Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) 64.2####.164.94:80
- TCP(TLS/1.0) nim.qi####.com:443
- TCP(TLS/1.0) l####.cmpass####.com:9443
- TCP(TLS/1.0) api.i####.org:443
- TCP(TLS/1.0) l####.cc:443
- TCP(TLS/1.0) qy-swa####.qi####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) sy.cl####.com:443
- TCP(TLS/1.0) s####.cl####.com:443
- TCP(TLS/1.0) rr18---####.g####.com:443
- TCP(TLS/1.0) 64.2####.164.94:443
- TCP(TLS/1.0) wa####.127.net:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) l####.net####.im:443
- TCP(TLS/1.0) al####.u####.com:443
- TCP(TLS/1.0) rr9---s####.g####.com:443
- TCP(TLS/1.0) ap####.uc.cn:443
- TCP(TLS/1.2) 64.2####.164.94:443
- TCP(TLS/1.2) 74.1####.131.139:443
- TCP(TLS/1.2) 1####.251.1.95:443
- TCP(TLS/1.2) and####.google####.com:443
- TCP(TLS/1.2) 64.2####.164.104:443
- UDP and####.google####.com:443
- TCP api.kuaixia####.com:443
- TCP l####.net####.im:8080
- a####.exc.mob.com
- and####.a####.go####.com
- and####.b####.qq.com
- and####.google####.com
- ap####.uc.cn
- api.i####.org
- api.kuaixia####.com
- i####.me
- l####.cc
- l####.cmpass####.com
- l####.net####.im
- l####.tbs.qq.com
- lbs.net####.im
- m####.go####.com
- nim.qi####.com
- p####.google####.com
- qy-swa####.qi####.com
- rr18---####.g####.com
- rr2---s####.g####.com
- rr9---s####.g####.com
- s####.cl####.com
- sy.cl####.com
- u####.u####.com
- wa####.127.net
- www.go####.com
- api.i####.org:443/?format=####
- nim.qi####.com:443/webapi/emoji/emojiPackage/map?appKey=####
- nim.qi####.com:443/webapi/user/da/config?appKey=####
- wa####.127.net:443/lbs?version=####
- a####.exc.mob.com/errconf
- al####.u####.com:443/unify_logs
- al####.u####.com:443/zcfg
- and####.b####.qq.com/rqd/async?aid=####
- ap####.uc.cn:443/collect?chk=####&vno=####&uuid=####&app=####&enc=####
- l####.cc:443/i/sdk/install
- l####.cmpass####.com:9443/log/logReport
- l####.tbs.qq.com/ajax?c=####&k=####
- nim.qi####.com:443/webapi/sdk/setting?appKey=####&fromType=####
- nim.qi####.com:443/webapi/user/create.action?deviceid=####&appKey=####
- s####.cl####.com:443/flash/fdr/v3
- sy.cl####.com:443/flash/accountInit/v3
- /data/data/####/.cl
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/1004
- /data/data/####/Alvin2.xml
- /data/data/####/AndroidAria.db
- /data/data/####/AndroidAria.db-journal
- /data/data/####/AndroidAria.db-journal (deleted)
- /data/data/####/AriaApp.cfg
- /data/data/####/AriaDGroup.cfg
- /data/data/####/AriaDownload.cfg
- /data/data/####/AriaUpload.cfg
- /data/data/####/ContextData.xml
- /data/data/####/LKME_Server_Request_Queue.xml
- /data/data/####/NIMSDK_Config_411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/NIMSDK_Config_411661bd233f0805626044b6d65fa74a_...34.xml
- /data/data/####/NIMSDK_Config_6b25cc9494815e9da2048b65f30ef546.xml
- /data/data/####/NIMSDK_Config_NEW_6b25cc9494815e9da2048b65f30ef546.xml
- /data/data/####/NIMSDK_Config_NEW_6b25cc9494815e9da2048b65f30ef546.xml.bak
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.bati
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.end
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.hdr
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.meminfo
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.pid
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.ps
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.st
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.start
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.status
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.sts
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.time
- /data/data/####/RMSA0DIORDNA0HCTAMRO0MOC.uptime
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/Unicorn.411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/Unicorn.411661bd233f0805626044b6d65fa74a.xml.bak
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/WindVane_wv_main_configcommonwv-data
- /data/data/####/WindVane_wv_main_configdomainwv-data
- /data/data/####/_app.xml
- /data/data/####/a==9.1.0&&2.3.2_1697701176208_envelope.log
- /data/data/####/aria_config.xml
- /data/data/####/bugly_db_-journal
- /data/data/####/bumo.db-journal (deleted)
- /data/data/####/bumo_share_data.xml
- /data/data/####/cdt.wa
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/classes.dex;classes5.dex
- /data/data/####/classes.dex;classes6.dex
- /data/data/####/classes.oat
- /data/data/####/com.ormatch.android.asmr_preferences.xml
- /data/data/####/com.qiyukf.analytics.xml
- /data/data/####/com.qiyukf.analytics.xml.bak
- /data/data/####/core_info
- /data/data/####/cr.wa
- /data/data/####/crashrecord.xml
- /data/data/####/ct_account_api_sdk.xml
- /data/data/####/delayed_transmission_flag_new.xml
- /data/data/####/device_id.xml.xml
- /data/data/####/download_upload
- /data/data/####/dt.wa
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/i==1.2.0&&2.3.2_1697701176557_envelope.log
- /data/data/####/imei.xml
- /data/data/####/info.xml
- /data/data/####/libjiagu.so
- /data/data/####/linkedme_referral_shared_pref.xml
- /data/data/####/linkedme_referral_shared_pref.xml.bak
- /data/data/####/local_crash_lock
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/msg.db-journal
- /data/data/####/native_record_lock
- /data/data/####/proc_auxv
- /data/data/####/qiyu_save_411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/security_info
- /data/data/####/shanyan_share_data.xml
- /data/data/####/shanyan_share_data.xml.bak
- /data/data/####/share_data.xml
- /data/data/####/ssoconfigs.xml
- /data/data/####/t==9.1.0&&2.3.2_1697701175824_envelope.log
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/um_session_id.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_config.xml.bak
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_sp_oaid.xml
- /data/data/####/umeng_sp_zdata.xml
- /data/data/####/umeng_zcfg_flag
- /data/data/####/umeng_zero_cache.db
- /data/data/####/umeng_zero_cache.db-journal
- /data/data/####/unicorn#cheese#
- /data/data/####/unique
- /data/data/####/ver
- /data/data/####/wv_web_info.dat
- /data/data/####/xx_NOS_LBS.xml
- /data/data/####/z==1.2.0&&2.3.2_1697701168707_envelope.log
- /data/media/####/.artc_lock
- /data/media/####/.at_lock
- /data/media/####/.bs_lock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.du_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.gm_lock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.lm_device_id
- /data/media/####/.mn_1666188972
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/4a6742040ca09c8aa9cde844fc722054.0.tmp
- /data/media/####/4a6742040ca09c8aa9cde844fc722054.1.tmp
- /data/media/####/553502e57553b8abeef082ac1cc68f1d.0.tmp
- /data/media/####/553502e57553b8abeef082ac1cc68f1d.1.tmp
- /data/media/####/623a63328522513621dee6afb8bb7fd1.0.tmp
- /data/media/####/623a63328522513621dee6afb8bb7fd1.1.tmp
- /data/media/####/6f1026c5ff60bbe2f57a6dd2d21818ed.0.tmp
- /data/media/####/6f1026c5ff60bbe2f57a6dd2d21818ed.1.tmp
- /data/media/####/89b1f1c458e9e5bd1f3b547e07de90ca.0.tmp
- /data/media/####/89b1f1c458e9e5bd1f3b547e07de90ca.1.tmp
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/WJSDK.mmap3
- /data/media/####/WJSDK_20231019.xlog
- /data/media/####/WJSDK_remote.mmap3
- /data/media/####/demo_20231019.log
- /data/media/####/journal
- /data/media/####/journal.tmp
- /data/media/####/nim_sdk.log
- /data/media/####/tbslog.txt
- /data/media/####/tmp_c_20231019
- /data/media/####/tmp_u_20231019
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- cat /sys/class/net/wlan0/address
- getprop
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- ip route list table all
- ls -l /system/bin/su
- ls -l /system/xbin/su
- ls /
- ls /sys/class/thermal
- ps
- sh -c type su
- libBugly
- libc++_shared
- libcrashsdk
- libjiagu
- libmarsstn
- libmarsxlog
- libumeng-spy
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RC4
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-GCM-NoPadding