安全声明:本平台专为移动应用安全风险研究与合规评估设计,严禁用于任何非法用途。如有疑问或建议,欢迎加入微信群交流

应用图标

文件基本信息

文件名称
8fc9cc71999c07db3ae09878db4cb762816df766a1d9e25f80675fc2ed412ffb.apk
文件大小
7.03MB
MD5
196ffced350d273ffd6133645b2b5940
SHA1
2556a664acd8e94ed22af5181e40218ea274fd43
SHA256
8fc9cc71999c07db3ae09878db4cb762816df766a1d9e25f80675fc2ed412ffb

应用基础信息

应用名称
Space War Ship
包名
batch.arcade.space.war.ship.combat
主活动
com.qbiki.seattleclouds.AppStarterActivity
目标SDK
17
最小SDK
10
版本号
1.0
子版本号
1
加固信息
未加壳

反编译与源码导出

Manifest文件 查看
Java源代码 查看 -- 下载

文件结构与资源列表

    应用签名证书信息

    二进制文件已签名
    v1 签名: True
    v2 签名: False
    v3 签名: False
    v4 签名: False
    主题: CN=Keah HB
    签名算法: rsassa_pkcs1v15
    有效期自: 2014-08-20 17:22:16+00:00
    有效期至: 2042-01-05 17:22:16+00:00
    发行人: CN=Keah HB
    序列号: 0x76a2166a
    哈希算法: sha256
    证书MD5: 49a8230617b268522c5fd117cf5126d9
    证书SHA1: defad55ea8c4741947d16fb59a3f9939c9f0c6be
    证书SHA256: 52924e53260486419cbab9b8c36dbfb94a248ae4ed3b197513d19e73f4057eea
    证书SHA512: c1581378cd26f6cebe715de72a630599131e28d43009b72e93e50097dd7276aa23b13fe34ee953015d15ff87de72d9b494c146b5b6463190eb7dab813bf2fe1c
    找到 1 个唯一证书

    权限声明与风险分级

    权限名称 安全等级 权限内容 权限描述 关联代码
    android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
    android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
    com/amazon/android/c/a.java
    com/amazon/mas/kiwi/util/Base64.java
    com/pollfish/c/e.java
    com/pollfish/c/f.java
    com/pollfish/c/j.java
    com/qbiki/mbfx/MBFXContext.java
    com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
    com/qbiki/modules/cameracover/CoverCamera.java
    com/qbiki/modules/dropbox/medialist/AsyncTaskParseResources.java
    com/qbiki/modules/dynamiclist/DynamicListAdapter.java
    com/qbiki/modules/epubreader/Decompress.java
    com/qbiki/modules/facebookfeeds/DownloadMediaFileAsyncTask.java
    com/qbiki/modules/fusioncharts/FusionChartsFragment.java
    com/qbiki/modules/fusioncharts/GetChartDataAsyncTask.java
    com/qbiki/modules/pdfreader/PDFDocumentHelper.java
    com/qbiki/modules/photoeffect/PhotoEffectFragment.java
    com/qbiki/modules/savephoto/SavePhotoActivity.java
    com/qbiki/modules/scandocument/ImageCropFragment.java
    com/qbiki/modules/scandocument/ScanDocumentFragment.java
    com/qbiki/modules/scoreboard/ScoreBoardFragment.java
    com/qbiki/modules/scoreboard/ScreenShotMaker.java
    com/qbiki/modules/sharepoint/SPFileDetailView.java
    com/qbiki/modules/sharepoint/SPItemEditorView.java
    com/qbiki/modules/sharepoint/SPListViewAdapter.java
    com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
    com/qbiki/modules/signaturestamp/SignatureStampFragment.java
    com/qbiki/modules/starbucks/CardStorageManager.java
    com/qbiki/modules/videolist/DownloadFileAsyncTask.java
    com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
    com/qbiki/seattleclouds/SCDownloadHostedPageResourcesFragment.java
    com/qbiki/seattleclouds/WebViewFragment.java
    com/qbiki/seattleclouds/asynctasks/InitResourcesAsyncTask.java
    com/qbiki/seattleclouds/asynctasks/SyncResourcesAsyncTask.java
    com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
    com/qbiki/util/DataUtil.java
    com/qbiki/util/ZipUtil.java
    com/revmob/android/FileCache.java
    com/revmob/internal/DownloadManager.java
    net/sourceforge/zbar/android/ZBarScanner.java
    org/ksoap2/transport/HttpTransportSE.java
    android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
    android.permission.GET_ACCOUNTS 普通 探索已知账号 允许应用程序访问帐户服务中的帐户列表。
    batch.arcade.space.war.ship.combat.permission.C2D_MESSAGE 未知 未知权限 来自 android 引用的未知权限。
    com.google.android.c2dm.permission.RECEIVE 普通 接收推送通知 允许应用程序接收来自云的推送通知。

    证书安全合规分析

    高危
    1
    警告
    0
    信息
    1
    标题 严重程度 描述信息
    已签名应用 信息 应用程序已使用代码签名证书进行签名
    应用程序存在Janus漏洞 高危 应用程序使用了v1签名方案进行签名,如果只使用v1签名方案,那么它就容易受到安卓5.0-8.0上的Janus漏洞的攻击。在安卓5.0-7.0上运行的使用了v1签名方案的应用程序,以及同时使用了v2/v3签名方案的应用程序也同样存在漏洞。

    Manifest 配置安全分析

    高危
    3
    警告
    6
    信息
    0
    屏蔽
    0
    序号 问题 严重程度 描述信息 操作
    1 应用程序可以安装在有漏洞的已更新 Android 版本上
    Android 2.3.3-2.3.7, [minSdk=10]
    警告 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
    2 Activity (com.qbiki.modules.search.SearchActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
    3 Activity (com.qbiki.modules.search.SearchActivity) 未被保护。
    [android:exported=true]
    警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
    4 Activity (com.qbiki.paypal.PayPalMessage) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
    5 Activity (com.qbiki.paypal.PayPalMessage) 未被保护。
    [android:exported=true]
    警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
    6 Activity (net.sourceforge.zbar.android.ZBarScanner) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
    7 Activity (net.sourceforge.zbar.android.ZBarScanner) 未被保护。
    [android:exported=true]
    警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
    8 Content Provider (com.qbiki.util.InternalFileContentProvider) 未被保护。
    [android:exported=true]
    警告 发现 Content Provider与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
    9 Broadcast Receiver (com.qbiki.gcm.GCMBroadcastReceiver) 受权限保护, 但是应该检查权限的保护级别。
    Permission: com.google.android.c2dm.permission.SEND
    [android:exported=true]
    警告 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

    可浏览 Activity 组件分析

    ACTIVITY INTENT
    com.qbiki.paypal.PayPalMessage Schemes: mobile-appbuilder.hbkeah14.gamesapp039://,

    网络通信安全风险分析

    序号 范围 严重级别 描述

    API调用分析

    API功能 源码文件
    一般功能-> 文件操作
    com/a/a/a/g.java
    com/actionbarsherlock/view/MenuInflater.java
    com/actionbarsherlock/widget/ActivityChooserModel.java
    com/actionbarsherlock/widget/SuggestionsAdapter.java
    com/amazon/android/c/a.java
    com/amazon/android/c/b.java
    com/amazon/android/c/c.java
    com/amazon/android/framework/prompt/e.java
    com/amazon/android/framework/task/command/f.java
    com/amazon/android/framework/util/a.java
    com/amazon/android/l/a.java
    com/amazon/android/l/c.java
    com/amazon/android/l/d.java
    com/amazon/android/licensing/l.java
    com/amazon/android/p/a.java
    com/amazon/android/p/b.java
    com/amazon/android/t/a.java
    com/amazon/mas/kiwi/util/ApkHelpers.java
    com/amazon/mas/kiwi/util/BC1.java
    com/amazon/mas/kiwi/util/Base64.java
    com/amazon/mas/kiwi/util/KiwiVersionEncrypter.java
    com/onbarcode/barcode/android/AbstractBarcode.java
    com/onbarcode/barcode/android/GeneratedBarcodeInfo.java
    com/pollfish/a/a.java
    com/pollfish/c/a.java
    com/pollfish/c/b.java
    com/pollfish/c/c.java
    com/pollfish/c/d.java
    com/pollfish/c/e.java
    com/pollfish/c/f.java
    com/pollfish/c/i.java
    com/pollfish/c/j.java
    com/pollfish/f/b/a.java
    com/pollfish/f/c.java
    com/pollfish/g/a.java
    com/qbiki/ads/SCAdView.java
    com/qbiki/analytics/SCAnalyticsTracker.java
    com/qbiki/billing/SCIabHelper.java
    com/qbiki/feedback/FeedbackFragment.java
    com/qbiki/feedback/FieldProcessing.java
    com/qbiki/gcm/GCMBroadcastReceiver.java
    com/qbiki/gcm/GCMHelper.java
    com/qbiki/geofencing/GeofenceManager.java
    com/qbiki/location/AsyncGeocoder.java
    com/qbiki/mbfx/DynamicHTML.java
    com/qbiki/mbfx/MBFXContext.java
    com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
    com/qbiki/modules/calendar/CalendarFragment.java
    com/qbiki/modules/calendar/EventsSyncAsyncTask.java
    com/qbiki/modules/cameracover/CameraCoverFrgament.java
    com/qbiki/modules/cameracover/CoverCamera.java
    com/qbiki/modules/cameracover/CoversPreviewFragment.java
    com/qbiki/modules/coupon/CouponFragment.java
    com/qbiki/modules/dropbox/medialist/AsyncTaskParseResources.java
    com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
    com/qbiki/modules/dropbox/medialist/GetMediaLinkAsyncTask.java
    com/qbiki/modules/dropbox/medialist/ListItemViews.java
    com/qbiki/modules/dropbox/medialist/MediaFile.java
    com/qbiki/modules/dynamiclist/DynamicListAdapter.java
    com/qbiki/modules/dynamiclist/DynamicListFragment.java
    com/qbiki/modules/epubreader/Decompress.java
    com/qbiki/modules/epubreader/ePubReaderFragment.java
    com/qbiki/modules/facebookfeeds/AppSignInWithFacebookFragment.java
    com/qbiki/modules/facebookfeeds/DownloadMediaFileAsyncTask.java
    com/qbiki/modules/facebookfeeds/FacebookFeedsUtils.java
    com/qbiki/modules/facebookfeeds/FeedsListFragment.java
    com/qbiki/modules/facebookfeeds/PostFeedFragment.java
    com/qbiki/modules/favorites/Favorites.java
    com/qbiki/modules/favorites/FavoritesFragment.java
    com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
    com/qbiki/modules/fusioncharts/FusionChartsFragment.java
    com/qbiki/modules/fusioncharts/GetChartDataAsyncTask.java
    com/qbiki/modules/gcmtopics/GCMTopicsFragment.java
    com/qbiki/modules/goaltracker/GoalTrackerCategories.java
    com/qbiki/modules/imagelist/ImageListFragment.java
    com/qbiki/modules/karaoke/KaraokeFragment.java
    com/qbiki/modules/locationlock/LocationLockFragment.java
    com/qbiki/modules/loyalty/LoyaltyFragment.java
    com/qbiki/modules/messenger/AppSignInFragment.java
    com/qbiki/modules/messenger/ConversationFragment.java
    com/qbiki/modules/messenger/MessengerFragment.java
    com/qbiki/modules/nativetetris/TetrisGame.java
    com/qbiki/modules/nativetetris/TetrisView.java
    com/qbiki/modules/nearbylocations/NearbyLocationFragment.java
    com/qbiki/modules/order/OrderFragment.java
    com/qbiki/modules/pdfeditorreader/PDFAudioFragment.java
    com/qbiki/modules/pdfeditorreader/PDFReaderEditorFragment.java
    com/qbiki/modules/pdfeditorreader/PDFVideoFragment.java
    com/qbiki/modules/pdfeditorreader/VideoViewFD.java
    com/qbiki/modules/pdfreader/PDFDocumentHelper.java
    com/qbiki/modules/pdfreader/PDFReaderFragment.java
    com/qbiki/modules/pdfviewer/PDFViewerFragment.java
    com/qbiki/modules/photoeffect/PhotoEffectFragment.java
    com/qbiki/modules/product/order/POContext.java
    com/qbiki/modules/quiz/QuizPrepareResourcesAsyncTask.java
    com/qbiki/modules/quiz/QuizSharedDataManager.java
    com/qbiki/modules/quizweb/QuizwebFragment.java
    com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
    com/qbiki/modules/rateandreview/RateAndReviewFragment.java
    com/qbiki/modules/rateandreview/RateAndReviewHandle.java
    com/qbiki/modules/rsspro/RssFeedsPullParser.java
    com/qbiki/modules/rsspro/RssFeedsSaxParser.java
    com/qbiki/modules/savephoto/SavePhotoActivity.java
    com/qbiki/modules/scandocument/ImageCropFragment.java
    com/qbiki/modules/scandocument/ScanDocumentFragment.java
    com/qbiki/modules/scoreboard/ScoreBoardFragment.java
    com/qbiki/modules/scoreboard/ScreenShotMaker.java
    com/qbiki/modules/scoreboard/SendEmailAsyncTask.java
    com/qbiki/modules/search/SearchFragment.java
    com/qbiki/modules/sharepoint/SPFileDetailView.java
    com/qbiki/modules/sharepoint/SPItemEditorView.java
    com/qbiki/modules/sharepoint/SPListViewAdapter.java
    com/qbiki/modules/sharepoint/SPParserXMLtoSOAPObject.java
    com/qbiki/modules/sharepoint/SPServer.java
    com/qbiki/modules/sharepoint/SPWeb.java
    com/qbiki/modules/sharepoint/SharePointFragment.java
    com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
    com/qbiki/modules/signaturestamp/SignatureStampFragment.java
    com/qbiki/modules/slideshow/SlideShowFragment.java
    com/qbiki/modules/slotmachine/SlotMachineFragment.java
    com/qbiki/modules/starbucks/CardStorageManager.java
    com/qbiki/modules/videolist/AsyncTaskParseResources.java
    com/qbiki/modules/videolist/DownloadFileAsyncTask.java
    com/qbiki/modules/videolist/VideoFilesListFragment.java
    com/qbiki/modules/videolist/VideoListXMLParser.java
    com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
    com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
    com/qbiki/paypal/PayPalProcessing.java
    com/qbiki/scapi/SCApi.java
    com/qbiki/scapi/SCApiRequestAsyncTask.java
    com/qbiki/seattleclouds/App.java
    com/qbiki/seattleclouds/AppConfigHandler.java
    com/qbiki/seattleclouds/AppStarterActivity.java
    com/qbiki/seattleclouds/SCDownloadHostedPageResourcesFragment.java
    com/qbiki/seattleclouds/WebViewFragment.java
    com/qbiki/seattleclouds/asynctasks/DownloadExternalResourcesAsyncTask.java
    com/qbiki/seattleclouds/asynctasks/InitResourcesAsyncTask.java
    com/qbiki/seattleclouds/asynctasks/ParseAppConfigAsyncTask.java
    com/qbiki/seattleclouds/asynctasks/SyncResourcesAsyncTask.java
    com/qbiki/seattleclouds/mosaic/MosaicFragment.java
    com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerAppViewFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
    com/qbiki/shoppingcart/ShoppingCart.java
    com/qbiki/util/CookieManager.java
    com/qbiki/util/DataUtil.java
    com/qbiki/util/FlushedInputStream.java
    com/qbiki/util/HTTPUtil.java
    com/qbiki/util/ImageUtil.java
    com/qbiki/util/InternalFileContentProvider.java
    com/qbiki/util/ResourceImageResizer.java
    com/qbiki/util/SCMediaPlayer.java
    com/qbiki/util/XmlPullUtil.java
    com/qbiki/util/YouTubeEmbedProcessor.java
    com/qbiki/util/ZipUtil.java
    com/qbiki/util/asyncrequester/AsynchronousSender.java
    com/qbiki/util/asyncrequester/Requester.java
    com/revmob/ads/banner/RevMobBanner.java
    com/revmob/ads/fullscreen/FullscreenActivity.java
    com/revmob/ads/internal/StaticAssets.java
    com/revmob/ads/popup/RevMobPopup.java
    com/revmob/android/FileCache.java
    com/revmob/android/RevMobContext.java
    com/revmob/android/StoredData.java
    com/revmob/internal/DownloadManager.java
    com/revmob/internal/HTTPHelper.java
    com/revmob/internal/RevMobEula.java
    com/revmob/internal/RevMobSoundPlayer.java
    net/sourceforge/zbar/android/ZBarScanner.java
    nl/siegmann/epublib/browsersupport/Navigator.java
    nl/siegmann/epublib/domain/Author.java
    nl/siegmann/epublib/domain/Book.java
    nl/siegmann/epublib/domain/Date.java
    nl/siegmann/epublib/domain/Guide.java
    nl/siegmann/epublib/domain/GuideReference.java
    nl/siegmann/epublib/domain/Identifier.java
    nl/siegmann/epublib/domain/MediaType.java
    nl/siegmann/epublib/domain/Metadata.java
    nl/siegmann/epublib/domain/Resource.java
    nl/siegmann/epublib/domain/ResourceReference.java
    nl/siegmann/epublib/domain/Resources.java
    nl/siegmann/epublib/domain/Spine.java
    nl/siegmann/epublib/domain/SpineReference.java
    nl/siegmann/epublib/domain/TOCReference.java
    nl/siegmann/epublib/domain/TableOfContents.java
    nl/siegmann/epublib/domain/TitledResourceReference.java
    nl/siegmann/epublib/epub/EpubProcessorSupport.java
    nl/siegmann/epublib/epub/EpubReader.java
    nl/siegmann/epublib/epub/EpubWriter.java
    nl/siegmann/epublib/epub/HtmlProcessor.java
    nl/siegmann/epublib/epub/NCXDocument.java
    nl/siegmann/epublib/epub/PackageDocumentMetadataWriter.java
    nl/siegmann/epublib/epub/PackageDocumentReader.java
    nl/siegmann/epublib/epub/PackageDocumentWriter.java
    nl/siegmann/epublib/util/IOUtil.java
    nl/siegmann/epublib/util/NoCloseOutputStream.java
    nl/siegmann/epublib/util/NoCloseWriter.java
    nl/siegmann/epublib/util/ResourceUtil.java
    nl/siegmann/epublib/util/commons/io/BOMInputStream.java
    nl/siegmann/epublib/util/commons/io/ByteOrderMark.java
    nl/siegmann/epublib/util/commons/io/ProxyInputStream.java
    nl/siegmann/epublib/util/commons/io/XmlStreamReader.java
    nl/siegmann/epublib/util/commons/io/XmlStreamReaderException.java
    org/jsoup/Connection.java
    org/jsoup/Jsoup.java
    org/jsoup/examples/ListLinks.java
    org/jsoup/helper/DataUtil.java
    org/jsoup/helper/HttpConnection.java
    org/kobjects/base64/Base64.java
    org/kobjects/crypt/Crypt.java
    org/kobjects/io/BoundInputStream.java
    org/kobjects/io/LookAheadReader.java
    org/kobjects/mime/Decoder.java
    org/kobjects/pim/PimParser.java
    org/kobjects/pim/PimWriter.java
    org/kobjects/rss/RssReader.java
    org/kobjects/util/Util.java
    org/kobjects/xml/XmlReader.java
    org/kobjects/xmlrpc/Driver.java
    org/kobjects/xmlrpc/XmlRpcParser.java
    org/ksoap2/SoapEnvelope.java
    org/ksoap2/SoapFault.java
    org/ksoap2/SoapFault12.java
    org/ksoap2/serialization/DM.java
    org/ksoap2/serialization/Marshal.java
    org/ksoap2/serialization/MarshalBase64.java
    org/ksoap2/serialization/MarshalDate.java
    org/ksoap2/serialization/MarshalFloat.java
    org/ksoap2/serialization/MarshalHashtable.java
    org/ksoap2/serialization/PropertyInfo.java
    org/ksoap2/serialization/SoapSerializationEnvelope.java
    org/ksoap2/transport/HttpTransportSE.java
    org/ksoap2/transport/HttpsServiceConnectionSE.java
    org/ksoap2/transport/HttpsServiceConnectionSEIgnoringConnectionClose.java
    org/ksoap2/transport/HttpsTransportSE.java
    org/ksoap2/transport/KeepAliveHttpTransportSE.java
    org/ksoap2/transport/KeepAliveHttpsTransportSE.java
    org/ksoap2/transport/ServiceConnection.java
    org/ksoap2/transport/ServiceConnectionSE.java
    org/ksoap2/transport/Transport.java
    org/kxml2/io/KXmlParser.java
    org/kxml2/io/KXmlSerializer.java
    org/kxml2/kdom/Document.java
    org/kxml2/kdom/Element.java
    org/kxml2/kdom/Node.java
    org/kxml2/wap/WbxmlParser.java
    org/kxml2/wap/WbxmlSerializer.java
    org/kxml2/wap/wv/WV.java
    pdftron/FDF/FDFDoc.java
    pdftron/PDF/PDFDoc.java
    pdftron/PDF/PDFNet.java
    pdftron/PDF/Tools/Pan.java
    pdftron/PDF/Tools/b.java
    pdftron/PDF/Tools/r.java
    pdftron/SDF/SDFDoc.java
    网络通信-> DefaultHttpClient Connection
    组件-> 发送广播
    一般功能-> IPC通信
    com/actionbarsherlock/internal/view/menu/ActionMenu.java
    com/actionbarsherlock/internal/view/menu/ActionMenuItem.java
    com/actionbarsherlock/internal/view/menu/MenuBuilder.java
    com/actionbarsherlock/internal/view/menu/MenuItemImpl.java
    com/actionbarsherlock/internal/view/menu/MenuItemWrapper.java
    com/actionbarsherlock/internal/view/menu/MenuWrapper.java
    com/actionbarsherlock/view/Menu.java
    com/actionbarsherlock/view/MenuItem.java
    com/actionbarsherlock/widget/ActivityChooserModel.java
    com/actionbarsherlock/widget/ActivityChooserView.java
    com/actionbarsherlock/widget/SearchView.java
    com/actionbarsherlock/widget/ShareActionProvider.java
    com/amazon/android/Kiwi.java
    com/amazon/android/f/a.java
    com/amazon/android/f/b.java
    com/amazon/android/f/c.java
    com/amazon/android/f/f.java
    com/amazon/android/framework/context/b.java
    com/amazon/android/framework/context/d.java
    com/amazon/android/framework/prompt/e.java
    com/amazon/android/framework/prompt/g.java
    com/amazon/android/framework/task/command/AbstractCommandTask.java
    com/amazon/android/framework/task/command/c.java
    com/amazon/android/framework/task/command/j.java
    com/amazon/android/framework/task/command/n.java
    com/amazon/venezia/command/Choice.java
    com/amazon/venezia/command/ChoiceContext.java
    com/amazon/venezia/command/Command.java
    com/amazon/venezia/command/CommandService.java
    com/amazon/venezia/command/DecisionExpirationContext.java
    com/amazon/venezia/command/DecisionResult.java
    com/amazon/venezia/command/ExceptionResult.java
    com/amazon/venezia/command/FailureResult.java
    com/amazon/venezia/command/ResultCallback.java
    com/amazon/venezia/command/SuccessResult.java
    com/amazon/venezia/command/a.java
    com/amazon/venezia/command/aa.java
    com/amazon/venezia/command/ab.java
    com/amazon/venezia/command/c.java
    com/amazon/venezia/command/d.java
    com/amazon/venezia/command/k.java
    com/amazon/venezia/command/l.java
    com/amazon/venezia/command/m.java
    com/amazon/venezia/command/n.java
    com/amazon/venezia/command/o.java
    com/amazon/venezia/command/p.java
    com/amazon/venezia/command/q.java
    com/amazon/venezia/command/t.java
    com/amazon/venezia/command/u.java
    com/amazon/venezia/command/v.java
    com/amazon/venezia/command/x.java
    com/amazon/venezia/command/z.java
    com/amazon/venezia/service/verify/IApplicationVerificationService.java
    com/pollfish/d/a.java
    com/qbiki/ads/AdManager.java
    com/qbiki/ads/SCAdView.java
    com/qbiki/c2dm/AnnouncementActivity.java
    com/qbiki/feedback/FeedbackFragment.java
    com/qbiki/gcm/GCMBroadcastReceiver.java
    com/qbiki/geofencing/GeofenceManager.java
    com/qbiki/geofencing/GeofenceRemover.java
    com/qbiki/geofencing/GeofenceRequester.java
    com/qbiki/geofencing/ReceiveTransitionsIntentService.java
    com/qbiki/location/LocationDetectorActivity.java
    com/qbiki/location/LocationDetectorFragment.java
    com/qbiki/modules/appshare/AppShare.java
    com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
    com/qbiki/modules/calendar/CalendarFragment.java
    com/qbiki/modules/calendar/EventEditActivity.java
    com/qbiki/modules/cameracover/CameraCoverFrgament.java
    com/qbiki/modules/cameracover/CoverCamera.java
    com/qbiki/modules/cameracover/CoversPreviewFragment.java
    com/qbiki/modules/coupon/CouponFragment.java
    com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
    com/qbiki/modules/dynamiclist/DynamicListFragment.java
    com/qbiki/modules/facebookfeeds/AppSignInWithFacebookFragment.java
    com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
    com/qbiki/modules/facebookfeeds/FeedsListFragment.java
    com/qbiki/modules/facebookfeeds/PostFeedFragment.java
    com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
    com/qbiki/modules/goaltracker/GoalTrackerAlarmReceiver.java
    com/qbiki/modules/imagelist/ImageListFragment.java
    com/qbiki/modules/locationlock/AutoFinishPageFragmentActivity.java
    com/qbiki/modules/locationlock/LocationLockFragment.java
    com/qbiki/modules/login/LoginFragment.java
    com/qbiki/modules/messenger/AppSignInFragment.java
    com/qbiki/modules/messenger/ConversationFragment.java
    com/qbiki/modules/messenger/MessengerFragment.java
    com/qbiki/modules/messenger/MessengerNotifications.java
    com/qbiki/modules/notes/NotePagerFragment.java
    com/qbiki/modules/order/OrderFragment.java
    com/qbiki/modules/order/OrderPaypalActivity.java
    com/qbiki/modules/pdfeditorreader/VideoViewFD.java
    com/qbiki/modules/phonegap/PhoneGapActivity.java
    com/qbiki/modules/photoeffect/PhotoEffectFragment.java
    com/qbiki/modules/quiz/QuizRootFragment.java
    com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
    com/qbiki/modules/rateandreview/RateAndReviewFragment.java
    com/qbiki/modules/rateandreview/RateAndReviewHandle.java
    com/qbiki/modules/savephoto/SavePhotoActivity.java
    com/qbiki/modules/scandocument/ScanDocumentFragment.java
    com/qbiki/modules/scoreboard/ScoreBoardFragment.java
    com/qbiki/modules/search/SearchActivity.java
    com/qbiki/modules/sharepoint/SPItemEditorFragment.java
    com/qbiki/modules/sharepoint/SPItemEditorView.java
    com/qbiki/modules/sharepoint/SharePointFragment.java
    com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
    com/qbiki/modules/signaturestamp/SignatureStampFragment.java
    com/qbiki/modules/starbucks/AddCardActivity.java
    com/qbiki/modules/starbucks/CardsListActivity.java
    com/qbiki/modules/starbucks/ViewCardActivity.java
    com/qbiki/modules/videolist/DownloadService.java
    com/qbiki/modules/videolist/VideoFilesListFragment.java
    com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
    com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
    com/qbiki/paypal/PayPalMessage.java
    com/qbiki/paypal/PayPalProcessing.java
    com/qbiki/seattleclouds/ActionBarTabsAppActivity.java
    com/qbiki/seattleclouds/App.java
    com/qbiki/seattleclouds/AppStarterActivity.java
    com/qbiki/seattleclouds/BaseAppActivity.java
    com/qbiki/seattleclouds/EmptyActivity.java
    com/qbiki/seattleclouds/ExpansionFilesDownloaderAlarmReceiver.java
    com/qbiki/seattleclouds/LegacyTabsAppActivity.java
    com/qbiki/seattleclouds/NestedFragmentCompat.java
    com/qbiki/seattleclouds/SCFragment.java
    com/qbiki/seattleclouds/SCFragmentActivity.java
    com/qbiki/seattleclouds/SCFragmentHelper.java
    com/qbiki/seattleclouds/SCListFragment.java
    com/qbiki/seattleclouds/SCMapFragment.java
    com/qbiki/seattleclouds/SCPageFragmentActivity.java
    com/qbiki/seattleclouds/SCTabsAppActivity.java
    com/qbiki/seattleclouds/SimpleAppActivity.java
    com/qbiki/seattleclouds/WebViewFragment.java
    com/qbiki/seattleclouds/mosaic/MosaicFragment.java
    com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerAboutActivity.java
    com/qbiki/seattleclouds/previewer/PreviewerActivity.java
    com/qbiki/seattleclouds/previewer/PreviewerAppViewActivity.java
    com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
    com/qbiki/util/IntentUtil.java
    com/revmob/ads/fullscreen/FullscreenActivity.java
    com/revmob/ads/fullscreen/RevMobFullscreen.java
    com/revmob/internal/AndroidHelper.java
    com/revmob/internal/MarketAsyncManager.java
    net/sourceforge/zbar/android/ZBarScanner.java
    pdftron/PDF/Annots/FreeText.java
    pdftron/PDF/Annots/Line.java
    pdftron/PDF/Annots/PolyLine.java
    pdftron/PDF/Element.java
    pdftron/PDF/GState.java
    pdftron/PDF/Image.java
    pdftron/PDF/OCG/Config.java
    pdftron/PDF/OCG/Group.java
    pdftron/PDF/Tools/k.java
    pdftron/PDF/Tools/n.java
    组件-> 启动 Activity
    com/actionbarsherlock/internal/view/menu/ActionMenuItem.java
    com/actionbarsherlock/internal/view/menu/MenuItemImpl.java
    com/actionbarsherlock/widget/ActivityChooserView.java
    com/actionbarsherlock/widget/SearchView.java
    com/actionbarsherlock/widget/ShareActionProvider.java
    com/amazon/android/f/a.java
    com/amazon/android/framework/context/d.java
    com/amazon/android/framework/prompt/g.java
    com/pollfish/d/a.java
    com/qbiki/ads/SCAdView.java
    com/qbiki/c2dm/AnnouncementActivity.java
    com/qbiki/feedback/FeedbackFragment.java
    com/qbiki/modules/appshare/AppShare.java
    com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
    com/qbiki/modules/calendar/CalendarFragment.java
    com/qbiki/modules/calendar/EventEditActivity.java
    com/qbiki/modules/cameracover/CameraCoverFrgament.java
    com/qbiki/modules/cameracover/CoversPreviewFragment.java
    com/qbiki/modules/coupon/CouponFragment.java
    com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
    com/qbiki/modules/dynamiclist/DynamicListFragment.java
    com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
    com/qbiki/modules/facebookfeeds/FeedsListFragment.java
    com/qbiki/modules/facebookfeeds/PostFeedFragment.java
    com/qbiki/modules/imagelist/ImageListFragment.java
    com/qbiki/modules/locationlock/LocationLockFragment.java
    com/qbiki/modules/login/LoginFragment.java
    com/qbiki/modules/messenger/AppSignInFragment.java
    com/qbiki/modules/messenger/ConversationFragment.java
    com/qbiki/modules/messenger/MessengerFragment.java
    com/qbiki/modules/notes/NotePagerFragment.java
    com/qbiki/modules/order/OrderFragment.java
    com/qbiki/modules/photoeffect/PhotoEffectFragment.java
    com/qbiki/modules/quiz/QuizRootFragment.java
    com/qbiki/modules/rateandreview/RateAndReviewFragment.java
    com/qbiki/modules/rateandreview/RateAndReviewHandle.java
    com/qbiki/modules/savephoto/SavePhotoActivity.java
    com/qbiki/modules/scandocument/ScanDocumentFragment.java
    com/qbiki/modules/scoreboard/ScoreBoardFragment.java
    com/qbiki/modules/sharepoint/SPItemEditorView.java
    com/qbiki/modules/sharepoint/SharePointFragment.java
    com/qbiki/modules/signaturestamp/SignatureStampFragment.java
    com/qbiki/modules/starbucks/CardsListActivity.java
    com/qbiki/modules/videolist/VideoFilesListFragment.java
    com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
    com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
    com/qbiki/paypal/PayPalMessage.java
    com/qbiki/paypal/PayPalProcessing.java
    com/qbiki/seattleclouds/App.java
    com/qbiki/seattleclouds/AppStarterActivity.java
    com/qbiki/seattleclouds/BaseAppActivity.java
    com/qbiki/seattleclouds/SCFragment.java
    com/qbiki/seattleclouds/SCFragmentHelper.java
    com/qbiki/seattleclouds/SCListFragment.java
    com/qbiki/seattleclouds/SCMapFragment.java
    com/qbiki/seattleclouds/WebViewFragment.java
    com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerActivity.java
    com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
    com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
    com/qbiki/util/IntentUtil.java
    com/revmob/ads/fullscreen/RevMobFullscreen.java
    com/revmob/internal/MarketAsyncManager.java
    net/sourceforge/zbar/android/ZBarScanner.java
    pdftron/PDF/Tools/k.java
    pdftron/PDF/Tools/n.java
    一般功能-> 获取系统服务(getSystemService)
    com/actionbarsherlock/internal/widget/IcsProgressBar.java
    com/actionbarsherlock/widget/SearchView.java
    com/actionbarsherlock/widget/SuggestionsAdapter.java
    com/amazon/android/c/b.java
    com/amazon/android/framework/prompt/e.java
    com/pollfish/f/c.java
    com/pollfish/g/a.java
    com/qbiki/analytics/SCAnalyticsTracker.java
    com/qbiki/c2dm/AnnouncementActivity.java
    com/qbiki/feedback/DatePicker.java
    com/qbiki/feedback/PickerView.java
    com/qbiki/feedback/TimePicker.java
    com/qbiki/gcm/GCMBroadcastReceiver.java
    com/qbiki/geofencing/ReceiveTransitionsIntentService.java
    com/qbiki/location/LocationDetectorFragment.java
    com/qbiki/location/SimpleLocationManager.java
    com/qbiki/modules/bmicalculator/BmiCalculatorFragment.java
    com/qbiki/modules/dropbox/medialist/ListItemViews.java
    com/qbiki/modules/dynamiclist/DynamicListFragment.java
    com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
    com/qbiki/modules/facebookfeeds/FeedsListFragment.java
    com/qbiki/modules/facebookfeeds/PostFeedFragment.java
    com/qbiki/modules/gcmtopics/GCMTopicsFragment.java
    com/qbiki/modules/goaltracker/GoalTrackerAlarmReceiver.java
    com/qbiki/modules/login/SCForgotPasswordFragment.java
    com/qbiki/modules/messenger/MessengerNotifications.java
    com/qbiki/modules/nearbylocations/NearbyLocationFragment.java
    com/qbiki/modules/notes/NoteFragment.java
    com/qbiki/modules/pdfreader/PDFDocumentHelper.java
    com/qbiki/modules/quiz/QuizHighscoresFragement.java
    com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
    com/qbiki/modules/rateandreview/RateAndReviewFragment.java
    com/qbiki/modules/scoreboard/AppsUsedToShareListAdapter.java
    com/qbiki/modules/scoreboard/RowView.java
    com/qbiki/modules/search/SearchFragment.java
    com/qbiki/modules/videolist/ListItemViews.java
    com/qbiki/scapi/SCApiRequestAsyncTask.java
    com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
    com/qbiki/util/ConnectionUtil.java
    com/qbiki/util/DeviceUtil.java
    com/qbiki/util/DialogUtil.java
    com/qbiki/util/SCMediaPlayer.java
    com/qbiki/util/WebViewUtil.java
    com/revmob/ads/fullscreen/FullscreenActivity.java
    kankan/wheel/widget/adapters/AbstractWheelTextAdapter.java
    pdftron/PDF/Tools/Pan.java
    pdftron/PDF/Tools/b.java
    pdftron/PDF/Tools/k.java
    pdftron/PDF/Tools/p.java
    pdftron/PDF/Tools/t.java
    一般功能-> 获取活动网路信息
    一般功能-> 加载so文件
    隐私数据-> 拍照摄像 com/qbiki/modules/cameracover/CoverCamera.java
    net/sourceforge/zbar/android/CameraPreview.java
    net/sourceforge/zbar/android/ZBarScanner.java
    一般功能-> 获取Android广告ID com/pollfish/c/a.java
    com/revmob/android/RevMobContext.java
    DEX-> 动态加载
    网络通信-> WebView JavaScript接口
    网络通信-> WebView GET请求
    JavaScript 接口方法 com/pollfish/g/a.java
    com/qbiki/modules/karaoke/KaraokeFragment.java
    com/qbiki/modules/starbucks/ViewCardActivity.java
    网络通信-> WebView使用File协议 com/pollfish/g/a.java
    com/qbiki/util/WebViewUtil.java
    网络通信-> WebView 相关
    隐私数据-> 获取已安装的应用程序
    网络通信-> HTTP请求、连接和会话 com/qbiki/util/asyncrequester/AsynchronousSender.java
    com/revmob/internal/HTTPHelper.java
    com/revmob/internal/MarketRedirector.java
    网络通信-> TCP套接字
    加密解密-> Base64 加密
    隐私数据-> 获取GPS位置信息
    加密解密-> 信息摘要算法
    网络通信-> HTTP建立连接
    网络通信-> WebView POST请求 com/revmob/internal/MarketAsyncManager.java
    进程操作-> 杀死进程 com/amazon/android/framework/prompt/e.java
    com/revmob/internal/RevMobEula.java
    调用java反射机制
    隐私数据-> 剪贴板数据读写操作 pdftron/PDF/Tools/b.java
    pdftron/PDF/Tools/t.java
    隐私数据-> 屏幕截图,截取自己应用内部界面 pdftron/PDF/PDFViewCtrl.java
    pdftron/PDF/Tools/t.java
    组件-> 启动 Service com/amazon/android/framework/task/command/c.java
    com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
    com/qbiki/modules/videolist/VideoFilesListFragment.java
    加密解密-> Base64 解密
    隐私数据-> 录制视频 com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
    网络通信-> URLConnection
    组件-> ContentProvider com/qbiki/util/InternalFileContentProvider.java
    组件-> Provider openFile com/qbiki/util/InternalFileContentProvider.java
    网络通信-> SSL证书处理 com/revmob/internal/HTTPHelper.java
    org/ksoap2/transport/HttpsServiceConnectionSE.java
    网络通信-> HTTPS建立连接 org/ksoap2/transport/HttpsServiceConnectionSE.java
    设备指纹-> getSimOperator com/amazon/android/framework/prompt/e.java
    加密解密-> Crypto加解密组件 com/amazon/android/l/a.java
    com/pollfish/b/a.java
    com/pollfish/f/c.java
    一般功能-> 获取WiFi相关信息 com/pollfish/f/c.java
    辅助功能accessibility相关 com/actionbarsherlock/widget/SearchView.java
    一般功能-> Android通知
    一般功能-> 传感器相关操作 com/revmob/ads/fullscreen/FullscreenActivity.java

    安全漏洞检测

    高危
    3
    警告
    8
    信息
    1
    安全
    1
    屏蔽
    0
    序号 问题 等级 参考标准 文件位置 操作
    1 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
    OWASP MASVS: MSTG-STORAGE-3
    升级会员:解锁高级权限
    2 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 警告 CWE: CWE-312: 明文存储敏感信息
    OWASP Top 10: M9: Reverse Engineering
    OWASP MASVS: MSTG-STORAGE-14
    升级会员:解锁高级权限
    3 不安全的Web视图实现。可能存在WebView任意代码执行漏洞 警告 CWE: CWE-749: 暴露危险方法或函数
    OWASP Top 10: M1: Improper Platform Usage
    OWASP MASVS: MSTG-PLATFORM-7
    升级会员:解锁高级权限
    4 WebView域控制不严格漏洞 高危 CWE: CWE-73: 外部控制文件名或路径 升级会员:解锁高级权限
    5 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
    OWASP Top 10: M2: Insecure Data Storage
    OWASP MASVS: MSTG-STORAGE-2
    升级会员:解锁高级权限
    6 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击 高危 CWE: CWE-79: 在Web页面生成时对输入的转义处理不恰当('跨站脚本')
    OWASP Top 10: M1: Improper Platform Usage
    OWASP MASVS: MSTG-PLATFORM-6
    升级会员:解锁高级权限
    7 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
    OWASP Top 10: M5: Insufficient Cryptography
    OWASP MASVS: MSTG-CRYPTO-6
    升级会员:解锁高级权限
    8 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
    OWASP Top 10: M5: Insufficient Cryptography
    OWASP MASVS: MSTG-CRYPTO-4
    升级会员:解锁高级权限
    9 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 警告 CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
    OWASP Top 10: M7: Client Code Quality
    升级会员:解锁高级权限
    10 IP地址泄露 警告 CWE: CWE-200: 信息泄露
    OWASP MASVS: MSTG-CODE-2
    升级会员:解锁高级权限
    11 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
    OWASP Top 10: M3: Insecure Communication
    OWASP MASVS: MSTG-NETWORK-3
    升级会员:解锁高级权限
    12 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
    OWASP Top 10: M5: Insufficient Cryptography
    OWASP MASVS: MSTG-CRYPTO-4
    升级会员:解锁高级权限
    13 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 安全
    OWASP MASVS: MSTG-NETWORK-4
    升级会员:解锁高级权限

    Native库安全分析

    No Shared Objects found.
    序号 动态库 NX(堆栈禁止执行) PIE STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)

    文件分析

    序号 问题 文件

    敏感权限分析

    恶意软件常用权限 1/30
    android.permission.GET_ACCOUNTS
    其它常用权限 4/46
    android.permission.INTERNET
    android.permission.WRITE_EXTERNAL_STORAGE
    android.permission.ACCESS_NETWORK_STATE
    com.google.android.c2dm.permission.RECEIVE

    恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
    其它常用权限 是已知恶意软件经常滥用的权限。

    IP地理位置

    恶意域名检测

    域名 状态 中国境内 位置信息 解析
    www.google-analytics.com 安全
    IP地址: 180.163.151.33
    国家: China
    地区: Shanghai
    城市: Shanghai
    查看: 高德地图

    example.com 安全
    IP地址: 93.184.216.34
    国家: United States of America
    地区: Virginia
    城市: Ashburn
    查看: Google 地图

    lbdb.pollfish.com 安全
    IP地址: 173.255.115.49
    国家: United States of America
    地区: Iowa
    城市: Council Bluffs
    查看: Google 地图

    www.wireless-village.org 安全
    IP地址: 104.21.11.240
    国家: United States of America
    地区: California
    城市: San Francisco
    查看: Google 地图

    media.admob.com 安全
    IP地址: 142.250.141.100
    国家: United States of America
    地区: California
    城市: Mountain View
    查看: Google 地图

    s.ytimg.com 安全
    IP地址: 142.250.68.78
    国家: United States of America
    地区: California
    城市: Mountain View
    查看: Google 地图

    purl.org 安全
    IP地址: 207.241.239.241
    国家: United States of America
    地区: California
    城市: San Francisco
    查看: Google 地图

    schemas.xmlsoap.org 安全
    IP地址: 13.107.213.71
    国家: United States of America
    地区: Washington
    城市: Redmond
    查看: Google 地图

    www.amazon.com 安全
    IP地址: 13.225.150.180
    国家: United States of America
    地区: California
    城市: Los Angeles
    查看: Google 地图

    wss.pollfish.com 安全
    IP地址: 34.69.135.100
    国家: United States of America
    地区: Iowa
    城市: Council Bluffs
    查看: Google 地图

    market.android.com 安全
    IP地址: 142.250.68.78
    国家: United States of America
    地区: California
    城市: Mountain View
    查看: Google 地图

    www.onbarcode.com 安全
    IP地址: 47.90.243.155
    国家: United States of America
    地区: California
    城市: San Mateo
    查看: Google 地图

    www.googletagmanager.com 安全
    IP地址: 180.163.150.41
    国家: China
    地区: Shanghai
    城市: Shanghai
    查看: 高德地图

    ssl.google-analytics.com 安全
    IP地址: 180.163.150.169
    国家: China
    地区: Shanghai
    城市: Shanghai
    查看: 高德地图

    www.starbucks.com 安全
    IP地址: 23.222.168.30
    国家: United States of America
    地区: California
    城市: El Segundo
    查看: Google 地图

    www.daisy.org 安全
    IP地址: 65.52.139.180
    国家: Netherlands
    地区: Noord-Holland
    城市: Amsterdam
    查看: Google 地图

    schemas.microsoft.com 安全
    IP地址: 13.105.221.22
    国家: United States of America
    地区: Washington
    城市: Redmond
    查看: Google 地图

    www.upcdatabase.org 安全
    IP地址: 104.21.64.53
    国家: United States of America
    地区: California
    城市: San Francisco
    查看: Google 地图

    android.revmob.com 安全
    没有可用的地理位置信息。
    i.ytimg.com 安全
    IP地址: 142.250.217.150
    国家: United States of America
    地区: California
    城市: Mountain View
    查看: Google 地图

    googleads.g.doubleclick.net 安全
    IP地址: 180.163.150.38
    国家: China
    地区: Shanghai
    城市: Shanghai
    查看: 高德地图

    www.openmobilealliance.org 安全
    IP地址: 104.26.8.105
    国家: United States of America
    地区: California
    城市: San Francisco
    查看: Google 地图

    revmob.com 安全
    没有可用的地理位置信息。
    www.idpf.org 安全
    IP地址: 217.70.184.56
    国家: France
    地区: Ile-de-France
    城市: Paris
    查看: Google 地图

    goo.gl 安全
    IP地址: 142.250.176.14
    国家: United States of America
    地区: California
    城市: Mountain View
    查看: Google 地图

    s3.amazonaws.com 安全
    IP地址: 52.217.224.112
    国家: United States of America
    地区: Virginia
    城市: Ashburn
    查看: Google 地图

    www.wapforum.org 安全
    IP地址: 172.67.190.29
    国家: United States of America
    地区: California
    城市: San Francisco
    查看: Google 地图

    手机号提取

    URL链接分析

    URL信息 源码文件
    http://www.opensource.org/licenses/mit-license.php
    http://bassistance.de/jquery-plugins/jquery-plugin-validation/
    http://www.wapforum.org/DTD/xhtml-mobile10.dtd
    http://www.apple.com/DTDs/PropertyList-1.0.dtd
    http://projects.scottsplayground.com/iri/
    http://sizzlejs.com/
    http://jquery.org/license
    http://projects.scottsplayground.com/email_address_validation/
    http://www.gnu.org/licenses/gpl.html
    自研引擎分析结果
    https://www.amazon.com/appstore-error-help
    com/amazon/android/framework/prompt/e.java
    http://www.onbarcode.com
    http://www.onbarcode.com/products/android_barcode/
    com/onbarcode/barcode/android/LicenseInformation.java
    https://developer.android.com/google/play-services/setup.html#ensure
    com/pollfish/c/a.java
    http://lbdb.pollfish.com:3000/notifier_api/v2/notices
    http://lbdb.pollfish.com:3000
    com/pollfish/f/b/a.java
    javascript:pollfish.nativeaccess.losefocus(true
    com/pollfish/g/a.java
    https://wss.pollfish.com
    com/pollfish/main/PollFish.java
    data:image/jpg;base64
    com/qbiki/feedback/FieldProcessing.java
    http://www.upcdatabase.org/api/xml/30a634c9cad463a5e5d5c7afb2496ff2/
    com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
    https://graph.facebook.com/%1$s?fields=name,picture&accesstoken=%2$s
    https://graph.facebook.com/%1$s/likes?limit=0&summary=1&accesstoken=%2$s
    https://graph.facebook.com/%1$s/comments?limit=0&summary=1&accesstoken=%2$s
    com/qbiki/modules/facebookfeeds/FeedsListFragment.java
    data:image/png;base64
    javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
    javascript:document.getelementbyid('
    com/qbiki/modules/favorites/Favorites.java
    http://graph.facebook.com/
    com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
    javascript:karaokejsinterface.linetimesparsed(getlinetimes
    com/qbiki/modules/karaoke/KaraokeFragment.java
    http://www.wapforum.org/dtd/xhtml-mobile10.dtd
    com/qbiki/modules/sharepoint/SPListViewAdapter.java
    http://schemas.microsoft.com/sharepoint/soap/getlistcollection
    http://schemas.microsoft.com/sharepoint/soap/getlistitems
    http://schemas.microsoft.com/sharepoint/soap/getlistandview
    http://schemas.microsoft.com/sharepoint/soap/getwebcollection
    http://schemas.microsoft.com/sharepoint/soap/updatelistitems
    http://schemas.microsoft.com/sharepoint/soap/getitem
    http://schemas.microsoft.com/sharepoint/soap/copyintoitems
    http://schemas.microsoft.com/sharepoint/soap/
    com/qbiki/modules/sharepoint/SPServer.java
    javascript:window.htmlout.showhtml(document.getelementbyid('fetch_balance').getelementsbytagname('span'
    https://www.starbucks.com/card
    com/qbiki/modules/starbucks/ViewCardActivity.java
    http://market.android.com/details?id=
    com/qbiki/seattleclouds/AppStarterActivity.java
    http://s.ytimg.com/yt/m/cssbin/mobile-blazer-sprite
    http://s.ytimg.com/yt/m/cssbin/mobile-swatch-sprite
    http://s.ytimg.com/yt/cssbin/mobile-swatch-sprite
    http://s.ytimg.com/yts/imgbin/mobile-nightshade
    http://i.ytimg.com/vi/
    javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
    javascript:document.getelementbyid('
    com/qbiki/seattleclouds/WebViewFragment.java
    javascript:document.getelementbyid
    com/qbiki/shoppingcart/ShoppingCart.java
    http://revmob.com
    com/revmob/client/InstallClientListener.java
    https://android.revmob.com
    http://revmob.com
    com/revmob/client/RevMobClient.java
    https://s3.amazonaws.com/www.revmob.com/revmob_i_agree_terms.txt
    com/revmob/internal/HTTPHelper.java
    http://www.daisy.org/z3986/2005/ncx/
    nl/siegmann/epublib/epub/NCXDocument.java
    http://purl.org/dc/elements/1.1/
    http://www.idpf.org/2007/opf
    nl/siegmann/epublib/epub/PackageDocumentBase.java
    http://schemas.xmlsoap.org/soap/encoding/
    http://schemas.xmlsoap.org/soap/envelope/
    org/ksoap2/SoapEnvelope.java
    http://www.wireless-village.org/csp
    http://www.wireless-village.org/pa
    http://www.wireless-village.org/trc
    http://www.openmobilealliance.org/dtd/wv-csp
    http://www.openmobilealliance.org/dtd/wv-pa
    http://www.openmobilealliance.org/dtd/wv-trc
    www.wireless-village.org
    org/kxml2/wap/wv/WV.java
    https://graph.facebook.com/%1$s/comments?limit=0&summary=1&accesstoken=%2$s
    javascript:cordova.firedocumentevent('backbutton'
    http://lbdb.pollfish.com:3000/notifier_api/v2/notices
    https://www.googletagmanager.com
    127.0.0.1
    http://www.wireless-village.org/csp
    https://s3.amazonaws.com/www.revmob.com/revmob_i_agree_terms.txt
    javascript:document.getelementbyid('
    javascript:cordova.firedocumentevent('searchbutton'
    http://www.idpf.org/2007/opf
    http://schemas.microsoft.com/sharepoint/soap/
    http://market.android.com/details?id=
    http://goo.gl/nafqqk
    http://schemas.microsoft.com/sharepoint/soap/getitem
    javascript:karaokejsinterface.linetimesparsed(getlinetimes
    javascript:cordova.firedocumentevent('volumeupbutton'
    http://schemas.microsoft.com/sharepoint/soap/updatelistitems
    http://www.daisy.org/z3986/2005/ncx/
    http://www.onbarcode.com
    http://www.wireless-village.org/pa
    https://graph.facebook.com/%1$s?fields=name,picture&accesstoken=%2$s
    www.wireless-village.org
    http://www.onbarcode.com/products/android_barcode/
    http://schemas.xmlsoap.org/soap/encoding/
    javascript:cordova.firedocumentevent('volumedownbutton'
    https://www.amazon.com/appstore-error-help
    http://revmob.com
    http://hostname/?
    https://graph.facebook.com/
    http://schemas.microsoft.com/sharepoint/soap/copyintoitems
    http://schemas.xmlsoap.org/soap/envelope/
    http://www.wapforum.org/dtd/xhtml-mobile10.dtd
    http://schemas.microsoft.com/sharepoint/soap/getwebcollection
    data:image/jpg;base64
    javascript:try{cordova.firedocumentevent('pause');}catch(e){console.log('exception
    http://schemas.microsoft.com/sharepoint/soap/getlistandview
    http://i.ytimg.com/vi/
    javascript:cordova.firedocumentevent('menubutton'
    javascript:window.htmlout.showhtml(document.getelementbyid('fetch_balance').getelementsbytagname('span'
    javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
    javascript:try{cordova.firedocumentevent('resume');}catch(e){console.log('exception
    http://s.ytimg.com/yts/imgbin/mobile-nightshade
    http://lbdb.pollfish.com:3000
    javascript:pollfish.nativeaccess.losefocus(true
    http://s.ytimg.com/yt/m/cssbin/mobile-swatch-sprite
    http://schemas.microsoft.com/sharepoint/soap/getlistcollection
    http://purl.org/dc/elements/1.1/
    javascript:afma_receivemessage('
    https://developer.android.com/google/play-services/setup.html#ensure
    http://plus.google.com/
    http://schemas.microsoft.com/sharepoint/soap/getlistitems
    javascript:document.getelementbyid
    https://www.starbucks.com/card
    http://www.openmobilealliance.org/dtd/wv-trc
    http://cdv_exec/
    javascript:try{cordova.require('cordova/channel').ondestroy.fire();}catch(e){console.log('exception
    http://www.openmobilealliance.org/dtd/wv-csp
    http://www.openmobilealliance.org/dtd/wv-pa
    http://graph.facebook.com/
    http://s.ytimg.com/yt/m/cssbin/mobile-blazer-sprite
    data:image/png;base64
    http://s.ytimg.com/yt/cssbin/mobile-swatch-sprite
    https://api.facebook.com/restserver.php
    https://graph.facebook.com/%1$s/likes?limit=0&summary=1&accesstoken=%2$s
    http://www.wireless-village.org/trc
    http://developers.facebook.com/docs/reference/rest/
    https://m.facebook.com/dialog/
    https://wss.pollfish.com
    https://android.revmob.com
    http://www.upcdatabase.org/api/xml/30a634c9cad463a5e5d5c7afb2496ff2/
    自研引擎分析结果

    Firebase配置检测

    邮箱地址提取

    EMAIL 源码文件
    dimame032@gmail.com
    com/qbiki/modules/order/OrderFragment.java
    example@mail.com
    com/qbiki/modules/product/order/POGeneralInfo.java
    dimame032@gmail.com
    example@mail.com
    myemail@mail.com
    自研引擎分析结果

    第三方追踪器

    敏感凭证泄露

    已显示 22 个secrets
    1、 谷歌地图的 "com.google.android.maps.v2.API_KEY" : "@string/google_maps_v2_api_key"
    2、 "username" : "hbkeah14"
    3、 "fb_api_key" : "268726946654893"
    4、 "google_maps_api_key" : "0jbe4NyXN3WOAa8Mit_l5WwllH9gK_llPyfn_mg"
    5、 "google_maps_v2_api_key" : "AIzaSyDv34iCTHltLaJP70MvYckYMNBeb3zUJoA"
    6、 "app_licensing_public_key" : ""
    7、 "sc_api_key" : "s1w3W2h8SzoZOUMuZM6D9Urw0jo9B5tBz2SdLctURECajJCnYt"
    8、 "auth_client_requested_by_msg" : "%1$sによるリクエスト"
    9、 "auth_client_using_bad_version_title" : "កម្មវិធី​​​ព្យាយាម​ប្រើ​កំណែ​មិនល្អ​របស់​សេវា​កម្ម​ឃ្លាំ​កម្មវិធី។"
    10、 "auth_client_needs_enabling_title" : "កម្មវិធី​ទាមទារ​​បើក​សេវាកម្ម​ឃ្លាំង​កម្មវិធី។"
    11、 "auth_client_needs_installation_title" : "កម្មវិធី​ទាមទារ​ការ​ដំឡើង​សេវាកម្ម​ឃ្លាំង​កម្មវិធី។"
    12、 "auth_client_requested_by_msg" : "「%1$s」提出要求"
    13、 "auth_client_requested_by_msg" : "由“%1$s”发出"
    14、 "auth_client_requested_by_msg" : "提出要求的應用程式:%1$s"
    15、 Y29tLmFuZHJvaWQudmVuZGluZy5saWNlbnNpbmcuSUxpY2Vuc2luZ1NlcnZpY2U=
    16、 30a634c9cad463a5e5d5c7afb2496ff2
    17、 3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2f
    18、 30820268308201d102044a9c4610300d06092a864886f70d0101040500307a310b3009060355040613025553310b3009060355040813024341311230100603550407130950616c6f20416c746f31183016060355040a130f46616365626f6f6b204d6f62696c653111300f060355040b130846616365626f6f6b311d301b0603550403131446616365626f6f6b20436f72706f726174696f6e3020170d3039303833313231353231365a180f32303530303932353231353231365a307a310b3009060355040613025553310b3009060355040813024341311230100603550407130950616c6f20416c746f31183016060355040a130f46616365626f6f6b204d6f62696c653111300f060355040b130846616365626f6f6b311d301b0603550403131446616365626f6f6b20436f72706f726174696f6e30819f300d06092a864886f70d010101050003818d0030818902818100c207d51df8eb8c97d93ba0c8c1002c928fab00dc1b42fca5e66e99cc3023ed2d214d822bc59e8e35ddcf5f44c7ae8ade50d7e0c434f500e6c131f4a2834f987fc46406115de2018ebbb0d5a3c261bd97581ccfef76afc7135a6d59e8855ecd7eacc8f8737e794c60a761c536b72b11fac8e603f5da1a2d54aa103b8a13c0dbc10203010001300d06092a864886f70d0101040500038181005ee9be8bcbb250648d3b741290a82a1c9dc2e76a0af2f2228f1d9f9c4007529c446a70175c5a900d5141812866db46be6559e2141616483998211f4a673149fb2232a10d247663b26a9031e15f84bc1c74d141ff98a02d76f85b2c8ab2571b6469b232d8e768a7f7ca04f7abe4a775615916c07940656b58717457b42bd928a2
    19、 boundary=3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2f
    20、 AIzaSyDcbnDqRozxjllddKHhKwfQEflvej1qd8A
    21、 E213051E4666E9872FA6F50E57A3102C
    22、 8288f9f5ef393b70d5121604a25da736

    字符串信息

    建议导出为TXT,方便查看。

    活动列表

    第三方SDK

    SDK名称 开发者 描述信息
    File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。

    污点分析

    当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
    规则名称 描述信息 操作
    病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
    漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
    隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
    密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
    Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析