1.0) tag.b####.com:443
- TCP(TLS/1.0) cdn.boo####.com.####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5227
- 571ccdc####.moretic####.com
- 7j####.c####.z0.####.com
- a####.u####.com
- acti####.moretic####.com
- adt.x####.com
- c####.g####.ig####.com
- c####.t####.cn
- c-h####.g####.com
- cdn.boo####.com
- h5.talking####.com
- hm.b####.com
- i####.t####.cn
- i####.t####.cn
- i####.t####.cn
- i.t####.com
- m.moretic####.com
- pub-####.qin####.com
- r####.wx.qq.com
- s3.ps####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sp0.b####.com
- sta####.t####.cn
- sta####.t####.cn
- tag.b####.com
- www.s####.com
- www.t####.cn
- zz.bdst####.com
- c####.t####.cn/config/Android.conf?project=####&token=####
- sni.c####.q####.####.net/config/hz-hzv3.conf
- sni.c####.q####.####.net/tdata_Soq141
- sni.c####.q####.####.net/tdata_vxj811
- t####.c####.q####.####.com/tdata_EDT356
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/-289777408127847021
- /data/data/####/-337723892247549734
- /data/data/####/-337723892247607615
- /data/data/####/-40764430735539254
- /data/data/####/-4467839211381268938
- /data/data/####/-D41r__YxLrNYn-UURcsC5HVL1g.-22727180.tmp
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/119170795118507261
- /data/data/####/119170795118565135
- /data/data/####/11946469341171131039
- /data/data/####/11946469341171131779
- /data/data/####/11946469341171131813
- /data/data/####/1531880672098_2084
- /data/data/####/1531880672117_2084
- /data/data/####/1531880672173_2084
- /data/data/####/1531880672499_2084
- /data/data/####/1531880676608_2172
- /data/data/####/1531880676682_2172
- /data/data/####/1555366853990239908
- /data/data/####/1555366853990297785
- /data/data/####/17166876991056709021
- /data/data/####/1GeoQFrFrTDBLMuqaUvvJf3sFX0.1331617188.tmp
- /data/data/####/2001829902-482534446
- /data/data/####/2025439735-1951979625
- /data/data/####/2951397581518497246
- /data/data/####/3rB0ZYXmz0j_8kDclbDd43oSpQM.-66758016.tmp
- /data/data/####/666978464-1143205749
- /data/data/####/69245f771a5f
- /data/data/####/6tKD4ROqNNdj4dfUH9HXerR9594.325980231.tmp
- /data/data/####/6zolZWR8IH4DFNA3SPzHe_zlCvg.-980696740.tmp
- /data/data/####/7UcbO7RaOze1zKJLKAl73BMDCDY.-1344368552.tmp
- /data/data/####/ApplicationCache.db-journal
- /data/data/####/Be2yEL6c8tEdd5zYVcD0umWUcXk.-1735327853.tmp
- /data/data/####/Bhdqi6tkfDPHCCvaLaOZIE_tfUQ.-857539286.tmp
- /data/data/####/CookiePrefsFile.xml
- /data/data/####/D-8uQiY-LZy9bmVTw3UZVq3I-r4.1980665917.tmp
- /data/data/####/DaAdOI8pGwnZWxFbsOa-wDAsEZ4.-876233378.tmp
- /data/data/####/DsG6goofK1Fw9Djc84VuQUwa4nc.-1447781937.tmp
- /data/data/####/EFtA9iU0EOEqT2KmQYLkCfOgNFA.-175211418.tmp
- /data/data/####/G8n-Tauz9ntyYo9Kkwa_IpzjCBY.-1848474201.tmp
- /data/data/####/L7Vo54dEwYwNVjrkSTuDgo5qJiY.722555424.tmp
- /data/data/####/LvTFiyHjSM4UDnywDf3boBdvR60.1533686185.tmp
- /data/data/####/PLf4qHSAnLwAow1iDUwZ6CVcqpM.-1374778256.tmp
- /data/data/####/QH8z1i5UHJS8H9eRS7Fp07wMlg0.-1032496404.tmp
- /data/data/####/QHkrq8u_nn4aMheO6KATSK1dWI0.-1207774253.tmp
- /data/data/####/SAqAbJ3fCO7XPlMyXf0-nw6WDQQ.900302556.tmp
- /data/data/####/TD_app_pefercen_profile.xml
- /data/data/####/TDpref_longtime.xml
- /data/data/####/TDpref_longtime1.xml
- /data/data/####/TDpref_shorttime.xml
- /data/data/####/TDpref_shorttime1.xml
- /data/data/####/TV5eVdpVFMCSy3u8n3OAeKVJPIE.-819154359.tmp
- /data/data/####/TxAHB8Sm3ykGVpTKcNgn6OrsLKI.602534014.tmp
- /data/data/####/Utibwj84e5vzTXd8bbS_jbkdsco.-1758165799.tmp
- /data/data/####/WJWQNJ5xz2zGQ6eQvvBxOywkHvk.-757516875.tmp
- /data/data/####/WUBylE9bwcj4-W5foTZmSf9UAig.710670315.tmp
- /data/data/####/_mV32e9Nmb6CSs6WQMpGh22teZM.625086225.tmp
- /data/data/####/aSkCx2OvNRlku91yQ3J9CQdP-Cs.1812550960.tmp
- /data/data/####/ajVSImimkGCJ02JOABZLchMpITA.2000408467.tmp
- /data/data/####/bbKO6tt6xqY4vaTamuUTlfUYOyc.2114122240.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.juqitech.niumowang-journal
- /data/data/####/com.juqitech.niumowang_preferences.xml
- /data/data/####/com.sensorsdata.analytics.android.sdk.SensorsDataAPI.xml
- /data/data/####/dOXS8GfGa3UJBTmY20VnesPv2Hs.-115986459.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/disk_entries_list_image_cache_720517864.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fEG4PHnIm3Q6O8nCgMK8gjAcV60.-1277577836.tmp
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/f_000005
- /data/data/####/f_000006
- /data/data/####/f_000007
- /data/data/####/f_000008
- /data/data/####/f_000009
- /data/data/####/f_00000a
- /data/data/####/f_00000b
- /data/data/####/f_00000c
- /data/data/####/f_00000d
- /data/data/####/f_00000e
- /data/data/####/f_00000f
- /data/data/####/f_000010
- /data/data/####/f_000011
- /data/data/####/f_000012
- /data/data/####/f_000013
- /data/data/####/f_000014
- /data/data/####/f_000015
- /data/data/####/f_000016
- /data/data/####/f_000017
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gsjOBs3YYwQV1-68jf9dVZsPB58.-324259673.tmp
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu.so
- /data/data/####/mtl_device_id.xml.xml
- /data/data/####/multidex.version.xml
- /data/data/####/niuniu.xml
- /data/data/####/nmw-site.xml
- /data/data/####/nmwdb-journal
- /data/data/####/o_uax1rBt3OZgh3bFX9tJoeaj9c.1326547603.tmp
- /data/data/####/pjNXeNRToSq5qnXw3JM96i24iEw.1955315248.tmp
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/pzc5Y6VZ-QolBJdXKA1cqQn-o1s.-748305898.tmp
- /data/data/####/qCBEJemRJCqvnBthpDbJY81FFqM.1933841181.tmp
- /data/data/####/qV4SWf8WFBD5uSY21fFhPp_dVTA.188656225.tmp
- /data/data/####/qYysB5trykyVcPUMYZ4CTRDy5mI.-1795171805.tmp
- /data/data/####/rKO34LjgwAW1m9LPB0aw-pd7eEw.-1703909520.tmp
- /data/data/####/run.pid
- /data/data/####/s-BMcBVdfNDNwCT2d8DOEqzvug8.-1313295134.tmp
- /data/data/####/sensorsdata.xml
- /data/data/####/snf2X0AmnMBO37XeTBhfVDa1PuI.666894364.tmp
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_vxj811
- /data/data/####/tdata_vxj811.jar
- /data/data/####/tdid.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/vILy-Deimf5k4RkrXo8wovgf1UU.1791338348.tmp
- /data/data/####/vRxH3WvsHdprwQTcAVBtbGLOQ_c.1774834567.tmp
- /data/data/####/vYCrf_4KEf5PgVy46JrXhsx8Zfo.1118232315.tmp
- /data/data/####/wUpUSdof0Tg2REmg-6piu-UZ3kk.1612748661.tmp
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/xi0SK5qlPU-xt9-Jcs_S1x3xLkA.-1293059444.tmp
- /data/data/####/yWGCARGigtNEA7CxvrqAjpkId6c.-1006647499.tmp
- /data/media/####/.tcookieid
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.juqitech.niumowang.bin
- /data/media/####/com.juqitech.niumowang.db
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_vxj811
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.gateway.push.GetuiPushService 25253 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- getprop
- mount
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.gateway.push.GetuiPushService 25253 300 0
- getuiext2
- gifimage
- imagepipeline
- libjiagu
- securitylib
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS7Padding
- DES-CBC-PKCS5Padding