Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.0) tcms-a####.wan####.ta####.com:443
- TCP(HTTP/1.0) tcms-a####.wan####.ta####.com:80
- TCP(HTTP/1.1) 47.1####.70.45:80
- TCP(HTTP/1.1) m.d####.mob.com:80
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) aliyun-####.al####.com:80
- TCP(HTTP/1.1) 1####.205.163.87:80
- TCP(HTTP/1.1) a####.a####.m.####.com:80
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) x####.tc.qq.com:443
- TCP(TLS/1.0) o####.map.b####.com:443
- TCP(TLS/1.0) xui.ptlo####.qq.com:443
- TCP(TLS/1.0) ty.cap####.qq.com:443
- TCP(TLS/1.0) g####.qq.com:443
- TCP(TLS/1.0) t####.qq.com:443
- TCP(TLS/1.0) p####.tc.qq.com:443
- TCP accscdn####.m.ta####.com:443
- TCP i####.wan####.ta####.com:443
- TCP accscdn####.m.ta####.com:80
- a####.exc.mob.com
- a####.m.ta####.com
- accscdn####.m.ta####.com
- ag####.m.ta####.com
- api.map.b####.com
- api.s####.mob.com
- g####.qq.com
- hotp####.wan####.ta####.com
- i####.wan####.ta####.com
- imgc####.qq.com
- m.d####.mob.com
- mpush####.al####.com
- o####.map.b####.com
- pin####.qq.com
- s####.qq.com
- s.u####.cn
- t####.qq.com
- tcms-a####.wan####.ta####.com
- ty.cap####.qq.com
- xui.ptlo####.qq.com
- m.d####.mob.com/v4/cconf?appkey=####&plat=####&apppkg=####&appver=####&n...
- tcms-a####.wan####.ta####.com:443/imlogingw/tcp60login?devid=####&ver=####
- a####.a####.m.####.com/amdc/mobileDispatch?appkey=####&deviceId=####&pla...
- a####.exc.mob.com/errconf
- aliyun-####.al####.com/config
- /data/data/####/-438691805-1599801663
- /data/data/####/.jg.ic
- /data/data/####/.lock
- /data/data/####/.mrecord
- /data/data/####/.mrecord (deleted)
- /data/data/####/.mrlock
- /data/data/####/.statistics
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michoup...e_2120
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michoup...e_2288
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michoup...e_2316
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michoup...l_2225
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michouproject_2077
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michouproject_2401
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michouproject_2459
- /data/data/####/07-17_10_14_com.mimakejil.administrator.michouproject_2513
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/DaemonServer
- /data/data/####/ThrowalbeLog.db
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/accs.db-journal
- /data/data/####/agoo.pid
- /data/data/####/ap.Lock
- /data/data/####/app.xml
- /data/data/####/authStatus_com.mimakejil.administrator.michoupr...te.xml
- /data/data/####/com.mimakejil.administrator.michouproject_preferences.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/eudemon
- /data/data/####/gal.db
- /data/data/####/gal.db-journal
- /data/data/####/getui_sp.xml
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/index
- /data/data/####/init_c1.pid
- /data/data/####/libcuid.so
- /data/data/####/libjiagu1150657287.so
- /data/data/####/message_accs_db
- /data/data/####/message_accs_db-journal
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/notification_config.xml
- /data/data/####/ofl.config
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/share_sdk_1
- /data/data/####/tcms_istied.xml
- /data/data/####/tcms_setting_sp.xml
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/data/####/xpush_status.xml
- /data/media/####/.artc_lock
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.iew
- /data/media/####/.mps
- /data/media/####/.nulplt
- /data/media/####/.pkg_lock
- /data/media/####/.rcTag
- /data/media/####/.rc_lock
- /data/media/####/.slw
- /data/media/####/2_20180717_r
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/yoh.dat
- /data/media/####/yol.dat
- /data/media/####/yom.dat
- <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"24856028","utdid":"W03BbVDirZ0DAGdzx1HT84E5","sdkVersion":"221"} -I agoodm.m.taobao.com -O 80 -T -Z
- chmod 500 <Package Folder>/files/DaemonServer
- chmod 755 <Package Folder>/.jiagu/libjiagu1150657287.so
- getprop ro.product.cpu.abi
- sh
- getuiext2
- inet.2.0
- libjiagu1150657287
- locSDK7b
- neh
- pl_droidsonroids_gif
- tnet-3.1
- ut_c_api
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- RSA-NONE-PKCS1Padding
- AES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding