安全分析报告: 梦幻遮天 v1.0.2

安全分数


安全分数 37/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

3

用户/设备跟踪器


调研结果

高危 10
中危 16
信息 2
安全 2
关注 31

高危 应用程序存在Janus漏洞

应用程序使用了v1签名方案进行签名,如果只使用v1签名方案,那么它就容易受到安卓5.0-8.0上的Janus漏洞的攻击。在安卓5.0-7.0上运行的使用了v1签名方案的应用程序,以及同时使用了v2/v3签名方案的应用程序也同样存在漏洞。

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/chuanglan/shanyan_sdk/utils/b.java, line(s) 206
com/sdk/q/b.java, line(s) 65,106
com/sdk/v/e.java, line(s) 65
com/unionpay/sdk/av.java, line(s) 18,32
com/unionpay/sdk/k.java, line(s) 141,223,258

高危 使用弱加密算法

使用弱加密算法
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/unionpay/sdk/k.java, line(s) 141,223,258
com/unionpay/utils/d.java, line(s) 16

高危 已启用远程WebView调试

已启用远程WebView调试
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04c-Tampering-and-Reverse-Engineering.md#debugging-and-tracing

Files:
cn/lqgame/sdk/floatwind/FloatWebView.java, line(s) 230,38,39
cn/lqgame/sdk/login/view/PwdRedDialog.java, line(s) 130,13,14

高危 默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同

默认情况下,调用Cipher.getInstance("AES")将返回AES ECB模式。众所周知,ECB模式很弱,因为它导致相同明文块的密文相同
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-block-cipher-mode

Files:
cn/lqgame/sdk/common/SE.java, line(s) 33,35

高危 应用程序在加密算法中使用ECB模式。ECB模式是已知的弱模式,因为它对相同的明文块[UNK]产生相同的密文

应用程序在加密算法中使用ECB模式。ECB模式是已知的弱模式,因为它对相同的明文块[UNK]产生相同的密文
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-block-cipher-mode

Files:
a/a/a/b/d.java, line(s) 553
cn/thinkingdata/android/encrypt/c.java, line(s) 36

高危 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击

不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#webview-server-certificate-verification

Files:
com/switfpass/pay/activity/G.java, line(s) 36,35

高危 该文件是World Readable。任何应用程序都可以读取文件

该文件是World Readable。任何应用程序都可以读取文件
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
com/unionpay/UPPayAssistEx.java, line(s) 621

高危 SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击

SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#android-network-apis

Files:
com/switfpass/pay/thread/NetHelper.java, line(s) 81,20,21

高危 该文件是World Writable。任何应用程序都可以写入文件

该文件是World Writable。任何应用程序都可以写入文件
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#testing-local-storage-for-sensitive-data-mstg-storage-1-and-mstg-storage-2

Files:
com/sdk/j/a.java, line(s) 27

中危 应用程序数据存在被泄露的风险

未设置[android:allowBackup]标志
这个标志 [android:allowBackup]应该设置为false。默认情况下它被设置为true,允许任何人通过adb备份你的应用程序数据。它允许已经启用了USB调试的用户从设备上复制应用程序数据。

中危 Activity设置了TaskAffinity属性

(com.tjqymhztand.game.wxapi.WXEntryActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Activity (cn.lqgame.sdk.pay.PayWebView) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 Broadcast Receiver (cn.lqgame.sdk.floatwind.DownUpdateBroadcastReceiver) 未被保护。

存在一个intent-filter。
发现 Broadcast Receiver与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Broadcast Receiver是显式导出的。

中危 Activity (com.alipay.sdk.app.PayResultActivity) 未被保护。

存在一个intent-filter。
发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
a/a/a/b/d.java, line(s) 88
cn/lqgame/sdk/common/Md5.java, line(s) 30,17
cn/lqgame/sdk/login/view/PhonePwdLogin.java, line(s) 444,445
com/chinaums/pppay/unify/UnifyMd5.java, line(s) 54,81
com/chuanglan/shanyan_sdk/tool/j.java, line(s) 26
com/chuanglan/shanyan_sdk/utils/b.java, line(s) 26
com/chuanglan/shanyan_sdk/utils/j.java, line(s) 27
com/nostra13/universalimageloader/cache/disc/naming/Md5FileNameGenerator.java, line(s) 19
com/sdk/b/a.java, line(s) 100,124
com/switfpass/pay/utils/MD5.java, line(s) 14,33
com/switfpass/pay/utils/Rsa.java, line(s) 49
com/unionpay/sdk/b.java, line(s) 468
com/unionpay/sdk/k.java, line(s) 249
com/unionpay/utils/b.java, line(s) 175

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
a/a/a/b/d.java, line(s) 45
com/chuanglan/shanyan_sdk/utils/e.java, line(s) 4
com/switfpass/pay/activity/PayPlugin.java, line(s) 35
com/switfpass/pay/utils/Util.java, line(s) 21
com/unionpay/sdk/c.java, line(s) 12
com/unionpay/sdk/r.java, line(s) 14

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
cn/lqgame/sdk/floatwind/FloatWebView.java, line(s) 759,768
cn/lqgame/sdk/floatwind/FloatWindowViewSimple.java, line(s) 161,375,384,392
cn/lqgame/sdk/login/LoginActivity.java, line(s) 105
cn/lqgame/sdk/login/RealCerterActivity.java, line(s) 80,81,84
cn/lqgame/sdk/login/ServiceDialog.java, line(s) 39
cn/lqgame/sdk/login/utils/ConfigUtils.java, line(s) 57,58,59,61,63
cn/lqgame/sdk/login/utils/ImageUtils.java, line(s) 36,42
cn/lqgame/sdk/login/view/BindPhoneMustView.java, line(s) 130,133
cn/lqgame/sdk/login/view/Permissions.java, line(s) 63,115
cn/lqgame/sdk/login/view/PhoneCodeLogin.java, line(s) 745,748
cn/lqgame/sdk/login/view/PhonePwdLogin.java, line(s) 645,648
cn/lqgame/sdk/login/view/RealViewMust.java, line(s) 120,123
cn/lqgame/sdk/login/view/ResetPwd.java, line(s) 330,333,336
cn/lqgame/sdk/service/CustomerActivity.java, line(s) 34,265
cn/lqgame/sdk/utils/CommMessage.java, line(s) 506,596,235
cn/lqgame/sdk/utils/FileStoreManager.java, line(s) 422,444,314,318,359,363,420,442
cn/lqgame/sdk/utils/LoginDialogUtils.java, line(s) 71,72
cn/lqgame/sdk/utils/LqLogUtil.java, line(s) 68,70,66
cn/lqgame/sdk/utils/PathUtils.java, line(s) 22
cn/lqgame/sdk/utils/WXAPIUtil.java, line(s) 78
com/chuanglan/shanyan_sdk/b/c.java, line(s) 21,21
com/nostra13/universalimageloader/utils/StorageUtils.java, line(s) 23,49,49,54,54,59
com/switfpass/pay/utils/Util.java, line(s) 176
com/unionpay/sdk/d.java, line(s) 96,99,101,146,157
com/unionpay/sdk/e.java, line(s) 338
com/unionpay/utils/j.java, line(s) 31

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
cn/lqgame/sdk/floatwind/FloatWebView.java, line(s) 244,220
cn/lqgame/sdk/login/view/PwdRedDialog.java, line(s) 65,122
cn/lqgame/sdk/pay/PayWebView.java, line(s) 85,79
cn/lqgame/sdk/pay/WebViewActivity.java, line(s) 74,69
cn/thinkingdata/android/ThinkingAnalyticsSDK.java, line(s) 1192,1191
com/switfpass/pay/activity/QQWapPayWebView.java, line(s) 43,67,80
com/unionpay/WebViewJavascriptBridge.java, line(s) 32,30

中危 IP地址泄露

IP地址泄露


Files:
cn/lqgame/sdk/entity/LQgameBaseInfo.java, line(s) 37
cn/lqgame/sdk/utils/NetworkUtil.java, line(s) 27
com/chuanglan/shanyan_sdk/a.java, line(s) 13
com/chuanglan/shanyan_sdk/a/a.java, line(s) 26
com/chuanglan/shanyan_sdk/d/f.java, line(s) 173
com/chuanglan/shanyan_sdk/e/d.java, line(s) 65,287
com/chuanglan/shanyan_sdk/e/g.java, line(s) 37,68
com/chuanglan/shanyan_sdk/tool/c.java, line(s) 207
com/chuanglan/shanyan_sdk/tool/i.java, line(s) 291
com/chuanglan/shanyan_sdk/tool/k.java, line(s) 292
com/chuanglan/shanyan_sdk/tool/l.java, line(s) 301,302
com/chuanglan/shanyan_sdk/utils/p.java, line(s) 24,24,24,24
com/switfpass/pay/activity/PayPlugin.java, line(s) 104
com/unionpay/sdk/c.java, line(s) 21,22,26,26
com/unionpay/sdk/f.java, line(s) 384

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
a/a/a/f/c/d.java, line(s) 44
com/bytedance/dr/impl/k.java, line(s) 103,121
com/chuanglan/shanyan_sdk/c/f.java, line(s) 113
com/chuanglan/shanyan_sdk/utils/b.java, line(s) 43
com/switfpass/pay/utils/Util.java, line(s) 318
com/unionpay/utils/UPUtils.java, line(s) 16
com/unionpay/utils/b.java, line(s) 160

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
cn/lqgame/sdk/common/SE.java, line(s) 10
cn/lqgame/sdk/login/utils/AccountHelper.java, line(s) 290
cn/lqgame/sdk/login/utils/DBHelper.java, line(s) 34,42,35,23,28,229,41,32
cn/lqgame/sdk/utils/ExternalSdkManager.java, line(s) 53
com/chuanglan/shanyan_sdk/utils/w.java, line(s) 121,85,97,109,74,43,53,64
com/sdk/base/framework/bean/DataUtils.java, line(s) 198
com/switfpass/pay/bean/RequestMsg.java, line(s) 197
com/switfpass/pay/utils/Constants.java, line(s) 11,16,5
com/unionpay/tsmservice/data/Constant.java, line(s) 189,191
com/unionpay/tsmservice/data/ResultCode.java, line(s) 73,60
com/unionpay/tsmservice/mi/data/Constant.java, line(s) 131,135
com/unionpay/tsmservice/mi/data/ResultCode.java, line(s) 31,29

中危 可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息

可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-6

Files:
cn/lqgame/sdk/floatwind/FloatWindowActivityDetail.java, line(s) 70,60
com/chuanglan/shanyan_sdk/view/CTCCPrivacyProtocolActivity.java, line(s) 97,99
com/lgame/sdk/X5WebView/X5WebView.java, line(s) 60,58

中危 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
cn/lqgame/sdk/login/utils/DBHelper.java, line(s) 7,8,50
cn/thinkingdata/android/c.java, line(s) 6,7,8,44
com/chuanglan/shanyan_sdk/b/e.java, line(s) 6,54
com/chuanglan/shanyan_sdk/b/f.java, line(s) 4,38
com/unionpay/sdk/bc.java, line(s) 5,468

中危 应用程序包含隐私跟踪程序

此应用程序有多个3隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
凭证信息=> "ksAppId" : "80645"
凭证信息=> "LoginKey" : "ZNwmK2D6KeHWzdfp"
凭证信息=> "oneKeyID" : "jMZhmt7l"
"lqgame_delete_normal_user" : "abc123456789"
c9828b237c6349969247464c92185012
64c2f89fdffa16729c9779f99562bc189d2ce4722ba0faedb11aa22d0d9db228fda
kiG9w0BAQUFADCBqjELMAkGA0JFSUpJTkcxEDAOBgNVBAcMB0JFSUpJTkcxFjAUBgNVB
861693111300f060355040713085368616e67686169311730
b1ff56cef0e21c87260c63ce3ca868bf5974c14
15060355040a130e4368696e6120556e696f6e50617931173015060355040b130e4
54aa526e7a37d8ba2311a1d3d2ab79b3fbeaf3ebb9e7da9e7cdd9be1ae5a53595f47
0f060355040713085368616e676861693117
0a54b19a13b6712dc04d1b49215423d8
92a864886f70d010101050003818d0030818902818100c42e6236d5054ffccaa
1001a3e74c601e3beb1b7ae4f9ab2872a0aaf1dbc2cba89c7528cd
891b9b2a1d867f95eefd537a56d4d805
e94ddc285669ec06b8a405dd4341eac4ea7030203010001300d06092a864886f70d010105050003818
0dc1c1c001c4d6c48241ce1ac41fd5a0
8cc1d6ed5e1b2cc00489215aec3fc2eac008e767b0215981cb5e
6e696f6e5061793111300f06035504031308556e696f6e5061
3015060355040a130e4368696e6120556e696
D75BB2802E61738A9A03BF014F927D9A
dee6172daef74f0895c7d185956ac0a7
d9255940da7b6cd07483f4b4243fd1825b2705
3634385a3078310b300906035504061302383631
f6e50617931173015060355040b130e4368696e6120556e696
11300f060355040813085368616e67686169311130
hjwg16Y0G83C18H9wpMLWi25KDSLyNLA2I509GQ5wydMj2qRYVHjf9fV7Xl9cfcFstlYsOtRAxdUcMOa0nkO1qhsbeEqirQRJmnW0Yub6Yar1FzfWJTlHutV43HJmd8E
536C79B93ACFBEA950AE365D8CE1AEF91FEA9535
89504e470d0a1a0a0000000d49484452000000210000003c0806000000e8acd32a000000097048597300000b1300000b1301009a9c1800000a4d6943435050686f746f73686f70204943432070726f66696c65000078da9d53775893f7163edff7650f5642d8f0b1976c81002223ac08c81059a21092006184101240c585880a561415119c4855c482d50a489d88e2a028b867418a885a8b555c38ee1fdca7b57d7aefededfbd7fbbce79ce7fcce79cf0f8011122691e6a26a003952853c3ad81f8f4f48c4c9bd80021548e0042010e6cbc26705c50000f00379787e74b03ffc01af6f00020070d52e2412c7e1ff83ba50265700209100e02212e70b01905200c82e54c81400c81800b053b3640a009400006c797c422200aa0d00ecf4493e0500d8a993dc1700d8a21ca908008d0100992847240240bb00605581522c02c0c200a0ac40222e04c0ae018059b632470280bd0500768e58900f4060008099422ccc0020380200431e13cd03204c03a030d2bfe0a95f7085b8480100c0cb95cd974bd23314b895d01a77f2f0e0e221e2c26cb142611729106609e4229c979b231348e7034cce0c00001af9d1c1fe383f90e7e6e4e1e666e76ceff4c5a2fe6bf06f223e21f1dffebc8c020400104ecfefda5fe5e5d60370c701b075bf6ba95b00da560068dff95d33db09a05a0ad07af98b7938fc401e9ea150c83c1d1c0a0b0bed2562a1bd30e38b3eff33e16fe08b7ef6fc401efedb7af000719a4099adc0a383fd71616e76ae528ee7cb0442316ef7e723fec7857ffd8e29d1e234b15c2c158af15889b850224dc779b952914421c995e212e97f32f11f96fd0993770d00ac864fc04eb607b5cb6cc07eee01028b0e58d27600407ef32d8c1a0b91001067343279f7000093bff98f402b0100cd97a4e30000bce8185ca894174cc608000044a0812ab041070cc114acc00e9cc11dbcc01702610644400c24c03c104206e4801c0aa11896411954c03ad804b5b0031aa0119ae110b4c131380de7e0125c81eb70170660189ec218bc86090441c8081361213a8811628ed822ce0817998e04226148349280a420e988145122c5c872a402a9426a915d4823f22d7214398d5c40fa90dbc820328afc8abc47319481b25103d4027540b9a81f1a8ac6a073d174340f5d8096a26bd11ab41e3d80b6a2a7d14be87574007d8a8e6380d1310e668cd9615c8c87456089581a26c71663e55835568f35631d583776151bc09e61ef0824028b8013ec085e8410c26c82909047584c5843a825ec23b412ba085709838431c2272293a84fb4257a12f9c478623ab1905846ac26ee211e219e255e270e135f9348240ec992e44e0a21259032490b496b48db482da453a43ed210699c4c26eb906dc9dee408b280ac209791b7900f904f92fbc9c3e4b7143ac588e24c09a22452a494124a35653fe504a59f324299a0aa51cda99ed408aa883a9f5a496da076502f5387a91334759a25cd9b1643cba42da3d5d09a696769f7682fe974ba09dd831e4597d097d26be807e9e7e983f4770c0d860d83c7486228196b197b19a718b7192f994ca605d39799c85430d7321b9967980f986f55582af62a7c1591ca12953a9556957e95e7aa545573553fd579aa0b54ab550fab5e567da64655b350e3a909d416abd5a91d55bba936aece5277528f50cf515fa3be5ffd82fa630db2868546a08648a35463b7c6198d2116c63265f15842d6725603eb2c6b984d625bb2f9ec4c7605fb1b762f7b4c534373aa66ac6691669de671cd010ec6b1e0f039d99c4ace21ce0dce7b2d032d3f2db1d66aad66ad7ead37da7adabeda62ed72ed16edebdaef75709d409d2c9df53a6d3af77509ba36ba51ba85badb75cfea3ed363eb79e909f5caf50ee9ddd147f56df4a3f517eaefd6efd11f373034083690196c313863f0cc9063e86b9869b8d1f084e1a811cb68ba91c468a3d149a327b826ee8767e33578173e66ac6f1c62ac34de65dc6b3c61626932dba4c4a4c5e4be29cd946b9a66bad1b4d374ccccc82cdcacd8acc9ec8e39d59c6b9e61bed9bcdbfc8d85a5459cc54a8b368bc796da967ccb05964d96f7ac98563e567956f556d7ac49d65ceb2ceb6dd6576c501b579b0c9b3a9bcbb6a8ad9badc4769b6ddf14e2148f29d229f5536eda31ecfcec0aec9aec06ed39f661f625f66df6cf1dcc1c121dd63b743b7c727475cc766c70bceba4e134c3a9c4a9c3e957671b67a1739df33517a64b90cb1297769717536da78aa76e9f7acb95e51aeebad2b5d3f5a39bbb9bdcadd96dd4ddcc3dc57dabfb4d2e9b1bc95dc33def41f4f0f758e271cce39da79ba7c2f390e72f5e765e595efbbd1e4fb39c269ed6306dc8dbc45be0bdcb7b603a3e3d65facee9033ec63e029f7a9f87bea6be22df3dbe237ed67e997e07fc9efb3bfacbfd8ff8bfe179f216f14e056001c101e501bd811a81b3036b031f049904a50735058d05bb062f0c3e15420c090d591f72936fc017f21bf96333dc672c9ad115ca089d155a1bfa30cc264c1ed6118e86cf08df107e6fa6f94ce9ccb60888e0476c88b81f69199917f97d14292a32aa2eea51b453747174f72cd6ace459fb67bd8ef18fa98cb93bdb6ab6727667ac6a6c526c63ec9bb880b8aab8817887f845f1971274132409ed89e4c4d8c43d89e37302e76c9a339ce49a54967463aee5dca2b917e6e9cecb9e773c593559907c3885981297b23fe5832042502f184fe5a76e4d1d13f2849b854f45bea28da251b1b7b84a3c92e69d5695f638dd3b7d43fa68864f4675c633094f522b79911992b923f34d5644d6deaccfd971d92d39949c949ca3520d6996b42bd730b728b74f662b2b930de479e66dca1b9387caf7e423f973f3db156c854cd1a3b452ae500e164c2fa82b785b185b78b848bd485ad433df66feeaf9230b82167cbd90b050b8b0b3d8b87859f1e022bf45bb16238b5317772e315d52ba647869f0d27dcb68cbb296fd50e2585255f26a79dcf28e5283d2a5a5432b82573495a994c9cb6eaef45ab9631561956455ef6a97d55b567f2a17955fac70aca8aef8b046b8e6e2574e5fd57cf5796ddadade4ab7caedeb48eba4eb6eacf759bfaf4abd6a41d5d086f00dad1bf18de51b5f6d4ade74a17a6af58ecdb4cdcacd03356135ed5bccb6acdbf2a136a3f67a9d7f5dcb56fdadabb7bed926dad6bfdd777bf30e831d153bdeef94ecbcb52b78576bbd457df56ed2ee82dd8f1a621bbabfe67eddb847774fc59e8f7ba57b07f645efeb6a746f6cdcafbfbfb2096d52368d1e483a70e59b806fda9bed9a77b5705a2a0ec241e5c127dfa67c7be350e8a1cec3dcc3cddf997fb7f508eb48792bd23abf75ac2da36da03da1bdefe88ca39d1d5e1d47beb7ff7eef31e36375c7358f579ea09d283df1f9e48293e3a764a79e9d4e3f3dd499dc79f74cfc996b5d515dbd6743cf9e3f1774ee4cb75ff7c9f3dee78f5df0bc70f422f762db25b74bad3dae3d477e70fde148af5b6feb65f7cbed573cae74f44deb3bd1efd37ffa6ac0d573d7f8d72e5d9f79bdefc6ec1bb76e26dd1cb825baf5f876f6ed17770aee4cdc5d7a8f78affcbedafdea07fa0fea7fb4feb165c06de0f860c060cfc3590fef0e09879efe94ffd387e1d247cc47d52346238d8f9d1f1f1b0d1abdf264ce93e1a7b2a713cfca7e56ff79eb73abe7dffde2fb4bcf58fcd8f00bf98bcfbfae79a9f372efaba9af3ac723c71fbcce793df1a6fcadcedb7defb8efbadfc7bd1f9928fc40fe50f3d1fa63c7a7d04ff73ee77cfefc2ff784f3fb25d29f33000000206348524d00007a25000080830000f9ff000080e9000075300000ea6000003a980000176f925fc546000002744944415478dabcd9c96b145110c7f1d734b6c9b8ef8a0b2e410cfe77826741100441c48324a006040f8a08828a8a102689c11d238a3b8a0b060feaf7e8e979e9816178f57a7b5587390df47c86ee7e55f52b0738c3cf3ae01af00f580226bdf7ce1af010f0439fbe25622db03802f0c02f2bc41a602100f0c094056215302f00ee0063da881ed01700f78071c069227ac0ac00b85f7eef3411bdf2874280d9618016621cb82b00faa3000dc4caf2610b01e6cb87d469220ae0b60058285f53a78928809b0260b13c299d26a2006e0880475580148802b82e009ed4017445ac28ab6108f014585ff75a6d11397055003c073636b95e1b440e5c11002f804d4dff5453440e5c16004bc09636b7b60922072e0980576d014d10393023005e035bbbbce6751019704100bc01b6753decaa1019705e00bc0576a438f263880c981200ef819da90a9f84c8807302e003b02b65f90f2132e0ac00f804ec4edd0485106704c067608f462b388a382d00be007bb51ae261c42901f015d8a739160c104705c037e080f6703440fc0900be03131623e200f137342302872d114784dbb10c4c5a211c704c80fc040e59211c705c80fc000e5a211c704280a83da852ed3869f9cac6aa68ecf0da6f85303bc6eb7456ea05ad6e7ba75adaeb36bab126e763d726a749cb9f01d31aed5ed3e127d6f8be6bdbf8b6190333e0626404d86e81483e0c758906928d855d4392d880fcb22e24455c5415156cb640740e4d524688b1f8e819b0c102d13a48d388956391e2e310442b602f805b75c355cd55432c667e50aea3d4110e18ab08dc575b20aa560f7340cf6a11175bc24c5bae24a575d4b2f57236b4989bb3460c569433c0ef1234e1bd77ff070038285c304da61b3c0000000049454e44ae426082
f6e5061793111300f06035504031308556e696f6e50617930819f300d060
0000000023456789abcdef12123456786789abcd
b1fdf62b0f540fca5458b063af9354925a6c3505a18ff164b6b195f6e517eaee1fb783
08eb9b5c67474d027fa03ce35109b11604083ab6bb4df2c46240f879f
9d101c97133837e13dde2d32a5054abb

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
a/a/a/c/d.java, line(s) 21
a/a/a/f/a.java, line(s) 80,83,105,107
a/a/a/g/b.java, line(s) 13,30,19,25
cn/lqgame/sdk/LqSdkManager.java, line(s) 116,127,237,350,375,384,448,480,520,462
cn/lqgame/sdk/RoleStatis.java, line(s) 56,57,58,59
cn/lqgame/sdk/common/GetDataImpl.java, line(s) 184
cn/lqgame/sdk/common/SE.java, line(s) 39,51,64
cn/lqgame/sdk/crash/LqCrashHandler.java, line(s) 53,130,157
cn/lqgame/sdk/dialog/DialogView.java, line(s) 47
cn/lqgame/sdk/entity/LQgameBaseInfo.java, line(s) 164,165
cn/lqgame/sdk/floatwind/FloatWebView.java, line(s) 121,203,204,213,243,265,273,412,420,426,452,463,466,480,486,489,495,683,784,814,229
cn/lqgame/sdk/floatwind/FloatWindowActivityDetail.java, line(s) 49,54,75,83,91,101,106,112,117,130,146,149,152,159,170,202
cn/lqgame/sdk/floatwind/FloatWindowService.java, line(s) 36,53,95,109
cn/lqgame/sdk/floatwind/FloatWindowView.java, line(s) 317,357
cn/lqgame/sdk/floatwind/FloatWindowViewNew.java, line(s) 352
cn/lqgame/sdk/floatwind/FloatWindowViewSimple.java, line(s) 113,118,122,123,127,128,188,228,235,251,252,362,367,368,458,465
cn/lqgame/sdk/floatwind/MyWindowManager.java, line(s) 21,59
cn/lqgame/sdk/floatwind/WindowServer.java, line(s) 35,40,45,65,66,71,72,74,75
cn/lqgame/sdk/login/LoginActivity.java, line(s) 81,204,207,211,223,228,231,235,247,333
cn/lqgame/sdk/login/ProtocolView.java, line(s) 92,119,161,169
cn/lqgame/sdk/login/RealCerterActivity.java, line(s) 186,237,372,219,286,290,347
cn/lqgame/sdk/login/ShowToastMsg.java, line(s) 18
cn/lqgame/sdk/login/utils/AccountHelper.java, line(s) 111,170
cn/lqgame/sdk/login/utils/DBHelper.java, line(s) 138,139,162,167
cn/lqgame/sdk/login/utils/ImageUtils.java, line(s) 40,41,42,61,71
cn/lqgame/sdk/login/view/AutoLogin.java, line(s) 54,84,119,131
cn/lqgame/sdk/login/view/BindPhoneMustView.java, line(s) 270,212,323,228
cn/lqgame/sdk/login/view/MainLogin.java, line(s) 79,115,126,172,188,265,294,363,382,418,419,420,423,426
cn/lqgame/sdk/login/view/Permissions.java, line(s) 72
cn/lqgame/sdk/login/view/PhoneCodeLogin.java, line(s) 723,154,174,202,434,478,505,510,514,515,665,679
cn/lqgame/sdk/login/view/PhonePwdLogin.java, line(s) 177,198,232,263,452,453,489,518,523,524,525,682,683
cn/lqgame/sdk/login/view/PwdRedDialog.java, line(s) 76,115,143,152,158,163,175,181,129
cn/lqgame/sdk/login/view/QuickLogin.java, line(s) 144,170,200,203
cn/lqgame/sdk/login/view/RealViewMust.java, line(s) 199,277,179,242,251,255,315,320,329,333,347,348,354,398,401
cn/lqgame/sdk/login/view/ResetPwd.java, line(s) 208,313,192,239,255,272
cn/lqgame/sdk/pay/CouponActivity.java, line(s) 58,80,105,182,214,215,216,276,302
cn/lqgame/sdk/pay/NewPayActivity.java, line(s) 272,289,345,346,546,551,633,649,650,809,842,847,855,856,865,866
cn/lqgame/sdk/pay/PayWebView.java, line(s) 89,133,151,207,215
cn/lqgame/sdk/service/CustomerActivity.java, line(s) 110,189
cn/lqgame/sdk/share/SystemShareManager.java, line(s) 48,83
cn/lqgame/sdk/utils/CommMessage.java, line(s) 249,261,291,294,310,322,331,332,333,351,359,364,387,412,414,478,484,486,489,521,531,533,537,538,573,575,576,578,579,582,612,623,627,628,730,732,749,775,776
cn/lqgame/sdk/utils/DeviceInfoManager.java, line(s) 164,189,246
cn/lqgame/sdk/utils/ExternalSdkManager.java, line(s) 35,44,53,58,64,78,84,83,82
cn/lqgame/sdk/utils/FileStoreManager.java, line(s) 134,163,172,197,202,228,260,267,277,379,385,397,400,407
cn/lqgame/sdk/utils/LqLogUtil.java, line(s) 44,78,94,88
cn/lqgame/sdk/utils/ManifestManager.java, line(s) 95,101,102,103,106
cn/lqgame/sdk/utils/OneKeyUtil.java, line(s) 35,42
cn/lqgame/sdk/utils/PackageManager.java, line(s) 32
cn/lqgame/sdk/utils/ThinkingManager.java, line(s) 169
cn/thinkingdata/android/TDConfig.java, line(s) 130,157,171,186,200,325
cn/thinkingdata/android/TDFirstEvent.java, line(s) 32
cn/thinkingdata/android/TDPresetProperties.java, line(s) 107,110
cn/thinkingdata/android/TDWebAppInterface.java, line(s) 154,106,121,163
cn/thinkingdata/android/ThinkingAnalyticsSDK.java, line(s) 204,215,277,1107,1194,1203,305,496,729,748,1379,1416,1503,531,283,289,413,655,663,979,1209,1291,1297
cn/thinkingdata/android/ThinkingDataRuntimeBridge.java, line(s) 116,451,1090,1107,219,483,575,678,774,828,857
cn/thinkingdata/android/aop/push/TAPushProcess.java, line(s) 35,60,72,85,82
cn/thinkingdata/android/b.java, line(s) 374,400,411,425,471,488,492,495,223,250,102,315,398,418,431,444,100,109,194,274,280,330,369,382,476,555
cn/thinkingdata/android/c.java, line(s) 64,71,160,231,213,254,273,282,334
cn/thinkingdata/android/encrypt/c.java, line(s) 26,40,17
cn/thinkingdata/android/f.java, line(s) 196
cn/thinkingdata/android/k.java, line(s) 114,115,117,123,194,200,223,226
cn/thinkingdata/android/l.java, line(s) 160
cn/thinkingdata/android/o.java, line(s) 330,61,158,271,280,292,308,353,367,389,393,414,377
cn/thinkingdata/android/p.java, line(s) 67,35,47
cn/thinkingdata/android/q/b.java, line(s) 59,108
cn/thinkingdata/android/r/b.java, line(s) 30
cn/thinkingdata/android/r/f.java, line(s) 32,34
cn/thinkingdata/android/r/g.java, line(s) 28
cn/thinkingdata/android/r/h.java, line(s) 68,58
cn/thinkingdata/android/utils/TDLog.java, line(s) 11,16,20,32,39,46,55,58,74,80,86,92
cn/thinkingdata/android/utils/d.java, line(s) 109
cn/thinkingdata/android/utils/h.java, line(s) 38,41,46,51,55
cn/thinkingdata/android/utils/j.java, line(s) 15,19,42
cn/thinkingdata/android/utils/l.java, line(s) 25
cn/thinkingdata/android/utils/r.java, line(s) 298,655,660,666,671,678,727
com/bun/miitmdid/core/MdidSdkHelper.java, line(s) 66,72
com/bun/miitmdid/core/Utils.java, line(s) 77,80,38,44,49
com/chinaums/pppay/unify/UnifyPayPlugin.java, line(s) 71,79,154,180,107,113
com/chinaums/pppay/unify/UnifyUtils.java, line(s) 124,128,67
com/chuanglan/shanyan_sdk/utils/o.java, line(s) 29,47,35,23,41
com/kwai/monitor/oaid/OADIDSDKHelper.java, line(s) 34,63,68,72,76
com/kwai/monitor/oaid/OADIDSDKHelper25.java, line(s) 32,63,67
com/lgame/sdk/X5WebView/X5CorePreLoadIS.java, line(s) 24,30,58,37,42,47
com/lgame/sdk/X5WebView/X5WebChromeClientImpl.java, line(s) 67,74,81,93,129
com/lgame/sdk/X5WebView/X5WebViewClientImpl.java, line(s) 63,70,30,77
com/lgame/sdk/X5WebView/X5WebViewCtrl.java, line(s) 24,56
com/lgame/sdk/manager/ManifestManager.java, line(s) 55
com/lgame/sdk/manager/SdkBase.java, line(s) 76,110
com/lgame/sdk/manager/SdkImp.java, line(s) 83,127,139
com/lgame/sdk/manager/SdkManager.java, line(s) 118,127,135,144,147,189,198,205,216
com/lgame/sdk/view/LGActivity.java, line(s) 85,132,133,137,186
com/nostra13/universalimageloader/cache/disc/impl/ext/DiskLruCache.java, line(s) 115
com/sdk/a/a.java, line(s) 40,68
com/sdk/a/c.java, line(s) 187,194,112,144,231,336
com/sdk/base/framework/utils/log/LogUtils.java, line(s) 18,44,53,63,81
com/sdk/d/c.java, line(s) 182
com/sdk/h/a.java, line(s) 13
com/sdk/mobile/manager/login/cucc/UiOauthManager.java, line(s) 27,31,32,38,39,40,41
com/sdk/n/a.java, line(s) 187,189,203,206
com/sdk/p/f.java, line(s) 58,63,72
com/sdk/w/a.java, line(s) 186
com/sdk/x/a.java, line(s) 57,95,172,324
com/sdk/x/c.java, line(s) 21,56
com/switfpass/pay/activity/AsyncTaskC0100e.java, line(s) 29,30,35
com/switfpass/pay/activity/C0111p.java, line(s) 105
com/switfpass/pay/activity/PayPlugin.java, line(s) 56,77
com/switfpass/pay/activity/PayResultActivity.java, line(s) 66
com/switfpass/pay/activity/PaySDKCaptureActivity.java, line(s) 196
com/switfpass/pay/activity/Result.java, line(s) 59,61
com/switfpass/pay/activity/ViewOnClickListenerC0098c.java, line(s) 50
com/switfpass/pay/activity/zxing/camera/CameraManager.java, line(s) 88
com/switfpass/pay/activity/zxing/camera/a.java, line(s) 21
com/switfpass/pay/activity/zxing/camera/b.java, line(s) 97,100,108,115,120,84,139,150
com/switfpass/pay/activity/zxing/camera/c.java, line(s) 31,43,61,69,75,86
com/switfpass/pay/activity/zxing/camera/d.java, line(s) 33
com/switfpass/pay/activity/zxing/decoding/PayCaptureActivityHandler.java, line(s) 48,53,66
com/switfpass/pay/activity/zxing/decoding/b.java, line(s) 63
com/switfpass/pay/service/GetAccessTokenResult.java, line(s) 16
com/switfpass/pay/service/GetPrepayIdResult.java, line(s) 17
com/switfpass/pay/service/b.java, line(s) 59,32
com/switfpass/pay/service/c.java, line(s) 78,33,53
com/switfpass/pay/service/d.java, line(s) 69,54
com/switfpass/pay/service/e.java, line(s) 83,37,59
com/switfpass/pay/service/f.java, line(s) 64,37,56
com/switfpass/pay/service/g.java, line(s) 63
com/switfpass/pay/service/h.java, line(s) 71,37,57
com/switfpass/pay/service/i.java, line(s) 82,36
com/switfpass/pay/service/j.java, line(s) 87,43,46
com/switfpass/pay/thread/NetHelper.java, line(s) 155,159,214,229,146,196
com/switfpass/pay/utils/HandlerC0126j.java, line(s) 19
com/switfpass/pay/utils/J.java, line(s) 23
com/switfpass/pay/utils/PayDialogInfo.java, line(s) 110
com/switfpass/pay/utils/Rsa.java, line(s) 23,24,26
com/switfpass/pay/utils/Util.java, line(s) 72,77,269,120,136,195,203,206,214,226,229,271,275,279,290,117,123,133,256
com/unionpay/b/d.java, line(s) 26
com/unionpay/b/g.java, line(s) 26
com/unionpay/sdk/UPAgent.java, line(s) 137,152,161
com/unionpay/sdk/ay.java, line(s) 14,20,8
com/unionpay/sdk/c.java, line(s) 98
com/unionpay/sdk/t.java, line(s) 23
com/unionpay/utils/j.java, line(s) 20,26,22,18,24

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
cn/lqgame/sdk/floatwind/FloatWebView.java, line(s) 10,665

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/switfpass/pay/thread/NetHelper.java, line(s) 50,81
com/switfpass/pay/utils/Util.java, line(s) 342,301
com/unionpay/a/b.java, line(s) 26,25,24,24
com/unionpay/sdk/b.java, line(s) 363,364

安全 此应用程序可能具有Root检测功能

此应用程序可能具有Root检测功能
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
cn/lqgame/sdk/utils/DeviceInfoManager.java, line(s) 346,336,336,336,336,336
com/unionpay/UPPayAssistEx.java, line(s) 240

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (ad.partner.gifshow.com) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (mobilegw.alipaydev.com) 通信。

{'ip': '221.229.209.223', 'country_short': 'CN', 'country_long': '中国', 'region': '浙江', 'city': 'Hankasalmi', 'latitude': '30.293650', 'longitude': '120.161583'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (api-e189.21cn.com) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '苏州', 'latitude': '31.311365', 'longitude': '120.617691'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (toblog.volceapplog.com) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': 'scsaba\x10Bekesszentandras\x08Bekhtery\x0bBekhteyevka\x07Bekilli\nBekkevoort\x06Bekovo\x08Bektemir\x06Bekwai\x07Bel Air\tBel Om', 'latitude': '32.397221', 'longitude': '119.435600'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (sdk.hnhuolang.com) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '苏州', 'latitude': '33.636440', 'longitude': '116.978851'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (open.e.189.cn) 通信。

{'ip': '193.112.234.72', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (alink.volceapplog.com) 通信。

{'ip': '193.112.234.72', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '-Balkarskaya Respublika\x08Kabarole\x0bKaberamaido\x05Kabul\x06Kachin\x07Kadiogo\x06Kaduna\x04Kaeb\x08Kaffrine\x0fKafr ash Shaykh\x06Kagawa\x06K', 'latitude': '32.397221', 'longitude': '119.435600'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (report-api.lexuangame.com) 通信。

{'ip': '193.112.234.72', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '苏州', 'latitude': '33.636440', 'longitude': '116.978851'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.cmpassport.com) 通信。

{'ip': '193.112.234.72', 'country_short': 'CN', 'country_long': '中国', 'region': '安徽', 'city': '合肥', 'latitude': '31.863815', 'longitude': '117.280830'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (auth.wosms.cn) 通信。

{'ip': '123.125.99.19', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (sdk.hnmengdou.com) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '常州', 'latitude': '31.783331', 'longitude': '119.966667'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (toblog-alink.ctobsnssdk.com) 通信。

{'ip': '221.229.209.223', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '镇江', 'latitude': '32.209366', 'longitude': '119.434372'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (toblog.ctobsnssdk.com) 通信。

{'ip': '193.112.234.72', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '镇江', 'latitude': '32.209366', 'longitude': '119.434372'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (opencloud.wostore.cn) 通信。

{'ip': '222.186.18.194', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (wap.cmpassport.com) 通信。

{'ip': '120.232.169.168', 'country_short': 'CN', 'country_long': '中国', 'region': '广东', 'city': '广州', 'latitude': '23.127361', 'longitude': '113.264572'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (abtest.volceapplog.com) 通信。

{'ip': '221.229.209.223', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '徐州', 'latitude': '34.266666', 'longitude': '117.166664'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (paya.swiftpass.cn) 通信。

{'ip': '221.229.209.223', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (tobapplog.volceapplog.com) 通信。

{'ip': '121.228.188.224', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '苏州', 'latitude': '31.311365', 'longitude': '120.617691'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (www.95516.com) 通信。

{'ip': '58.220.75.72', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '扬州', 'latitude': '32.397221', 'longitude': '119.435600'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (e.189.cn) 通信。

{'ip': '221.231.83.99', 'country_short': 'CN', 'country_long': '中国', 'region': '北京', 'city': '北京', 'latitude': '39.907501', 'longitude': '116.397102'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (log.snssdk.com) 通信。

{'ip': '221.231.83.99', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '盐城', 'latitude': '33.385559', 'longitude': '120.125282'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (ichannel.snssdk.com) 通信。

{'ip': '101.133.104.19', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '苏州', 'latitude': '31.311365', 'longitude': '120.617691'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (klink.volceapplog.com) 通信。

{'ip': '222.186.18.199', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '苏州', 'latitude': '31.311365', 'longitude': '120.617691'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (log-api.oceanengine.com) 通信。

{'ip': '60.188.67.206', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '镇江', 'latitude': '32.209366', 'longitude': '119.434372'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (slog.hnmengdou.com) 通信。

{'ip': '60.188.67.206', 'country_short': 'CN', 'country_long': '中国', 'region': '浙江', 'city': '台州', 'latitude': '28.666668', 'longitude': '121.349998'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (sysdk.cl2009.com) 通信。

{'ip': '60.188.67.206', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (tobapplog.ctobsnssdk.com) 通信。

{'ip': '61.147.168.161', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '镇江', 'latitude': '32.209366', 'longitude': '119.434372'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (sy.cl2m.cn) 通信。

{'ip': '106.14.53.48', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (fs.cl2009.com) 通信。

{'ip': '58.215.85.78', 'country_short': 'CN', 'country_long': '中国', 'region': '上海', 'city': '上海', 'latitude': '31.224333', 'longitude': '121.468948'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (api.e.kuaishou.com) 通信。

{'ip': '58.215.85.78', 'country_short': 'CN', 'country_long': '中国', 'region': '江苏', 'city': '无锡', 'latitude': '31.569349', 'longitude': '120.288788'}

关注 应用程序可能与位于OFAC制裁国家 (中国) 的服务器 (dlhw.hnmengdou.com) 通信。

{'ip': '106.225.238.100', 'country_short': 'CN', 'country_long': '中国', 'region': '江西', 'city': '南昌', 'latitude': '28.683331', 'longitude': '115.883331'}

安全评分: ( 梦幻遮天 1.0.2)