温馨提示:本平台仅供研究软件风险、安全评估,禁止用于非法用途。由于展示的数据过于全面,请耐心等待加载完成。如有疑问或建议, 可加入我们的微信群讨论

APP评分

病毒检测 文件安全

安全评分

文件信息

文件名称 air.com.fernus.mobilelibrary.kronometre v1.0.10.apk
文件大小 3.55MB
MD5 053585df63c896fb6a84917192afc828
SHA1 94be015702ef9e62b7254f1ccf9db7ca51c1c02c
SHA256 31d22994469548d385e8058ca2d637f685f76618abfb29889c33a6eec2efbfcb

应用信息

应用名称 Kronometre Mobil Kütüphane
包名 air.com.fernus.mobilelibrary.kronometre
主活动 air.com.fernus.mobilelibrary.kronometre.AIRAppEntry
目标SDK 31     最小SDK 14
版本号 1.0.10     子版本号 1000010
加固信息 未加壳

GooglePlay应用信息

标题 Kronometre Mobil Kütüphane
评分 2.8181818
安装 5,000+   次下载
价格 0
Android版本支持
分类 教育
Play 商店链接 air.com.fernus.mobilelibrary.kronometre
开发者 FERNUS EĞİTİM TEKNOLOJİLERİ A.Ş.
开发者 ID 7704437305331823648
开发者 地址 None
开发者 主页 https://www.fernus.com.tr/
开发者 Email iletisim@fernus.com.tr
发布日期 2021年6月14日
隐私政策 Privacy link

关于此应用
秒表移动图书馆

您可以从移动设备访问的 z-book 应用程序。

组件导出信息

扫描选项

重新扫描 管理规则 动态分析

反编译代码

Manifest文件 查看
APK文件 下载
Java源代码 查看 -- 下载

证书信息

二进制文件已签名
v1 签名: True
v2 签名: True
v3 签名: True
v4 签名: False
主题: C=TR, O=Fernus BT, OU=Fernus, CN=kryrnrj
签名算法: rsassa_pkcs1v15
有效期自: 2013-10-09 07:31:14+00:00
有效期至: 2038-10-10 07:31:14+00:00
发行人: C=TR, O=Fernus BT, OU=Fernus, CN=kryrnrj
序列号: 0x2d35616337346464613a31343161313436643065663a2d38303030
哈希算法: sha1
证书MD5: 6be3c465e3b2f72ee0cb852834aeb6ec
证书SHA1: 595080c9bb055d72124410bc92e0414ed79c0c02
证书SHA256: 3c34b77f54f438b377777ce2ebcf0540b7188df5cbaab1607410503ba40bab35
证书SHA512: 751e307431ea686d544e3d763f728922719cc0025f7055ed2fbec7f488fcc163e9df47281dd8ee3355992eddfd076decbc34b4c9cc867a46989c8d2c124ebfbb
公钥算法: rsa
密钥长度: 1024
指纹: 52be4265bee93d4138cacd85af1a48285aa05557a8a6be9d5d0a9a6d735013ec
找到 1 个唯一证书

应用程序权限

权限名称 安全等级 权限内容 权限描述 关联代码
android.permission.DISABLE_KEYGUARD 危险 禁用键盘锁 允许应用程序停用键锁和任何关联的密码安全设置。例如,在手机上接听电话时停用键锁,在通话结束后重新启用键锁。
android.permission.WAKE_LOCK 危险 防止手机休眠 允许应用程序防止手机休眠,在手机屏幕关闭后后台进程仍然运行。
android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
android.permission.ACCESS_WIFI_STATE 普通 查看Wi-Fi状态 允许应用程序查看有关Wi-Fi状态的信息。
android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
android.permission.READ_PHONE_STATE 危险 读取手机状态和标识 允许应用程序访问设备的手机功能。有此权限的应用程序可确定此手机的号码和序列号,是否正在通话,以及对方的号码等。
android.permission.READ_EXTERNAL_STORAGE 危险 读取SD卡内容 允许应用程序从SD卡读取信息。
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
android.permission.FOREGROUND_SERVICE 普通 创建前台Service Android 9.0以上允许常规应用程序使用 Service.startForeground,用于podcast播放(推送悬浮播放,锁屏播放)
android.permission.CAMERA 危险 拍照和录制视频 允许应用程序拍摄照片和视频,且允许应用程序收集相机在任何时候拍到的图像。

证书分析

高危
0
警告
1
信息
1
标题 严重程度 描述信息
已签名应用 信息 应用程序已使用代码签名证书进行签名

MANIFEST分析

高危
1
警告
0
信息
0
屏蔽
0
序号 问题 严重程度 描述信息 操作
1 应用程序可以安装在有漏洞的已更新 Android 版本上
Android 4.0-4.0.2, [minSdk=14]
信息 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
2 Activity (air.com.fernus.mobilelibrary.kronometre.AIRAppEntry) 的启动模式不是standard模式 高危 Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。

可浏览的ACTIVITIES

ACTIVITY INTENT
air.com.fernus.mobilelibrary.kronometre.AIRAppEntry Schemes: air.com.fernus.mobilelibrary.kronometre://,

网络安全配置

序号 范围 严重级别 描述

API调用分析

API功能 源码文件
加密解密-> Crypto加解密组件 com/distriqt/core/utils/VDK.java
加密解密-> Base64 解密
加密解密-> 信息摘要算法 com/distriqt/core/utils/VDK.java
com/harman/services/AIRRuntimeCheck.java
调用java反射机制
一般功能-> 文件操作
com/adobe/air/AIRSharedPref.java
com/adobe/air/AdobeAIR.java
com/adobe/air/AdobeAIRMainActivity.java
com/adobe/air/AndroidActivityWrapper.java
com/adobe/air/AndroidEncryptedLocalStore.java
com/adobe/air/AndroidGcmIntentService.java
com/adobe/air/AndroidGcmRegistrationService.java
com/adobe/air/AndroidMediaManager.java
com/adobe/air/AndroidMediaStream.java
com/adobe/air/AndroidStageText.java
com/adobe/air/AndroidWebView.java
com/adobe/air/ApplicationFileManager.java
com/adobe/air/CameraUI.java
com/adobe/air/CameraUIProvider.java
com/adobe/air/Certificate.java
com/adobe/air/DeviceProfiling.java
com/adobe/air/Entrypoints.java
com/adobe/air/FlashEGL10.java
com/adobe/air/FlashEGL14.java
com/adobe/air/JavaTrustStoreHelper.java
com/adobe/air/ResourceFileManager.java
com/adobe/air/microphone/AIRMicrophoneRecorder.java
com/adobe/air/utils/DeviceInfo.java
com/adobe/air/utils/Utils.java
com/adobe/air/wand/connection/WandWebSocket.java
com/distriqt/core/utils/Assets.java
com/distriqt/core/utils/FREImageUtils.java
com/distriqt/core/utils/FileProviderUtils.java
com/distriqt/extension/application/alarms/store/AlarmStore.java
com/distriqt/extension/application/autostart/AutoStartController.java
com/distriqt/extension/application/defaults/DefaultsController.java
com/distriqt/extension/application/receivers/ApplicationStartupReceiver.java
com/distriqt/extension/application/settings/SettingsController.java
com/distriqt/extension/permissions/PermissionsController.java
com/distriqt/extension/scanner/controller/view/ScannerCameraPreview.java
com/harman/services/AIRRuntimeCheck.java
一般功能-> 获取系统服务(getSystemService)
com/adobe/air/AIRExpandableFileChooser.java
com/adobe/air/AIRWindowSurfaceView.java
com/adobe/air/Accelerometer.java
com/adobe/air/AndroidActivityWrapper.java
com/adobe/air/AndroidGcmIntentService.java
com/adobe/air/AndroidGcmRegistrationService.java
com/adobe/air/AndroidIdleState.java
com/adobe/air/AndroidInputManager.java
com/adobe/air/DeviceRotation.java
com/adobe/air/InstallOfferPingUtils.java
com/adobe/air/ShakeListener.java
com/adobe/air/ShakeListenerService.java
com/adobe/air/SystemCapabilities.java
com/adobe/air/location/Geolocation.java
com/adobe/air/microphone/AIRMicrophoneRecorder.java
com/adobe/air/net/AndroidNetworkInfo.java
com/adobe/air/telephony/AndroidTelephonyManager.java
com/adobe/air/utils/Utils.java
com/adobe/air/wand/WandManager.java
com/adobe/air/wand/connection/WandWebSocket.java
com/adobe/air/wand/motionsensor/MotionSensor.java
com/distriqt/core/utils/FREUtils.java
com/distriqt/extension/application/alarms/AlarmActivity.java
com/distriqt/extension/application/alarms/AlarmManager.java
com/distriqt/extension/application/alarms/AlarmReceiver.java
com/distriqt/extension/application/controller/ApplicationStateMonitor.java
com/distriqt/extension/application/controller/device/DeviceController.java
com/distriqt/extension/application/functions/accessibility/VoiceOverEnabledFunction.java
com/distriqt/extension/application/functions/device/PropertiesFunction.java
com/distriqt/extension/application/keyboard/KeyboardMonitor.java
com/distriqt/extension/application/keyboard/SoftKeyboard.java
com/distriqt/extension/networkinfo/telephony/TelephonyController.java
com/distriqt/extension/scanner/controller/view/ScannerCameraPreview.java
一般功能-> 加载so文件
一般功能-> 传感器相关操作
组件-> 启动 Activity
一般功能-> IPC通信
air/com/adobe/appentry/AppEntry.java
com/adobe/air/AIRService.java
com/adobe/air/AIRUpdateDialog.java
com/adobe/air/AdobeAIR.java
com/adobe/air/AdobeAIRMainActivity.java
com/adobe/air/AdobeAIRWebView.java
com/adobe/air/AndroidActivityWrapper.java
com/adobe/air/AndroidGcmBroadcastReceiver.java
com/adobe/air/AndroidGcmIntentService.java
com/adobe/air/AndroidGcmRegistrationService.java
com/adobe/air/AndroidIdleState.java
com/adobe/air/AndroidMediaManager.java
com/adobe/air/AndroidNetworkDetector.java
com/adobe/air/AndroidWebView.java
com/adobe/air/CameraUI.java
com/adobe/air/ConfigDownloadListener.java
com/adobe/air/Entrypoints.java
com/adobe/air/FileChooserBroadcastReceiver.java
com/adobe/air/GamePreviewAppEntry.java
com/adobe/air/RemoteDebuggerListenerDialog.java
com/adobe/air/ShakeListenerService.java
com/adobe/air/wand/ConnectionChangeReceiver.java
com/adobe/flashplayer/HDMIUtils.java
com/distriqt/core/ActivityStateListener.java
com/distriqt/core/utils/FileProviderUtils.java
com/distriqt/extension/application/ApplicationContext.java
com/distriqt/extension/application/alarms/AlarmActivity.java
com/distriqt/extension/application/alarms/AlarmManager.java
com/distriqt/extension/application/alarms/AlarmReceiver.java
com/distriqt/extension/application/autostart/AutoStartController.java
com/distriqt/extension/application/controller/ApplicationController.java
com/distriqt/extension/application/controller/ApplicationStateMonitor.java
com/distriqt/extension/application/controller/device/DeviceController.java
com/distriqt/extension/application/display/DisplayController.java
com/distriqt/extension/application/functions/CheckURLSchemeSupportFunction.java
com/distriqt/extension/application/permissions/Authorisation.java
com/distriqt/extension/application/permissions/AuthorisationActivity.java
com/distriqt/extension/application/receivers/ApplicationStartupReceiver.java
com/distriqt/extension/application/settings/SettingsController.java
com/distriqt/extension/application/splash/SplashActivity.java
com/distriqt/extension/application/splash/SplashApplication.java
com/distriqt/extension/permissions/PermissionsContext.java
com/distriqt/extension/permissions/PermissionsController.java
com/distriqt/extension/permissions/permissions/Authorisation.java
com/distriqt/extension/permissions/permissions/AuthorisationActivity.java
com/distriqt/extension/scanner/ScannerContext.java
com/distriqt/extension/scanner/controller/ScannerController.java
com/distriqt/extension/scanner/permissions/Authorisation.java
com/distriqt/extension/scanner/permissions/AuthorisationActivity.java
com/distriqt/extension/scanner/zbar/ZBarScannerActivity.java
com/distriqt/extension/systemgestures/SystemGesturesContext.java
隐私数据-> 获取GPS位置信息 com/adobe/air/AndroidGcmRegistrationService.java
com/adobe/air/location/AIRLocationListener.java
com/adobe/air/location/Geolocation.java
一般功能-> PowerManager操作 com/distriqt/extension/application/alarms/AlarmActivity.java
com/distriqt/extension/application/controller/ApplicationStateMonitor.java
组件-> 启动 Service
一般功能-> 查询数据库(短信、联系人、通话记录、浏览器历史等) com/adobe/air/AndroidMediaManager.java
加密解密-> Base64 加密 com/adobe/air/AndroidEncryptedLocalStore.java
com/adobe/air/AndroidWebView.java
com/distriqt/core/utils/FREImageUtils.java
组件-> 发送广播 com/adobe/air/AIRService.java
com/adobe/air/AndroidActivityWrapper.java
com/distriqt/extension/scanner/controller/ScannerController.java
网络通信-> TCP服务器套接字 com/adobe/air/AndroidActivityWrapper.java
网络通信-> TCP套接字 com/adobe/air/AndroidActivityWrapper.java
com/adobe/air/RemoteDebuggerListenerDialog.java
com/adobe/air/wand/connection/WandWebSocket.java
DEX-> 动态加载 air/com/adobe/appentry/AppEntry.java
com/adobe/air/GamePreviewAppEntry.java
com/adobe/air/ResourceFileManager.java
网络通信-> WebView JavaScript接口 com/adobe/air/AdobeAIRWebView.java
com/adobe/air/AndroidWebView.java
com/adobe/air/StaticPageActivity.java
网络通信-> WebView 相关
网络通信-> WebView GET请求 com/adobe/air/AndroidWebView.java
网络通信-> WebView使用File协议 com/adobe/air/AndroidWebView.java
进程操作-> 杀死进程
进程操作-> 获取进程pid
设备指纹-> 查看本机号码 com/distriqt/extension/application/functions/device/PropertiesFunction.java
网络通信-> HTTP建立连接 com/adobe/air/AndroidGcmIntentService.java
com/adobe/air/wand/connection/WandWebSocket.java
一般功能-> 获取WiFi相关信息 com/adobe/air/net/AndroidNetworkInfo.java
com/adobe/air/wand/connection/WandWebSocket.java
一般功能-> 获取网络接口信息 com/adobe/air/wand/connection/WandWebSocket.java
网络通信-> DefaultHttpClient Connection com/adobe/air/wand/connection/WandWebSocket.java
隐私数据-> 录制音频行为 com/adobe/air/microphone/AIRMicrophoneRecorder.java
隐私数据-> 拍照摄像 com/adobe/air/AndroidCamera.java
com/distriqt/extension/scanner/controller/view/ScannerCameraPreview.java
组件-> ContentProvider com/adobe/air/CameraUIProvider.java
组件-> Provider openFile com/adobe/air/CameraUIProvider.java
隐私数据-> 获取已安装的应用程序 com/distriqt/core/utils/FileProviderUtils.java
com/distriqt/extension/application/functions/CheckURLSchemeSupportFunction.java
com/distriqt/extension/application/settings/SettingsController.java
进程操作-> 获取运行的进程\服务 com/adobe/air/ShakeListenerService.java
一般功能-> 获取活动网路信息 com/adobe/air/utils/Utils.java
一般功能-> Android通知 com/adobe/air/AndroidGcmIntentService.java

源代码分析

高危
2
警告
7
信息
1
安全
1
屏蔽
0
序号 问题 等级 参考标准 文件位置 操作
1 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
com/distriqt/core/utils/VDK.java
2 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3
3 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
com/harman/services/AIRRuntimeCheck.java
4 IP地址泄露 警告 CWE: CWE-200: 信息泄露
OWASP MASVS: MSTG-CODE-2
air/com/adobe/appentry/GetVersionCode.java
com/adobe/air/GetVersionCode.java
5 可能存在跨域漏洞。在 WebView 中启用从 URL 访问文件可能会泄漏文件系统中的敏感信息 警告 CWE: CWE-200: 信息泄露
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-7
com/adobe/air/AndroidWebView.java
6 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
OWASP Top 10: M3: Insecure Communication
OWASP MASVS: MSTG-NETWORK-3
com/adobe/air/AndroidWebView.java
7 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 安全
OWASP MASVS: MSTG-NETWORK-4
com/adobe/air/JavaTrustStoreHelper.java
8 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
9 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-6
com/adobe/air/AdobeAIRMainActivity.java
10 应用程序创建临时文件。敏感信息永远不应该被写进临时文件 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
com/adobe/air/CameraUI.java
11 该文件是World Readable。任何应用程序都可以读取文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
com/adobe/air/utils/Utils.java

动态库分析

No Shared Objects found.
序号 动态库 NX(堆栈禁止执行) STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)

文件分析

序号 问题 文件

VIRUSTOTAL扫描

  检出率: 0 / 67       完整报告

滥用权限

恶意软件常用权限 3/30
android.permission.WAKE_LOCK
android.permission.READ_PHONE_STATE
android.permission.CAMERA
其它常用权限 6/46
android.permission.INTERNET
android.permission.ACCESS_WIFI_STATE
android.permission.ACCESS_NETWORK_STATE
android.permission.READ_EXTERNAL_STORAGE
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.FOREGROUND_SERVICE

恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。

IP地图

域名检测

域名 状态 中国境内 位置信息 解析
s3-us-west-1.amazonaws.com 安全
IP地址: 52.219.117.144
国家: 美利坚合众国
地区: 加利福尼亚
城市: 圣何塞
查看: Google 地图





dh8vjmvwgc27o.cloudfront.net 安全
没有可用的地理位置信息。




手机号码

网址

网址信息 源码文件
http://www.kronometredijital.com/data_json.php
自研引擎-A
http://dh8vjmvwgc27o.cloudfront.net/airgamepad/connect_ping.txt
http://dh8vjmvwgc27o.cloudfront.net/airgamepad/connect_ping.txt?publisher=
com/adobe/air/wand/connection/WandWebSocket.java
http://gamespace.adobe.com
https://dh8vjmvwgc27o.cloudfront.net
com/adobe/air/AndroidGcmIntentService.java
https://www.adobe.com/airgames/5/
com/adobe/air/AdobeAIR.java
http://s3-us-west-1.amazonaws.com/gamepreview/prod/airandroid/air.properties
http://www.adobe.com/airgames/3/
https://www.adobe.com/gamepreview/?game=notification/notificationclicked.html_
com/adobe/air/AdobeAIRMainActivity.java
www.adobe.com
com/adobe/air/AndroidActivityWrapper.java
https://airdownload2.adobe.com/air?
air/com/adobe/appentry/AppEntry.java
https://airdownload2.adobe.com/air?
com/adobe/air/AIRUpdateDialog.java
file:///android_res/raw/startga.html
www.adobe.com
https://www.adobe.com/airgames/4/
com/adobe/air/AdobeAIRWebView.java
www.adobe.com/devnet
com/adobe/air/AIRWindowSurfaceView.java
http://dh8vjmvwgc27o.cloudfront.net/airgamepad/connect_ping.txt?publisher=
file:///android_res/raw/startga.html
http://gamespace.adobe.com
www.adobe.com
http://s3-us-west-1.amazonaws.com/gamepreview/prod/airandroid/air.properties
https://airdownload2.adobe.com/air?
www.adobe.com/devnet
https://www.adobe.com/gamepreview/?game=notification/notificationclicked.html_
http://www.adobe.com/airgames/3/
http://dh8vjmvwgc27o.cloudfront.net/airgamepad/connect_ping.txt
https://www.adobe.com/airgames/5/
https://dh8vjmvwgc27o.cloudfront.net
https://www.adobe.com/airgames/4/
自研引擎-S

FIREBASE实例

邮箱

追踪器

名称 类别 网址

密钥凭证

字符串列表

建议导出为TXT,方便查看。

活动列表

已显示 6 个activities
1、 air.com.fernus.mobilelibrary.kronometre.AIRAppEntry
2、 air.com.fernus.mobilelibrary.kronometre.MainActivity
3、 com.distriqt.extension.application.settings.SettingsActivity
4、 com.distriqt.extension.permissions.permissions.AuthorisationActivity
5、 com.distriqt.extension.scanner.zbar.ZBarScannerActivity
6、 com.distriqt.extension.scanner.permissions.AuthorisationActivity

服务列表

广播接收者列表

内容提供者列表

已显示 2 个providers
1、 com.adobe.air.CameraUIProvider
2、 androidx.lifecycle.ProcessLifecycleOwnerInitializer

第三方SDK

SDK名称 开发者 描述信息
Jetpack Lifecycle Google 生命周期感知型组件可执行操作来响应另一个组件(如 Activity 和 Fragment)的生命周期状态的变化。这些组件有助于您写出更有条理且往往更精简的代码,这样的代码更易于维护。
File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。
Jetpack App Startup Google App Startup 库提供了一种直接,高效的方法来在应用程序启动时初始化组件。库开发人员和应用程序开发人员都可以使用 App Startup 来简化启动顺序并显式设置初始化顺序。App Startup 允许您定义共享单个内容提供程序的组件初始化程序,而不必为需要初始化的每个组件定义单独的内容提供程序。这可以大大缩短应用启动时间。
Jetpack Media Google 与其他应用共享媒体内容和控件。已被 media2 取代。

文件列表

AndroidManifest.xml
META-INF/androidx.activity_activity.version
META-INF/androidx.arch.core_core-runtime.version
META-INF/androidx.asynclayoutinflater_asynclayoutinflater.version
META-INF/androidx.coordinatorlayout_coordinatorlayout.version
META-INF/androidx.core_core.version
META-INF/androidx.cursoradapter_cursoradapter.version
META-INF/androidx.customview_customview.version
META-INF/androidx.documentfile_documentfile.version
META-INF/androidx.drawerlayout_drawerlayout.version
META-INF/androidx.fragment_fragment.version
META-INF/androidx.interpolator_interpolator.version
META-INF/androidx.legacy_legacy-support-core-ui.version
META-INF/androidx.legacy_legacy-support-core-utils.version
META-INF/androidx.legacy_legacy-support-v4.version
META-INF/androidx.lifecycle_lifecycle-extensions.version
META-INF/androidx.lifecycle_lifecycle-livedata-core.version
META-INF/androidx.lifecycle_lifecycle-livedata.version
META-INF/androidx.lifecycle_lifecycle-process.version
META-INF/androidx.lifecycle_lifecycle-runtime.version
META-INF/androidx.lifecycle_lifecycle-service.version
META-INF/androidx.lifecycle_lifecycle-viewmodel-savedstate.version
META-INF/androidx.lifecycle_lifecycle-viewmodel.version
META-INF/androidx.loader_loader.version
META-INF/androidx.localbroadcastmanager_localbroadcastmanager.version
META-INF/androidx.media_media.version
META-INF/androidx.print_print.version
META-INF/androidx.savedstate_savedstate.version
META-INF/androidx.slidingpanelayout_slidingpanelayout.version
META-INF/androidx.startup_startup-runtime.version
META-INF/androidx.swiperefreshlayout_swiperefreshlayout.version
META-INF/androidx.tracing_tracing.version
META-INF/androidx.versionedparcelable_versionedparcelable.version
META-INF/androidx.viewpager_viewpager.version
androidsupportmultidexversion.txt
assets/META-INF/AIR/application.xml
assets/META-INF/AIR/extensions/androidx.core/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/androidx.core/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/androidx.core/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/androidx.core/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/androidx.core/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/androidx.core/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Application/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Application/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Application/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Application/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Application/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.Application/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Core/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Core/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Core/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Core/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Core/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.Core/library.swf
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.NetworkInfo/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Permissions/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Permissions/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Permissions/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Permissions/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Permissions/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.Permissions/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Scanner/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Scanner/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Scanner/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Scanner/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.Scanner/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.Scanner/library.swf
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/META-INF/ANE/Android-ARM/library.swf
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/META-INF/ANE/Android-ARM64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/META-INF/ANE/Android-x64/library.swf
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/META-INF/ANE/Android-x86/library.swf
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/META-INF/ANE/extension.xml
assets/META-INF/AIR/extensions/com.distriqt.SystemGestures/library.swf
assets/META-INF/AIR/license.txt
assets/alphasiz512.png
assets/android-tanitim.png
assets/publisher.json
assets/publisher.png
assets/z-kitap-mobile-new.swf
classes.dex
res/anim/fragment_close_enter.xml
res/anim/fragment_close_exit.xml
res/anim/fragment_fade_enter.xml
res/anim/fragment_fade_exit.xml
res/anim/fragment_fast_out_extra_slow_in.xml
res/anim/fragment_open_enter.xml
res/anim/fragment_open_exit.xml
res/anim-v21/fragment_fast_out_extra_slow_in.xml
res/drawable/$ic_adobe_logo__0.xml
res/drawable/$ic_adobe_logo__1.xml
res/drawable/$ic_adobe_logo__2.xml
res/drawable/air_72px_mobile_eula.png
res/drawable/banner.png
res/drawable/distriqt_splash_background.xml
res/drawable/ic_adobe_logo.xml
res/drawable/ic_adobe_tm_logo.xml
res/drawable/ic_harman_logo.xml
res/drawable/mp_warning_32x32_n.png
res/drawable/notification_bg.xml
res/drawable/notification_bg_low.xml
res/drawable/notification_icon_background.xml
res/drawable/notification_tile_bg.xml
res/drawable-hdpi-v4/home.png
res/drawable-nodpi-v4/splash_landscape.png
res/drawable-nodpi-v4/splash_portrait.png
res/drawable-v21/notification_action_background.xml
res/drawable-xhdpi-v4/ouya_icon.png
res/layout/activity_static_page.xml
res/layout/custom_dialog.xml
res/layout/distriqt_keyboardheight_popupwindow.xml
res/layout/expandable_chooser_row.xml
res/layout/expandable_multiple_chooser_row.xml
res/layout/main.xml
res/layout/multiple_file_selection_panel.xml
res/layout/notification_action.xml
res/layout/notification_action_tombstone.xml
res/layout/notification_media_action.xml
res/layout/notification_media_cancel_action.xml
res/layout/notification_template_big_media.xml
res/layout/notification_template_big_media_custom.xml
res/layout/notification_template_big_media_narrow.xml
res/layout/notification_template_big_media_narrow_custom.xml
res/layout/notification_template_custom_big.xml
res/layout/notification_template_icon_group.xml
res/layout/notification_template_lines_media.xml
res/layout/notification_template_media.xml
res/layout/notification_template_media_custom.xml
res/layout/notification_template_part_chronometer.xml
res/layout/notification_template_part_time.xml
res/layout/scanner_view.xml
res/layout/splash_screen_layout.xml
res/layout/ssl_certificate_warning.xml
res/layout-land/splash_screen_layout.xml
res/layout-land-v16/splash_screen_layout.xml
res/layout-v16/notification_template_custom_big.xml
res/layout-v16/splash_screen_layout.xml
res/layout-v17/notification_action.xml
res/layout-v17/notification_action_tombstone.xml
res/layout-v17/notification_template_big_media.xml
res/layout-v17/notification_template_big_media_custom.xml
res/layout-v17/notification_template_big_media_narrow.xml
res/layout-v17/notification_template_big_media_narrow_custom.xml
res/layout-v17/notification_template_custom_big.xml
res/layout-v17/notification_template_lines_media.xml
res/layout-v17/notification_template_media.xml
res/layout-v17/notification_template_media_custom.xml
res/layout-v21/notification_action.xml
res/layout-v21/notification_action_tombstone.xml
res/layout-v21/notification_template_custom_big.xml
res/layout-v21/notification_template_icon_group.xml
res/mipmap-hdpi-v4/icon.png
res/mipmap-ldpi-v4/icon.png
res/mipmap-mdpi-v4/icon.png
res/mipmap-xhdpi-v4/icon.png
res/mipmap-xhdpi-v4/ouya_icon.png
res/mipmap-xxhdpi-v4/icon.png
res/mipmap-xxxhdpi-v4/icon.png
res/raw/adobelogo.gif
res/raw/debugger.info
res/raw/debuginfo
res/raw/icon.jpg
res/raw/mms_cfg.png
res/raw/rgba8888
res/raw/ss_cfg.png
res/raw/ss_sgn.png
res/raw/startga.html
res/xml/provider_paths.xml
res/xml/splits0.xml
resources.arsc
stamp-cert-sha256
META-INF/BNDLTOOL.SF
META-INF/BNDLTOOL.RSA
META-INF/MANIFEST.MF

污点分析

当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
规则名称 描述信息 操作
病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析