温馨提示:本平台仅供研究软件风险、安全评估,禁止用于非法用途。由于展示的数据过于全面,请耐心等待加载完成。如有疑问或建议, 可加入我们的微信群讨论

应用图标

应用评分

文件信息

文件名称 8fc9cc71999c07db3ae09878db4cb762816df766a1d9e25f80675fc2ed412ffb.apk
文件大小 7.03MB
MD5 196ffced350d273ffd6133645b2b5940
SHA1 2556a664acd8e94ed22af5181e40218ea274fd43
SHA256 8fc9cc71999c07db3ae09878db4cb762816df766a1d9e25f80675fc2ed412ffb
病毒检测 ⚠️ 9 个厂商报毒⚠️

应用信息

应用名称 Space War Ship
包名 batch.arcade.space.war.ship.combat
主活动 com.qbiki.seattleclouds.AppStarterActivity
目标SDK 17 最小SDK 10
版本号 1.0 子版本号 1
加固信息 未加壳

非法应用检测 (该功能即将上线,识别赌博、诈骗、色情和黑产等类型应用)

组件导出信息

反编译代码

Manifest文件 查看
Java源代码 查看 -- 下载

证书信息

二进制文件已签名
v1 签名: True
v2 签名: False
v3 签名: False
v4 签名: False
主题: CN=Keah HB
签名算法: rsassa_pkcs1v15
有效期自: 2014-08-20 17:22:16+00:00
有效期至: 2042-01-05 17:22:16+00:00
发行人: CN=Keah HB
序列号: 0x76a2166a
哈希算法: sha256
证书MD5: 49a8230617b268522c5fd117cf5126d9
证书SHA1: defad55ea8c4741947d16fb59a3f9939c9f0c6be
证书SHA256: 52924e53260486419cbab9b8c36dbfb94a248ae4ed3b197513d19e73f4057eea
证书SHA512: c1581378cd26f6cebe715de72a630599131e28d43009b72e93e50097dd7276aa23b13fe34ee953015d15ff87de72d9b494c146b5b6463190eb7dab813bf2fe1c
找到 1 个唯一证书

应用程序权限

权限名称 安全等级 权限内容 权限描述 关联代码
android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
com/amazon/android/c/a.java
com/amazon/mas/kiwi/util/Base64.java
com/pollfish/c/e.java
com/pollfish/c/f.java
com/pollfish/c/j.java
com/qbiki/mbfx/MBFXContext.java
com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
com/qbiki/modules/cameracover/CoverCamera.java
com/qbiki/modules/dropbox/medialist/AsyncTaskParseResources.java
com/qbiki/modules/dynamiclist/DynamicListAdapter.java
com/qbiki/modules/epubreader/Decompress.java
com/qbiki/modules/facebookfeeds/DownloadMediaFileAsyncTask.java
com/qbiki/modules/fusioncharts/FusionChartsFragment.java
com/qbiki/modules/fusioncharts/GetChartDataAsyncTask.java
com/qbiki/modules/pdfreader/PDFDocumentHelper.java
com/qbiki/modules/photoeffect/PhotoEffectFragment.java
com/qbiki/modules/savephoto/SavePhotoActivity.java
com/qbiki/modules/scandocument/ImageCropFragment.java
com/qbiki/modules/scandocument/ScanDocumentFragment.java
com/qbiki/modules/scoreboard/ScoreBoardFragment.java
com/qbiki/modules/scoreboard/ScreenShotMaker.java
com/qbiki/modules/sharepoint/SPFileDetailView.java
com/qbiki/modules/sharepoint/SPItemEditorView.java
com/qbiki/modules/sharepoint/SPListViewAdapter.java
com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
com/qbiki/modules/signaturestamp/SignatureStampFragment.java
com/qbiki/modules/starbucks/CardStorageManager.java
com/qbiki/modules/videolist/DownloadFileAsyncTask.java
com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
com/qbiki/seattleclouds/SCDownloadHostedPageResourcesFragment.java
com/qbiki/seattleclouds/WebViewFragment.java
com/qbiki/seattleclouds/asynctasks/InitResourcesAsyncTask.java
com/qbiki/seattleclouds/asynctasks/SyncResourcesAsyncTask.java
com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
com/qbiki/util/DataUtil.java
com/qbiki/util/ZipUtil.java
com/revmob/android/FileCache.java
com/revmob/internal/DownloadManager.java
net/sourceforge/zbar/android/ZBarScanner.java
org/ksoap2/transport/HttpTransportSE.java
android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
android.permission.GET_ACCOUNTS 普通 探索已知账号 允许应用程序访问帐户服务中的帐户列表。
batch.arcade.space.war.ship.combat.permission.C2D_MESSAGE 未知 未知权限 来自 android 引用的未知权限。
com.google.android.c2dm.permission.RECEIVE 普通 接收推送通知 允许应用程序接收来自云的推送通知。

证书安全分析

高危
1
警告
0
信息
1
标题 严重程度 描述信息
已签名应用 信息 应用程序已使用代码签名证书进行签名
应用程序存在Janus漏洞 高危 应用程序使用了v1签名方案进行签名,如果只使用v1签名方案,那么它就容易受到安卓5.0-8.0上的Janus漏洞的攻击。在安卓5.0-7.0上运行的使用了v1签名方案的应用程序,以及同时使用了v2/v3签名方案的应用程序也同样存在漏洞。

MANIFEST分析

高危
3
警告
6
信息
0
屏蔽
0
序号 问题 严重程度 描述信息 操作
1 应用程序可以安装在有漏洞的已更新 Android 版本上
Android 2.3.3-2.3.7, [minSdk=10]
警告 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
2 Activity (com.qbiki.modules.search.SearchActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
3 Activity (com.qbiki.modules.search.SearchActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
4 Activity (com.qbiki.paypal.PayPalMessage) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
5 Activity (com.qbiki.paypal.PayPalMessage) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
6 Activity (net.sourceforge.zbar.android.ZBarScanner) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (17) 更新到 29 或更高版本以在平台级别修复此问题。
7 Activity (net.sourceforge.zbar.android.ZBarScanner) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
8 Content Provider (com.qbiki.util.InternalFileContentProvider) 未被保护。
[android:exported=true]
警告 发现 Content Provider与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。
9 Broadcast Receiver (com.qbiki.gcm.GCMBroadcastReceiver) 受权限保护, 但是应该检查权限的保护级别。
Permission: com.google.android.c2dm.permission.SEND
[android:exported=true]
警告 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

可浏览的Activity组件

ACTIVITY INTENT
com.qbiki.paypal.PayPalMessage Schemes: mobile-appbuilder.hbkeah14.gamesapp039://,

网络通信安全

序号 范围 严重级别 描述

API调用分析

API功能 源码文件
一般功能-> 文件操作
com/a/a/a/g.java
com/actionbarsherlock/view/MenuInflater.java
com/actionbarsherlock/widget/ActivityChooserModel.java
com/actionbarsherlock/widget/SuggestionsAdapter.java
com/amazon/android/c/a.java
com/amazon/android/c/b.java
com/amazon/android/c/c.java
com/amazon/android/framework/prompt/e.java
com/amazon/android/framework/task/command/f.java
com/amazon/android/framework/util/a.java
com/amazon/android/l/a.java
com/amazon/android/l/c.java
com/amazon/android/l/d.java
com/amazon/android/licensing/l.java
com/amazon/android/p/a.java
com/amazon/android/p/b.java
com/amazon/android/t/a.java
com/amazon/mas/kiwi/util/ApkHelpers.java
com/amazon/mas/kiwi/util/BC1.java
com/amazon/mas/kiwi/util/Base64.java
com/amazon/mas/kiwi/util/KiwiVersionEncrypter.java
com/onbarcode/barcode/android/AbstractBarcode.java
com/onbarcode/barcode/android/GeneratedBarcodeInfo.java
com/pollfish/a/a.java
com/pollfish/c/a.java
com/pollfish/c/b.java
com/pollfish/c/c.java
com/pollfish/c/d.java
com/pollfish/c/e.java
com/pollfish/c/f.java
com/pollfish/c/i.java
com/pollfish/c/j.java
com/pollfish/f/b/a.java
com/pollfish/f/c.java
com/pollfish/g/a.java
com/qbiki/ads/SCAdView.java
com/qbiki/analytics/SCAnalyticsTracker.java
com/qbiki/billing/SCIabHelper.java
com/qbiki/feedback/FeedbackFragment.java
com/qbiki/feedback/FieldProcessing.java
com/qbiki/gcm/GCMBroadcastReceiver.java
com/qbiki/gcm/GCMHelper.java
com/qbiki/geofencing/GeofenceManager.java
com/qbiki/location/AsyncGeocoder.java
com/qbiki/mbfx/DynamicHTML.java
com/qbiki/mbfx/MBFXContext.java
com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
com/qbiki/modules/calendar/CalendarFragment.java
com/qbiki/modules/calendar/EventsSyncAsyncTask.java
com/qbiki/modules/cameracover/CameraCoverFrgament.java
com/qbiki/modules/cameracover/CoverCamera.java
com/qbiki/modules/cameracover/CoversPreviewFragment.java
com/qbiki/modules/coupon/CouponFragment.java
com/qbiki/modules/dropbox/medialist/AsyncTaskParseResources.java
com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
com/qbiki/modules/dropbox/medialist/GetMediaLinkAsyncTask.java
com/qbiki/modules/dropbox/medialist/ListItemViews.java
com/qbiki/modules/dropbox/medialist/MediaFile.java
com/qbiki/modules/dynamiclist/DynamicListAdapter.java
com/qbiki/modules/dynamiclist/DynamicListFragment.java
com/qbiki/modules/epubreader/Decompress.java
com/qbiki/modules/epubreader/ePubReaderFragment.java
com/qbiki/modules/facebookfeeds/AppSignInWithFacebookFragment.java
com/qbiki/modules/facebookfeeds/DownloadMediaFileAsyncTask.java
com/qbiki/modules/facebookfeeds/FacebookFeedsUtils.java
com/qbiki/modules/facebookfeeds/FeedsListFragment.java
com/qbiki/modules/facebookfeeds/PostFeedFragment.java
com/qbiki/modules/favorites/Favorites.java
com/qbiki/modules/favorites/FavoritesFragment.java
com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
com/qbiki/modules/fusioncharts/FusionChartsFragment.java
com/qbiki/modules/fusioncharts/GetChartDataAsyncTask.java
com/qbiki/modules/gcmtopics/GCMTopicsFragment.java
com/qbiki/modules/goaltracker/GoalTrackerCategories.java
com/qbiki/modules/imagelist/ImageListFragment.java
com/qbiki/modules/karaoke/KaraokeFragment.java
com/qbiki/modules/locationlock/LocationLockFragment.java
com/qbiki/modules/loyalty/LoyaltyFragment.java
com/qbiki/modules/messenger/AppSignInFragment.java
com/qbiki/modules/messenger/ConversationFragment.java
com/qbiki/modules/messenger/MessengerFragment.java
com/qbiki/modules/nativetetris/TetrisGame.java
com/qbiki/modules/nativetetris/TetrisView.java
com/qbiki/modules/nearbylocations/NearbyLocationFragment.java
com/qbiki/modules/order/OrderFragment.java
com/qbiki/modules/pdfeditorreader/PDFAudioFragment.java
com/qbiki/modules/pdfeditorreader/PDFReaderEditorFragment.java
com/qbiki/modules/pdfeditorreader/PDFVideoFragment.java
com/qbiki/modules/pdfeditorreader/VideoViewFD.java
com/qbiki/modules/pdfreader/PDFDocumentHelper.java
com/qbiki/modules/pdfreader/PDFReaderFragment.java
com/qbiki/modules/pdfviewer/PDFViewerFragment.java
com/qbiki/modules/photoeffect/PhotoEffectFragment.java
com/qbiki/modules/product/order/POContext.java
com/qbiki/modules/quiz/QuizPrepareResourcesAsyncTask.java
com/qbiki/modules/quiz/QuizSharedDataManager.java
com/qbiki/modules/quizweb/QuizwebFragment.java
com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
com/qbiki/modules/rateandreview/RateAndReviewFragment.java
com/qbiki/modules/rateandreview/RateAndReviewHandle.java
com/qbiki/modules/rsspro/RssFeedsPullParser.java
com/qbiki/modules/rsspro/RssFeedsSaxParser.java
com/qbiki/modules/savephoto/SavePhotoActivity.java
com/qbiki/modules/scandocument/ImageCropFragment.java
com/qbiki/modules/scandocument/ScanDocumentFragment.java
com/qbiki/modules/scoreboard/ScoreBoardFragment.java
com/qbiki/modules/scoreboard/ScreenShotMaker.java
com/qbiki/modules/scoreboard/SendEmailAsyncTask.java
com/qbiki/modules/search/SearchFragment.java
com/qbiki/modules/sharepoint/SPFileDetailView.java
com/qbiki/modules/sharepoint/SPItemEditorView.java
com/qbiki/modules/sharepoint/SPListViewAdapter.java
com/qbiki/modules/sharepoint/SPParserXMLtoSOAPObject.java
com/qbiki/modules/sharepoint/SPServer.java
com/qbiki/modules/sharepoint/SPWeb.java
com/qbiki/modules/sharepoint/SharePointFragment.java
com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
com/qbiki/modules/signaturestamp/SignatureStampFragment.java
com/qbiki/modules/slideshow/SlideShowFragment.java
com/qbiki/modules/slotmachine/SlotMachineFragment.java
com/qbiki/modules/starbucks/CardStorageManager.java
com/qbiki/modules/videolist/AsyncTaskParseResources.java
com/qbiki/modules/videolist/DownloadFileAsyncTask.java
com/qbiki/modules/videolist/VideoFilesListFragment.java
com/qbiki/modules/videolist/VideoListXMLParser.java
com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
com/qbiki/paypal/PayPalProcessing.java
com/qbiki/scapi/SCApi.java
com/qbiki/scapi/SCApiRequestAsyncTask.java
com/qbiki/seattleclouds/App.java
com/qbiki/seattleclouds/AppConfigHandler.java
com/qbiki/seattleclouds/AppStarterActivity.java
com/qbiki/seattleclouds/SCDownloadHostedPageResourcesFragment.java
com/qbiki/seattleclouds/WebViewFragment.java
com/qbiki/seattleclouds/asynctasks/DownloadExternalResourcesAsyncTask.java
com/qbiki/seattleclouds/asynctasks/InitResourcesAsyncTask.java
com/qbiki/seattleclouds/asynctasks/ParseAppConfigAsyncTask.java
com/qbiki/seattleclouds/asynctasks/SyncResourcesAsyncTask.java
com/qbiki/seattleclouds/mosaic/MosaicFragment.java
com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
com/qbiki/seattleclouds/previewer/PreviewerAppViewFragment.java
com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
com/qbiki/shoppingcart/ShoppingCart.java
com/qbiki/util/CookieManager.java
com/qbiki/util/DataUtil.java
com/qbiki/util/FlushedInputStream.java
com/qbiki/util/HTTPUtil.java
com/qbiki/util/ImageUtil.java
com/qbiki/util/InternalFileContentProvider.java
com/qbiki/util/ResourceImageResizer.java
com/qbiki/util/SCMediaPlayer.java
com/qbiki/util/XmlPullUtil.java
com/qbiki/util/YouTubeEmbedProcessor.java
com/qbiki/util/ZipUtil.java
com/qbiki/util/asyncrequester/AsynchronousSender.java
com/qbiki/util/asyncrequester/Requester.java
com/revmob/ads/banner/RevMobBanner.java
com/revmob/ads/fullscreen/FullscreenActivity.java
com/revmob/ads/internal/StaticAssets.java
com/revmob/ads/popup/RevMobPopup.java
com/revmob/android/FileCache.java
com/revmob/android/RevMobContext.java
com/revmob/android/StoredData.java
com/revmob/internal/DownloadManager.java
com/revmob/internal/HTTPHelper.java
com/revmob/internal/RevMobEula.java
com/revmob/internal/RevMobSoundPlayer.java
net/sourceforge/zbar/android/ZBarScanner.java
nl/siegmann/epublib/browsersupport/Navigator.java
nl/siegmann/epublib/domain/Author.java
nl/siegmann/epublib/domain/Book.java
nl/siegmann/epublib/domain/Date.java
nl/siegmann/epublib/domain/Guide.java
nl/siegmann/epublib/domain/GuideReference.java
nl/siegmann/epublib/domain/Identifier.java
nl/siegmann/epublib/domain/MediaType.java
nl/siegmann/epublib/domain/Metadata.java
nl/siegmann/epublib/domain/Resource.java
nl/siegmann/epublib/domain/ResourceReference.java
nl/siegmann/epublib/domain/Resources.java
nl/siegmann/epublib/domain/Spine.java
nl/siegmann/epublib/domain/SpineReference.java
nl/siegmann/epublib/domain/TOCReference.java
nl/siegmann/epublib/domain/TableOfContents.java
nl/siegmann/epublib/domain/TitledResourceReference.java
nl/siegmann/epublib/epub/EpubProcessorSupport.java
nl/siegmann/epublib/epub/EpubReader.java
nl/siegmann/epublib/epub/EpubWriter.java
nl/siegmann/epublib/epub/HtmlProcessor.java
nl/siegmann/epublib/epub/NCXDocument.java
nl/siegmann/epublib/epub/PackageDocumentMetadataWriter.java
nl/siegmann/epublib/epub/PackageDocumentReader.java
nl/siegmann/epublib/epub/PackageDocumentWriter.java
nl/siegmann/epublib/util/IOUtil.java
nl/siegmann/epublib/util/NoCloseOutputStream.java
nl/siegmann/epublib/util/NoCloseWriter.java
nl/siegmann/epublib/util/ResourceUtil.java
nl/siegmann/epublib/util/commons/io/BOMInputStream.java
nl/siegmann/epublib/util/commons/io/ByteOrderMark.java
nl/siegmann/epublib/util/commons/io/ProxyInputStream.java
nl/siegmann/epublib/util/commons/io/XmlStreamReader.java
nl/siegmann/epublib/util/commons/io/XmlStreamReaderException.java
org/jsoup/Connection.java
org/jsoup/Jsoup.java
org/jsoup/examples/ListLinks.java
org/jsoup/helper/DataUtil.java
org/jsoup/helper/HttpConnection.java
org/kobjects/base64/Base64.java
org/kobjects/crypt/Crypt.java
org/kobjects/io/BoundInputStream.java
org/kobjects/io/LookAheadReader.java
org/kobjects/mime/Decoder.java
org/kobjects/pim/PimParser.java
org/kobjects/pim/PimWriter.java
org/kobjects/rss/RssReader.java
org/kobjects/util/Util.java
org/kobjects/xml/XmlReader.java
org/kobjects/xmlrpc/Driver.java
org/kobjects/xmlrpc/XmlRpcParser.java
org/ksoap2/SoapEnvelope.java
org/ksoap2/SoapFault.java
org/ksoap2/SoapFault12.java
org/ksoap2/serialization/DM.java
org/ksoap2/serialization/Marshal.java
org/ksoap2/serialization/MarshalBase64.java
org/ksoap2/serialization/MarshalDate.java
org/ksoap2/serialization/MarshalFloat.java
org/ksoap2/serialization/MarshalHashtable.java
org/ksoap2/serialization/PropertyInfo.java
org/ksoap2/serialization/SoapSerializationEnvelope.java
org/ksoap2/transport/HttpTransportSE.java
org/ksoap2/transport/HttpsServiceConnectionSE.java
org/ksoap2/transport/HttpsServiceConnectionSEIgnoringConnectionClose.java
org/ksoap2/transport/HttpsTransportSE.java
org/ksoap2/transport/KeepAliveHttpTransportSE.java
org/ksoap2/transport/KeepAliveHttpsTransportSE.java
org/ksoap2/transport/ServiceConnection.java
org/ksoap2/transport/ServiceConnectionSE.java
org/ksoap2/transport/Transport.java
org/kxml2/io/KXmlParser.java
org/kxml2/io/KXmlSerializer.java
org/kxml2/kdom/Document.java
org/kxml2/kdom/Element.java
org/kxml2/kdom/Node.java
org/kxml2/wap/WbxmlParser.java
org/kxml2/wap/WbxmlSerializer.java
org/kxml2/wap/wv/WV.java
pdftron/FDF/FDFDoc.java
pdftron/PDF/PDFDoc.java
pdftron/PDF/PDFNet.java
pdftron/PDF/Tools/Pan.java
pdftron/PDF/Tools/b.java
pdftron/PDF/Tools/r.java
pdftron/SDF/SDFDoc.java
网络通信-> DefaultHttpClient Connection
组件-> 发送广播
一般功能-> IPC通信
com/actionbarsherlock/internal/view/menu/ActionMenu.java
com/actionbarsherlock/internal/view/menu/ActionMenuItem.java
com/actionbarsherlock/internal/view/menu/MenuBuilder.java
com/actionbarsherlock/internal/view/menu/MenuItemImpl.java
com/actionbarsherlock/internal/view/menu/MenuItemWrapper.java
com/actionbarsherlock/internal/view/menu/MenuWrapper.java
com/actionbarsherlock/view/Menu.java
com/actionbarsherlock/view/MenuItem.java
com/actionbarsherlock/widget/ActivityChooserModel.java
com/actionbarsherlock/widget/ActivityChooserView.java
com/actionbarsherlock/widget/SearchView.java
com/actionbarsherlock/widget/ShareActionProvider.java
com/amazon/android/Kiwi.java
com/amazon/android/f/a.java
com/amazon/android/f/b.java
com/amazon/android/f/c.java
com/amazon/android/f/f.java
com/amazon/android/framework/context/b.java
com/amazon/android/framework/context/d.java
com/amazon/android/framework/prompt/e.java
com/amazon/android/framework/prompt/g.java
com/amazon/android/framework/task/command/AbstractCommandTask.java
com/amazon/android/framework/task/command/c.java
com/amazon/android/framework/task/command/j.java
com/amazon/android/framework/task/command/n.java
com/amazon/venezia/command/Choice.java
com/amazon/venezia/command/ChoiceContext.java
com/amazon/venezia/command/Command.java
com/amazon/venezia/command/CommandService.java
com/amazon/venezia/command/DecisionExpirationContext.java
com/amazon/venezia/command/DecisionResult.java
com/amazon/venezia/command/ExceptionResult.java
com/amazon/venezia/command/FailureResult.java
com/amazon/venezia/command/ResultCallback.java
com/amazon/venezia/command/SuccessResult.java
com/amazon/venezia/command/a.java
com/amazon/venezia/command/aa.java
com/amazon/venezia/command/ab.java
com/amazon/venezia/command/c.java
com/amazon/venezia/command/d.java
com/amazon/venezia/command/k.java
com/amazon/venezia/command/l.java
com/amazon/venezia/command/m.java
com/amazon/venezia/command/n.java
com/amazon/venezia/command/o.java
com/amazon/venezia/command/p.java
com/amazon/venezia/command/q.java
com/amazon/venezia/command/t.java
com/amazon/venezia/command/u.java
com/amazon/venezia/command/v.java
com/amazon/venezia/command/x.java
com/amazon/venezia/command/z.java
com/amazon/venezia/service/verify/IApplicationVerificationService.java
com/pollfish/d/a.java
com/qbiki/ads/AdManager.java
com/qbiki/ads/SCAdView.java
com/qbiki/c2dm/AnnouncementActivity.java
com/qbiki/feedback/FeedbackFragment.java
com/qbiki/gcm/GCMBroadcastReceiver.java
com/qbiki/geofencing/GeofenceManager.java
com/qbiki/geofencing/GeofenceRemover.java
com/qbiki/geofencing/GeofenceRequester.java
com/qbiki/geofencing/ReceiveTransitionsIntentService.java
com/qbiki/location/LocationDetectorActivity.java
com/qbiki/location/LocationDetectorFragment.java
com/qbiki/modules/appshare/AppShare.java
com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
com/qbiki/modules/calendar/CalendarFragment.java
com/qbiki/modules/calendar/EventEditActivity.java
com/qbiki/modules/cameracover/CameraCoverFrgament.java
com/qbiki/modules/cameracover/CoverCamera.java
com/qbiki/modules/cameracover/CoversPreviewFragment.java
com/qbiki/modules/coupon/CouponFragment.java
com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
com/qbiki/modules/dynamiclist/DynamicListFragment.java
com/qbiki/modules/facebookfeeds/AppSignInWithFacebookFragment.java
com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
com/qbiki/modules/facebookfeeds/FeedsListFragment.java
com/qbiki/modules/facebookfeeds/PostFeedFragment.java
com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
com/qbiki/modules/goaltracker/GoalTrackerAlarmReceiver.java
com/qbiki/modules/imagelist/ImageListFragment.java
com/qbiki/modules/locationlock/AutoFinishPageFragmentActivity.java
com/qbiki/modules/locationlock/LocationLockFragment.java
com/qbiki/modules/login/LoginFragment.java
com/qbiki/modules/messenger/AppSignInFragment.java
com/qbiki/modules/messenger/ConversationFragment.java
com/qbiki/modules/messenger/MessengerFragment.java
com/qbiki/modules/messenger/MessengerNotifications.java
com/qbiki/modules/notes/NotePagerFragment.java
com/qbiki/modules/order/OrderFragment.java
com/qbiki/modules/order/OrderPaypalActivity.java
com/qbiki/modules/pdfeditorreader/VideoViewFD.java
com/qbiki/modules/phonegap/PhoneGapActivity.java
com/qbiki/modules/photoeffect/PhotoEffectFragment.java
com/qbiki/modules/quiz/QuizRootFragment.java
com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
com/qbiki/modules/rateandreview/RateAndReviewFragment.java
com/qbiki/modules/rateandreview/RateAndReviewHandle.java
com/qbiki/modules/savephoto/SavePhotoActivity.java
com/qbiki/modules/scandocument/ScanDocumentFragment.java
com/qbiki/modules/scoreboard/ScoreBoardFragment.java
com/qbiki/modules/search/SearchActivity.java
com/qbiki/modules/sharepoint/SPItemEditorFragment.java
com/qbiki/modules/sharepoint/SPItemEditorView.java
com/qbiki/modules/sharepoint/SharePointFragment.java
com/qbiki/modules/signaturestamp/DrawSurfaceActivity.java
com/qbiki/modules/signaturestamp/SignatureStampFragment.java
com/qbiki/modules/starbucks/AddCardActivity.java
com/qbiki/modules/starbucks/CardsListActivity.java
com/qbiki/modules/starbucks/ViewCardActivity.java
com/qbiki/modules/videolist/DownloadService.java
com/qbiki/modules/videolist/VideoFilesListFragment.java
com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
com/qbiki/paypal/PayPalMessage.java
com/qbiki/paypal/PayPalProcessing.java
com/qbiki/seattleclouds/ActionBarTabsAppActivity.java
com/qbiki/seattleclouds/App.java
com/qbiki/seattleclouds/AppStarterActivity.java
com/qbiki/seattleclouds/BaseAppActivity.java
com/qbiki/seattleclouds/EmptyActivity.java
com/qbiki/seattleclouds/ExpansionFilesDownloaderAlarmReceiver.java
com/qbiki/seattleclouds/LegacyTabsAppActivity.java
com/qbiki/seattleclouds/NestedFragmentCompat.java
com/qbiki/seattleclouds/SCFragment.java
com/qbiki/seattleclouds/SCFragmentActivity.java
com/qbiki/seattleclouds/SCFragmentHelper.java
com/qbiki/seattleclouds/SCListFragment.java
com/qbiki/seattleclouds/SCMapFragment.java
com/qbiki/seattleclouds/SCPageFragmentActivity.java
com/qbiki/seattleclouds/SCTabsAppActivity.java
com/qbiki/seattleclouds/SimpleAppActivity.java
com/qbiki/seattleclouds/WebViewFragment.java
com/qbiki/seattleclouds/mosaic/MosaicFragment.java
com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
com/qbiki/seattleclouds/previewer/PreviewerAboutActivity.java
com/qbiki/seattleclouds/previewer/PreviewerActivity.java
com/qbiki/seattleclouds/previewer/PreviewerAppViewActivity.java
com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
com/qbiki/util/IntentUtil.java
com/revmob/ads/fullscreen/FullscreenActivity.java
com/revmob/ads/fullscreen/RevMobFullscreen.java
com/revmob/internal/AndroidHelper.java
com/revmob/internal/MarketAsyncManager.java
net/sourceforge/zbar/android/ZBarScanner.java
pdftron/PDF/Annots/FreeText.java
pdftron/PDF/Annots/Line.java
pdftron/PDF/Annots/PolyLine.java
pdftron/PDF/Element.java
pdftron/PDF/GState.java
pdftron/PDF/Image.java
pdftron/PDF/OCG/Config.java
pdftron/PDF/OCG/Group.java
pdftron/PDF/Tools/k.java
pdftron/PDF/Tools/n.java
组件-> 启动 Activity
com/actionbarsherlock/internal/view/menu/ActionMenuItem.java
com/actionbarsherlock/internal/view/menu/MenuItemImpl.java
com/actionbarsherlock/widget/ActivityChooserView.java
com/actionbarsherlock/widget/SearchView.java
com/actionbarsherlock/widget/ShareActionProvider.java
com/amazon/android/f/a.java
com/amazon/android/framework/context/d.java
com/amazon/android/framework/prompt/g.java
com/pollfish/d/a.java
com/qbiki/ads/SCAdView.java
com/qbiki/c2dm/AnnouncementActivity.java
com/qbiki/feedback/FeedbackFragment.java
com/qbiki/modules/appshare/AppShare.java
com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
com/qbiki/modules/calendar/CalendarFragment.java
com/qbiki/modules/calendar/EventEditActivity.java
com/qbiki/modules/cameracover/CameraCoverFrgament.java
com/qbiki/modules/cameracover/CoversPreviewFragment.java
com/qbiki/modules/coupon/CouponFragment.java
com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
com/qbiki/modules/dynamiclist/DynamicListFragment.java
com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
com/qbiki/modules/facebookfeeds/FeedsListFragment.java
com/qbiki/modules/facebookfeeds/PostFeedFragment.java
com/qbiki/modules/imagelist/ImageListFragment.java
com/qbiki/modules/locationlock/LocationLockFragment.java
com/qbiki/modules/login/LoginFragment.java
com/qbiki/modules/messenger/AppSignInFragment.java
com/qbiki/modules/messenger/ConversationFragment.java
com/qbiki/modules/messenger/MessengerFragment.java
com/qbiki/modules/notes/NotePagerFragment.java
com/qbiki/modules/order/OrderFragment.java
com/qbiki/modules/photoeffect/PhotoEffectFragment.java
com/qbiki/modules/quiz/QuizRootFragment.java
com/qbiki/modules/rateandreview/RateAndReviewFragment.java
com/qbiki/modules/rateandreview/RateAndReviewHandle.java
com/qbiki/modules/savephoto/SavePhotoActivity.java
com/qbiki/modules/scandocument/ScanDocumentFragment.java
com/qbiki/modules/scoreboard/ScoreBoardFragment.java
com/qbiki/modules/sharepoint/SPItemEditorView.java
com/qbiki/modules/sharepoint/SharePointFragment.java
com/qbiki/modules/signaturestamp/SignatureStampFragment.java
com/qbiki/modules/starbucks/CardsListActivity.java
com/qbiki/modules/videolist/VideoFilesListFragment.java
com/qbiki/modules/voicerecord/SCVoiceRecordListFragment.java
com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
com/qbiki/paypal/PayPalMessage.java
com/qbiki/paypal/PayPalProcessing.java
com/qbiki/seattleclouds/App.java
com/qbiki/seattleclouds/AppStarterActivity.java
com/qbiki/seattleclouds/BaseAppActivity.java
com/qbiki/seattleclouds/SCFragment.java
com/qbiki/seattleclouds/SCFragmentHelper.java
com/qbiki/seattleclouds/SCListFragment.java
com/qbiki/seattleclouds/SCMapFragment.java
com/qbiki/seattleclouds/WebViewFragment.java
com/qbiki/seattleclouds/mosaic/MosaicImageFragment.java
com/qbiki/seattleclouds/previewer/PreviewerActivity.java
com/qbiki/seattleclouds/previewer/PreviewerAppsFragment.java
com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
com/qbiki/util/IntentUtil.java
com/revmob/ads/fullscreen/RevMobFullscreen.java
com/revmob/internal/MarketAsyncManager.java
net/sourceforge/zbar/android/ZBarScanner.java
pdftron/PDF/Tools/k.java
pdftron/PDF/Tools/n.java
一般功能-> 获取系统服务(getSystemService)
com/actionbarsherlock/internal/widget/IcsProgressBar.java
com/actionbarsherlock/widget/SearchView.java
com/actionbarsherlock/widget/SuggestionsAdapter.java
com/amazon/android/c/b.java
com/amazon/android/framework/prompt/e.java
com/pollfish/f/c.java
com/pollfish/g/a.java
com/qbiki/analytics/SCAnalyticsTracker.java
com/qbiki/c2dm/AnnouncementActivity.java
com/qbiki/feedback/DatePicker.java
com/qbiki/feedback/PickerView.java
com/qbiki/feedback/TimePicker.java
com/qbiki/gcm/GCMBroadcastReceiver.java
com/qbiki/geofencing/ReceiveTransitionsIntentService.java
com/qbiki/location/LocationDetectorFragment.java
com/qbiki/location/SimpleLocationManager.java
com/qbiki/modules/bmicalculator/BmiCalculatorFragment.java
com/qbiki/modules/dropbox/medialist/ListItemViews.java
com/qbiki/modules/dynamiclist/DynamicListFragment.java
com/qbiki/modules/facebookfeeds/FeedCommentsFragment.java
com/qbiki/modules/facebookfeeds/FeedsListFragment.java
com/qbiki/modules/facebookfeeds/PostFeedFragment.java
com/qbiki/modules/gcmtopics/GCMTopicsFragment.java
com/qbiki/modules/goaltracker/GoalTrackerAlarmReceiver.java
com/qbiki/modules/login/SCForgotPasswordFragment.java
com/qbiki/modules/messenger/MessengerNotifications.java
com/qbiki/modules/nearbylocations/NearbyLocationFragment.java
com/qbiki/modules/notes/NoteFragment.java
com/qbiki/modules/pdfreader/PDFDocumentHelper.java
com/qbiki/modules/quiz/QuizHighscoresFragement.java
com/qbiki/modules/rateandreview/NewRateAndCommentActivity.java
com/qbiki/modules/rateandreview/RateAndReviewFragment.java
com/qbiki/modules/scoreboard/AppsUsedToShareListAdapter.java
com/qbiki/modules/scoreboard/RowView.java
com/qbiki/modules/search/SearchFragment.java
com/qbiki/modules/videolist/ListItemViews.java
com/qbiki/scapi/SCApiRequestAsyncTask.java
com/qbiki/seattleclouds/previewer/PreviewerLoginFragment.java
com/qbiki/util/ConnectionUtil.java
com/qbiki/util/DeviceUtil.java
com/qbiki/util/DialogUtil.java
com/qbiki/util/SCMediaPlayer.java
com/qbiki/util/WebViewUtil.java
com/revmob/ads/fullscreen/FullscreenActivity.java
kankan/wheel/widget/adapters/AbstractWheelTextAdapter.java
pdftron/PDF/Tools/Pan.java
pdftron/PDF/Tools/b.java
pdftron/PDF/Tools/k.java
pdftron/PDF/Tools/p.java
pdftron/PDF/Tools/t.java
一般功能-> 获取活动网路信息
一般功能-> 加载so文件
隐私数据-> 拍照摄像 com/qbiki/modules/cameracover/CoverCamera.java
net/sourceforge/zbar/android/CameraPreview.java
net/sourceforge/zbar/android/ZBarScanner.java
一般功能-> 获取Android广告ID com/pollfish/c/a.java
com/revmob/android/RevMobContext.java
DEX-> 动态加载
网络通信-> WebView JavaScript接口
网络通信-> WebView GET请求
JavaScript 接口方法 com/pollfish/g/a.java
com/qbiki/modules/karaoke/KaraokeFragment.java
com/qbiki/modules/starbucks/ViewCardActivity.java
网络通信-> WebView使用File协议 com/pollfish/g/a.java
com/qbiki/util/WebViewUtil.java
网络通信-> WebView 相关
隐私数据-> 获取已安装的应用程序
网络通信-> HTTP请求、连接和会话 com/qbiki/util/asyncrequester/AsynchronousSender.java
com/revmob/internal/HTTPHelper.java
com/revmob/internal/MarketRedirector.java
网络通信-> TCP套接字
加密解密-> Base64 加密
隐私数据-> 获取GPS位置信息
加密解密-> 信息摘要算法
网络通信-> HTTP建立连接
网络通信-> WebView POST请求 com/revmob/internal/MarketAsyncManager.java
进程操作-> 杀死进程 com/amazon/android/framework/prompt/e.java
com/revmob/internal/RevMobEula.java
调用java反射机制
隐私数据-> 剪贴板数据读写操作 pdftron/PDF/Tools/b.java
pdftron/PDF/Tools/t.java
隐私数据-> 屏幕截图,截取自己应用内部界面 pdftron/PDF/PDFViewCtrl.java
pdftron/PDF/Tools/t.java
组件-> 启动 Service com/amazon/android/framework/task/command/c.java
com/qbiki/modules/dropbox/medialist/DropboxMediaListFragment.java
com/qbiki/modules/videolist/VideoFilesListFragment.java
加密解密-> Base64 解密
隐私数据-> 录制视频 com/qbiki/modules/voicerecord/VoiceRecordPickerActivity.java
网络通信-> URLConnection
组件-> ContentProvider com/qbiki/util/InternalFileContentProvider.java
组件-> Provider openFile com/qbiki/util/InternalFileContentProvider.java
网络通信-> SSL证书处理 com/revmob/internal/HTTPHelper.java
org/ksoap2/transport/HttpsServiceConnectionSE.java
网络通信-> HTTPS建立连接 org/ksoap2/transport/HttpsServiceConnectionSE.java
设备指纹-> getSimOperator com/amazon/android/framework/prompt/e.java
加密解密-> Crypto加解密组件 com/amazon/android/l/a.java
com/pollfish/b/a.java
com/pollfish/f/c.java
一般功能-> 获取WiFi相关信息 com/pollfish/f/c.java
辅助功能accessibility相关 com/actionbarsherlock/widget/SearchView.java
一般功能-> Android通知
一般功能-> 传感器相关操作 com/revmob/ads/fullscreen/FullscreenActivity.java

安全漏洞检测

高危
3
警告
8
信息
1
安全
1
屏蔽
0
序号 问题 等级 参考标准 文件位置 操作
1 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3
升级会员:解锁高级权限
2 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 警告 CWE: CWE-312: 明文存储敏感信息
OWASP Top 10: M9: Reverse Engineering
OWASP MASVS: MSTG-STORAGE-14
升级会员:解锁高级权限
3 不安全的Web视图实现。可能存在WebView任意代码执行漏洞 警告 CWE: CWE-749: 暴露危险方法或函数
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-7
升级会员:解锁高级权限
4 WebView域控制不严格漏洞 高危 CWE: CWE-73: 外部控制文件名或路径 升级会员:解锁高级权限
5 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
升级会员:解锁高级权限
6 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击 高危 CWE: CWE-79: 在Web页面生成时对输入的转义处理不恰当('跨站脚本')
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-6
升级会员:解锁高级权限
7 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-6
升级会员:解锁高级权限
8 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
升级会员:解锁高级权限
9 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 警告 CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
OWASP Top 10: M7: Client Code Quality
升级会员:解锁高级权限
10 IP地址泄露 警告 CWE: CWE-200: 信息泄露
OWASP MASVS: MSTG-CODE-2
升级会员:解锁高级权限
11 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
OWASP Top 10: M3: Insecure Communication
OWASP MASVS: MSTG-NETWORK-3
升级会员:解锁高级权限
12 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
升级会员:解锁高级权限
13 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 安全
OWASP MASVS: MSTG-NETWORK-4
升级会员:解锁高级权限

Native库安全分析

No Shared Objects found.
序号 动态库 NX(堆栈禁止执行) PIE STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)

文件分析

序号 问题 文件

敏感权限分析

恶意软件常用权限 1/30
android.permission.GET_ACCOUNTS
其它常用权限 4/46
android.permission.INTERNET
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.ACCESS_NETWORK_STATE
com.google.android.c2dm.permission.RECEIVE

恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。

IP地理位置

恶意域名检测

域名 状态 中国境内 位置信息 解析
www.google-analytics.com 安全
IP地址: 180.163.151.33
国家: China
地区: Shanghai
城市: Shanghai
查看: 高德地图

example.com 安全
IP地址: 93.184.216.34
国家: United States of America
地区: Virginia
城市: Ashburn
查看: Google 地图

lbdb.pollfish.com 安全
IP地址: 173.255.115.49
国家: United States of America
地区: Iowa
城市: Council Bluffs
查看: Google 地图

www.wireless-village.org 安全
IP地址: 104.21.11.240
国家: United States of America
地区: California
城市: San Francisco
查看: Google 地图

media.admob.com 安全
IP地址: 142.250.141.100
国家: United States of America
地区: California
城市: Mountain View
查看: Google 地图

s.ytimg.com 安全
IP地址: 142.250.68.78
国家: United States of America
地区: California
城市: Mountain View
查看: Google 地图

purl.org 安全
IP地址: 207.241.239.241
国家: United States of America
地区: California
城市: San Francisco
查看: Google 地图

schemas.xmlsoap.org 安全
IP地址: 13.107.213.71
国家: United States of America
地区: Washington
城市: Redmond
查看: Google 地图

www.amazon.com 安全
IP地址: 13.225.150.180
国家: United States of America
地区: California
城市: Los Angeles
查看: Google 地图

wss.pollfish.com 安全
IP地址: 34.69.135.100
国家: United States of America
地区: Iowa
城市: Council Bluffs
查看: Google 地图

market.android.com 安全
IP地址: 142.250.68.78
国家: United States of America
地区: California
城市: Mountain View
查看: Google 地图

www.onbarcode.com 安全
IP地址: 47.90.243.155
国家: United States of America
地区: California
城市: San Mateo
查看: Google 地图

www.googletagmanager.com 安全
IP地址: 180.163.150.41
国家: China
地区: Shanghai
城市: Shanghai
查看: 高德地图

ssl.google-analytics.com 安全
IP地址: 180.163.150.169
国家: China
地区: Shanghai
城市: Shanghai
查看: 高德地图

www.starbucks.com 安全
IP地址: 23.222.168.30
国家: United States of America
地区: California
城市: El Segundo
查看: Google 地图

www.daisy.org 安全
IP地址: 65.52.139.180
国家: Netherlands
地区: Noord-Holland
城市: Amsterdam
查看: Google 地图

schemas.microsoft.com 安全
IP地址: 13.105.221.22
国家: United States of America
地区: Washington
城市: Redmond
查看: Google 地图

www.upcdatabase.org 安全
IP地址: 104.21.64.53
国家: United States of America
地区: California
城市: San Francisco
查看: Google 地图

android.revmob.com 安全
没有可用的地理位置信息。
i.ytimg.com 安全
IP地址: 142.250.217.150
国家: United States of America
地区: California
城市: Mountain View
查看: Google 地图

googleads.g.doubleclick.net 安全
IP地址: 180.163.150.38
国家: China
地区: Shanghai
城市: Shanghai
查看: 高德地图

www.openmobilealliance.org 安全
IP地址: 104.26.8.105
国家: United States of America
地区: California
城市: San Francisco
查看: Google 地图

revmob.com 安全
没有可用的地理位置信息。
www.idpf.org 安全
IP地址: 217.70.184.56
国家: France
地区: Ile-de-France
城市: Paris
查看: Google 地图

goo.gl 安全
IP地址: 142.250.176.14
国家: United States of America
地区: California
城市: Mountain View
查看: Google 地图

s3.amazonaws.com 安全
IP地址: 52.217.224.112
国家: United States of America
地区: Virginia
城市: Ashburn
查看: Google 地图

www.wapforum.org 安全
IP地址: 172.67.190.29
国家: United States of America
地区: California
城市: San Francisco
查看: Google 地图

手机号提取

URL链接分析

URL信息 源码文件
http://www.opensource.org/licenses/mit-license.php
http://bassistance.de/jquery-plugins/jquery-plugin-validation/
http://www.wapforum.org/DTD/xhtml-mobile10.dtd
http://www.apple.com/DTDs/PropertyList-1.0.dtd
http://projects.scottsplayground.com/iri/
http://sizzlejs.com/
http://jquery.org/license
http://projects.scottsplayground.com/email_address_validation/
http://www.gnu.org/licenses/gpl.html
自研引擎分析结果
https://www.amazon.com/appstore-error-help
com/amazon/android/framework/prompt/e.java
http://www.onbarcode.com
http://www.onbarcode.com/products/android_barcode/
com/onbarcode/barcode/android/LicenseInformation.java
https://developer.android.com/google/play-services/setup.html#ensure
com/pollfish/c/a.java
http://lbdb.pollfish.com:3000/notifier_api/v2/notices
http://lbdb.pollfish.com:3000
com/pollfish/f/b/a.java
javascript:pollfish.nativeaccess.losefocus(true
com/pollfish/g/a.java
https://wss.pollfish.com
com/pollfish/main/PollFish.java
data:image/jpg;base64
com/qbiki/feedback/FieldProcessing.java
http://www.upcdatabase.org/api/xml/30a634c9cad463a5e5d5c7afb2496ff2/
com/qbiki/modules/barcodescanner/BarcodeScannerFragment.java
https://graph.facebook.com/%1$s?fields=name,picture&accesstoken=%2$s
https://graph.facebook.com/%1$s/likes?limit=0&summary=1&accesstoken=%2$s
https://graph.facebook.com/%1$s/comments?limit=0&summary=1&accesstoken=%2$s
com/qbiki/modules/facebookfeeds/FeedsListFragment.java
data:image/png;base64
javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
javascript:document.getelementbyid('
com/qbiki/modules/favorites/Favorites.java
http://graph.facebook.com/
com/qbiki/modules/fbfanpage/FacebookFunPageFragment.java
javascript:karaokejsinterface.linetimesparsed(getlinetimes
com/qbiki/modules/karaoke/KaraokeFragment.java
http://www.wapforum.org/dtd/xhtml-mobile10.dtd
com/qbiki/modules/sharepoint/SPListViewAdapter.java
http://schemas.microsoft.com/sharepoint/soap/getlistcollection
http://schemas.microsoft.com/sharepoint/soap/getlistitems
http://schemas.microsoft.com/sharepoint/soap/getlistandview
http://schemas.microsoft.com/sharepoint/soap/getwebcollection
http://schemas.microsoft.com/sharepoint/soap/updatelistitems
http://schemas.microsoft.com/sharepoint/soap/getitem
http://schemas.microsoft.com/sharepoint/soap/copyintoitems
http://schemas.microsoft.com/sharepoint/soap/
com/qbiki/modules/sharepoint/SPServer.java
javascript:window.htmlout.showhtml(document.getelementbyid('fetch_balance').getelementsbytagname('span'
https://www.starbucks.com/card
com/qbiki/modules/starbucks/ViewCardActivity.java
http://market.android.com/details?id=
com/qbiki/seattleclouds/AppStarterActivity.java
http://s.ytimg.com/yt/m/cssbin/mobile-blazer-sprite
http://s.ytimg.com/yt/m/cssbin/mobile-swatch-sprite
http://s.ytimg.com/yt/cssbin/mobile-swatch-sprite
http://s.ytimg.com/yts/imgbin/mobile-nightshade
http://i.ytimg.com/vi/
javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
javascript:document.getelementbyid('
com/qbiki/seattleclouds/WebViewFragment.java
javascript:document.getelementbyid
com/qbiki/shoppingcart/ShoppingCart.java
http://revmob.com
com/revmob/client/InstallClientListener.java
https://android.revmob.com
http://revmob.com
com/revmob/client/RevMobClient.java
https://s3.amazonaws.com/www.revmob.com/revmob_i_agree_terms.txt
com/revmob/internal/HTTPHelper.java
http://www.daisy.org/z3986/2005/ncx/
nl/siegmann/epublib/epub/NCXDocument.java
http://purl.org/dc/elements/1.1/
http://www.idpf.org/2007/opf
nl/siegmann/epublib/epub/PackageDocumentBase.java
http://schemas.xmlsoap.org/soap/encoding/
http://schemas.xmlsoap.org/soap/envelope/
org/ksoap2/SoapEnvelope.java
http://www.wireless-village.org/csp
http://www.wireless-village.org/pa
http://www.wireless-village.org/trc
http://www.openmobilealliance.org/dtd/wv-csp
http://www.openmobilealliance.org/dtd/wv-pa
http://www.openmobilealliance.org/dtd/wv-trc
www.wireless-village.org
org/kxml2/wap/wv/WV.java
https://graph.facebook.com/%1$s/comments?limit=0&summary=1&accesstoken=%2$s
javascript:cordova.firedocumentevent('backbutton'
http://lbdb.pollfish.com:3000/notifier_api/v2/notices
https://www.googletagmanager.com
127.0.0.1
http://www.wireless-village.org/csp
https://s3.amazonaws.com/www.revmob.com/revmob_i_agree_terms.txt
javascript:document.getelementbyid('
javascript:cordova.firedocumentevent('searchbutton'
http://www.idpf.org/2007/opf
http://schemas.microsoft.com/sharepoint/soap/
http://market.android.com/details?id=
http://goo.gl/nafqqk
http://schemas.microsoft.com/sharepoint/soap/getitem
javascript:karaokejsinterface.linetimesparsed(getlinetimes
javascript:cordova.firedocumentevent('volumeupbutton'
http://schemas.microsoft.com/sharepoint/soap/updatelistitems
http://www.daisy.org/z3986/2005/ncx/
http://www.onbarcode.com
http://www.wireless-village.org/pa
https://graph.facebook.com/%1$s?fields=name,picture&accesstoken=%2$s
www.wireless-village.org
http://www.onbarcode.com/products/android_barcode/
http://schemas.xmlsoap.org/soap/encoding/
javascript:cordova.firedocumentevent('volumedownbutton'
https://www.amazon.com/appstore-error-help
http://revmob.com
http://hostname/?
https://graph.facebook.com/
http://schemas.microsoft.com/sharepoint/soap/copyintoitems
http://schemas.xmlsoap.org/soap/envelope/
http://www.wapforum.org/dtd/xhtml-mobile10.dtd
http://schemas.microsoft.com/sharepoint/soap/getwebcollection
data:image/jpg;base64
javascript:try{cordova.firedocumentevent('pause');}catch(e){console.log('exception
http://schemas.microsoft.com/sharepoint/soap/getlistandview
http://i.ytimg.com/vi/
javascript:cordova.firedocumentevent('menubutton'
javascript:window.htmlout.showhtml(document.getelementbyid('fetch_balance').getelementsbytagname('span'
javascript:document.getelementbyid('rsstable').contentwindow.document.getelementbyid('
javascript:try{cordova.firedocumentevent('resume');}catch(e){console.log('exception
http://s.ytimg.com/yts/imgbin/mobile-nightshade
http://lbdb.pollfish.com:3000
javascript:pollfish.nativeaccess.losefocus(true
http://s.ytimg.com/yt/m/cssbin/mobile-swatch-sprite
http://schemas.microsoft.com/sharepoint/soap/getlistcollection
http://purl.org/dc/elements/1.1/
javascript:afma_receivemessage('
https://developer.android.com/google/play-services/setup.html#ensure
http://plus.google.com/
http://schemas.microsoft.com/sharepoint/soap/getlistitems
javascript:document.getelementbyid
https://www.starbucks.com/card
http://www.openmobilealliance.org/dtd/wv-trc
http://cdv_exec/
javascript:try{cordova.require('cordova/channel').ondestroy.fire();}catch(e){console.log('exception
http://www.openmobilealliance.org/dtd/wv-csp
http://www.openmobilealliance.org/dtd/wv-pa
http://graph.facebook.com/
http://s.ytimg.com/yt/m/cssbin/mobile-blazer-sprite
data:image/png;base64
http://s.ytimg.com/yt/cssbin/mobile-swatch-sprite
https://api.facebook.com/restserver.php
https://graph.facebook.com/%1$s/likes?limit=0&summary=1&accesstoken=%2$s
http://www.wireless-village.org/trc
http://developers.facebook.com/docs/reference/rest/
https://m.facebook.com/dialog/
https://wss.pollfish.com
https://android.revmob.com
http://www.upcdatabase.org/api/xml/30a634c9cad463a5e5d5c7afb2496ff2/
自研引擎分析结果

Firebase配置检测

邮箱地址提取

EMAIL 源码文件
dimame032@gmail.com
com/qbiki/modules/order/OrderFragment.java
example@mail.com
com/qbiki/modules/product/order/POGeneralInfo.java
dimame032@gmail.com
example@mail.com
myemail@mail.com
自研引擎分析结果

第三方追踪器

敏感凭证泄露

已显示 22 个secrets
1、 谷歌地图的 "com.google.android.maps.v2.API_KEY" : "@string/google_maps_v2_api_key"
2、 "username" : "hbkeah14"
3、 "fb_api_key" : "268726946654893"
4、 "google_maps_api_key" : "0jbe4NyXN3WOAa8Mit_l5WwllH9gK_llPyfn_mg"
5、 "google_maps_v2_api_key" : "AIzaSyDv34iCTHltLaJP70MvYckYMNBeb3zUJoA"
6、 "app_licensing_public_key" : ""
7、 "sc_api_key" : "s1w3W2h8SzoZOUMuZM6D9Urw0jo9B5tBz2SdLctURECajJCnYt"
8、 "auth_client_requested_by_msg" : "%1$sによるリクエスト"
9、 "auth_client_using_bad_version_title" : "កម្មវិធី​​​ព្យាយាម​ប្រើ​កំណែ​មិនល្អ​របស់​សេវា​កម្ម​ឃ្លាំ​កម្មវិធី។"
10、 "auth_client_needs_enabling_title" : "កម្មវិធី​ទាមទារ​​បើក​សេវាកម្ម​ឃ្លាំង​កម្មវិធី។"
11、 "auth_client_needs_installation_title" : "កម្មវិធី​ទាមទារ​ការ​ដំឡើង​សេវាកម្ម​ឃ្លាំង​កម្មវិធី។"
12、 "auth_client_requested_by_msg" : "「%1$s」提出要求"
13、 "auth_client_requested_by_msg" : "由“%1$s”发出"
14、 "auth_client_requested_by_msg" : "提出要求的應用程式:%1$s"
15、 Y29tLmFuZHJvaWQudmVuZGluZy5saWNlbnNpbmcuSUxpY2Vuc2luZ1NlcnZpY2U=
16、 30a634c9cad463a5e5d5c7afb2496ff2
17、 3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2f
18、 30820268308201d102044a9c4610300d06092a864886f70d0101040500307a310b3009060355040613025553310b3009060355040813024341311230100603550407130950616c6f20416c746f31183016060355040a130f46616365626f6f6b204d6f62696c653111300f060355040b130846616365626f6f6b311d301b0603550403131446616365626f6f6b20436f72706f726174696f6e3020170d3039303833313231353231365a180f32303530303932353231353231365a307a310b3009060355040613025553310b3009060355040813024341311230100603550407130950616c6f20416c746f31183016060355040a130f46616365626f6f6b204d6f62696c653111300f060355040b130846616365626f6f6b311d301b0603550403131446616365626f6f6b20436f72706f726174696f6e30819f300d06092a864886f70d010101050003818d0030818902818100c207d51df8eb8c97d93ba0c8c1002c928fab00dc1b42fca5e66e99cc3023ed2d214d822bc59e8e35ddcf5f44c7ae8ade50d7e0c434f500e6c131f4a2834f987fc46406115de2018ebbb0d5a3c261bd97581ccfef76afc7135a6d59e8855ecd7eacc8f8737e794c60a761c536b72b11fac8e603f5da1a2d54aa103b8a13c0dbc10203010001300d06092a864886f70d0101040500038181005ee9be8bcbb250648d3b741290a82a1c9dc2e76a0af2f2228f1d9f9c4007529c446a70175c5a900d5141812866db46be6559e2141616483998211f4a673149fb2232a10d247663b26a9031e15f84bc1c74d141ff98a02d76f85b2c8ab2571b6469b232d8e768a7f7ca04f7abe4a775615916c07940656b58717457b42bd928a2
19、 boundary=3i2ndDfv2rTHiSisAbouNdArYfORhtTPEefj3q2f
20、 AIzaSyDcbnDqRozxjllddKHhKwfQEflvej1qd8A
21、 E213051E4666E9872FA6F50E57A3102C
22、 8288f9f5ef393b70d5121604a25da736

字符串信息

建议导出为TXT,方便查看。

活动列表

第三方SDK

SDK名称 开发者 描述信息
File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。

文件列表

    污点分析

    当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
    规则名称 描述信息 操作
    病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
    漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
    隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
    密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
    Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析