Technical information
- Adware.Gexin.1.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.u####.com:80
- TCP(HTTP/1.1) cb####.z####.com:80
- TCP(HTTP/1.1) api.z####.com:80
- TCP(HTTP/1.1) cb####.z####.com:9009
- TCP(HTTP/1.1) i####.z####.com:80
- TCP(HTTP/1.1) a####.a####.m.####.com:80
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) mobile-####.tin####.com:443
- TCP(TLS/1.0) redi####.network####.com:443
- TCP(TLS/1.0) msg.umengc####.com:443
- TCP(TLS/1.0) a####.a####.m.####.com:443
- TCP(TLS/1.0) dc1.network####.com:443
- TCP openj####.m.ta####.com:443
- TCP ope####.m.ta####.com:443
- a####.m.ta####.com
- a####.u####.com
- ag####.m.ta####.com
- api.map.b####.com
- api.z####.com
- cb####.z####.com
- dc1.network####.com
- i####.z####.com
- mobile-####.tin####.com
- msg.umengc####.com
- mt####.go####.com
- redi####.network####.com
- umen####.m.ta####.com
- umengj####.m.ta####.com
- cb####.z####.com/?c=####&a=####&game=####&rentId=####®ionId=####&vesi...
- i####.z####.com/icons_img/caizhushou_imgv_small_min.jpg
- i####.z####.com/news_img/20181109/1541735917312079665.jpg
- i####.z####.com/news_img/20181109/1541735949511001899.jpg
- i####.z####.com/news_img/20181109/1541736036938028296.jpg
- i####.z####.com/news_img/20181109/1541736100222005705.jpg
- i####.z####.com/news_img/20181109/1541736133536010221.jpg
- i####.z####.com/news_img/20181109/1541736165221031781.jpg
- i####.z####.com/news_img/20181109/1541736195711038443.jpg
- i####.z####.com/news_img/20181109/1541736225567093729.jpg
- i####.z####.com/news_img/20181109/1541736254437034189.jpg
- i####.z####.com/news_img/20181109/1541739505938096314.jpg
- i####.z####.com/news_img/20181109/1541739565089048345.jpg
- i####.z####.com/news_img/20181109/1541739617499063171.jpg
- i####.z####.com/news_img/20181109/1541739681353031680.jpg
- i####.z####.com/news_img/20181109/1541739718576053598.jpg
- i####.z####.com/news_img/20181109/1541739767092092110.jpg
- i####.z####.com/news_img/20181109/1541739798057041420.jpg
- i####.z####.com/news_img/20181109/1541739834006038376.jpg
- i####.z####.com/news_img/20181109/1541739884644096684.jpg
- i####.z####.com/news_img/20181109/1541747270663045747.png
- i####.z####.com/news_img/20181109/1541751473186033158.jpg
- i####.z####.com/news_img/20181109/1541751914054025413.jpg
- i####.z####.com/news_img/20181109/1541752112114020244.jpg
- i####.z####.com/news_img/20181109/1541752426543093058.jpg
- i####.z####.com/news_img/20181109/1541753147508051103.jpg
- i####.z####.com/news_img/20181109/1541761370387049472.jpg
- i####.z####.com/news_img/20181109/1541761408073076794.jpg
- i####.z####.com/news_img/20181109/1541761469655021614.jpg
- i####.z####.com/news_img/20181109/1541761546177027409.jpg
- a####.a####.m.####.com/amdc/mobileDispatch?appkey=####&platform=####&v=#...
- a####.u####.com/app_logs
- api.z####.com/api/lottery/getResults
- api.z####.com/api/news/getNewsList
- api.z####.com/api/news/getProgramaListByCzs
- api.z####.com/api/our/secret/lottery/resultsAction
- api.z####.com/api/user/startover
- cb####.z####.com/?c=####&a=####&callType=####&rand=####
- cb####.z####.com:9009/api/system/selectAppUpdate
- cb####.z####.com:9009/api/system/selectUserAppModule
- /data/data/####/.imprint
- /data/data/####/19272663d42769c5e1b23223b455d5efb13166614c218cd....0.tmp
- /data/data/####/1e44d2455580cf3b404519be1087e3edebb54ae122b193f....0.tmp
- /data/data/####/213b1158a45cc98cc3f0f5034b6d59113a16634666ebf1b....0.tmp
- /data/data/####/23d53c383d198d1ecd224089ef43bd43d8e3d7430fa7395....0.tmp
- /data/data/####/44d5ef653689637f385ff614621e88e38fa3a25080dce30....0.tmp
- /data/data/####/52b12bfaeb7937487c820549818ce3eca92adfbcae9301d....0.tmp
- /data/data/####/52c67a522152555a837e9114a641804ea9d06230efa8f75....0.tmp
- /data/data/####/60f628d0fc86a3d4be29228aebfbc47ba072a94e3438998....0.tmp
- /data/data/####/69ff6ef486ae1ef6128322eb45d3456595853b4e22976fa....0.tmp
- /data/data/####/795b685eea511efaaca8377bf53afb6fb5a35d466774132....0.tmp
- /data/data/####/83a82ac72d5034d7e69fe99ade94fe4c69fc68bee8406c3....0.tmp
- /data/data/####/855ad5de30690d4b9dda6a28001b6ef3f6cdd48ab9aed5e....0.tmp
- /data/data/####/85e32178fdc54d51ada5d39ccf28ea40ef48e6c8e068b14....0.tmp
- /data/data/####/8deface9916b762484b96672ee0bc2eeaf27d565ca0e2f4....0.tmp
- /data/data/####/8e86d22ab7e99f5a979884c1ab0e313f2cac63137be9ea1....0.tmp
- /data/data/####/ACCS_BINDumeng;5b02349df29d9834d3000020.xml
- /data/data/####/ACCS_SDK.xml
- /data/data/####/ACCS_SDK_CHANNEL.xml
- /data/data/####/AGOO_BIND.xml
- /data/data/####/Agoo_AppStore.xml
- /data/data/####/Alvin2.xml
- /data/data/####/ContextData.xml
- /data/data/####/CookiePersistence.xml
- /data/data/####/DaemonServer
- /data/data/####/MessageStore.db-journal
- /data/data/####/MsgLogStore.db-journal
- /data/data/####/NBSAnrStore.xml
- /data/data/####/NBSCrashStore.xml
- /data/data/####/PREFS_KEY_UNIQUE_IDENTIFIER.xml
- /data/data/####/aa7c243dfb65319441af728045c7730b231e85c8be39637....0.tmp
- /data/data/####/accs.db-journal
- /data/data/####/af0ea6ec2c64354dca747e8324e12f6e7997e005ea972b4....0.tmp
- /data/data/####/agoo.pid
- /data/data/####/authStatus_com.zbbt.caizhushou.xml
- /data/data/####/authStatus_com.zbbt.caizhushou;channel.xml
- /data/data/####/b2c1a213747be562771aaec3b3728b18ead67aeba6d9520....0.tmp
- /data/data/####/b8b76f964ff7080f47f60de04a0d1b6353ccf61d32657db....0.tmp
- /data/data/####/ba2c342e713661db5142b1c48cf0df0ace19dfa30a5ed63....0.tmp
- /data/data/####/c0cba10509c05631e66605c929ed4ce454c39810dbdede3....0.tmp
- /data/data/####/cache-db-journal
- /data/data/####/cc.db
- /data/data/####/cc.db-journal
- /data/data/####/com.networkbench.agent.impl.v2_com.zbbt.caizhushou.xml
- /data/data/####/d182774a2a1f3c289ac5991c8293421c9c23c7556144178....0.tmp
- /data/data/####/d6f99c7e9c1aa768cf78113d6644f89c6f397c69bd41217....0.tmp
- /data/data/####/d7f7cf993f4290df88741362787063d175d27b2cdf576a0....0.tmp
- /data/data/####/d8b4f7ecfdc5a9bae2f8e718adbfe2cbff4aa60e32973bf....0.tmp
- /data/data/####/dc820d3c77003673d4e16bec6c82a6c8c8e735b7e3b3838....0.tmp
- /data/data/####/de5f29170adc7a543af1df2592ac1445eb314425fbdde3f....0.tmp
- /data/data/####/e3964ca340efe12636b3a1d607bdfb03069748de13f3668....0.tmp
- /data/data/####/e8954a7a4db5e77fe3be233cd19aacd0.0.tmp
- /data/data/####/e8954a7a4db5e77fe3be233cd19aacd0.1.tmp
- /data/data/####/eudemon
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/ezy.update.prefs.xml
- /data/data/####/f29532ca1319da7f85551cc99a5ec708.0.tmp
- /data/data/####/f29532ca1319da7f85551cc99a5ec708.1.tmp
- /data/data/####/f5b105820f49034c38ed840b0172b6766354bc220505f53....0.tmp
- /data/data/####/fb6608f29065d426c146228e2f2bba05984026eda118986....0.tmp
- /data/data/####/fragment_json.xml
- /data/data/####/initcheck.xml
- /data/data/####/journal.tmp
- /data/data/####/libcuid.so
- /data/data/####/libjiagu-1870512094.so
- /data/data/####/message_accs_db
- /data/data/####/message_accs_db-journal
- /data/data/####/multidex.version.xml
- /data/data/####/qihoo_jiagu_crash_report.xml
- /data/data/####/share_name_def.xml
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
- /data/data/####/webviewCookiesChromiumPrivate.db-journal
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.nomedia
- /data/media/####/31d99ef1e2a2455b9c3eb882c6e82123
- /data/media/####/56cf48f10e4cf6043fbf53bbbc4009e3
- /data/media/####/5f5cc98a78554b88b31ad20ab405e2c4
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/aacf35d9ba7b4b46936e483fa1c5572e
- /data/media/####/deviceToken
- /data/media/####/inapp_20181109.log
- <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:5b02349df29d9834d3000020","utdid":"W+X7cexTArcDAGdzx1HJF31P","sdkVersion":"220"} -I agoodm.m.taobao.com -O 80 -T -Z
- chmod 500 <Package Folder>/files/DaemonServer
- chmod 755 <Package Folder>/.jiagu/libjiagu-1870512094.so
- sh
- BaiduMapSDK_base_v4_2_1
- libjiagu-1870512094
- tnet-3.1
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding