Technical information
- Adware.Gexin.2.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) sdk.o####.p####.####.com:80
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(HTTP/1.1) tinychi####.q####.com.####.com:80
- TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
- TCP(HTTP/1.1) c-h####.g####.com:80
- TCP(HTTP/1.1) ti####.c####.l####.####.com:80
- TCP(TLS/1.0) api.map.b####.com:443
- TCP(TLS/1.0) loc.map.b####.com:443
- TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
- TCP(TLS/1.0) o####.map.b####.com:443
- TCP(TLS/1.0) fp.fraudme####.cn:443
- TCP(TLS/1.0) event-t####.yangqia####.com:443
- TCP(TLS/1.0) k####.eas####.com:443
- TCP(TLS/1.0) api.yangqia####.com:443
- TCP sdk.o####.t####.####.com:5224
- TCP cm-1####.g####.com:5225
- 7j####.c####.z0.####.com
- and####.b####.qq.com
- api.map.b####.com
- api.yangqia####.com
- c-h####.g####.com
- cdn-sdk####.g####.com
- cm-1####.g####.com
- event-t####.yangqia####.com
- fp.fraudme####.cn
- k####.eas####.com
- loc.map.b####.com
- log.u####.com
- o####.map.b####.com
- plb####.u####.com
- sdk-ope####.g####.com
- sdk.c####.g####.com
- sdk.o####.p####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- u####.u####.com
- cdn-sdk####.g####.com.####.com/tdata_Qna477
- cdn-sdk####.g####.com.####.com/tdata_trp703
- cdn-sdk####.g####.com.####.com/tdata_xEA084
- sdk.o####.p####.####.com/api/addr.htm
- ti####.c####.l####.####.com/tdata_LRe817
- tinychi####.q####.com.####.com/config/hzv9.conf
- and####.b####.qq.com/rqd/async?aid=####
- c-h####.g####.com/api.php?format=####&t=####
- sdk.o####.p####.####.com/api.php?format=####&t=####
- /data/data/####/.imprint
- /data/data/####/.jg.ic
- /data/data/####/.td-3
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/BUGLY_COMMON_VALUES.xml
- /data/data/####/CookiePersistence.xml
- /data/data/####/MultiDex.lock
- /data/data/####/a==7.5.3&&2.5.0_1587910084249_envelope.log
- /data/data/####/androidUUID.xml
- /data/data/####/authStatus_com.lingyue.zebraloan;remote.xml
- /data/data/####/bugly_db_-journal
- /data/data/####/com.lingyue.zebraloan.BETA_VALUES.xml
- /data/data/####/crashrecord.xml
- /data/data/####/dW1weF9zaGFyZV8xNTg3OTEwMDk4MTYx;
- /data/data/####/dW1weF9zaGFyZV8xNTg3OTEwMTEwNjY4;
- /data/data/####/device_id.xml.xml
- /data/data/####/exchangeIdentity.json
- /data/data/####/exid.dat
- /data/data/####/fetchConfigData.xml
- /data/data/####/firll.dat
- /data/data/####/fm_shared.xml
- /data/data/####/gal.db
- /data/data/####/gal.db-journal
- /data/data/####/gdaemon_20161017
- /data/data/####/getui_sp.xml
- /data/data/####/gkt-journal
- /data/data/####/hst.db
- /data/data/####/hst.db-journal
- /data/data/####/httpclient-req-1032741212.cache
- /data/data/####/httpclient-req-1032741212.cache (deleted)
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/kefuinfo.xml
- /data/data/####/latestVersionCode.xml
- /data/data/####/libcuid_v3.so
- /data/data/####/libjiagu450609810.so
- /data/data/####/libtdbugdumper.so
- /data/data/####/localStorageKeySampleId.xml
- /data/data/####/local_crash_lock
- /data/data/####/multidex.version.xml
- /data/data/####/native_record_lock
- /data/data/####/ofl.config
- /data/data/####/ofl_location.db
- /data/data/####/ofl_location.db-journal
- /data/data/####/ofl_statistics.db
- /data/data/####/ofl_statistics.db-journal
- /data/data/####/push.pid
- /data/data/####/pushext.db-journal
- /data/data/####/pushg.db-journal
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/share.db-journal
- /data/data/####/share_name.xml
- /data/data/####/tdata_Qna477
- /data/data/####/tdata_Qna477.jar
- /data/data/####/tdata_trp703
- /data/data/####/tdata_trp703.jar
- /data/data/####/tdata_xEA084
- /data/data/####/tdata_xEA084.jar
- /data/data/####/ua.db
- /data/data/####/ua.db-journal
- /data/data/####/umeng_common_config.xml
- /data/data/####/umeng_common_config.xml.bak
- /data/data/####/umeng_general_config.xml
- /data/data/####/umeng_it.cache
- /data/data/####/umeng_socialize.xml
- /data/data/####/webview.db-journal
- /data/media/####/.td-3
- /data/media/####/.tdck
- /data/media/####/app.db
- /data/media/####/com.getui.sdk.deviceId.db
- /data/media/####/com.igexin.sdk.deviceId.db
- /data/media/####/com.lingyue.zebraloan.bin
- /data/media/####/com.lingyue.zebraloan.db
- /data/media/####/conlts.dat
- /data/media/####/ls.db
- /data/media/####/ls.db-journal
- /data/media/####/tdata_Qna477
- /data/media/####/tdata_trp703
- /data/media/####/tdata_xEA084
- /data/media/####/test.log
- /system/bin/sh -c getprop
- <Package Folder>/files/gdaemon_20161017 0 <Package>/com.lingyue.banana.getuiapi.YqdPushService 25134 300 0
- chmod 700 <Package Folder>/files/gdaemon_20161017
- getenforce
- getprop
- grep com.android.commands.monkey
- grep magisk
- id
- ls /sbin
- ps
- sh -c df | grep /sbin/.magisk
- sh -c mount | grep /sbin/.magisk
- sh -c ls /sbin | grep magisk
- sh -c ps | grep magisk
- sh -c ps|grep com.android.commands.monkey
- sh <Package Folder>/files/gdaemon_20161017 0 <Package>/com.lingyue.banana.getuiapi.YqdPushService 25134 300 0
- Bugly
- getuiext3
- hyphenate
- libjiagu450609810
- locSDK8a
- sqlite
- tdbugreport
- tongdun
- AES-CBC-PKCS5Padding
- AES-CBC-PKCS7Padding
- AES-ECB-PKCS5Padding
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-CBC-PKCS5PADDING
- AES-CBC-PKCS5Padding
- AES-GCM-NoPadding