Техническая информация
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) tt####.systemd####.com:8088
- TCP(HTTP/1.1) et2-na6####.wagbr####.ali####.####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(HTTP/1.1) t####.systemd####.com:8080
- TCP(HTTP/1.1) n####.91s####.com:82
- TCP(HTTP/1.1) t####.c####.q####.####.com:80
- TCP(HTTP/1.1) p####.tc.qq.com:80
- TCP(HTTP/1.1) n####.91s####.com:83
- TCP(HTTP/1.1) s####.e.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) isds####.qq.com:80
- TCP(HTTP/1.1) s####.91s####.com:8700
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) qin####.com.www.####.com:80
- TCP(HTTP/1.1) r####.v####.qq.com:80
- TCP(HTTP/1.1) mi.g####.qq.com:80
- TCP(HTTP/1.1) dup.baidust####.com:80
- TCP(TLS/1.0) z.c####.com:443
- TCP(TLS/1.0) mobads-####.b####.com:443
- TCP(TLS/1.0) dup.baidust####.com:443
- TCP(TLS/1.0) shp.q####.cn:443
- TCP(TLS/1.0) sec.v####.qq.com:443
- TCP(TLS/1.0) bt####.v####.qq.com:443
- TCP(TLS/1.0) v.q####.com:443
- TCP(TLS/1.0) cgiac####.tc.qq.com:443
- TCP(TLS/1.0) gm.mm####.com:443
- TCP(TLS/1.0) i.g####.cn.####.com:443
- TCP(TLS/1.0) pos.b####.com:443
- TCP(TLS/1.0) c.c####.com:443
- TCP(TLS/1.0) l####.v####.qq.com:443
- TCP(TLS/1.0) v####.qq.com.####.net:443
- TCP(TLS/1.0) p####.tc.qq.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5224
- 7j####.c####.z0.####.com
- a####.u####.com
- bt####.v####.qq.com
- c####.g####.ig####.com
- c####.g####.ig####.com
- c####.mm####.com
- c-h####.g####.com
- c.c####.com
- dup.baidust####.com
- ec####.b####.com
- h####.v####.qq.com
- i.g####.cn
- imgc####.qq.com
- isds####.qq.com
- l####.v####.qq.com
- log.u####.com
- mi.g####.qq.com
- mo####.b####.com
- mobads-####.b####.com
- n####.91s####.com
- pos.b####.com
- pub-####.qin####.com
- r####.v####.qq.com
- s####.91s####.com
- s####.e.qq.com
- s####.u####.com
- s11.c####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sec.v####.qq.com
- shp.q####.cn
- t####.systemd####.com
- tt####.systemd####.com
- v####.qq.com
- v.q####.com
- z13.c####.com
- dup.baidust####.com/js/ds.js
- et2-na6####.wagbr####.ali####.####.com/bar/get/59cca6c51c5dd00c46000202/...
- isds####.qq.com/cgi-bin/v.cgi?flag1=####&flag2=####&1=####&2=####
- mi.g####.qq.com/gdt_mview.fcg?actual_width=####&count=####&r=####&templa...
- n####.91s####.com:82/H5/commentHot?articleid=####&model=####&token=G####
- n####.91s####.com:82/H5/commentHot?articleid=####&model=####&token=M####
- n####.91s####.com:82/H5/getRelatList?articleid=####&model=####&catid=###...
- n####.91s####.com:82/v3/appStart?version=####&phonetype=####&phonecate=#...
- n####.91s####.com:82/v3/catAll?model=####&version=####&phonetype=####&ph...
- n####.91s####.com:82/v3/getpop?ispop=####&version=####&phonetype=####&ph...
- n####.91s####.com:82/v3/index?model=####&catid=####&version=####&phonety...
- n####.91s####.com:82/v3/pushWeather?ptype=####&version=####&phonetype=##...
- n####.91s####.com:82/v3/version?version=####&phonetype=####&phonecate=##...
- n####.91s####.com:83/Api/onclick/artid/452147/pubid/60000452147
- n####.91s####.com:83/news/n/39/d/452147?fontsize=####&version=####&phone...
- n####.91s####.com:83/yuequ/css/article.css
- n####.91s####.com:83/yuequ/images/gray.png
- n####.91s####.com:83/yuequ/images/xg.png
- n####.91s####.com:83/yuequ/js/art.js
- n####.91s####.com:83/yuequ/js/echo.js
- n####.91s####.com:83/yuequ/js/zepto.min.js
- p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
- qin####.com.www.####.com/tdata_EDT369
- r####.v####.qq.com/web_report?cmd=3529&url=http://news.91s2b2c.com:83/ne...
- r####.v####.qq.com/web_report?cmd=3532&url=http://news.91s2b2c.com:83/ne...
- r####.v####.qq.com/web_report?cmd=3536&url=http://news.91s2b2c.com:83/ne...
- t####.c####.q####.####.com/tdata_Rnl693
- t####.c####.q####.####.com/tdata_Soq141
- t####.c####.q####.####.com/tdata_fEV688
- t####.c####.q####.####.com/tdata_siA393
- t####.systemd####.com:8080/Public/videoimg/2018/08/25/20180825051813_835...
- t####.systemd####.com:8080/Public/videoimg/2018/08/25/20180825052702_473...
- t####.systemd####.com:8080/Public/videoimg/2018/12/12/20181212062703_601...
- t####.systemd####.com:8080/Public/videoimg/2018/12/12/20181212062704_798...
- ti####.c####.l####.####.com/config/hz-hzv3.conf
- tt####.systemd####.com:8088/Public/upload/2019/03/21/20190321120015_2809...
- tt####.systemd####.com:8088/Public/upload/2019/03/25/20190325160011_9701...
- tt####.systemd####.com:8088/Public/upload/2019/03/26/20190326000020_3910...
- tt####.systemd####.com:8088/Public/upload/2019/03/26/20190326000020_5015...
- tt####.systemd####.com:8088/Public/upload/2019/03/26/20190326000020_8783...
- tt####.systemd####.com:8088/Public/upload/2019/03/27/20190327120002_8332...
- tt####.systemd####.com:8088/Public/upload/2019/03/28/20190328120004_7570...
- a####.u####.com/app_logs
- c-h####.g####.com/api.php?format=####&t=####
- n####.91s####.com:82/v3/reportMbAct
- s####.91s####.com:8700/
- s####.e.qq.com/activate
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/00fdbdc3a90f6bce09d4418283e234c89d3575dee1e8328....0.tmp
- /data/data/####/1554415394889.log
- /data/data/####/1ef6f0a80a9e64bd01c4b50c1e57b1e29fc7d0d4dbd3a36....0.tmp
- /data/data/####/57254db267e36f932e9332f9676551d198a06008e992173....0.tmp
- /data/data/####/5e164e2a7339e625fa86a5a990ac6c3f782454afc6cb94f....0.tmp
- /data/data/####/7b7d8ec53a36
- /data/data/####/8679e99ba7f3d9dd75f51ad09bdd0ea6038dbfca37d9982....0.tmp
- /data/data/####/8fb1714c89e0fc375acf0938c495b0687fc01973e0e4e59....0.tmp
- /data/data/####/94a2b9b608ec77f35e0af59c56e1c9e589bfa2bc0aef3eb....0.tmp
- /data/data/####/BuglySdkInfos.xml
- /data/data/####/GDTSDK.db
- /data/data/####/GDTSDK.db-journal
- /data/data/####/MY_DB-journal
- /data/data/####/__x_adsdk_agent_header__.xml
- /data/data/####/__xadsdk__remote__final__builtin__.jar
- /data/data/####/b8266b2d03dbf15c96861be9dd5a43a7d7b9f081f991406....0.tmp
- /data/data/####/c229e2bf98e8d9dfaadc316ac672d912d02b765cebeebe8....0.tmp
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.baidu.mobads.loader.xml
- /data/data/####/d0f5fc529c133865875db9d17cdfb2bb45b51546379cde7....0.tmp
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/data_3 (deleted)
- /data/data/####/devCloudSetting.cfg
- /data/data/####/devCloudSetting.sig
- /data/data/####/df00d43f9738b1f0c2b4bd85b3b8f8bcb1d4d65fd1673ce....0.tmp
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/f_000004
- /data/data/####/gdaemon_20161017
- /data/data/####/gdt_plugin.jar
- /data/data/####/gdt_plugin.jar.sig
- /data/data/####/gdt_plugin.tmp
- /data/data/####/gdt_plugin.tmp.sig
- /data/data/####/gdt_suid
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jg_so_upgrade_setting.xml
- /data/data/####/journal.tmp
- /data/data/####/keep
- /data/data/####/libjiagu.so
- /data/data/####/maiyadb.db-journal
- /data/data/####/maiyasp.xml
- /data/data/####/multidex.version.xml
- /data/data/####/mycfig.xml
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/sdkCloudSetting.cfg
- /data/data/####/sdkCloudSetting.sig
- /data/data/####/tdata_Rnl693
- /data/data/####/tdata_Rnl693.jar
- /data/data/####/tdata_Soq141
- /data/data/####/tdata_Soq141.jar
- /data/data/####/tdata_fEV688
- /data/data/####/tdata_fEV688.jar
- /data/data/####/tdata_siA393
- /data/data/####/tdata_siA393.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/data/####/update_lc
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal (deleted)
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.malt.topnews.bin
- /data/media/####/com.malt.topnews.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/tdata_Rnl693
- /data/media/####/tdata_Soq141
- /data/media/####/tdata_fEV688
- /data/media/####/tdata_siA393
- /data/media/####/test.log
- <Package Folder>/files/gdaemon_20161017 0 <Package>/<Package>.serviceandreceiver.DemoPushService 24625 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- chmod 777 <Package Folder>/files/keep
- getprop ro.miui.ui.version.name
- mount
- sh
- getuiext2
- libjiagu
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-NoPadding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-ECB-PKCS1Padding