Техническая информация
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) st####.co####.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) app.co####.com:80
- TCP(HTTP/1.1) i####.co####.com:80
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) uc.co####.com:80
- TCP(HTTP/1.1) s####.it####.jrj.####.cn:80
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) adser####.go####.nl:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
- TCP(TLS/1.0) googl####.g.doublec####.net:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5224
- 7j####.c####.z0.####.com
- adser####.go####.com
- adser####.go####.nl
- app.co####.com
- c####.g####.ig####.com
- c-h####.g####.com
- googl####.g.doublec####.net
- i####.co####.com
- log.u####.com
- pub-####.qin####.com
- s####.it####.jrj.####.cn
- s####.u####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- ssl.gst####.com
- st####.co####.com
- uc.co####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
- i####.co####.com/uploads/appbanner/2017-06-03/59327e22a5095.jpg
- i####.co####.com/uploads/appbanner/2017-06-03/59327e91a3015.jpg
- i####.co####.com/uploads/appbanner/2017-06-03/59327eb7234c4.jpg
- i####.co####.com/uploads/appbanner/2017-06-03/59327f083765d.jpg
- i####.co####.com/uploads/appbanner/2018-01-03/5a4c74a999c79.jpg
- i####.co####.com/uploads/appbanner/2018-03-08/5aa101d4eebc4.jpg
- i####.co####.com/uploads/appbanner/2018-04-12/5aceb2bd8aba6.jpg
- i####.co####.com/uploads/appbanner/2018-04-12/5acf469f38057.jpg
- i####.co####.com/uploads/appbanner/2018-06-26/5b31e690c97ed.jpg
- i####.co####.com/uploads/appbanner/2018-06-26/5b31e6a4baf22.jpg
- i####.co####.com/uploads/appbanner/2018-06-26/5b31e6b43ede1.jpg
- i####.co####.com/uploads/appbanner/2018-06-26/5b31e6c1d90f2.jpg
- i####.co####.com/uploads/avatar/003/05/46/56_avatar_big.jpg_avatar-100
- i####.co####.com/uploads/avatar/003/07/28/68_avatar_big.jpg_avatar-100
- i####.co####.com/uploads/avatar/004/48/03/37_avatar_big.jpg_avatar-100
- i####.co####.com/uploads/avatar/noavatar_middle.gif
- i####.co####.com/uploads/group/2019-03-04/ee33nfhxdk6kc.png_group-logo-200
- i####.co####.com/uploads/group/2019-03-11/4e148fd2-5723-40cb-b174-43fc82...
- i####.co####.com/uploads/group/2019-03-11/sxh99iwt5rkkn.png_group-logo-200
- i####.co####.com/uploads/group/default/3.png_group-logo-200
- i####.co####.com/uploads/picture/2017-02-14/570b4b13bd997.png
- i####.co####.com/uploads/picture/2017-02-14/570b4ccfe7b0c.png
- i####.co####.com/uploads/picture/2017-02-14/570b4d2cc9015.png
- i####.co####.com/uploads/picture/2017-02-14/570b4d604c3c6.png
- i####.co####.com/uploads/picture/2017-07-03/5959f5765420b.jpg
- i####.co####.com/uploads/picture/2017-08-26/59a11205c9e87.jpg
- i####.co####.com/uploads/picture/2019-03-11/5c85be1aad0f2.jpg_fourm-300
- s####.it####.jrj.####.cn/stock/code?key=####
- st####.co####.com/public/images/koufu/dx_logo_small.png
- t####.c####.q####.####.com/tdata_RSQ274
- t####.c####.q####.####.com/tdata_RbW195
- t####.c####.q####.####.com/tdata_qHR433
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- app.co####.com/Home/APP/banner
- app.co####.com/Home/APP/group
- app.co####.com/Home/APP/hotGroup
- app.co####.com/Home/APP/hotThread
- app.co####.com/Home/APP/indexLink
- app.co####.com/Home/APP/niuren_entrust
- app.co####.com/Home/APP/position
- app.co####.com/Home/APP/threadCate
- app.co####.com/Home/APP/version
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- uc.co####.com/app.php
- /data/data/####/.jg.ic
- /data/data/####/1552306226789.log
- /data/data/####/LOGINED_USER_INFO.xml
- /data/data/####/MultiDex.lock
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/cofoo_u_login.xml
- /data/data/####/com.tech.koufu_preferences.xml
- /data/data/####/config.xml
- /data/data/####/gdaemon_20161017
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/init.pid
- /data/data/####/init_c.pid
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/jrjstockdic.db
- /data/data/####/jrjstockdic.db-journal
- /data/data/####/libjiagu.so
- /data/data/####/mobclick_agent_cached_com.tech.koufu65
- /data/data/####/multidex.version.xml
- /data/data/####/null.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/tdata_RSQ274
- /data/data/####/tdata_RSQ274.jar
- /data/data/####/tdata_RbW195
- /data/data/####/tdata_RbW195.jar
- /data/data/####/tdata_qHR433
- /data/data/####/tdata_qHR433.jar
- /data/data/####/thinkive.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_socialize.xml
- /data/media/####/09c7b7344c449e9c8edfd3c9d9a126e6.0
- /data/media/####/0af1fc14d0539175e51b20da449c7a11.0
- /data/media/####/20fb993fca95925903b6ef7de5bdd05f.0
- /data/media/####/21425ca7e3797b68d8b00624762d5e56.0
- /data/media/####/24fcb546fa247e4c94b600d1227cbf0c.0
- /data/media/####/27d196dfbd0f7b18c797c5f86ce3f823.0
- /data/media/####/34d180de8772f410dd399d831f260e56.0
- /data/media/####/37060d52eef7200555a3e4b25f57d6ad.0
- /data/media/####/40a5249c99bd5ca64f78ab240492c4d8.0
- /data/media/####/46a3e3af392e76a560accef788638afa.0
- /data/media/####/49b2650d3c2fc56683c76dde2b913e7c.0
- /data/media/####/50d8c4373acb17410957f243050974e5.0
- /data/media/####/6124e15b469863518f3465aea9ec82db.0
- /data/media/####/72008c87022f7c523eef7f6c8891fb4a.0
- /data/media/####/7fba72b42e6f7bff1bd78fed698dfdc5.0
- /data/media/####/8f1afe33b11eafcf4d9a94b848442dff.0
- /data/media/####/905a3c94001bacba58131f8c88ab2d5b.0
- /data/media/####/a5f830cd5f269d2322153c6886ba5778.0
- /data/media/####/ad593b8f45cdab3bbdbaa27cf4ebcd5e.0
- /data/media/####/ad695eea98a312c0b3b5b6e73200cdf3.0
- /data/media/####/af9e04ebba5266c99f68f3e3f15165c7.0
- /data/media/####/app.db
- /data/media/####/c860270ad1ea0ad1cec1d465d7671999.0
- /data/media/####/ce974938eeec7272d5de91baf13a5ffc.0
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.tech.koufu.db
- /data/media/####/crash-2019-03-11-12-10-24-1552306224996.log
- /data/media/####/crash-2019-03-11-12-10-26-1552306226650.log
- /data/media/####/crash-2019-03-11-12-10-26-1552306226666.log
- /data/media/####/ec3c92e56b37a1f70b9bc31b5ce88004.0
- /data/media/####/eca28ee94c06f842d8fec3b288a23084.0
- /data/media/####/efd34f7d5fa76cee21b44a891d394093.0
- /data/media/####/fe07823370df93f5b9d2f76831b0a368.0
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/journal.tmp
- /data/media/####/tdata_RSQ274
- /data/media/####/tdata_RbW195
- /data/media/####/tdata_qHR433
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.igexin.sdk.PushService 24385 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- mount
- ping -c 1 -w 2 120.27.182.208
- getuiext2
- libjiagu
- AES-CBC-NoPadding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-ECB-PKCS5Padding