Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(DNS) <Google DNS>
- TCP(HTTP/1.1) q####.c####.l####.####.com:80
- TCP(HTTP/1.1) up####.sdk.jig####.cn:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) 2####.107.1.1:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(TLS/1.0) f####.cug####.com:443
- TCP(TLS/1.0) statson####.pu####.b####.com:443
- TCP(TLS/1.0) 2####.58.211.110:443
- TCP(TLS/1.0) res####.a####.com:443
- TCP(TLS/1.0) cug231####.oss-cn-####.aliy####.com:443
- TCP(TLS/1.0) regi####.xm####.xi####.com:443
- TCP(TLS/1.0) api.tui####.b####.com:443
- TCP(TLS/1.0) s####.j####.cn:443
- TCP cm-1####.ig####.com:5225
- TCP sdk.o####.t####.####.com:5224
- UDP s.j####.cn:19000
- TCP 1####.202.138.17:7004
- UDP easytom####.com:19000
- TCP sa4.tui####.b####.com:5287
- 7j####.c####.z0.####.com
- a####.tui####.b####.com
- and####.b####.qq.com
- api.tui####.b####.com
- c-h####.g####.com
- cm-1####.ig####.com
- cug231####.oss-cn-####.aliy####.com
- easytom####.com
- f####.cug####.com
- pub-####.qin####.com
- regi####.xm####.xi####.com
- res####.a####.com
- s####.j####.cn
- s.j####.cn
- sa4.tui####.b####.com
- sdk-ope####.g####.com
- sdk.c####.ig####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- sis.j####.io
- statson####.pu####.b####.com
- up####.sdk.jig####.cn
- q####.c####.l####.####.com/config/hz-hzv6.conf
- q####.c####.l####.####.com/tdata_EDT369
- q####.c####.l####.####.com/tdata_FhD658
- q####.c####.l####.####.com/tdata_VGu461
- q####.c####.l####.####.com/tdata_vHH584
- q####.c####.l####.####.com/tdata_wiL967
- sdk.o####.p####.####.com/api/addr.htm
- and####.b####.qq.com/rqd/async?aid=####
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
- up####.sdk.jig####.cn/v1/push/sdk/postlist
- /data/data/####/.jg.ic
- /data/data/####/1004
- /data/data/####/11cdbec5-85be-40a1-9ec9-bd0c3164973f
- /data/data/####/1d2b904cbeadfb72ed9546111a231c85.0
- /data/data/####/42aad0dd3932
- /data/data/####/529b031d-dc50-4719-946e-d96b2a730bbc
- /data/data/####/69581065-50a9-478c-acd4-a2cba0fb39f6
- /data/data/####/92344d7c-6e9a-4dc9-b2b4-965129e0dbfa
- /data/data/####/CUG_PREF.xml
- /data/data/####/JPushSA_Config.xml
- /data/data/####/MultiDex.lock
- /data/data/####/a9d569e0-ccb8-43aa-a8f2-6e0a6199dc59
- /data/data/####/appPackageNames_v2
- /data/data/####/bd3522dc-0c49-4f2a-82bd-038656703360
- /data/data/####/bugly_db_-journal
- /data/data/####/cn.jpush.android.user.profile.xml
- /data/data/####/cn.jpush.preferences.v2.rid.xml
- /data/data/####/cn.jpush.preferences.v2.xml
- /data/data/####/com.baidu.pushservice.BIND_CACHE.xml
- /data/data/####/com.baidu.pushservice.app_stat.xml
- /data/data/####/com.baidu.pushservice.friend.xml
- /data/data/####/com.baidu.pushservice.single_conn.xml
- /data/data/####/com.cug.maintenance.push_sync.xml
- /data/data/####/com.cug.maintenance.self_push_sync.xml
- /data/data/####/crashrecord.xml
- /data/data/####/gdaemon_20161017
- /data/data/####/geofencing.db
- /data/data/####/geofencing.db-journal
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/gx_sp.xml
- /data/data/####/hmdb
- /data/data/####/hmdb-journal
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/journal
- /data/data/####/journal.tmp
- /data/data/####/jpush_device_info.xml
- /data/data/####/jpush_local_notification.db
- /data/data/####/jpush_local_notification.db-journal
- /data/data/####/jpush_local_notification.db-wal
- /data/data/####/jpush_stat_cache.json
- /data/data/####/jpush_stat_cache_history.json
- /data/data/####/jpush_statistics.db
- /data/data/####/jpush_statistics.db-journal
- /data/data/####/jpush_statistics.db-shm (deleted)
- /data/data/####/jpush_statistics.db-wal
- /data/data/####/k.store
- /data/data/####/libcuid.so
- /data/data/####/libjiagu-1013262925.so
- /data/data/####/local_crash_lock
- /data/data/####/logdb.db
- /data/data/####/logdb.db-journal
- /data/data/####/mipush.xml
- /data/data/####/mipush_extra.xml
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/pref.xml
- /data/data/####/pst.xml
- /data/data/####/pst.xml.bak
- /data/data/####/push.pid
- /data/data/####/pushclient.xml
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushinfo.db
- /data/data/####/pushinfo.db-journal
- /data/data/####/pushk.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/pushstat_6.1.1.db
- /data/data/####/pushstat_6.1.1.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/tdata_FhD658
- /data/data/####/tdata_FhD658.jar
- /data/data/####/tdata_VGu461
- /data/data/####/tdata_VGu461.jar
- /data/data/####/tdata_vHH584
- /data/data/####/tdata_vHH584.jar
- /data/data/####/tdata_wiL967
- /data/data/####/tdata_wiL967.jar
- /data/data/####/tiny_data.data
- /data/data/####/tiny_data.lock
- /data/media/####/.cuid
- /data/media/####/.cuid2
- /data/media/####/.nomedia
- /data/media/####/.oxy_uuid
- /data/media/####/.push_deviceid
- /data/media/####/1568214107274.db
- /data/media/####/alsn20170807.db
- /data/media/####/alsn20170807.db-journal
- /data/media/####/app.db
- /data/media/####/com.cug.maintenance.bin
- /data/media/####/com.cug.maintenance.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/gkt-journal
- /data/media/####/gktper
- /data/media/####/log-2019-09-11
- /data/media/####/log.lock
- /data/media/####/log1.txt
- /data/media/####/tdata_FhD658
- /data/media/####/tdata_VGu461
- /data/media/####/tdata_vHH584
- /data/media/####/tdata_wiL967
- /data/media/####/test.log
- /system/bin/cat /proc/cpuinfo
- /system/bin/sh -c getprop
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.oxy.pushlibrary.getui.CUGGetTuiPushService 24885 300 0
- cat /sys/class/net/wlan0/address
- chmod 700 <Package Folder>/files/gdaemon_20161017
- getprop
- mount
- sh
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.oxy.pushlibrary.getui.CUGGetTuiPushService 24885 300 0
- Bugly
- bdpush_V2_9
- getuiext2
- jcore121
- libjiagu-1013262925
- native-lib
- AES
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES
- AES-CBC-PKCS5Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding