Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) oss.lanlan####.com:80
- TCP(HTTP/1.1) wb.110.ta####.com:80
- TCP(HTTP/1.1) www.lanlan####.com:80
- TCP(HTTP/1.1) beacon####.aliy####.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) sqb.xiaosh####.com:80
- TCP(HTTP/1.1) zhg.ali####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) sni.c####.q####.####.net:80
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
- TCP(HTTP/1.1) o####.lanlan####.com:80
- TCP(TLS/1.0) st3.lanlan####.com:443
- TCP(TLS/1.0) nbsdk-b####.al####.com:443
- TCP(TLS/1.0) api.w####.com:443
- TCP(TLS/1.0) 2####.107.1.97:443
- TCP(TLS/1.0) st2.lanlan####.com:443
- TCP(TLS/1.0) sh.wagbr####.ta####.com:443
- TCP(TLS/1.0) ada####.ut.ta####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP c####.g####.ig####.com:5227
- 7j####.c####.z0.####.com
- a####.man.aliy####.com
- a####.u####.com
- ada####.ut.ta####.com
- adas####.ut.ta####.com
- and####.b####.qq.com
- api.w####.com
- beacon####.aliy####.com
- c####.g####.ig####.com
- c-h####.g####.com
- l####.tbs.qq.com
- nbsdk-b####.al####.com
- o####.lanlan####.com
- o####.lanlan####.com
- o####.lanlan####.com
- oss.lanlan####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sqb.xiaosh####.com
- st2.lanlan####.com
- st3.lanlan####.com
- wb.110.ta####.com
- www.lanlan####.com
- y####.al####.com
- o####.lanlan####.com/0006d6c0d2d1e0513bbd649b5c65a31d_800x800.jpg
- o####.lanlan####.com/0381d6f53f78e510de65113aedde2107_126x126.png
- o####.lanlan####.com/03e8bd55c3fd94d9d153eba0b11cb933_800x800.jpg@!1-300...
- o####.lanlan####.com/046c76ea76ed5c69034585e4700efb96_800x800.jpg
- o####.lanlan####.com/056f5b79a11550ce51830b2c514ff08b_400x400.jpg
- o####.lanlan####.com/0c38427fc9bcb55130dd42330a709c8b_426x628.jpg
- o####.lanlan####.com/15f833764adb7de27f87e338b3990e0c_126x126.png
- o####.lanlan####.com/192a828f9b28ff0d128e91ad91f67a57_126x126.png
- o####.lanlan####.com/1b337bae6b96beeddf767b3c0a6a2ef6_126x126.png
- o####.lanlan####.com/22ef7dd24a4e1d4f9248e988349536b6_126x126.png
- o####.lanlan####.com/2545a30802c58e057e24e4f6b6408164_800x800.jpg@!1-300...
- o####.lanlan####.com/2b83964ecd637ed6f6c2cc922562a418_60x60.png
- o####.lanlan####.com/2da9bec617019c2b68e31aa4d6c151b0_126x126.png
- o####.lanlan####.com/31384904757ca4af46248102a4052b31_800x800.jpg
- o####.lanlan####.com/3eb2d6f410443c288e5682e445db20d1_126x126.png
- o####.lanlan####.com/3f655f82516398276028269839cc0bcb_800x800.jpg
- o####.lanlan####.com/3f681b35cd2518c925786f7b44e24cf8_26x26.png
- o####.lanlan####.com/4109e03f9ba2a341417397606a356c9a_126x126.png
- o####.lanlan####.com/4739fb89df57b417ee41149595bcab5c_126x126.png
- o####.lanlan####.com/52ee623de35d17ccc6b01e5922d58f5c_800x800.jpg
- o####.lanlan####.com/52f4f0693722f2f5a0a3706117f5948f_126x126.png
- o####.lanlan####.com/5b04f1b3cea19a640519855a4248bb79_126x126.png
- o####.lanlan####.com/5de73450199b20c686a0caeae840e041_800x800.jpg
- o####.lanlan####.com/5f6080d7617bddf7efae5841fe4729e2_126x126.png
- o####.lanlan####.com/6003209836c02d5488037ab295a16dd8_800x800.jpg@!1-300...
- o####.lanlan####.com/64773af6b9674e039de9e9c3538f126a_800x800.jpg@!1-300...
- o####.lanlan####.com/689d00a653ca562f66090f9c8d82f490_126x126.png
- o####.lanlan####.com/6b68b2f591ff25603e952e7896537fcf_800x800.jpg@!1-300...
- o####.lanlan####.com/6eb00042623b63232629ce17f6d079b3_800x800.jpg
- o####.lanlan####.com/75750b5345e2ad0eef4f2f9ee58563f7_300x750.jpg
- o####.lanlan####.com/7c03d565e8ac71691413f5499573d033_126x126.png
- o####.lanlan####.com/90c79e643d888e14f672d22db3e9b1f2_800x800.jpg
- o####.lanlan####.com/93d58b105ba8c9a1128d5846ee0d2ec1_126x126.png
- o####.lanlan####.com/975053dfab93aa8345b84a71a3e154d6_126x126.png
- o####.lanlan####.com/9d8e965ef0fadf7739bbd3f70cd2bc58_800x800.jpg@!1-300...
- o####.lanlan####.com/9da6adc6a460da8d80a7680d7b419d5c_126x126.png
- o####.lanlan####.com/9f88771ae33e0ac8eb46047701b1047d_126x126.png
- o####.lanlan####.com/a5d05fa1b92c45079be5b8bffd6e60ef_408x616.jpg
- o####.lanlan####.com/a6413cfbe1a60a083e54f9e783cac654_800x800.jpg
- o####.lanlan####.com/a9ef3c852b6549a35888c624f09ea58c_126x126.png
- o####.lanlan####.com/b4d265effc94867c6661811b472bb2e4_800x800.jpg
- o####.lanlan####.com/b77de4b693118e7b657420356e921572_126x126.png
- o####.lanlan####.com/b91337ad687218af77ff0eed0c10808e_800x800.jpg@!1-300...
- o####.lanlan####.com/c26bd4b9db0145131a4b43c48e05497b_800x800.jpg@!1-300...
- o####.lanlan####.com/c4f979fce4ad167640412fe9f81af054_126x126.png
- o####.lanlan####.com/d5edb16b7abe2a31ec75b732b57fe597_256x256.png
- o####.lanlan####.com/d9d7233844cc3311f7e9fa47235346b2_126x126.png
- o####.lanlan####.com/dac90b424a1e228d22ea6117d8135daf_233x263.jpg@!1-300...
- o####.lanlan####.com/dacf6bc3fe493814b481c9d915f5bfb7_800x800.jpg@!1-300...
- o####.lanlan####.com/e1f91a0196e2ca1bede7a7aaba546772_788x788.jpg
- o####.lanlan####.com/e81fda4ee7f33c8723dc2c87204bc92a_126x126.png
- o####.lanlan####.com/e88139588386f6c080c6a50d8691f256_740x740.png
- o####.lanlan####.com/e8aa20c6ba198967fffdeb479903a22c_126x126.png
- o####.lanlan####.com/e926d4b0a85913d643f634eba61c8b92_132x224.png
- o####.lanlan####.com/f0495181e86c6444b171f29248fd75fa_126x126.png
- o####.lanlan####.com/f35167ec7779eabce4d259990abdde53_130x466.png
- o####.lanlan####.com/f4ee5462afc7eb69241c9f88513d9225_126x126.png
- o####.lanlan####.com/f87493c5f309d8b282476c232df6bd4b_26x26.png
- o####.lanlan####.com/jd618-payout-activity.webp
- oss.lanlan####.com/104ce9b8ab991a178a56b767bcf0f4d6_126x126.png
- oss.lanlan####.com/5d047f2d2b45c21535a810e626d80296_126x126.png
- oss.lanlan####.com/64075030483a3fc53cca2cd235974ef8_348x632.png
- oss.lanlan####.com/6f7c9e6046ffb6e7fbea0bf96556bf6f_800x800.jpg
- oss.lanlan####.com/7401f07249d24132665bc754f2baf2ff_126x126.png
- oss.lanlan####.com/76c7b9ac7b1df943559c2ed1f387750c_800x800.jpg
- oss.lanlan####.com/8f2b9a8a088609316b2eaf6b2ef0a832_126x126.png
- oss.lanlan####.com/92a03ed6179dd20c08369a1dd802e1d3_132x222.png
- oss.lanlan####.com/961513f2acaaf151b34f4a95d856f827_800x800.jpg
- oss.lanlan####.com/9ef199967812d1b350f59784c85c734f_800x800.jpg
- oss.lanlan####.com/afb02a859871f45e807aeaf85a7547b9_280x224.png
- oss.lanlan####.com/cbf5cd9ff239cc262f34a08025c34a0a_698x698.jpg
- sni.c####.q####.####.net/config/hz-hzv3.conf
- sni.c####.q####.####.net/tdata_rRG322
- sni.c####.q####.####.net/tdata_vHH584
- sqb.xiaosh####.com/api/1/app/init?_did=####&_app=####&_atype=####&_netwo...
- sqb.xiaosh####.com/api/1/index/getCategory?_did=####&_app=####&_atype=##...
- sqb.xiaosh####.com/api/1/index/getHot?_did=####&_app=####&_atype=####&_n...
- sqb.xiaosh####.com/api/1/index/index?_did=####&_app=####&_atype=####&_ne...
- sqb.xiaosh####.com/api/2/circle/unReadInfo?_did=####&_app=####&_atype=##...
- sqb.xiaosh####.com/api/2/preferred/list?_did=####&_app=####&_atype=####&...
- www.lanlan####.com/h5/help/superSearch
- a####.u####.com/app_logs
- and####.b####.qq.com/rqd/async?aid=####
- beacon####.aliy####.com/beacon/fetch/config/byappkey
- c-h####.g####.com/api.php?format=####&t=####
- l####.tbs.qq.com/ajax?c=####&k=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
- wb.110.ta####.com/api/update.do
- zhg.ali####.com/saveWb.json
- /data/anr/traces.txt
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/0a231bd8575dcf72.txt
- /data/data/####/1004
- /data/data/####/1d77ea041509fe06.lock
- /data/data/####/21c22f492aba3de8.lock
- /data/data/####/8ef9c457b3bbb403.lock
- /data/data/####/930a31b34bd52c08.lock
- /data/data/####/AlibcLinkPartner.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/SGMANAGER_DATA2.tmp
- /data/data/####/UTCommon.xml
- /data/data/####/XiaoShiJie.db-journal
- /data/data/####/XsjDB-journal
- /data/data/####/aliTradeConfigSP.xml
- /data/data/####/ap.Lock
- /data/data/####/bugly_db_-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.xiaoshijie.sqb_preferences.xml
- /data/data/####/com_alibaba_aliyun_crash_defend_sdk_info
- /data/data/####/core_info
- /data/data/####/crashrecord.xml
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/f_000001
- /data/data/####/f_000002
- /data/data/####/f_000003
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gx_sp.xml
- /data/data/####/httpdns_config_cache.xml
- /data/data/####/index
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/libjiagu1359582446.so
- /data/data/####/libsgmainso-5.1.81.so.tmp
- /data/data/####/libsgsecuritybodyso-5.1.25.so.tmp
- /data/data/####/local_crash_lock
- /data/data/####/lock.lock
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/sf_data.xml
- /data/data/####/sp.lock
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/tdata_rRG322
- /data/data/####/tdata_rRG322.jar
- /data/data/####/tdata_vHH584
- /data/data/####/tdata_vHH584.jar
- /data/data/####/timestamp
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/ut.db
- /data/data/####/ut.db-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/media/####/.nomedia
- /data/media/####/1rN4J0UA26VO8yKnCU1y1ovDiJ8.-1532613061.tmp
- /data/media/####/33J3fzXY8YHJoAA-CSYVqubM0E4.-368858966.tmp
- /data/media/####/3vhTeI67nIeP3gvYWyhWSbQ0AFk.-362120578.tmp
- /data/media/####/6c709c11d2d46a7b
- /data/media/####/6mYrD8NEw7kZ8LOxMkkngGgDSiQ.-629453191.tmp
- /data/media/####/7RBnETSuRwMh_Ui0PqKMkMCbkcM.-1889066982.tmp
- /data/media/####/8TWgWLW4DpXpY2byZDV-Y_maHhY.-455135196.tmp
- /data/media/####/Alvin2.xml
- /data/media/####/Cb8N0es3k6ZghlZtV2xwAbsRAa4.-1116405866.tmp
- /data/media/####/ContextData.xml
- /data/media/####/DHCWT9Xbuu7aDMLGd9-KT7LpZjI.-1084122576.tmp
- /data/media/####/DKuWpEu9ZFPWr42_gDylRO80l6w.478111045.tmp
- /data/media/####/D_5fouwyAzsBEJvntnkTRugIwYo.-1813503494.tmp
- /data/media/####/DvlrGNZNcC-MChYYwi1x8sYLQOc.768881585.tmp
- /data/media/####/ER7Z4vqDfmZEijZi2sh08JXG1nQ.326469483.tmp
- /data/media/####/Fy0YXnbPPcDR19OgGB6_F-dCTb8.-911557686.tmp
- /data/media/####/Hg86RXRGfXWYnmD8jYfrsITQnUk.218751101.tmp
- /data/media/####/Is-UFvDWlLJ8LrnTBZD2cNfrhvU.107049124.tmp
- /data/media/####/KAOb4zTfauUjG0IXOVwaXyYXD8U.255676805.tmp
- /data/media/####/L5Cv7AihZj6V9emHh1l8mEMBGW4.-1822292464.tmp
- /data/media/####/R-mbNZONsbrCB5eNzcbldrPvE5U.596055608.tmp
- /data/media/####/RkaJxcSGeFj_fVslr51kuzhtqxs.-639825432.tmp
- /data/media/####/STYi6SV3H9juQ1VDF9wQkGrE4tA.-472894755.tmp
- /data/media/####/VZFNXkbsQ4X1LJdXOPhrPVnpxGw.561023682.tmp
- /data/media/####/WthbHajO0FHLeQZHgAJSRvCbN_k.2016207622.tmp
- /data/media/####/Xz30kL5hpbhs_lX_lfMZ7rSileQ.-941224047.tmp
- /data/media/####/YLJL4mL_4hpE1CIUYtgkycfNU0M.220679350.tmp
- /data/media/####/YLhcmi7cz9pAi4cvcWEt9EjZIFk.-223205846.tmp
- /data/media/####/YQYQKLR4_q-J2AWmEXd2PZ4IoV4.239420211.tmp
- /data/media/####/Z4MwIuZx9SRuN332NV_PFcPdV-c.-1513970485.tmp
- /data/media/####/ZA4iLBIXOhTOQOxHXqsYwPCSh-Q.-1319658317.tmp
- /data/media/####/ZoLkr_QWmUvkB9RpmxhJoltMseU.1839088946.tmp
- /data/media/####/_GNL-jPI1zlGdiKD3IBgiTu7XYE.1113712341.tmp
- /data/media/####/adKzGSMh3XvItT9JbUwz0w6mjYQ.1586576850.tmp
- /data/media/####/aouW9hsQNvvW5XdGCjn3Cx9l-Xs.551405795.tmp
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.xiaoshijie.sqb.bin
- /data/media/####/com.xiaoshijie.sqb.db
- /data/media/####/dd7893586a493dc3
- /data/media/####/gNVQGfTMzApxRrCyT_m1AnNXJio.1066433150.tmp
- /data/media/####/hid.dat
- /data/media/####/j3bkp5VGu-6pElFYf0HYOH8_MIA.-1186692438.tmp
- /data/media/####/j6CqlL2ofC2yrxb6G5LXaYGBFxI.-130269646.tmp
- /data/media/####/jtsaJyRAlxLqnMwrM9Jj_QNdOz8.1717167408.tmp
- /data/media/####/jvFw9B-9cNlDqsryhpk_wH2bjIg.562884052.tmp
- /data/media/####/nRVcsVk6kAetwtxBfaxT0xzbql8.973730270.tmp
- /data/media/####/nz-VQB2he3fAXyIio3oEkw0LzdU.1748271556.tmp
- /data/media/####/oFFTdPAE5RSjUFt9uR7WEFurx7c.-1780899694.tmp
- /data/media/####/oGYcnrzovMSx5wlc4cK1kQ8sAUw.2070133919.tmp
- /data/media/####/ppXMHa1JxyDz2lDtRxMHxMofaX4.-1965555403.tmp
- /data/media/####/qV7yypQKHCXtf162nt7SUHbC2z0.1399774449.tmp
- /data/media/####/qk_7NrGU4fLIbmum_N0exv4VuiE.1219363982.tmp
- /data/media/####/rrRJihQpkWt8b2NNs4awmKZLFoA.1712523897.tmp
- /data/media/####/se8rQN5RSvKbUomCTscAU9TZzAU.-557816675.tmp
- /data/media/####/tbslog.txt
- /data/media/####/tdata_rRG322
- /data/media/####/tdata_vHH584
- /data/media/####/test.log
- /data/media/####/uv35K6c4jJOoSZOrwvBs0PLue6U.-1776287881.tmp
- /data/media/####/vzrFzwMcNqKLpj_HEGXULaAx2ho.-632563892.tmp
- /data/media/####/wLX7o4SS_AqvTLSn5hoP-XHiLCE.-1361156023.tmp
- /data/media/####/xXVYwp6msRHVd8nsBDcFVnUtCsI.1203740287.tmp
- /system/bin/sh -c getprop
- /system/bin/sh -c type su
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.xiaoshijie.service.SqbPushService 24806 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- chmod 755 <Package Folder>/.jiagu/libjiagu1359582446.so
- getprop
- getprop ro.product.cpu.abi
- Bugly
- bitmaps
- getuiext2
- libjiagu1359582446
- memchunk
- sgmainso-5.1
- sgsecuritybodyso-5.1
- static-webp
- ut_c_api
- webp
- webpimage
- weibosdkcore
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5Padding
- AES-GCM-NoPadding