Technical information
- Adware.Gexin.2.origin
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) ot####.x2.tc.####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) s####.s####.swift####.cn:443
- TCP(TLS/1.0) 64.2####.161.95:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) 64.2####.164.95:443
- TCP(TLS/1.2) 64.2####.161.138:443
- TCP(TLS/1.2) 64.2####.164.95:443
- TCP(TLS/1.2) 1####.194.73.94:443
- TCP(TLS/1.2) 64.2####.162.95:443
- and####.b####.qq.com
- and####.google####.com
- instant####.google####.com
- m####.go####.com
- s####.s####.swift####.cn
- s.b####.g####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.com
- sdk.o####.t####.####.net
- and####.b####.qq.com/rqd/async?aid=####
- /data/data/####/0c1e37fe1a1f35c8_0
- /data/data/####/1002
- /data/data/####/1004
- /data/data/####/3b820703-2141-4513-85e8-e8e5cb2bd269.zip (deleted)
- /data/data/####/752107434b8c3a5f_0
- /data/data/####/BUGLY_COMMON_VALUES.xml
- /data/data/####/Cookies-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/bugly_db_
- /data/data/####/bugly_db_-journal
- /data/data/####/changed_classes.dex.dex
- /data/data/####/changed_classes.dex.dex.flock (deleted)
- /data/data/####/changed_classes.dex.jar
- /data/data/####/cn.swiftpass.enterprise.spdb.BETA_VALUES.xml
- /data/data/####/cn.swiftpass.enterprise.spdb.BETA_VALUES.xml.bak
- /data/data/####/cn.swiftpass.enterprise.spdb_preferences.xml
- /data/data/####/crashrecord.xml
- /data/data/####/getui_sp.xml
- /data/data/####/ijm_ifr.xml
- /data/data/####/ijm_sharedecryption.xml
- /data/data/####/index
- /data/data/####/info.lock
- /data/data/####/init.pid
- /data/data/####/init_c1.pid
- /data/data/####/jni_log_1619713870427.txt
- /data/data/####/jni_log_1619713874482.txt
- /data/data/####/libexec.so
- /data/data/####/libexecmain.so
- /data/data/####/libijmDataEncryption.so
- /data/data/####/local_crash_lock
- /data/data/####/local_crash_lock (deleted)
- /data/data/####/metrics_guid
- /data/data/####/native_record_lock
- /data/data/####/native_record_lock (deleted)
- /data/data/####/patch-e6d62037.apk
- /data/data/####/patch.apk
- /data/data/####/patch.info
- /data/data/####/patch.retry
- /data/data/####/prefs.xml
- /data/data/####/proc_auxv
- /data/data/####/push.pid
- /data/data/####/pushsdk.db-journal
- /data/data/####/run.pid
- /data/data/####/security_info
- /data/data/####/sys_log_1619713870427.txt
- /data/data/####/sys_log_1619713874482.txt
- /data/data/####/temp.apk
- /data/data/####/test.dex.jar
- /data/data/####/the-real-index
- /data/data/####/tinker_classN.apk
- /data/data/####/tinker_classN.dex
- /data/data/####/tinker_classN.dex.flock (deleted)
- /data/data/####/tinker_own_config_cn.swiftpass.enterprise.spdb.xml
- /data/data/####/tinker_own_config_cn.swiftpass.enterprise.spdb;...ce.xml
- /data/data/####/tmpPatch.apk
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/tinker/patch-e6d62037/dex/changed_classes.dex.jar --oat-fd=51 --oat-location=/data/user/0/<Package>/tinker/patch-e6d62037/odex/changed_classes.dex.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/tinker/patch-e6d62037/dex/tinker_classN.apk --oat-fd=44 --oat-location=/data/user/0/<Package>/tinker/patch-e6d62037/odex/tinker_classN.dex --compiler-filter=speed
- app_process /system/bin com.android.commands.pm.Pm list package -3
- getprop
- getprop ro.product.cpu.abi
- sh
- sh -c cat /proc/3558/wchan
- sh -c cat /proc/3588/wchan
- sh -c cat /proc/3644/wchan
- sh -c cat /proc/3782/wchan
- sh -c cat /proc/3811/wchan
- sh -c cat /proc/3862/wchan
- sh -c cat /proc/4167/wchan
- sh -c cat /proc/5536/wchan
- sh -c cat /proc/5568/wchan
- sh -c cat /proc/5614/wchan
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
- RSA-NONE-OAEPWithSHA1AndMGF1Padding
- AES-GCM-NoPadding