Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a####.exc.mob.com:80
- TCP(HTTP/1.1) 64.2####.162.94:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) l####.tbs.qq.com:80
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) u####.u####.com:443
- TCP(TLS/1.0) qy-swa####.qi####.com:443
- TCP(TLS/1.0) 64.2####.162.94:443
- TCP(TLS/1.0) ap####.uc.cn:443
- TCP(TLS/1.0) l####.cc:443
- TCP(TLS/1.0) api.i####.org:443
- TCP(TLS/1.0) sy.cl####.com:443
- TCP(TLS/1.0) lbs.net####.im:443
- TCP(TLS/1.0) rr9---s####.g####.com:443
- TCP(TLS/1.0) l####.cmpass####.com:9443
- TCP(TLS/1.0) nim.qi####.com:443
- TCP(TLS/1.0) wa####.127.net:443
- TCP(TLS/1.2) and####.google####.com:443
- TCP(TLS/1.2) www.go####.com:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 1####.250.150.102:443
- TCP(TLS/1.2) 74.1####.205.102:443
- UDP and####.google####.com:443
- UDP 1####.194.163.36:443
- TCP api.cerjia####.com:443
- TCP lbs.net####.im:8080
- a####.exc.mob.com
- and####.b####.qq.com
- and####.cli####.go####.com
- and####.google####.com
- ap####.uc.cn
- api.cerjia####.com
- api.i####.org
- i####.me
- l####.cc
- l####.cmpass####.com
- l####.net####.im
- l####.tbs.qq.com
- lbs.net####.im
- m####.go####.com
- md####.google####.com
- nim.qi####.com
- pla####.googleu####.com
- qy-swa####.qi####.com
- rr9---s####.g####.com
- sy.cl####.com
- u####.u####.com
- wa####.127.net
- www.go####.com
- api.i####.org:443/?format=####
- nim.qi####.com:443/webapi/emoji/emojiPackage/map?appKey=####
- nim.qi####.com:443/webapi/user/da/config?appKey=####
- wa####.127.net:443/lbs?version=####
- a####.exc.mob.com/errconf
- and####.b####.qq.com/rqd/async?aid=####
- ap####.uc.cn:443/collect?chk=####&vno=####&uuid=####&app=####&enc=####
- l####.cc:443/i/sdk/install
- l####.cc:443/i/sdk/open
- l####.cmpass####.com:9443/log/logReport
- l####.tbs.qq.com/ajax?c=####&k=####
- nim.qi####.com:443/webapi/sdk/setting?appKey=####&fromType=####
- nim.qi####.com:443/webapi/user/create.action?deviceid=####&appKey=####
- sy.cl####.com:443/flash/accountInit/v3
- u####.u####.com:443/unify_logs
- u####.u####.com:443/zcfg
- /data/data/####/.cl
- /data/data/####/.duid
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.jgck
- /data/data/####/.lock
- /data/data/####/.vpl_lock
- /data/data/####/1004
- /data/data/####/Alvin2.xml
- /data/data/####/AndroidAria.db
- /data/data/####/AndroidAria.db-journal
- /data/data/####/AndroidAria.db-journal (deleted)
- /data/data/####/AndroidAria.db-shm (deleted)
- /data/data/####/AndroidAria.db-wal (deleted)
- /data/data/####/AriaApp.cfg
- /data/data/####/ContextData.xml
- /data/data/####/LKME_Server_Request_Queue.xml
- /data/data/####/NIMSDK_Config_411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/NIMSDK_Config_411661bd233f0805626044b6d65fa74a_...bb.xml
- /data/data/####/NIMSDK_Config_6b25cc9494815e9da2048b65f30ef546.xml
- /data/data/####/NIMSDK_Config_NEW_6b25cc9494815e9da2048b65f30ef546.xml
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.anrtmp
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.bati
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.end
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.hdr
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.meminfo
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.pid
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.ps
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.st
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.start
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.status
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.sts
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.time
- /data/data/####/RMSA0DIORDNA0ECIOV0SO.uptime
- /data/data/####/ThrowalbeLog.db-journal
- /data/data/####/UM_PROBE_DATA.xml
- /data/data/####/Unicorn.411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/Unicorn.411661bd233f0805626044b6d65fa74a.xml.bak
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/WindVane_wv_main_configcommonwv-data
- /data/data/####/WindVane_wv_main_configdomainwv-data
- /data/data/####/_app.xml
- /data/data/####/_app.xml.bak
- /data/data/####/bugly_db_-journal
- /data/data/####/cdt.wa
- /data/data/####/chuanglan_report_2.2.1.db
- /data/data/####/chuanglan_report_2.2.1.db-journal
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/classes.dex;classes5.dex
- /data/data/####/classes.dex;classes6.dex
- /data/data/####/com.qiyukf.analytics.xml
- /data/data/####/com.qiyukf.analytics.xml.bak
- /data/data/####/core_info
- /data/data/####/cr.wa
- /data/data/####/crashrecord.xml
- /data/data/####/ct_account_api_sdk.xml
- /data/data/####/delayed_transmission_flag_new.xml
- /data/data/####/device_id.xml.xml
- /data/data/####/download_upload
- /data/data/####/dt.wa
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/i==1.2.0&&1.2.5_1701276714908_envelope.log
- /data/data/####/imei.xml
- /data/data/####/info.xml
- /data/data/####/libjiagu.so
- /data/data/####/linkedme_referral_shared_pref.xml
- /data/data/####/linkedme_referral_shared_pref.xml.bak
- /data/data/####/linkedme_referral_shared_pref.xml.bak (deleted)
- /data/data/####/local_crash_lock
- /data/data/####/maoer.db-journal (deleted)
- /data/data/####/maoer_share_data.xml
- /data/data/####/mob_commons_1
- /data/data/####/mob_sdk_exception_1
- /data/data/####/msg.db-journal
- /data/data/####/native_record_lock
- /data/data/####/native_record_lock (deleted)
- /data/data/####/os.voice.android.asmr_preferences.xml
- /data/data/####/proc_auxv
- /data/data/####/qiyu_save_411661bd233f0805626044b6d65fa74a.xml
- /data/data/####/security_info
- /data/data/####/shanyan_share_data.xml
- /data/data/####/shanyan_share_data.xml.bak
- /data/data/####/share_data.xml
- /data/data/####/ssoconfigs.xml
- /data/data/####/tbs_download_config.xml
- /data/data/####/tbs_download_config.xml.bak
- /data/data/####/tbs_download_config.xml.bak (deleted)
- /data/data/####/tbs_download_stat.xml
- /data/data/####/tbs_pv_config
- /data/data/####/tbscoreinstall.txt
- /data/data/####/tbslock.txt
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/um_pri.xml
- /data/data/####/um_session_id.xml
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_location.xml
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_general_config.xml.bak
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_sp_oaid.xml
- /data/data/####/umeng_sp_zdata.xml
- /data/data/####/umeng_zcfg_flag
- /data/data/####/umeng_zero_cache.db
- /data/data/####/umeng_zero_cache.db-journal
- /data/data/####/unicorn#cheese#
- /data/data/####/unique
- /data/data/####/ver
- /data/data/####/wv_web_info.dat
- /data/data/####/xx_NOS_LBS.xml
- /data/data/####/z==1.2.0&&1.2.5_1701276705268_envelope.log
- /data/media/####/.artc_lock
- /data/media/####/.at_lock
- /data/media/####/.bs_lock
- /data/media/####/.di
- /data/media/####/.dic_lock
- /data/media/####/.du_lock
- /data/media/####/.duid
- /data/media/####/.globalLock
- /data/media/####/.gm_lock
- /data/media/####/.im_lock
- /data/media/####/.lesd_lock
- /data/media/####/.lm_device_id
- /data/media/####/.mn_1666188972
- /data/media/####/.nomedia
- /data/media/####/.pkg_lock
- /data/media/####/.pkgs_lock
- /data/media/####/.slw
- /data/media/####/.ss_lock
- /data/media/####/00d98febfbddb2e3e8da2dd035f3382b.0.tmp
- /data/media/####/00d98febfbddb2e3e8da2dd035f3382b.1
- /data/media/####/19974152ebe9b8fd4f15defd7750d124.0.tmp
- /data/media/####/19974152ebe9b8fd4f15defd7750d124.1
- /data/media/####/19e81b013d0dd0c1bc55dc94153147bc.0.tmp
- /data/media/####/19e81b013d0dd0c1bc55dc94153147bc.1
- /data/media/####/19e81b013d0dd0c1bc55dc94153147bc.1.tmp
- /data/media/####/23ad9d42aa3670eb9bd3b5561582a725.0.tmp
- /data/media/####/23ad9d42aa3670eb9bd3b5561582a725.1
- /data/media/####/23ad9d42aa3670eb9bd3b5561582a725.1.tmp
- /data/media/####/540c70ca15560b015f6c54d641bb6796.0.tmp
- /data/media/####/540c70ca15560b015f6c54d641bb6796.1
- /data/media/####/594e889bc825cf009e9765830eaaad49.0.tmp
- /data/media/####/594e889bc825cf009e9765830eaaad49.1
- /data/media/####/594e889bc825cf009e9765830eaaad49.1.tmp
- /data/media/####/623a63328522513621dee6afb8bb7fd1.0.tmp
- /data/media/####/623a63328522513621dee6afb8bb7fd1.1
- /data/media/####/623a63328522513621dee6afb8bb7fd1.1.tmp
- /data/media/####/Alvin2.xml
- /data/media/####/ContextData.xml
- /data/media/####/WJSDK.mmap3
- /data/media/####/WJSDK_20231129.xlog
- /data/media/####/WJSDK_remote.mmap3
- /data/media/####/WJSDK_remote_20231129.xlog
- /data/media/####/a87dd63777e9c8bca527698b09ea074e.0
- /data/media/####/a87dd63777e9c8bca527698b09ea074e.1
- /data/media/####/a9a89e71b58754bc53d42daa8f6df760.0.tmp
- /data/media/####/a9a89e71b58754bc53d42daa8f6df760.1
- /data/media/####/a9a89e71b58754bc53d42daa8f6df760.1.tmp
- /data/media/####/b71c4ecb3b9c2da09c8ed53ff46a2fe9.0.tmp
- /data/media/####/b71c4ecb3b9c2da09c8ed53ff46a2fe9.1
- /data/media/####/b71c4ecb3b9c2da09c8ed53ff46a2fe9.1.tmp
- /data/media/####/c5724521f135e2e6a0fb2df9d07588e5.0.tmp
- /data/media/####/c5724521f135e2e6a0fb2df9d07588e5.1
- /data/media/####/c5724521f135e2e6a0fb2df9d07588e5.1.tmp
- /data/media/####/demo_20231129.log
- /data/media/####/journal
- /data/media/####/nim_sdk.log
- /data/media/####/tbslog.txt
- /data/media/####/tmp_c_20231129
- /data/media/####/tmp_u_20231129
- /data/misc/####/primary.prof
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- cat /sys/class/net/wlan0/address
- getprop
- getprop ro.build.version.emui
- getprop ro.build.version.opporom
- getprop ro.miui.ui.version.name
- getprop ro.product.cpu.abi
- getprop ro.smartisan.version
- getprop ro.vivo.os.version
- ip route list table all
- ls -l /system/bin/su
- ls -l /system/xbin/su
- ls /
- ls /sys/class/thermal
- ps
- sh -c type su
- libBugly
- libc++_shared
- libcrashsdk
- libjiagu
- libmarsstn
- libmarsxlog
- libumeng-spy
- libzegoliveroom
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-ECB-PKCS7Padding
- AES-GCM-NoPadding
- RC4
- RSA-ECB-NoPadding
- RSA-ECB-PKCS1Padding
- AES-CBC-PKCS7Padding
- AES-ECB-NoPadding
- AES-GCM-NoPadding