温馨提示:本平台仅供研究软件风险、安全评估,禁止用于非法用途。由于展示的数据过于全面,请耐心等待加载完成。如有疑问或建议, 可加入我们的微信群讨论

APP评分

病毒检测 11 个厂商报毒

安全评分

文件信息

文件名称 921b6cd7bb547adc012f9b5791a73ec169770c6f55d005872251e186428d7f1f.apk
文件大小 10.79MB
MD5 2605738f37f8ddb81288799ddcbfcbe8
SHA1 3a9f7c3766696f6470463522b068f43bf2e761ac
SHA256 921b6cd7bb547adc012f9b5791a73ec169770c6f55d005872251e186428d7f1f

应用信息

应用名称 Maxcredito
包名 com.maxcredito.mexico.fast.cash.prestamo.loan
主活动 com.xinmi.android.moneed.guide.SplashActivity
目标SDK 30     最小SDK 21
版本号 1.2.1     子版本号 21
加固信息 未加壳

组件导出信息

反编译代码

Manifest文件 查看
APK文件 下载
Java源代码 查看 -- 下载

证书信息

二进制文件已签名
v1 签名: True
v2 签名: True
v3 签名: True
v4 签名: False
主题: CN=xgo
签名算法: rsassa_pkcs1v15
有效期自: 2019-02-26 10:23:13+00:00
有效期至: 2044-02-20 10:23:13+00:00
发行人: CN=xgo
序列号: 0x1ef87ffc
哈希算法: sha256
证书MD5: c99e6f994d58f71edc7dcf8af7b52689
证书SHA1: 58453a4b95f91068b391bc7a1288888bd66d16c8
证书SHA256: b1cd96db35893fb39e7568d9eb5f3e54ec958c17a2923b1334a25fd72ad177d3
证书SHA512: 8d78b9e31ab3aea2cbc31e63641f31a6207ef3831962a66877fbad7c8e9ab19ec40df9b14072bb495f3853a58b00a3b8db118845e05efbd5dfc4f466f53dec5e
公钥算法: rsa
密钥长度: 2048
指纹: fc647c268592e78c58a12f3a884c95952fe6fab8f5d0eb0a40edabc482146ee5
找到 1 个唯一证书

应用程序权限

权限名称 安全等级 权限内容 权限描述 关联代码
android.permission.ACCESS_WIFI_STATE 普通 查看Wi-Fi状态 允许应用程序查看有关Wi-Fi状态的信息。
android.permission.CHANGE_WIFI_STATE 危险 改变Wi-Fi状态 允许应用程序改变Wi-Fi状态。
android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
android.permission.READ_EXTERNAL_STORAGE 危险 读取SD卡内容 允许应用程序从SD卡读取信息。
android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
android.permission.READ_PHONE_STATE 危险 读取手机状态和标识 允许应用程序访问设备的手机功能。有此权限的应用程序可确定此手机的号码和序列号,是否正在通话,以及对方的号码等。
android.permission.CAMERA 危险 拍照和录制视频 允许应用程序拍摄照片和视频,且允许应用程序收集相机在任何时候拍到的图像。
android.permission.ACCESS_FINE_LOCATION 危险 获取精确位置 通过GPS芯片接收卫星的定位信息,定位精度达10米以内。恶意程序可以用它来确定您所在的位置。
android.permission.ACCESS_COARSE_LOCATION 危险 获取粗略位置 通过WiFi或移动基站的方式获取用户错略的经纬度信息,定位精度大概误差在30~1500米。恶意程序可以用它来确定您的大概位置。
android.permission.READ_CONTACTS 危险 读取联系人信息 允允许应用程序读取您手机上存储的所有联系人(地址)数据。恶意应用程序可借此将您的数据发送给其他人。
android.permission.WRITE_CONTACTS 危险 写入联系人信息 允许应用程序修改您手机上存储的联系人(地址)数据。恶意应用程序可借此清除或修改您的联系人数据。
android.permission.VIBRATE 普通 控制振动器 允许应用程序控制振动器,用于消息通知振动功能。
android.permission.REQUEST_INSTALL_PACKAGES 危险 允许安装应用程序 Android8.0 以上系统允许安装未知来源应用程序权限。
android.permission.QUERY_ALL_PACKAGES 普通 获取已安装应用程序列表 Android 11引入与包可见性相关的权限,允许查询设备上的任何普通应用程序,而不考虑清单声明。
android.permission.READ_SMS 危险 读取短信 允许应用程序读取您的手机或 SIM 卡中存储的短信。恶意应用程序可借此读取您的机密信息。
android.permission.READ_CALL_LOG 危险 读取通话记录 允许应用程序读取用户的通话记录
android.permission.WAKE_LOCK 危险 防止手机休眠 允许应用程序防止手机休眠,在手机屏幕关闭后后台进程仍然运行。
android.permission.RECORD_AUDIO 危险 获取录音权限 允许应用程序获取录音权限。
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE 普通 Google 定义的权限 由 Google 定义的自定义权限。
com.google.android.c2dm.permission.RECEIVE 普通 接收推送通知 允许应用程序接收来自云的推送通知。
android.permission.RECEIVE_BOOT_COMPLETED 普通 开机自启 允许应用程序在系统完成启动后即自行启动。这样会延长手机的启动时间,而且如果应用程序一直运行,会降低手机的整体速度。
android.permission.SYSTEM_ALERT_WINDOW 危险 弹窗 允许应用程序弹窗。 恶意程序可以接管手机的整个屏幕。
android.permission.FOREGROUND_SERVICE 普通 创建前台Service Android 9.0以上允许常规应用程序使用 Service.startForeground,用于podcast播放(推送悬浮播放,锁屏播放)

证书分析

高危
0
警告
1
信息
1
标题 严重程度 描述信息
已签名应用 信息 应用程序已使用代码签名证书进行签名

MANIFEST分析

高危
2
警告
10
信息
0
屏蔽
0
序号 问题 严重程度 描述信息 操作
1 应用程序可以安装在有漏洞的已更新 Android 版本上
Android 5.0-5.0.2, [minSdk=21]
信息 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
2 应用程序已启用明文网络流量
[android:usesCleartextTraffic=true]
警告 应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。
3 应用程序具有网络安全配置
[android:networkSecurityConfig=@xml/d]
信息 网络安全配置功能让应用程序可以在一个安全的,声明式的配置文件中自定义他们的网络安全设置,而不需要修改应用程序代码。这些设置可以针对特定的域名和特定的应用程序进行配置。
4 App 链接 assetlinks.json 文件未找到
[android:name=com.xinmi.android.moneed.ui.main.activity.MainActivity]
[android:host=https://maxcredito.app.link]
高危 App Link 资产验证 URL (https://maxcredito.app.link/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:200)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。
5 App 链接 assetlinks.json 文件未找到
[android:name=com.xinmi.android.moneed.ui.main.activity.MainActivity]
[android:host=https://maxcredito-alternate.app.link]
高危 App Link 资产验证 URL (https://maxcredito-alternate.app.link/.well-known/assetlinks.json) 未找到或配置不正确。(状态代码:200)。应用程序链接允许用户从 Web URL/电子邮件重定向到移动应用程序。如果此文件丢失或为 App Link 主机/域配置不正确,则恶意应用程序可以劫持此类 URL。这可能会导致网络钓鱼攻击,泄露 URI 中的敏感数据,例如 PII、OAuth 令牌、魔术链接/密码重置令牌等。您必须通过托管 assetlinks.json 文件并通过 Activity intent-filter 中的 [android:autoVerify=“true”] 启用验证来验证 App Link 网域。
6 Activity (com.xinmi.android.moneed.ui.main.activity.MainActivity) 未被保护。
存在一个intent-filter。
警告 发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。
7 Content Provider (com.facebook.FacebookContentProvider) 未被保护。
[android:exported=true]
警告 发现 Content Provider与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
8 Service (com.xinmi.android.moneed.push.MyFirebaseMessagingService) 未被保护。
存在一个intent-filter。
警告 发现 Service与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Service是显式导出的。
9 Activity (com.facebook.CustomTabActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
10 Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) 受权限保护, 但是应该检查权限的保护级别。
Permission: com.google.android.c2dm.permission.SEND
[android:exported=true]
警告 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。
11 Service (androidx.work.impl.background.systemjob.SystemJobService) 受权限保护, 但是应该检查权限的保护级别。
Permission: android.permission.BIND_JOB_SERVICE
[android:exported=true]
警告 发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。
12 Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) 受权限保护, 但是应该检查权限的保护级别。
Permission: android.permission.DUMP
[android:exported=true]
警告 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。
13 Broadcast Receiver (com.appsflyer.SingleInstallBroadcastReceiver) 未被保护。
[android:exported=true]
警告 发现 Broadcast Receiver与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
14 Service (com.google.android.play.core.assetpacks.AssetPackExtractionService) 未被保护。
[android:exported=true]
警告 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

可浏览的ACTIVITIES

ACTIVITY INTENT
com.xinmi.android.moneed.ui.main.activity.MainActivity Schemes: saef122a84://, maxcredito://, https://,
Hosts: open, maxcredito.app.link, maxcredito-alternate.app.link,
com.facebook.CustomTabActivity Schemes: fbconnect://,
Hosts: cct.com.maxcredito.mexico.fast.cash.prestamo.loan,

网络安全配置

高危
1
警告
0
信息
0
安全
0
序号 范围 严重级别 描述
1 *
基本配置不安全地配置为允许到所有域的明文流量。

API调用分析

API功能 源码文件
一般功能-> IPC通信
com/appsflyer/MultipleInstallBroadcastReceiver.java
com/appsflyer/SingleInstallBroadcastReceiver.java
com/appsflyer/internal/aa.java
com/appsflyer/internal/ab.java
com/appsflyer/internal/af.java
com/appsflyer/internal/ah.java
com/appsflyer/internal/ao.java
com/appsflyer/internal/b.java
com/appsflyer/internal/ba.java
com/appsflyer/internal/e.java
com/appsflyer/internal/f.java
com/appsflyer/share/CrossPromotionHelper.java
com/bigalan/common/R.java
com/bigalan/common/commonutils/IntentUtils$sendSms$smsToUri$1.java
com/bigalan/common/commonutils/IntentUtils$sendSms$smsToUri$2.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/SystemEventsBreadcrumbsIntegration.java
com/getmati/mati_sdk/ui/data_prefetch/DataPrefetchActivity$observeVerificationDataState$1.java
com/getmati/mati_sdk/ui/data_prefetch/DataPrefetchActivity.java
com/getmati/mati_sdk/ui/kyc/KYCActivity.java
com/getmati/mati_sdk/ui/permission_denial/PermissionDenialInfoFragment.java
com/getmati/mati_sdk/ui/start/StartVerificationFragment.java
com/hiii/mobile/track/R.java
com/sensorsdata/abtest/service/GlobalLoopService.java
com/sensorsdata/abtest/util/AlarmManagerUtils.java
com/xinmi/android/moneed/R.java
com/xinmi/android/moneed/base/AppBaseActivity.java
com/xinmi/android/moneed/base/AppBaseFragment.java
com/xinmi/android/moneed/camera/CameraActivity.java
com/xinmi/android/moneed/camera/CameraPortraitActivity.java
com/xinmi/android/moneed/coupon/activity/CouponsListActivity.java
com/xinmi/android/moneed/guide/SplashActivity.java
com/xinmi/android/moneed/library/R.java
com/xinmi/android/moneed/profile/flow/BorrowHistoryDetailActivity.java
com/xinmi/android/moneed/profile/flow/CashFlowDetailActivity.java
com/xinmi/android/moneed/push/MyFirebaseMessagingService.java
com/xinmi/android/moneed/ui/loan/activity/BankTransferRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/CashRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/CreditResultActivity.java
com/xinmi/android/moneed/ui/loan/activity/DeferRepayActivity.java
com/xinmi/android/moneed/ui/loan/activity/PayNetRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayLoanActivity$$ARouter$$Autowired.java
com/xinmi/android/moneed/ui/loan/activity/RepayLoanActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayMethodActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepaymentResultActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginEntranceActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginWithPasswordActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginWithSMSActivity.java
com/xinmi/android/moneed/ui/login/activity/RegisterFirstStepActivity.java
com/xinmi/android/moneed/ui/login/activity/RegisterSecondActivity.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordFirstStepActivity$$ARouter$$Autowired.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordFirstStepActivity.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordSecondStepActivity$$ARouter$$Autowired.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordSecondStepActivity.java
com/xinmi/android/moneed/ui/main/activity/MainActivity.java
com/xinmi/android/moneed/ui/main/activity/PermissionActivity.java
com/xinmi/android/moneed/ui/main/fragment/MyLoanFragment.java
com/xinmi/android/moneed/ui/main/fragment/MyProfileFragment.java
com/xinmi/android/moneed/ui/mine/activity/BankAccountInfoActivity.java
com/xinmi/android/moneed/ui/mine/activity/BindAccountActivity.java
com/xinmi/android/moneed/ui/mine/activity/EditUserInfoActivity.java
com/xinmi/android/moneed/ui/mine/activity/IDCardActivity.java
com/xinmi/android/moneed/ui/mine/activity/InviteFriendsActivity.java
com/xinmi/android/moneed/ui/mine/activity/InviteFriendsRulesActivity.java
com/xinmi/android/moneed/ui/mine/fragment/FamilyInfoEditFragment.java
com/xinmi/android/moneed/web/activity/WebActivity.java
com/xinmi/android/moneed/webprogress/RemoteWebIBinderPool.java
com/xinmi/android/moneed/webprogress/activity/WebProgressActivity.java
com/xinmi/android/moneed/webprogress/service/MainProWebViewBrigdeService.java
e/a/j/e/a.java
e/a/j/e/b.java
e/a/j/e/c.java
e/a/j/e/d.java
e/a/j/e/e.java
e/a/j/e/f.java
e/a0/c.java
e/a0/d.java
e/a0/g.java
e/b/d/i/a.java
e/b/d/i/g.java
e/b/d/i/h.java
e/b/d/i/m.java
e/b/e/b.java
e/d/a/d.java
e/d/a/e.java
e/d/a/f.java
e/d/a/g.java
e/d/a/h.java
e/d/b/e.java
e/f0/n0.java
e/h/d/r/t/i.java
e/l/a/c.java
e/l/a/e.java
e/l/a/f.java
e/l/a/h.java
e/l/a/i.java
e/l/a/n.java
e/l/l/h.java
e/l0/m/j/b/a.java
e/l0/m/j/b/b.java
e/l0/m/j/b/c.java
e/l0/m/j/b/d.java
e/l0/m/j/b/e.java
e/l0/m/k/f/a.java
e/l0/m/k/f/b.java
e/l0/m/k/f/c.java
e/l0/m/k/f/e.java
e/l0/m/k/f/f.java
e/r/a/h.java
e/v/a/a.java
e/w/b.java
e/y/f.java
f/c.java
g/a/a/a/b/b.java
g/b/a/b/h.java
g/b/a/b/o.java
g/d/a/l/e.java
g/g/a/b.java
g/g/a/i/a/a/n2/a/r.java
g/g/a/k/p/b.java
g/i/a/a/c.java
g/i/a/a/f.java
g/j/a/a/a.java
g/j/a/a/b.java
g/j/a/a/c.java
g/j/a/a/g/a.java
g/j/a/a/n/a.java
g/j/a/a/r/b/a/a.java
g/j/a/a/r/c/a/a.java
g/j/a/a/s/d0.java
g/j/a/a/s/h.java
g/j/a/a/s/i0/c.java
g/j/a/a/v/b.java
h/a/b/f0.java
h/a/b/i.java
h/a/b/k0/a.java
h/a/b/y.java
io/branch/referral/Branch.java
io/branch/referral/Defines$IntentKeys.java
io/branch/referral/Defines$Jsonkey.java
io/branch/referral/R.java
一般功能-> 文件操作
bolts/AggregateException.java
com/appsflyer/AFKeystoreWrapper.java
com/appsflyer/AFLogger.java
com/appsflyer/CreateOneLinkHttpTask.java
com/appsflyer/internal/aa.java
com/appsflyer/internal/ab.java
com/appsflyer/internal/ag.java
com/appsflyer/internal/ah.java
com/appsflyer/internal/ai.java
com/appsflyer/internal/am.java
com/appsflyer/internal/an.java
com/appsflyer/internal/ar.java
com/appsflyer/internal/bx.java
com/appsflyer/internal/bz.java
com/appsflyer/internal/d.java
com/appsflyer/internal/j.java
com/appsflyer/internal/m.java
com/appsflyer/share/LinkGenerator.java
com/bigalan/common/bean/AppInfo.java
com/bigalan/common/bean/CallLogInfo.java
com/bigalan/common/bean/ContactInfo.java
com/bigalan/common/bean/SmsInfo.java
com/bigalan/common/network/NoNetworkException.java
com/getmati/mati_sdk/sentry/io/sentry/CircularFifoQueue.java
com/getmati/mati_sdk/sentry/io/sentry/SynchronizedCollection.java
com/getmati/mati_sdk/sentry/io/sentry/UnknownPropertiesTypeAdapterFactory.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/AnrIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/AppComponentsBreadcrumbsIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/PhoneStateBreadcrumbsIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/SystemEventsBreadcrumbsIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/TempSensorBreadcrumbsIntegration.java
com/getmati/mati_sdk/server/Request.java
com/getmati/mati_sdk/server/RequestManager$request$3.java
com/getmati/mati_sdk/ui/camera/CameraFragment.java
com/getmati/mati_sdk/ui/camera/VideoCameraFragment.java
com/getmati/mati_sdk/ui/document/DocumentCameraFragment$itemPickResultLauncher$1$$special$$inlined$let$lambda$1.java
com/getmati/mati_sdk/ui/document/DocumentCameraFragment$onImageSaved$1.java
com/getmati/mati_sdk/ui/document/DocumentCameraFragment.java
com/getmati/mati_sdk/ui/document/DocumentHintFragment$itemPickResultLauncher$1$$special$$inlined$let$lambda$1.java
com/getmati/mati_sdk/ui/document/ProofOfResidenceHintFragment$itemPickResultLauncher$1$$special$$inlined$let$lambda$1.java
com/getmati/mati_sdk/ui/kyc/KYCActivity$onCreate$$inlined$let$lambda$1.java
com/getmati/mati_sdk/ui/kyc/KYCActivity.java
com/getmati/mati_sdk/ui/kyc/KycVm.java
com/getmati/mati_sdk/ui/liveness/LivenessFragment$onVideoSaved$1.java
com/getmati/mati_sdk/ui/liveness/LivenessFragment.java
com/getmati/mati_sdk/ui/liveness/VoiceLivenessFragment$onVideoSaved$1.java
com/getmati/mati_sdk/ui/liveness/VoiceLivenessFragment.java
com/getmati/mati_sdk/ui/selfie/SelfieCameraFragment$onImageSaved$1.java
com/getmati/mati_sdk/ui/selfie/SelfieCameraFragment.java
com/getmati/mati_sdk/ui/selfie/SelfiePreviewFragment.java
com/getmati/mati_sdk/ui/selfie/SelfieUploadFragment.java
com/getmati/mati_sdk/ui/utils/ImagePickerKt$copyContentToCache$2.java
com/getmati/mati_sdk/ui/utils/ImagePickerKt.java
com/sensorsdata/abtest/util/SPUtils.java
com/vdurmont/emoji/Emoji.java
com/vdurmont/emoji/EmojiLoader.java
com/vdurmont/emoji/EmojiManager.java
com/xinmi/android/moneed/api/ApiClient.java
com/xinmi/android/moneed/bean/AppInfo.java
com/xinmi/android/moneed/bean/BankCardData.java
com/xinmi/android/moneed/bean/BannerData.java
com/xinmi/android/moneed/bean/BaseLoanData.java
com/xinmi/android/moneed/bean/ContactInfo.java
com/xinmi/android/moneed/bean/CouponItemData.java
com/xinmi/android/moneed/bean/DeviceInfo.java
com/xinmi/android/moneed/bean/FeeData.java
com/xinmi/android/moneed/bean/HasBindAccountAndCard.java
com/xinmi/android/moneed/bean/LoanExtendData.java
com/xinmi/android/moneed/bean/LoanListData.java
com/xinmi/android/moneed/bean/ProductInfo.java
com/xinmi/android/moneed/bean/RegisterData.java
com/xinmi/android/moneed/bean/RepayInfoData.java
com/xinmi/android/moneed/bean/RepayInfoItem.java
com/xinmi/android/moneed/bean/ResetPasswordData.java
com/xinmi/android/moneed/bean/SmsInfo.java
com/xinmi/android/moneed/bean/UpgradeCreditInfoData.java
com/xinmi/android/moneed/bean/WindowInfoData.java
com/xinmi/android/moneed/bean/base/BaseResponse.java
com/xinmi/android/moneed/camera/CameraActivity.java
com/xinmi/android/moneed/camera/CameraPortraitActivity.java
com/xinmi/android/moneed/request/BaseRequest.java
com/xinmi/android/moneed/request/ContactItem.java
com/xinmi/android/moneed/ui/loan/activity/CreditResultActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayLoanActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayMethodActivity.java
com/xinmi/android/moneed/viewmodel/security/LoginViewModel.java
com/xinmi/android/moneed/viewmodel/security/RegisterViewModel.java
com/xinmi/android/moneed/widget/BirthdayInfoItemSelectView.java
com/xinmi/android/moneed/widget/CommonInfoItemGridSelectGridView.java
com/xinmi/android/moneed/widget/InfoItemEditView.java
com/xinmi/android/moneed/widget/InfoItemReviewView.java
com/xinmi/android/moneed/widget/InfoItemSelectView.java
e/b/c/a/a.java
e/b/e/b.java
e/b/e/u.java
e/b/e/w.java
e/c0/a/b.java
e/c0/a/c.java
e/c0/a/d.java
e/c0/a/g/a.java
e/e/b/j3.java
e/e/b/m3/o1/a.java
e/e/b/m3/o1/c.java
e/e/b/m3/o1/e.java
e/e/b/n3/l.java
e/g0/a/a/c.java
e/g0/a/a/d.java
e/g0/a/a/e.java
e/g0/a/a/i.java
e/j/a/b/h.java
e/j/a/b/q.java
e/j/c/a.java
e/j/c/b.java
e/j/c/d.java
e/l/b/e/a.java
e/l/b/e/b.java
e/l/b/e/c.java
e/l/b/e/d.java
e/l/b/e/f.java
e/l/c/g.java
e/l/c/i.java
e/l/c/k.java
e/l/c/l.java
e/l/c/m.java
e/l/c/n/a.java
e/l/j/j.java
e/l0/d.java
e/l0/m/l/p.java
e/q/a/a.java
e/r/a/a.java
e/r/a/h.java
e/r/a/p.java
e/r/a/v.java
e/t/b0.java
e/t/d.java
e/t/e0.java
e/u/a/a.java
e/u/a/b.java
e/x/a.java
e/x/b.java
e/y/l.java
e/y/p.java
e/z/j.java
e/z/l.java
e/z/m.java
e/z/n.java
g/a/a/a/a/c.java
g/a/a/a/d/a.java
g/a/a/a/d/d.java
g/b/a/b/a.java
g/b/a/b/e.java
g/b/a/b/r.java
g/b/a/f/a.java
g/b/a/g/d.java
g/b/a/i/b.java
g/d/a/b.java
g/d/a/i/a.java
g/d/a/i/b.java
g/d/a/i/c.java
g/d/a/k/a.java
g/d/a/k/b.java
g/d/a/k/f.java
g/d/a/k/i/a.java
g/d/a/k/i/b.java
g/d/a/k/i/c.java
g/d/a/k/i/e.java
g/d/a/k/i/g.java
g/d/a/k/i/h.java
g/d/a/k/i/i.java
g/d/a/k/i/j.java
g/d/a/k/i/k.java
g/d/a/k/i/l.java
g/d/a/k/i/m.java
g/d/a/k/i/n.java
g/d/a/k/i/o/a.java
g/d/a/k/i/o/c.java
g/d/a/k/i/o/e.java
g/d/a/k/j/b.java
g/d/a/k/j/d.java
g/d/a/k/j/f.java
g/d/a/k/j/g.java
g/d/a/k/j/t.java
g/d/a/k/j/y/a.java
g/d/a/k/j/y/b.java
g/d/a/k/j/y/d.java
g/d/a/k/j/y/e.java
g/d/a/k/j/z/b.java
g/d/a/k/k/a.java
g/d/a/k/k/b.java
g/d/a/k/k/c.java
g/d/a/k/k/d.java
g/d/a/k/k/e.java
g/d/a/k/k/f.java
g/d/a/k/k/r.java
g/d/a/k/k/s.java
g/d/a/k/k/t.java
g/d/a/k/k/v.java
g/d/a/k/k/w.java
g/d/a/k/k/x/a.java
g/d/a/k/k/x/b.java
g/d/a/k/l/a.java
g/d/a/k/l/d/a.java
g/d/a/k/l/d/b.java
g/d/a/k/l/d/c.java
g/d/a/k/l/d/d.java
g/d/a/k/l/d/g.java
g/d/a/k/l/d/h.java
g/d/a/k/l/d/k.java
g/d/a/k/l/d/n.java
g/d/a/k/l/d/p.java
g/d/a/k/l/d/q.java
g/d/a/k/l/d/r.java
g/d/a/k/l/d/t.java
g/d/a/k/l/d/v.java
g/d/a/k/l/g/a.java
g/d/a/k/l/g/b.java
g/d/a/k/l/h/c.java
g/d/a/k/l/h/i.java
g/d/a/k/l/i/a.java
g/d/a/q/a.java
g/d/a/q/c.java
g/d/a/q/d.java
g/d/a/q/h.java
g/g/a/i/a/a/a0.java
g/g/a/i/a/a/d0.java
g/g/a/i/a/a/d1.java
g/g/a/i/a/a/d2.java
g/g/a/i/a/a/e0.java
g/g/a/i/a/a/e2.java
g/g/a/i/a/a/h0.java
g/g/a/i/a/a/k0.java
g/g/a/i/a/a/k1.java
g/g/a/i/a/a/m2.java
g/g/a/i/a/a/n2/a/a0.java
g/g/a/i/a/a/n2/a/c0/d.java
g/g/a/i/a/a/n2/a/k.java
g/g/a/i/a/a/n2/a/m.java
g/g/a/i/a/a/n2/a/o.java
g/g/a/i/a/a/n2/a/r.java
g/g/a/i/a/a/n2/a/s.java
g/g/a/i/a/a/n2/a/t.java
g/g/a/i/a/a/n2/a/x.java
g/g/a/i/a/a/o1.java
g/g/a/i/a/a/p1.java
g/g/a/i/a/a/r1.java
g/g/a/i/a/a/r2/b.java
g/g/a/i/a/a/r2/e.java
g/g/a/i/a/a/r2/g.java
g/g/a/i/a/a/r2/j.java
g/g/a/i/a/a/s0.java
g/g/a/i/a/a/s1.java
g/g/a/i/a/a/u1.java
g/g/a/i/a/a/y1.java
g/g/a/j/b.java
g/g/a/k/f/a.java
g/g/a/k/p/d.java
g/g/a/k/p/e.java
g/j/a/a/g/c/a.java
g/j/a/a/g/c/b.java
g/j/a/a/o/a/a.java
g/j/a/a/o/a/b.java
g/j/a/a/r/a/b/a.java
g/j/a/a/r/c/a/a.java
g/j/a/a/s/f.java
g/j/a/a/s/g0.java
g/j/a/a/t/f/f.java
h/a/a/b.java
h/a/b/a0.java
h/a/b/g.java
h/a/b/h0.java
h/a/b/i0/a.java
h/a/b/k.java
h/a/b/l.java
h/a/b/p.java
h/a/b/r.java
h/a/b/y.java
h/c/d/a/b/b.java
h/c/e/a.java
io/socket/utf8/UTF8Exception.java
j/y/a.java
j/y/b.java
j/y/c.java
j/y/e.java
k/a/h3/k.java
l/a0.java
l/b.java
l/b0.java
l/c.java
l/c0.java
l/e.java
l/f.java
l/g0/a.java
l/g0/c.java
l/g0/e/a.java
l/g0/e/b.java
l/g0/e/d.java
l/g0/f/a.java
l/g0/f/b.java
l/g0/f/c.java
l/g0/f/e.java
l/g0/f/f.java
l/g0/g/a.java
l/g0/g/b.java
l/g0/g/c.java
l/g0/g/g.java
l/g0/g/j.java
l/g0/g/k.java
l/g0/h/a.java
l/g0/i/b.java
l/g0/i/c.java
l/g0/i/d.java
l/g0/i/e.java
l/g0/i/f.java
l/g0/i/g.java
l/g0/i/h.java
l/g0/i/i.java
l/g0/i/j.java
l/g0/j/a.java
l/g0/j/f.java
l/g0/k/a.java
l/g0/m/a.java
l/g0/m/c.java
l/g0/m/d.java
l/p.java
l/q.java
l/r.java
l/u.java
l/w.java
l/x.java
l/y.java
m/a.java
m/b.java
m/c.java
m/d.java
m/e.java
m/f.java
m/g.java
m/h.java
m/i.java
m/j.java
m/k.java
m/l.java
m/m.java
m/p.java
m/q.java
m/r.java
o/c/e/a.java
p/a/a/b.java
p/a/a/c.java
p/a/a/d.java
p/a/a/e.java
top/zibin/luban/Checker.java
调用java反射机制
com/appsflyer/MultipleInstallBroadcastReceiver.java
com/appsflyer/internal/ac.java
com/appsflyer/internal/ah.java
com/appsflyer/internal/al.java
com/appsflyer/internal/b.java
com/appsflyer/internal/ba.java
com/appsflyer/internal/bp.java
com/appsflyer/internal/d.java
com/appsflyer/oaid/OaidClient.java
com/bigalan/common/commonwidget/ExpandableTextView.java
com/getmati/mati_sdk/sentry/io/sentry/UnknownPropertiesTypeAdapterFactory.java
com/sensorsdata/abtest/SensorsABTest.java
com/sensorsdata/abtest/util/AppInfoUtils.java
com/xinmi/android/moneed/push/MyFirebaseMessagingService.java
com/xinmi/android/moneed/util/AppCrashHandler.java
com/zhpan/bannerview/provider/ScrollDurationManger.java
e/a0/h.java
e/b/a/d.java
e/b/a/g.java
e/b/e/h0.java
e/b/e/m.java
e/b/e/p.java
e/d0/a.java
e/e/a/e/l2/o/f.java
e/e/b/n3/m/b.java
e/e0/a.java
e/f0/b.java
e/f0/b0.java
e/f0/c0.java
e/f0/g.java
e/f0/i.java
e/f0/l0.java
e/h/d/k/p.java
e/h/d/p/s0.java
e/h0/a.java
e/j/a/b/g.java
e/j/a/b/l.java
e/j/a/b/r.java
e/j/a/b/s.java
e/l/a/c.java
e/l/a/e.java
e/l/a/i.java
e/l/a/j.java
e/l/b/e/f.java
e/l/c/g.java
e/l/c/h.java
e/l/c/i.java
e/l/c/j.java
e/l/c/l.java
e/l/c/n/a.java
e/l/c/n/e.java
e/l/i/b.java
e/l/k/g.java
e/l/k/g0.java
e/l/k/h.java
e/l/k/x.java
e/l/k/y.java
e/l/l/c.java
e/l/l/g.java
e/l/l/h.java
e/l0/e.java
e/l0/l.java
e/l0/m/e.java
e/l0/m/m/b.java
e/r/a/g.java
e/r/a/r.java
e/t/c.java
e/t/t.java
e/w/d.java
e/x/a.java
e/y/p.java
g/a/a/a/a/a.java
g/a/a/a/a/c.java
g/a/a/a/d/a.java
g/b/a/b/y.java
g/d/a/b.java
g/g/a/i/a/a/n2/a/o.java
g/g/a/i/a/a/n2/a/y.java
g/j/a/a/r/c/a/a.java
h/a/b/f0.java
h/a/b/g.java
h/a/b/i.java
h/a/b/m.java
h/a/b/o.java
h/a/b/q.java
io/branch/referral/Branch.java
j/w/g/a/e.java
j/w/g/a/g.java
j/x/a.java
j/x/b.java
j/z/c/w.java
k/a/f3/a/c.java
k/a/h3/b0.java
k/a/h3/e.java
k/a/h3/k.java
k/a/h3/l.java
k/a/z.java
l/g0/c.java
l/g0/j/a.java
l/g0/j/b.java
l/g0/j/c.java
l/g0/j/d.java
l/g0/j/e.java
l/g0/j/f.java
n/a/a/n.java
n/a/a/o.java
n/a/a/q/a.java
网络通信-> SSL证书处理
一般功能-> 获取系统服务(getSystemService)
com/appsflyer/internal/ad.java
com/appsflyer/internal/ah.java
com/appsflyer/internal/b.java
com/appsflyer/internal/u.java
com/appsflyer/internal/v.java
com/appsflyer/internal/y.java
com/getmati/mati_sdk/analytics/WSTracker.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/PhoneStateBreadcrumbsIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/TempSensorBreadcrumbsIntegration.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/util/ConnectivityChecker.java
com/getmati/mati_sdk/ui/camera/CameraFragment.java
com/getmati/mati_sdk/ui/kyc/KYCActivity.java
com/getmati/mati_sdk/ui/phonevalidation/PhoneInputFragment.java
com/getmati/mati_sdk/ui/phonevalidation/SelectPhoneCodeFragment$onViewCreated$$inlined$let$lambda$1.java
com/sensorsdata/abtest/util/AlarmManagerUtils.java
com/xinmi/android/moneed/camera/CameraActivity.java
com/xinmi/android/moneed/camera/CameraPortraitActivity.java
com/xinmi/android/moneed/profile/flow/CashFlowDetailActivity.java
com/xinmi/android/moneed/ui/loan/activity/BankTransferRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/CashRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/PayNetRepaymentActivity.java
com/xinmi/android/moneed/ui/mine/activity/CLABEInfoActivity.java
com/xinmi/android/moneed/ui/mine/activity/InviteFriendsActivity.java
e/b/a/i.java
e/b/d/d.java
e/b/d/i/j.java
e/b/e/e0.java
e/b/e/f0.java
e/b/e/i.java
e/b/e/k.java
e/e/a/e/c2.java
e/e/a/e/l2/n.java
e/e/d/s.java
e/h/d/g/a.java
e/l/a/d.java
e/l/a/j.java
e/l/g/j.java
e/l/k/x.java
e/l0/m/j/b/a.java
e/l0/m/j/c/b.java
e/l0/m/k/f/e.java
e/l0/m/m/g.java
e/m/a/c.java
e/n/a/a.java
g/b/a/a/c.java
g/b/a/b/d.java
g/b/a/b/i.java
g/b/a/b/l.java
g/b/a/b/n.java
g/b/a/b/o.java
g/b/a/b/u.java
g/d/a/l/e.java
g/d/a/o/h/i.java
g/g/a/i/a/a/n2/a/j.java
g/g/a/i/a/a/n2/a/r.java
g/g/a/k/n/b.java
g/g/a/l/b.java
g/i/a/a/l.java
g/j/a/a/f/a.java
g/j/a/a/s/i0/c.java
g/j/a/a/s/v.java
g/j/a/a/s/w.java
h/a/b/f0.java
h/a/b/k.java
o/a/d.java
o/c/a.java
网络通信-> HTTP建立连接
网络通信-> TCP套接字
网络通信-> URLConnection com/getmati/mati_sdk/server/RequestManager$request$3.java
com/getmati/mati_sdk/ui/kyc/KYCActivity$onCreate$$inlined$let$lambda$1.java
g/g/a/i/a/a/r2/e.java
网络通信-> HTTPS建立连接
组件-> 启动 Activity
com/appsflyer/share/CrossPromotionHelper.java
com/getmati/mati_sdk/ui/data_prefetch/DataPrefetchActivity$observeVerificationDataState$1.java
com/getmati/mati_sdk/ui/permission_denial/PermissionDenialInfoFragment.java
com/getmati/mati_sdk/ui/start/StartVerificationFragment.java
com/xinmi/android/moneed/coupon/activity/CouponsListActivity.java
com/xinmi/android/moneed/guide/SplashActivity.java
com/xinmi/android/moneed/profile/flow/BorrowHistoryDetailActivity.java
com/xinmi/android/moneed/profile/flow/CashFlowDetailActivity.java
com/xinmi/android/moneed/ui/loan/activity/BankTransferRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/CashRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/CreditResultActivity.java
com/xinmi/android/moneed/ui/loan/activity/DeferRepayActivity.java
com/xinmi/android/moneed/ui/loan/activity/PayNetRepaymentActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayLoanActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepayMethodActivity.java
com/xinmi/android/moneed/ui/loan/activity/RepaymentResultActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginEntranceActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginWithPasswordActivity.java
com/xinmi/android/moneed/ui/login/activity/LoginWithSMSActivity.java
com/xinmi/android/moneed/ui/login/activity/RegisterFirstStepActivity.java
com/xinmi/android/moneed/ui/login/activity/RegisterSecondActivity.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordFirstStepActivity.java
com/xinmi/android/moneed/ui/login/activity/ResetPasswordSecondStepActivity.java
com/xinmi/android/moneed/ui/main/activity/MainActivity.java
com/xinmi/android/moneed/ui/main/activity/PermissionActivity.java
com/xinmi/android/moneed/ui/main/fragment/MyLoanFragment.java
com/xinmi/android/moneed/ui/main/fragment/MyProfileFragment.java
com/xinmi/android/moneed/ui/mine/activity/BindAccountActivity.java
com/xinmi/android/moneed/ui/mine/activity/EditUserInfoActivity.java
com/xinmi/android/moneed/ui/mine/activity/IDCardActivity.java
com/xinmi/android/moneed/ui/mine/activity/InviteFriendsActivity.java
com/xinmi/android/moneed/ui/mine/activity/InviteFriendsRulesActivity.java
com/xinmi/android/moneed/web/activity/WebActivity.java
com/xinmi/android/moneed/webprogress/activity/WebProgressActivity.java
e/b/d/i/h.java
e/d/a/e.java
e/l/a/f.java
e/l/a/n.java
e/r/a/h.java
g/a/a/a/b/b.java
g/b/a/b/h.java
g/b/a/b/o.java
g/g/a/b.java
g/j/a/a/g/a.java
g/j/a/a/n/a.java
g/j/a/a/r/b/a/a.java
g/j/a/a/r/c/a/a.java
g/j/a/a/s/d0.java
g/j/a/a/s/h.java
g/j/a/a/s/i0/c.java
h/a/b/k0/a.java
io/branch/referral/Branch.java
DEX-> 动态加载
DEX-> 加载和操作Dex文件 e/x/a.java
g/a/a/a/d/a.java
加密解密-> Crypto加解密组件
组件-> 启动 Service
隐私数据-> 读写通讯录 g/j/a/a/s/q.java
加密解密-> 信息摘要算法
一般功能-> 获取活动网路信息
加密解密-> Base64 加密
加密解密-> Base64 解密
进程操作-> 获取进程pid
隐私数据-> 剪贴板数据读写操作
一般功能-> 查询数据库(短信、联系人、通话记录、浏览器历史等)
网络通信-> WebView JavaScript接口
网络通信-> WebView 相关
JavaScript 接口方法 g/j/a/a/u/a.java
g/j/a/a/v/d.java
辅助功能accessibility相关 e/l/k/a.java
e/l/k/h0/c.java
隐私数据-> 获取已安装的应用程序
一般功能-> Android通知 g/b/a/b/o.java
隐私数据-> 获取GPS位置信息
一般功能-> 查看\修改Android系统属性 com/appsflyer/internal/ah.java
h/a/b/g.java
一般功能-> 获取网络接口信息 com/appsflyer/internal/ah.java
h/a/b/f0.java
网络通信-> WebView GET请求 h/a/b/l.java
进程操作-> 杀死进程 g/b/a/a/c.java
g/g/a/e/a.java
一般功能-> 获取Android广告ID com/appsflyer/internal/ac.java
com/appsflyer/oaid/OaidClient.java
一般功能-> 传感器相关操作 com/appsflyer/internal/ad.java
com/appsflyer/internal/b.java
com/getmati/mati_sdk/sentry/io/sentry/android/core/TempSensorBreadcrumbsIntegration.java
命令执行-> getRuntime.exec() g/g/a/i/a/a/n2/a/c0/d.java
设备指纹-> 查看本机IMSI g/j/a/a/s/v.java
设备指纹-> 查看本机SIM卡序列号 g/j/a/a/s/v.java
设备指纹-> getSimOperator com/appsflyer/internal/u.java
g/j/a/a/s/v.java
g/j/a/a/s/w.java
设备指纹-> 查看运营商信息 com/appsflyer/internal/u.java
g/j/a/a/s/v.java
g/j/a/a/s/w.java
隐私数据-> 录制视频 com/getmati/mati_sdk/ui/media/MediaUtilsKt$captureVideoAsync$1.java
敏感行为-> 检测了是否被jdb调试 g/g/a/i/a/a/n2/a/j.java
进程操作-> 获取运行的进程\服务 g/j/a/a/f/a.java
隐私数据-> 录制音频行为 e/e/b/j3.java
组件-> ContentProvider razerdp/basepopup/BasePopupInitializer.java
一般功能-> 获取WiFi相关信息 g/b/a/b/i.java
隐私数据-> 屏幕截图,截取自己应用内部界面 com/xinmi/android/moneed/camera/cropper/CropOverlayView.java

源代码分析

高危
4
警告
9
信息
3
安全
2
屏蔽
0
序号 问题 等级 参考标准 文件位置 操作
1 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3
com/appsflyer/AFLogger.java
com/bigalan/common/commonutils/SmsCodeDetector.java
com/bigalan/common/commonwidget/EmailAutoCompleteTextView.java
com/contrarywind/view/WheelView.java
com/getmati/mati_sdk/ui/camera/CameraFragment.java
com/getmati/mati_sdk/ui/kyc/KYCActivity$onCreate$$inlined$let$lambda$1.java
com/getmati/mati_sdk/ui/media/MediaUtilsKt$captureVideoAsync$1.java
com/getmati/mati_sdk/ui/media/MediaUtilsKt$photoPreviewAsync$2.java
com/sensorsdata/abtest/SensorsABTest.java
com/sensorsdata/abtest/core/SABErrorDispatcher.java
com/sensorsdata/abtest/core/SensorsABTestApiRequestHelper.java
com/sensorsdata/abtest/core/SensorsABTestCacheManager.java
com/sensorsdata/abtest/core/SensorsABTestH5Helper.java
com/sensorsdata/abtest/core/SensorsABTestHelper.java
com/sensorsdata/abtest/core/SensorsABTestSchemeHandler.java
com/sensorsdata/abtest/core/SensorsABTestTrackHelper.java
com/sensorsdata/abtest/entity/Experiment.java
com/sensorsdata/abtest/entity/ExperimentRequest.java
com/sensorsdata/abtest/service/GlobalLoopService.java
com/sensorsdata/abtest/util/AppInfoUtils.java
com/sensorsdata/abtest/util/UrlUtil.java
e/a0/f.java
e/a0/g.java
e/b/a/d.java
e/b/a/g.java
e/b/a/i.java
e/b/b/a/a.java
e/b/d/i/h.java
e/b/e/b.java
e/b/e/c0.java
e/b/e/e0.java
e/b/e/f0.java
e/b/e/h0.java
e/b/e/i.java
e/b/e/m.java
e/b/e/p.java
e/b/e/t.java
e/b/e/w.java
e/b/e/x.java
e/c0/a/c.java
e/e/b/n3/m/b.java
e/e/b/x2.java
e/e0/a.java
e/f0/c0.java
e/f0/g.java
e/f0/l0.java
e/g0/a/a/i.java
e/h/d/g/c.java
e/h/d/g/g.java
e/h/d/o/g.java
e/h/d/p/s0.java
e/h/d/r/t/n.java
e/j/a/a/c.java
e/j/a/b/a.java
e/j/a/b/d.java
e/j/a/b/f.java
e/j/a/b/g.java
e/j/a/b/h.java
e/j/a/b/i.java
e/j/a/b/k.java
e/j/a/b/l.java
e/j/a/b/m.java
e/j/a/b/n.java
e/j/a/b/q.java
e/j/a/b/r.java
e/j/a/b/s.java
e/j/a/b/t.java
e/j/b/d.java
e/j/b/j/d.java
e/j/c/a.java
e/j/c/b.java
e/j/c/d.java
e/l/a/c.java
e/l/a/e.java
e/l/a/f.java
e/l/a/i.java
e/l/a/n.java
e/l/b/e/a.java
e/l/b/e/b.java
e/l/b/e/f.java
e/l/c/e.java
e/l/c/g.java
e/l/c/h.java
e/l/c/i.java
e/l/c/l.java
e/l/c/m.java
e/l/c/n/a.java
e/l/c/n/e.java
e/l/g/d.java
e/l/g/i.java
e/l/i/b.java
e/l/k/b0.java
e/l/k/g0.java
e/l/k/h.java
e/l/k/h0/c.java
e/l/k/j.java
e/l/k/x.java
e/l/k/y.java
e/l/l/c.java
e/l/l/g.java
e/l/l/h.java
e/l/l/i.java
e/l0/d.java
e/l0/f.java
e/n/a/c.java
e/q/a/a.java
e/r/a/a.java
e/r/a/b.java
e/r/a/c.java
e/r/a/i.java
e/r/a/l.java
e/r/a/o.java
e/r/a/p.java
e/r/a/v.java
e/u/a/b.java
e/v/a/a.java
e/w/d.java
e/x/a.java
e/y/w/b.java
e/z/m.java
g/a/a/a/d/a.java
g/a/a/a/d/b.java
g/b/a/a/c.java
g/b/a/b/d.java
g/b/a/b/h.java
g/b/a/b/o.java
g/b/a/d/a.java
g/b/a/f/b.java
g/b/a/g/c.java
g/d/a/b.java
g/d/a/i/a.java
g/d/a/j/d.java
g/d/a/j/e.java
g/d/a/k/i/b.java
g/d/a/k/i/j.java
g/d/a/k/i/l.java
g/d/a/k/i/o/c.java
g/d/a/k/i/o/e.java
g/d/a/k/j/g.java
g/d/a/k/j/i.java
g/d/a/k/j/w.java
g/d/a/k/j/x/j.java
g/d/a/k/j/x/k.java
g/d/a/k/j/y/e.java
g/d/a/k/j/z/a.java
g/d/a/k/j/z/b.java
g/d/a/k/k/c.java
g/d/a/k/k/d.java
g/d/a/k/k/f.java
g/d/a/k/k/r.java
g/d/a/k/k/s.java
g/d/a/k/l/a.java
g/d/a/k/l/d/c.java
g/d/a/k/l/d/d.java
g/d/a/k/l/d/k.java
g/d/a/k/l/d/l.java
g/d/a/k/l/d/p.java
g/d/a/k/l/d/w.java
g/d/a/k/l/h/c.java
g/d/a/k/l/h/i.java
g/d/a/l/e.java
g/d/a/l/f.java
g/d/a/l/o.java
g/d/a/l/q.java
g/d/a/l/r.java
g/d/a/o/h/i.java
g/d/a/p/b.java
g/d/a/q/l/a.java
g/g/a/i/a/a/n2/a/l.java
g/i/a/a/e.java
g/j/a/a/g/c/b.java
g/j/a/a/s/q.java
g/j/a/a/w/d.java
g/k/a/f/a.java
h/a/b/r.java
n/a/a/f.java
o/a/d.java
o/b/a.java
p/a/a/d.java
razerdp/util/log/PopupLog.java
top/zibin/luban/Checker.java
2 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-6
3 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 警告 CWE: CWE-312: 明文存储敏感信息
OWASP Top 10: M9: Reverse Engineering
OWASP MASVS: MSTG-STORAGE-14
4 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
com/appsflyer/internal/aj.java
g/b/a/b/d.java
g/b/a/b/s.java
5 应用程序在加密算法中使用ECB模式。ECB模式是已知的弱模式,因为它对相同的明文块[UNK]产生相同的密文 高危 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-2
g/b/a/d/a.java
g/j/a/a/o/a/a.java
6 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它 信息
OWASP MASVS: MSTG-STORAGE-10
7 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 安全
OWASP MASVS: MSTG-NETWORK-4
g/b/a/g/c.java
l/g0/c.java
8 不安全的Web视图实现。可能存在WebView任意代码执行漏洞 警告 CWE: CWE-749: 暴露危险方法或函数
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-7
com/xinmi/android/moneed/ui/main/activity/PermissionActivity.java
com/xinmi/android/moneed/web/activity/WebActivity.java
com/xinmi/android/moneed/webprogress/activity/WebProgressActivity.java
9 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
OWASP Top 10: M3: Insecure Communication
OWASP MASVS: MSTG-NETWORK-3
com/xinmi/android/moneed/ui/main/activity/PermissionActivity.java
com/xinmi/android/moneed/web/activity/WebActivity.java
com/xinmi/android/moneed/webprogress/activity/WebProgressActivity.java
10 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
g/g/a/i/a/a/n2/a/r.java
g/j/a/a/g/c/a.java
11 该文件是World Writable。任何应用程序都可以写入文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
g/b/a/i/b.java
12 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击 高危 CWE: CWE-79: 在Web页面生成时对输入的转义处理不恰当('跨站脚本')
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-6
h/a/b/l.java
13 应用程序创建临时文件。敏感信息永远不应该被写进临时文件 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
e/q/a/a.java
14 此应用程序可能会请求root(超级用户)权限 警告 CWE: CWE-250: 以不必要的权限执行
OWASP MASVS: MSTG-RESILIENCE-1
g/g/a/i/a/a/n2/a/c0/d.java
15 此应用程序可能具有Root检测功能 安全
OWASP MASVS: MSTG-RESILIENCE-1
g/g/a/i/a/a/n2/a/c0/d.java
16 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 警告 CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
OWASP Top 10: M7: Client Code Quality
e/c0/a/g/a.java
17 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
com/appsflyer/internal/aj.java
18 应用程序可以写入应用程序目录。敏感信息应加密 信息 CWE: CWE-276: 默认权限不正确
OWASP MASVS: MSTG-STORAGE-14
g/b/a/f/a.java

动态库分析

No Shared Objects found.
序号 动态库 NX(堆栈禁止执行) STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)

文件分析

序号 问题 文件

VIRUSTOTAL扫描

  检出率: 11 / 67       完整报告

反病毒引擎 检出结果
Avast-Mobile APK:CRepMalware [PUP]
Avira ANDROID/SmsAgent.YLF.Gen
CAT-QuickHeal Android.SpyLoan.GEN49644 (PUP)
Cynet Malicious (score: 99)
ESET-NOD32 a variant of Android/Spy.Agent.CEA
F-Secure Malware.ANDROID/SmsAgent.YLF.Gen
Fortinet Android/Agent.CEA!tr
Google Detected
Ikarus Trojan-Spy.AndroidOS.Agent
Kaspersky not-a-virus:HEUR:RiskTool.AndroidOS.SpyLoan.bn
ZoneAlarm not-a-virus:HEUR:RiskTool.AndroidOS.SpyLoan.bn

滥用权限

恶意软件常用权限 14/30
android.permission.READ_PHONE_STATE
android.permission.CAMERA
android.permission.ACCESS_FINE_LOCATION
android.permission.ACCESS_COARSE_LOCATION
android.permission.READ_CONTACTS
android.permission.WRITE_CONTACTS
android.permission.VIBRATE
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.READ_SMS
android.permission.READ_CALL_LOG
android.permission.WAKE_LOCK
android.permission.RECORD_AUDIO
android.permission.RECEIVE_BOOT_COMPLETED
android.permission.SYSTEM_ALERT_WINDOW
其它常用权限 9/46
android.permission.ACCESS_WIFI_STATE
android.permission.CHANGE_WIFI_STATE
android.permission.INTERNET
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.READ_EXTERNAL_STORAGE
android.permission.ACCESS_NETWORK_STATE
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
com.google.android.c2dm.permission.RECEIVE
android.permission.FOREGROUND_SERVICE

恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。

IP地图

域名检测

域名 状态 中国境内 位置信息 解析
graph.s 安全
没有可用的地理位置信息。




sgcdsdk.s 安全
没有可用的地理位置信息。




api2.branch.io 安全
IP地址: 18.64.8.118
国家: 大韩民国
地区: 京畿道
城市: Icheon
查看: Google 地图





sstats.s 安全
没有可用的地理位置信息。




www.banxico.org.mx 安全
IP地址: 170.70.115.76
国家: 墨西哥
地区: 墨西哥城
城市: 墨西哥城
查看: Google 地图





media.getmati.com 安全
IP地址: 44.209.63.104
国家: 美利坚合众国
地区: 弗吉尼亚州
城市: 阿什本
查看: Google 地图





salasa.xcreditech.com 安全
IP地址: 142.250.207.1
国家: 南非
地区: 豪登省
城市: 约翰内斯堡
查看: Google 地图





schema.org 安全
IP地址: 142.250.207.1
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图





sattr.s 安全
没有可用的地理位置信息。




testhk10.xcreditech.com 安全
IP地址: 119.8.109.35
国家: 中国
地区: 香港
城市: 香港
查看: 高德地图





app-measurement.com 安全
IP地址: 180.163.150.161
国家: 中国
地区: 上海
城市: 上海
查看: 高德地图





sinapps.s 安全
没有可用的地理位置信息。




o566293.ingest.sentry.io 安全
IP地址: 34.120.195.249
国家: 美利坚合众国
地区: 密苏里州
城市: 堪萨斯城
查看: Google 地图





cdn.branch.io 安全
IP地址: 54.230.61.18
国家: 大韩民国
地区: 京畿道
城市: Icheon
查看: Google 地图





googlemobileadssdk.page.link 安全
IP地址: 142.250.207.1
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图





exoplayer.dev 安全
IP地址: 185.199.109.153
国家: 美利坚合众国
地区: 宾夕法尼亚
城市: 加利福尼亚
查看: Google 地图





graph-video.s 安全
没有可用的地理位置信息。




api.branch.io 安全
IP地址: 13.225.114.60
国家: 大韩民国
地区: 京畿道
城市: Icheon
查看: Google 地图





sadrevenue.s 安全
没有可用的地理位置信息。




sregister.s 安全
没有可用的地理位置信息。




goo.gle 安全
IP地址: 67.199.248.12
国家: 美利坚合众国
地区: 纽约
城市: 纽约市
查看: Google 地图





ssdk-services.s 安全
没有可用的地理位置信息。




wa.me 安全
IP地址: 31.13.82.51
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图





api.stage.getmati.com 安全
IP地址: 52.38.242.170
国家: 美利坚合众国
地区: 俄勒冈
城市: 博德曼
查看: Google 地图





facebook.com 安全
IP地址: 157.240.31.35
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图





googleads.g.doubleclick.net 安全
IP地址: 180.163.151.166
国家: 中国
地区: 上海
城市: 上海
查看: 高德地图





sapp.s 安全
没有可用的地理位置信息。




pagead2.googlesyndication.com 安全
IP地址: 180.163.151.38
国家: 中国
地区: 上海
城市: 上海
查看: 高德地图





sdlsdk.s 安全
没有可用的地理位置信息。




getmati.com 安全
IP地址: 3.219.183.5
国家: 美利坚合众国
地区: 弗吉尼亚州
城市: 阿什本
查看: Google 地图





manual.sensorsdata.cn 安全
IP地址: 157.240.31.35
国家: 中国
地区: 上海
城市: 上海
查看: 高德地图





slaunches.s 安全
没有可用的地理位置信息。




sconversions.s 安全
没有可用的地理位置信息。




admob-gmats.uc.r.appspot.com 安全
IP地址: 34.64.4.20
国家: 美利坚合众国
地区: 加利福尼亚
城市: 山景城
查看: Google 地图





simpression.s 安全
没有可用的地理位置信息。




mxloanapi.maxcredito.cc 安全
IP地址: 94.74.73.221
国家: 墨西哥
地区: 墨西哥城
城市: 米格尔·伊达尔戈
查看: Google 地图





maxcredito.cc 安全
没有可用的地理位置信息。




svalidate.s 安全
没有可用的地理位置信息。




smonitorsdk.s 安全
没有可用的地理位置信息。




api.getmati.com 安全
IP地址: 44.217.158.143
国家: 美利坚合众国
地区: 弗吉尼亚州
城市: 阿什本
查看: Google 地图





media.stage.getmati.com 安全
IP地址: 35.83.35.25
国家: 美利坚合众国
地区: 俄勒冈
城市: 博德曼
查看: Google 地图





bnc.lt 安全
IP地址: 18.67.51.35
国家: 大韩民国
地区: 京畿道
城市: Icheon
查看: Google 地图





en.wikipedia.org 安全
IP地址: 103.102.166.224
国家: 美利坚合众国
地区: 印第安纳州
城市: 弗朗西斯科
查看: Google 地图





goo.gl 安全
IP地址: 142.250.196.110
国家: 美利坚合众国
地区: 加利福尼亚
城市: 山景城
查看: Google 地图





sonelink.s 安全
没有可用的地理位置信息。




google.com 安全
IP地址: 142.250.207.14
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图





手机号码

手机号 源码文件
18222222222
19222222222
com/appsflyer/internal/ah.java

网址

网址信息 源码文件
https://%sstats.%s/stats
https://%sadrevenue.%s/api/v
https://%sconversions.%s/api/v
https://%slaunches.%s/api/v
https://%sinapps.%s/api/v
https://%sattr.%s/api/v
com/appsflyer/internal/ah.java
https://%sonelink.%s/shortlink-sdk/v1
com/appsflyer/internal/am.java
https://%smonitorsdk.%s/remote-debug?app_id=
com/appsflyer/internal/ap.java
https://%sdlsdk.%s/v1.0/android/
com/appsflyer/internal/ar.java
https://%sregister.%s/api/v
com/appsflyer/internal/ba.java
https://%sgcdsdk.%s/install_data/v4.0/
com/appsflyer/internal/bc.java
https://%sapp.%s
com/appsflyer/internal/bu.java
https://%ssdk-services.%s/validate-android-signature
https://%svalidate.%s/api/v
com/appsflyer/internal/z.java
https://%simpression.%s
com/appsflyer/share/CrossPromotionHelper.java
https://api.getmati.com/
https://media.getmati.com/
https://api.stage.getmati.com/
https://media.stage.getmati.com/
com/getmati/mati_sdk/server/RequestManager.java
https://getmati.com/privacypolicy
https://getmati.com/termsofservice
com/getmati/mati_sdk/ui/start/StartVerificationFragment.java
javascript:window.sensorsdata_app_call_js
com/sensorsdata/abtest/core/SensorsABTestH5Helper.java
https://testhk10.xcreditech.com/loan/
http://119.8.109.35:9097/loan/
https://mxloanapi.maxcredito.cc/loan/
com/xinmi/android/moneed/app/App.java
https://32cd461009cf4a43a1a0721c5855dc17@o566293.ingest.sentry.io/5708944
g/g/a/i/a/a/n2/a/m.java
wss://api.getmati.com
wss://api.stage.getmati.com
wss://api
g/g/a/j/g.java
https://salasa.xcreditech.com/sa?project=production
g/j/a/a/f/a.java
https://maxcredito.cc/h5/loanprocessing/maxcredito
https://testhk10.xcreditech.com/h5/privacypolicy/maxcredito
https://maxcredito.cc/h5/privacypolicy/maxcredito
g/j/a/a/h/b.java
https://play.google.com/store/apps/details?id=
g/j/a/a/n/a.java
https://play.google.com/store/apps/details?id=
g/j/a/a/r/b/a/a.java
https://cdn.branch.io/
https://api2.branch.io/
https://api.branch.io/
h/a/b/r.java
https://bnc.lt/a/
h/a/b/t.java
www.google.com
https://goo.gl/naoooi
https://media.stage.getmati.com/
https://.facebook.com
http://schema.org/photographaction
https://testhk10.xcreditech.com/h5/privacypolicy/maxcredito
https://bnc.lt/a/
https://firebase.google.com/support/privacy/init-options
http://schema.org/bookmarkaction
http://schema.org/communicateaction
https://graph.%s
https://%sapp.%s
https://manual.sensorsdata.cn/sa/latest/tech_sdk_client_web_access-7545017.html
https://32cd461009cf4a43a1a0721c5855dc17@o566293.ingest.sentry.io/5708944
https://maxcredito.cc/h5/privacypolicy/maxcredito
https://%sconversions.%s/api/v
wss://api
http://schema.org/listenaction
http://schema.org/filmaction
http://schema.org/searchaction
https://facebook.com/device?user_code=%1$s&qr=1
https://www.banxico.org.mx/cep/
http://play.google.com/store/apps/details?id=com.facebook.orca
https://www.google.com/dfp/senddebugdata
https://%sinapps.%s/api/v
https://getmati.com/termsofservice
https://%s/%s/%s
https://api.getmati.com/
http://schema.org/completedactionstatus
https://admob-gmats.uc.r.appspot.com/
https://googlemobileadssdk.page.link/admob-interstitial-policies
https://www.google.com
https://firebase.google.com/support/guides/disable-analytics
https://%svalidate.%s/api/v
https://play.google.com/store/apps/details?id=
http://schema.org/activeactionstatus
https://%simpression.%s
https://%sattr.%s/api/v
https://fundingchoicesmessages.google.com/a/consent
https://%sdlsdk.%s/v1.0/android/
http://schema.org/reserveaction
http://www.google.com
https://testhk10.xcreditech.com/loan/
http://schema.org/activateaction
http://schema.org/likeaction
https://api.stage.getmati.com/
https://mxloanapi.maxcredito.cc/loan/
https://media.getmati.com/
https://%sadrevenue.%s/api/v
https://googlemobileadssdk.page.link/admob-android-update-manifest
wss://api.stage.getmati.com
https://exoplayer.dev/issues/player-accessed-on-wrong-thread
http://schema.org/addaction
https://graph-video.%s
http://schema.org/failedactionstatus
https://cdn.branch.io/
https://www.google.com/dfp/linkdevice
https://exoplayer.dev/issues/cleartext-not-permitted
https://%sregister.%s/api/v
https://www.google.com/dfp/inapppreview
https://%smonitorsdk.%s/remote-debug?app_id=
https://wa.me/%s
https://facebook.com
https://api2.branch.io/
https://www.google.com/dfp/debugsignals
https://app-measurement.com/a
https://maxcredito.cc/h5/loanprocessing/maxcredito
http://schema.org/watchaction
https://api.branch.io/
https://%sstats.%s/stats
https://goo.gl/j1swqy
https://googlemobileadssdk.page.link/ad-manager-android-update-manifest
https://google.com/search?
https://getmati.com/privacypolicy
https://%sonelink.%s/shortlink-sdk/v1
https://goo.gle/compose-feedback
https://%sgcdsdk.%s/install_data/v4.0/
http://119.8.109.35:9097/loan/
https://adservice.google.com/getconfig/pubvendors
https://plus.google.com/
https://%ssdk-services.%s/validate-android-signature
https://salasa.xcreditech.com/sa?project=production
https://%slaunches.%s/api/v
https://pagead2.googlesyndication.com/pagead/gen_204?id=gmob-apps
javascript:window.sensorsdata_app_call_js
http://schema.org/wantaction
wss://api.getmati.com
http://schema.org/viewaction
自研引擎-S

FIREBASE实例

邮箱

EMAIL 源码文件
32cd461009cf4a43a1a0721c5855dc17@o566293.ingest
g/g/a/i/a/a/n2/a/m.java
32cd461009cf4a43a1a0721c5855dc17@o566293.ingest
自研引擎-S

密钥凭证

已显示 50 个secrets
1、 凭证信息=> "io.branch.sdk.BranchKey" : "key_live_joZdAu25uaPLMfVigYMfqomjstgIAVof"
2、 "google_api_key" : "AIzaSyCPq5HQkxIKQ3BtfF8n54hi-p8JLkaeGXI"
3、 "google_crash_reporting_api_key" : "AIzaSyCPq5HQkxIKQ3BtfF8n54hi-p8JLkaeGXI"
4、 MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQDmpvCBbR9T15wX
5、 a4b7452e2ed8f5f191058ca7bbfd26b0d3214bfc
6、 5e8f16062ea3cd2c4a0d547876baa6f38cabf625
7、 nRfXAGyVULi2Feyea7oXw6yHm+TSgHrH+u53DPW0W3kH/43Fb8oyj40OTFM18jW4e
8、 FBA3AF4E7757D9016E953FB3EE4671CA2BD9AF725F9A53D52ED4A38EAAA08901
9、 cc2751449a350f668590264ed76692694a80308a
10、 nfWp+B5rTu9Serv9xVGquremmjXJKHQMr5REw7qOxl+nh6ERhr/WBrOavDIh3NDSV
11、 nTyRr0oS26c9haca9RcLqywB/52w65dPjT1WceZRjlUsZduSRRK7G3uu39GK0u8Qz
12、 ntjwcKgqEa3d1JclRZI0bUQw8f2VICTJfuEedlNvh1Gxe1YHGhqQGnf+o0mMHPHz0
13、 nh2XLv7yh7pydNQdMOQOxZ3miKlT+IAW2mT6g2alJH93VNJTQFY2uWJO52zaTliM9
14、 nj4GDKEqTR1gQsTGlxSeUOw/1NZUrL9GqGwWGVNpsy23zGTNGzNpj7N0Xykd5G25J
15、 ngJoChkEiZQUeIYmKpjp4OGuiD7ELxFydqjilCygbQS4dJpI6STbgC0receZ6guLq
16、 n9hqIEwHtF4CjXiu1te9bWXsNSJ/uLppWpjbnVetZI0msW7pLw0AD7NbDCDEMalFE
17、 E3F9E1E0CF99D0E56A055BA65E241B3399F7CEA524326B0CDD6EC1327ED0FDC1
18、 MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA5qbwgW0fU9ecF0X1wBsl
19、 n9NohZjwr9QGqXSp0Y1Dt1hGjjBlqC7rm0DkdaBxPMQKBgQD69jfSBcHxGBo9/i+M
20、 n+Jo9bifiuxwaDLHAM9Czy6+pMHuyAds9IP4q13oz11LlxVy/1TU9cRDMHL2rf2zB
21、 9b8f518b086098de3d77736f9458a3d2f6f95a37
22、 niEsAlKMDgJJ5LJCAE6am2C3Eqg+tIrQDg/l5EnbtbfD75qDObswi1YLmJ0NmC6gO
23、 FFE391E0EA186D0734ED601E4E70E3224B7309D48E2075BAC46D8C667EAE7212
24、 naH6pjqtmZyZxEiPR/X59a4gXFYz0eTqUHmqXxUA3W8e4poEqWQmdHSulnO1THEtN
25、 258EAFA5-E914-47DA-95CA-C5AB0DC85B11
26、 nYi5rgVShAgMBAAECggEAJDYXUiqAnZgfEGRSZbudS68IRImGOUOzUZSIuQts4KqR
27、 2438bce1ddb7bd026d5ff89f598b3b5e5bb824b3
28、 nmRhyGHQy5Z4QPHmie8rUbFgLKowD9Y2rRcdhd8Lfi88iEFPPg46fIWLHmrtZPnoT
29、 df6b721c8b4d3b6eb44c861d4415007e5a35fc95
30、 nxdTVEv9GQLCGZG8zy6Kifa/sl9wFp1cLr6aqTcmdOUzJLeORXIdQCGRJlum2CpEQ
31、 n4KVft1rxz3+drh/mlbXHCjg2lHBk0VHtjRz5WbfP5jstn3NoAQ+FK1HK85dWJ1HN
32、 nQaQJkjP6o1nj9SebzuwwWJvKb+EbNsPkxMBvfJkC0dtK9Y9452e12GWtYemxjdAm
33、 MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv+4Pref7OXrLHMsqLnXp
34、 32cd461009cf4a43a1a0721c5855dc17
35、 n48TcVFa6U0+cA2hNBd0yFtD8MMfsTOMGBUnsLLSyRsiSdg32zvbjL92WmKLxRt/t
36、 nIpjBuEehCsCno6FP5ZppP8BV+XvG30l8a80LsqZcQ3moiW2bV3LXbzrru2Iua4FU
37、 3BAF59A2E5331C30675FAB35FF5FFF0D116142D3D4664F1C3CB804068B40614F
38、 ngCWzKvlU3X24zVtg3fXIlHjzajGTHGqVBEf5qVZWVzWyD/rrDVjkP7Mzh95LiQqu
39、 neEbBGC+uVAwKa6Mn0hfwpSSruU3xq5+2uhHJvb7+C+fKmM+MjubHPliSVhuEm3Qj
40、 noqDCYN6AmgKGQSJlBR4hiYqmOng4a6IPsQvEXJ2qOKULKBtBLh0mkjpJNuALSt5x
41、 ngCQQxi09+QcBz3j+NsYbA8lVbw+1RBsVSp7lkitkP8zUcA6scDjQFBQQFFfSWQzb
42、 8a3c4b262d721acd49a4bf97d5213199c86fa2b9
43、 MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAst3XsEjql59qV+6s0O2i
44、 nwATT85JkyNOU5heik19ycfbmRdEnaK5y8gQTq1oRZwPP6NKUgQ/cm8uST6KgwmDe
45、 nG40nMXcS8zC4mqncTXkniCCzra0Do2lkxKZVj9gStucFuEikA/fI64MZxyRS24U0
46、 nBU4NQaa2Jr30HKlnlajpvZ0jccb1T9WgcUAYb5J7ubDIWdgk7IaTPOB/DKYSgKPj
47、 niuPGDKnzf8PR2DsuMvvuKbnmFk5lOeltTaSVH5Irrlqwc0WiLMm1GoDBAoGAOTjf
48、 nZcvcCvQ+Y9VDpYk8zucrR3wYgfPS0jMwY3pU6X+Kq2DefBX5M7Co1BnpymKe9WkU
49、 nMBmZrGAcahJoCMYbGWM/vZsn0taF7ZumyI6gVvyx1vNsKq3n5UdkAlut57HhSXaa
50、 nt2ob47fABNPzkmTI05TmF6KTX3Jx9uZF0SdornLyBBOrWhFnA8/o0pSBD9yby5JP

字符串列表

建议导出为TXT,方便查看。

活动列表

已显示 47 个activities
1、 com.xinmi.android.moneed.ui.mine.activity.IDCardActivity
2、 com.xinmi.android.moneed.guide.WelcomeActivity
3、 com.xinmi.android.moneed.ui.loan.activity.RepayMethodActivity
4、 com.xinmi.android.moneed.ui.loan.activity.CashRepaymentActivity
5、 com.xinmi.android.moneed.ui.loan.activity.PayNetRepaymentActivity
6、 com.xinmi.android.moneed.ui.loan.activity.CreditResultActivity
7、 com.xinmi.android.moneed.ui.loan.activity.RepaymentResultActivity
8、 com.xinmi.android.moneed.ui.loan.activity.RepayLoanActivity
9、 com.xinmi.android.moneed.profile.flow.CashFlowDetailActivity
10、 com.xinmi.android.moneed.profile.flow.BorrowHistoryDetailActivity
11、 com.xinmi.android.moneed.profile.flow.CashFlowActivity
12、 com.xinmi.android.moneed.profile.flow.BorrowHistoryActivity
13、 com.xinmi.android.moneed.coupon.activity.CouponsListActivity
14、 com.xinmi.android.moneed.ui.mine.activity.ReviewInfoActivity
15、 com.xinmi.android.moneed.ui.mine.activity.EditUserInfoActivity
16、 com.xinmi.android.moneed.ui.login.activity.RegisterSecondActivity
17、 com.xinmi.android.moneed.ui.login.activity.RegisterFirstStepActivity
18、 com.xinmi.android.moneed.guide.SplashActivity
19、 com.xinmi.android.moneed.ui.main.activity.MainActivity
20、 com.xinmi.android.moneed.ui.login.activity.LoginEntranceActivity
21、 com.xinmi.android.moneed.ui.login.activity.LoginWithPasswordActivity
22、 com.xinmi.android.moneed.ui.login.activity.LoginWithSMSActivity
23、 com.xinmi.android.moneed.ui.login.activity.ResetPasswordFirstStepActivity
24、 com.xinmi.android.moneed.ui.login.activity.ResetPasswordSecondStepActivity
25、 com.xinmi.android.moneed.profile.SettingActivity
26、 com.xinmi.android.moneed.ui.mine.activity.CustomAboutUsActivity
27、 com.xinmi.android.moneed.web.activity.WebActivity
28、 com.xinmi.android.moneed.camera.CameraActivity
29、 com.xinmi.android.moneed.camera.CameraPortraitActivity
30、 com.xinmi.android.moneed.ui.mine.activity.BindAccountActivity
31、 com.xinmi.android.moneed.ui.mine.activity.CLABEInfoActivity
32、 com.xinmi.android.moneed.ui.mine.activity.BankAccountInfoActivity
33、 com.xinmi.android.moneed.ui.mine.activity.InviteFriendsActivity
34、 com.xinmi.android.moneed.ui.mine.activity.InviteFriendsRulesActivity
35、 com.xinmi.android.moneed.ui.main.activity.PermissionActivity
36、 com.xinmi.android.moneed.ui.loan.activity.BankTransferRepaymentActivity
37、 com.xinmi.android.moneed.ui.loan.activity.DeferRepayActivity
38、 com.xinmi.android.moneed.webprogress.activity.WebProgressActivity
39、 com.getmati.mati_sdk.ui.data_prefetch.DataPrefetchActivity
40、 com.getmati.mati_sdk.ui.kyc.KYCActivity
41、 com.facebook.FacebookActivity
42、 com.facebook.CustomTabMainActivity
43、 com.facebook.CustomTabActivity
44、 com.google.android.gms.common.api.GoogleApiActivity
45、 com.google.android.gms.ads.AdActivity
46、 com.google.android.play.core.missingsplits.PlayCoreMissingSplitsActivity
47、 com.google.android.play.core.common.PlayCoreDialogWrapperActivity

服务列表

已显示 15 个services
1、 com.xinmi.android.moneed.push.MyFirebaseMessagingService
2、 com.xinmi.android.moneed.webprogress.service.MainProWebViewBrigdeService
3、 com.google.firebase.components.ComponentDiscoveryService
4、 com.google.android.gms.measurement.AppMeasurementService
5、 com.google.android.gms.measurement.AppMeasurementJobService
6、 com.google.firebase.messaging.FirebaseMessagingService
7、 com.google.android.gms.ads.AdService
8、 androidx.work.impl.background.systemalarm.SystemAlarmService
9、 androidx.work.impl.background.systemjob.SystemJobService
10、 androidx.room.MultiInstanceInvalidationService
11、 com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
12、 com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
13、 com.sensorsdata.abtest.service.GlobalLoopService
14、 com.google.android.play.core.assetpacks.AssetPackExtractionService
15、 com.google.android.play.core.assetpacks.ExtractionForegroundService

广播接收者列表

已显示 13 个receivers
1、 com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
2、 com.google.android.gms.measurement.AppMeasurementReceiver
3、 com.google.firebase.iid.FirebaseInstanceIdReceiver
4、 androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
5、 androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
6、 androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
7、 androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
8、 androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
9、 androidx.work.impl.background.systemalarm.RescheduleReceiver
10、 androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
11、 androidx.profileinstaller.ProfileInstallReceiver
12、 com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
13、 com.appsflyer.SingleInstallBroadcastReceiver

内容提供者列表

已显示 11 个providers
1、 com.facebook.FacebookContentProvider
2、 com.getmati.mati_sdk.ui.utils.MatiFileProvider
3、 com.facebook.marketing.internal.MarketingInitProvider
4、 com.facebook.internal.FacebookInitProvider
5、 com.google.android.gms.ads.MobileAdsInitProvider
6、 com.google.firebase.provider.FirebaseInitProvider
7、 androidx.work.impl.WorkManagerInitializer
8、 androidx.lifecycle.ProcessLifecycleOwnerInitializer
9、 androidx.startup.InitializationProvider
10、 razerdp.basepopup.BasePopupInitializer
11、 com.sensorsdata.analytics.android.sdk.data.SensorsDataContentProvider

第三方SDK

SDK名称 开发者 描述信息
Google Play Service Google 借助 Google Play 服务,您的应用可以利用由 Google 提供的最新功能,例如地图,Google+ 等,并通过 Google Play 商店以 APK 的形式分发自动平台更新。 这样一来,您的用户可以更快地接收更新,并且可以更轻松地集成 Google 必须提供的最新信息。
神策分析 SDK 神策 神策分析,是针对企业级客户推出的深度用户行为分析产品,支持私有化部署,客户端、服务器、业务数据、第三方数据的全端采集和建模,驱动营销渠道效果评估、用户精细化运营改进、产品功能及用户体验优化、老板看板辅助管理决策、产品个性化推荐改造、用户标签体系构建等应用场景。作为 PaaS 平台支持二次开发,可通过 BI、大数据平台、CRM、ERP 等内部 IT 系统,构建用户数据体系,让用户行为数据发挥深远的价值。
Jetpack Lifecycle Google 生命周期感知型组件可执行操作来响应另一个组件(如 Activity 和 Fragment)的生命周期状态的变化。这些组件有助于您写出更有条理且往往更精简的代码,这样的代码更易于维护。
File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。
Jetpack App Startup Google App Startup 库提供了一种直接,高效的方法来在应用程序启动时初始化组件。库开发人员和应用程序开发人员都可以使用 App Startup 来简化启动顺序并显式设置初始化顺序。App Startup 允许您定义共享单个内容提供程序的组件初始化程序,而不必为需要初始化的每个组件定义单独的内容提供程序。这可以大大缩短应用启动时间。
Jetpack WorkManager Google 使用 WorkManager API 可以轻松地调度即使在应用退出或设备重启时仍应运行的可延迟异步任务。
Firebase Google Firebase 提供了分析、数据库、消息传递和崩溃报告等功能,可助您快速采取行动并专注于您的用户。
Jetpack Media Google 与其他应用共享媒体内容和控件。已被 media2 取代。
Jetpack ProfileInstaller Google 让库能够提前预填充要由 ART 读取的编译轨迹。
Firebase Analytics Google Google Analytics(分析)是一款免费的应用衡量解决方案,可提供关于应用使用情况和用户互动度的分析数据。
Jetpack Room Google Room 持久性库在 SQLite 的基础上提供了一个抽象层,让用户能够在充分利用 SQLite 的强大功能的同时,获享更强健的数据库访问机制。

文件列表

AndroidManifest.xml
DebugProbesKt.bin
META-INF/activity-compose_release.kotlin_module
META-INF/activity-ktx_release.kotlin_module
META-INF/androidx.activity_activity-compose.version
META-INF/androidx.activity_activity-ktx.version
META-INF/androidx.activity_activity.version
META-INF/androidx.annotation_annotation-experimental.version
META-INF/androidx.appcompat_appcompat-resources.version
META-INF/androidx.appcompat_appcompat.version
META-INF/androidx.arch.core_core-runtime.version
META-INF/androidx.asynclayoutinflater_asynclayoutinflater.version
META-INF/androidx.autofill_autofill.version
META-INF/androidx.browser_browser.version
META-INF/androidx.camera_camera-camera2.version
META-INF/androidx.camera_camera-core.version
META-INF/androidx.camera_camera-lifecycle.version
META-INF/androidx.camera_camera-view.version
META-INF/androidx.cardview_cardview.version
META-INF/androidx.compose.animation_animation-core.version
META-INF/androidx.compose.animation_animation.version
META-INF/androidx.compose.foundation_foundation-layout.version
META-INF/androidx.compose.runtime_runtime-saveable.version
META-INF/androidx.compose.runtime_runtime.version
META-INF/androidx.compose.ui_ui-geometry.version
META-INF/androidx.compose.ui_ui-graphics.version
META-INF/androidx.compose.ui_ui-text.version
META-INF/androidx.compose.ui_ui-unit.version
META-INF/androidx.compose.ui_ui-util.version
META-INF/androidx.compose.ui_ui.version
META-INF/androidx.coordinatorlayout_coordinatorlayout.version
META-INF/androidx.core_core-ktx.version
META-INF/androidx.core_core.version
META-INF/androidx.cursoradapter_cursoradapter.version
META-INF/androidx.customview_customview.version
META-INF/androidx.databinding_baseAdapters.version
META-INF/androidx.databinding_library.version
META-INF/androidx.databinding_viewbinding.version
META-INF/androidx.documentfile_documentfile.version
META-INF/androidx.drawerlayout_drawerlayout.version
META-INF/androidx.dynamicanimation_dynamicanimation.version
META-INF/androidx.exifinterface_exifinterface.version
META-INF/androidx.fragment_fragment-ktx.version
META-INF/androidx.fragment_fragment.version
META-INF/androidx.interpolator_interpolator.version
META-INF/androidx.legacy_legacy-support-core-ui.version
META-INF/androidx.legacy_legacy-support-core-utils.version
META-INF/androidx.legacy_legacy-support-v4.version
META-INF/androidx.lifecycle_lifecycle-extensions.version
META-INF/androidx.lifecycle_lifecycle-livedata-core-ktx.version
META-INF/androidx.lifecycle_lifecycle-livedata-core.version
META-INF/androidx.lifecycle_lifecycle-livedata.version
META-INF/androidx.lifecycle_lifecycle-process.version
META-INF/androidx.lifecycle_lifecycle-runtime-ktx.version
META-INF/androidx.lifecycle_lifecycle-runtime.version
META-INF/androidx.lifecycle_lifecycle-service.version
META-INF/androidx.lifecycle_lifecycle-viewmodel-compose.version
META-INF/androidx.lifecycle_lifecycle-viewmodel-ktx.version
META-INF/androidx.lifecycle_lifecycle-viewmodel-savedstate.version
META-INF/androidx.lifecycle_lifecycle-viewmodel.version
META-INF/androidx.loader_loader.version
META-INF/androidx.localbroadcastmanager_localbroadcastmanager.version
META-INF/androidx.media_media.version
META-INF/androidx.navigation_navigation-common-ktx.version
META-INF/androidx.navigation_navigation-common.version
META-INF/androidx.navigation_navigation-compose.version
META-INF/androidx.navigation_navigation-dynamic-features-fragment.version
META-INF/androidx.navigation_navigation-dynamic-features-runtime.version
META-INF/androidx.navigation_navigation-fragment-ktx.version
META-INF/androidx.navigation_navigation-fragment.version
META-INF/androidx.navigation_navigation-runtime-ktx.version
META-INF/androidx.navigation_navigation-runtime.version
META-INF/androidx.navigation_navigation-ui-ktx.version
META-INF/androidx.navigation_navigation-ui.version
META-INF/androidx.print_print.version
META-INF/androidx.profileinstaller_profileinstaller.version
META-INF/androidx.recyclerview_recyclerview.version
META-INF/androidx.room_room-runtime.version
META-INF/androidx.savedstate_savedstate-ktx.version
META-INF/androidx.savedstate_savedstate.version
META-INF/androidx.slidingpanelayout_slidingpanelayout.version
META-INF/androidx.sqlite_sqlite-framework.version
META-INF/androidx.sqlite_sqlite.version
META-INF/androidx.startup_startup-runtime.version
META-INF/androidx.swiperefreshlayout_swiperefreshlayout.version
META-INF/androidx.tracing_tracing.version
META-INF/androidx.transition_transition.version
META-INF/androidx.vectordrawable_vectordrawable-animated.version
META-INF/androidx.vectordrawable_vectordrawable.version
META-INF/androidx.versionedparcelable_versionedparcelable.version
META-INF/androidx.viewpager2_viewpager2.version
META-INF/androidx.viewpager_viewpager.version
META-INF/animation-core_release.kotlin_module
META-INF/animation_release.kotlin_module
META-INF/annotation-experimental_release.kotlin_module
META-INF/bannerview_release.kotlin_module
META-INF/base_googleRelease.kotlin_module
META-INF/base_library_release.kotlin_module
META-INF/collection-ktx.kotlin_module
META-INF/com.github.CymChad.brvah.kotlin_module
META-INF/com.google.android.material_material.version
META-INF/com.google.firebase-firebase-common-ktx.kotlin_module
META-INF/com.google.firebase-firebase-config-ktx.kotlin_module
META-INF/core-ktx_release.kotlin_module
META-INF/foundation-layout_release.kotlin_module
META-INF/fragment-ktx_release.kotlin_module
META-INF/indicator_release.kotlin_module
META-INF/kotlin-android-extensions-runtime.kotlin_module
META-INF/kotlin-stdlib-common.kotlin_module
META-INF/kotlin-stdlib-jdk7.kotlin_module
META-INF/kotlin-stdlib-jdk8.kotlin_module
META-INF/kotlin-stdlib.kotlin_module
META-INF/kotlinx-coroutines-android.kotlin_module
META-INF/kotlinx-coroutines-core.kotlin_module
META-INF/lifecycle-livedata-core-ktx_release.kotlin_module
META-INF/lifecycle-runtime-ktx_release.kotlin_module
META-INF/lifecycle-viewmodel-compose_release.kotlin_module
META-INF/lifecycle-viewmodel-ktx_release.kotlin_module
META-INF/mati-sdk_productionRelease.kotlin_module
META-INF/maxcredito_googleRelease.kotlin_module
META-INF/navigation-common_release.kotlin_module
META-INF/navigation-compose_release.kotlin_module
META-INF/navigation-dynamic-features-fragment_release.kotlin_module
META-INF/navigation-dynamic-features-runtime_release.kotlin_module
META-INF/navigation-fragment-ktx_release.kotlin_module
META-INF/navigation-runtime_release.kotlin_module
META-INF/navigation-ui-ktx_release.kotlin_module
META-INF/parcelize-runtime.kotlin_module
META-INF/retrofit.kotlin_module
META-INF/runtime-saveable_release.kotlin_module
META-INF/runtime_release.kotlin_module
META-INF/savedstate-ktx_release.kotlin_module
META-INF/services/kotlinx.coroutines.CoroutineExceptionHandler
META-INF/services/kotlinx.coroutines.internal.MainDispatcherFactory
META-INF/track_library_release.kotlin_module
META-INF/ui-geometry_release.kotlin_module
META-INF/ui-graphics_release.kotlin_module
META-INF/ui-text_release.kotlin_module
META-INF/ui-unit_release.kotlin_module
META-INF/ui-util_release.kotlin_module
META-INF/ui_release.kotlin_module
androidsupportmultidexversion.txt
assets/mexico.db
assets/sa_mcc_mnc_mini.json
assets/supplierconfig.json
classes.dex
classes2.dex
classes3.dex
com/appsflyer/internal/a-
com/appsflyer/internal/b-
emojis.json
firebase-abt.properties
firebase-analytics.properties
firebase-annotations.properties
firebase-appindexing.properties
firebase-common-ktx.properties
firebase-common.properties
firebase-components.properties
firebase-config-ktx.properties
firebase-config.properties
firebase-core.properties
firebase-datatransport.properties
firebase-encoders-json.properties
firebase-encoders.properties
firebase-iid-interop.properties
firebase-installations-interop.properties
firebase-installations.properties
firebase-measurement-connector.properties
firebase-messaging.properties
kotlin/annotation/annotation.kotlin_builtins
kotlin/collections/collections.kotlin_builtins
kotlin/coroutines/coroutines.kotlin_builtins
kotlin/internal/internal.kotlin_builtins
kotlin/kotlin.kotlin_builtins
kotlin/ranges/ranges.kotlin_builtins
kotlin/reflect/reflect.kotlin_builtins
okhttp3/internal/publicsuffix/publicsuffixes.gz
play-services-ads-base.properties
play-services-ads-identifier.properties
play-services-ads-lite.properties
play-services-ads.properties
play-services-base.properties
play-services-basement.properties
play-services-cloud-messaging.properties
play-services-measurement-api.properties
play-services-measurement-base.properties
play-services-measurement-impl.properties
play-services-measurement-sdk-api.properties
play-services-measurement-sdk.properties
play-services-measurement.properties
play-services-stats.properties
play-services-tasks.properties
res/a/a.xml
res/a/a0.xml
res/a/a1.xml
res/a/a2.xml
res/a/a3.xml
res/a/a4.xml
res/a/a5.xml
res/a/a6.xml
res/a/a7.xml
res/a/a8.xml
res/a/a9.xml
res/a/a_.xml
res/a/aa.xml
res/a/ab.xml
res/a/ac.xml
res/a/ad.xml
res/a/ae.xml
res/a/af.xml
res/a/ag.xml
res/a/ah.xml
res/a/ai.xml
res/a/aj.xml
res/a/ak.xml
res/a/al.xml
res/a/am.xml
res/a/an.xml
res/a/ao.xml
res/a/ap.xml
res/a/aq.xml
res/a/ar.xml
res/a/as.xml
res/a/at.xml
res/a/au.xml
res/a/av.xml
res/a/b.xml
res/a/c.xml
res/a/d.xml
res/a/e.xml
res/a/f.xml
res/a/g.xml
res/a/h.xml
res/a/i.xml
res/a/j.xml
res/a/k.xml
res/a/l.xml
res/a/m.xml
res/a/n.xml
res/a/o.xml
res/a/p.xml
res/a/q.xml
res/a/r.xml
res/a/s.xml
res/a/t.xml
res/a/u.xml
res/a/v.xml
res/a/w.xml
res/a/x.xml
res/a/y.xml
res/a/z.xml
res/a0/a.ttf
res/a0/b.ttf
res/a0/c.ttf
res/a1/a.xml
res/a1/b.xml
res/a1/c.xml
res/a1/d.xml
res/a1/e.xml
res/a2/a.xml
res/a2/b.xml
res/a3/a.xml
res/a3/a0.xml
res/a3/a1.xml
res/a3/a2.xml
res/a3/a3.xml
res/a3/a4.xml
res/a3/a5.xml
res/a3/a6.xml
res/a3/a7.xml
res/a3/a8.xml
res/a3/a9.xml
res/a3/a_.xml
res/a3/aa.xml
res/a3/ab.xml
res/a3/ac.xml
res/a3/ad.xml
res/a3/ae.xml
res/a3/af.xml
res/a3/ag.xml
res/a3/ah.xml
res/a3/ai.xml
res/a3/aj.xml
res/a3/ak.xml
res/a3/al.xml
res/a3/am.xml
res/a3/an.xml
res/a3/ao.xml
res/a3/ap.xml
res/a3/aq.xml
res/a3/ar.xml
res/a3/as.xml
res/a3/at.xml
res/a3/au.xml
res/a3/av.xml
res/a3/aw.xml
res/a3/ax.xml
res/a3/ay.xml
res/a3/az.xml
res/a3/b.xml
res/a3/b0.xml
res/a3/b1.xml
res/a3/b2.xml
res/a3/b3.xml
res/a3/b4.xml
res/a3/b5.xml
res/a3/b6.xml
res/a3/b7.xml
res/a3/b8.xml
res/a3/b9.xml
res/a3/b_.xml
res/a3/ba.xml
res/a3/bb.xml
res/a3/bc.xml
res/a3/bd.xml
res/a3/be.xml
res/a3/bf.xml
res/a3/bg.xml
res/a3/bh.xml
res/a3/bi.xml
res/a3/bj.xml
res/a3/bk.xml
res/a3/bl.xml
res/a3/bm.xml
res/a3/bn.xml
res/a3/bo.xml
res/a3/bp.xml
res/a3/bq.xml
res/a3/br.xml
res/a3/bs.xml
res/a3/bt.xml
res/a3/bu.xml
res/a3/bv.xml
res/a3/bw.xml
res/a3/bx.xml
res/a3/by.xml
res/a3/bz.xml
res/a3/c.xml
res/a3/c0.xml
res/a3/c1.xml
res/a3/c2.xml
res/a3/c3.xml
res/a3/c4.xml
res/a3/c5.xml
res/a3/c6.xml
res/a3/c7.xml
res/a3/c8.xml
res/a3/c9.xml
res/a3/c_.xml
res/a3/ca.xml
res/a3/cb.xml
res/a3/cc.xml
res/a3/cd.xml
res/a3/ce.xml
res/a3/cf.xml
res/a3/cg.xml
res/a3/ch.xml
res/a3/ci.xml
res/a3/cj.xml
res/a3/ck.xml
res/a3/cl.xml
res/a3/cm.xml
res/a3/cn.xml
res/a3/co.xml
res/a3/cp.xml
res/a3/cq.xml
res/a3/cr.xml
res/a3/cs.xml
res/a3/ct.xml
res/a3/cu.xml
res/a3/cv.xml
res/a3/cw.xml
res/a3/cx.xml
res/a3/cy.xml
res/a3/cz.xml
res/a3/d.xml
res/a3/d0.xml
res/a3/d1.xml
res/a3/d2.xml
res/a3/d3.xml
res/a3/d4.xml
res/a3/d5.xml
res/a3/d6.xml
res/a3/d7.xml
res/a3/d8.xml
res/a3/d9.xml
res/a3/d_.xml
res/a3/da.xml
res/a3/db.xml
res/a3/dc.xml
res/a3/dd.xml
res/a3/de.xml
res/a3/df.xml
res/a3/dg.xml
res/a3/dh.xml
res/a3/di.xml
res/a3/dj.xml
res/a3/dk.xml
res/a3/dl.xml
res/a3/dm.xml
res/a3/dn.xml
res/a3/do.xml
res/a3/dp.xml
res/a3/dq.xml
res/a3/dr.xml
res/a3/ds.xml
res/a3/dt.xml
res/a3/du.xml
res/a3/dv.xml
res/a3/dw.xml
res/a3/dx.xml
res/a3/dy.xml
res/a3/dz.xml
res/a3/e.xml
res/a3/e0.xml
res/a3/e1.xml
res/a3/e2.xml
res/a3/e3.xml
res/a3/e4.xml
res/a3/e5.xml
res/a3/e6.xml
res/a3/e7.xml
res/a3/e8.xml
res/a3/e9.xml
res/a3/e_.xml
res/a3/ea.xml
res/a3/eb.xml
res/a3/ec.xml
res/a3/ed.xml
res/a3/ee.xml
res/a3/ef.xml
res/a3/eg.xml
res/a3/eh.xml
res/a3/ei.xml
res/a3/ej.xml
res/a3/ek.xml
res/a3/el.xml
res/a3/em.xml
res/a3/en.xml
res/a3/eo.xml
res/a3/ep.xml
res/a3/eq.xml
res/a3/er.xml
res/a3/es.xml
res/a3/et.xml
res/a3/eu.xml
res/a3/ev.xml
res/a3/ew.xml
res/a3/ex.xml
res/a3/ey.xml
res/a3/ez.xml
res/a3/f.xml
res/a3/f0.xml
res/a3/f1.xml
res/a3/f2.xml
res/a3/f3.xml
res/a3/f4.xml
res/a3/f5.xml
res/a3/f6.xml
res/a3/f7.xml
res/a3/f8.xml
res/a3/f9.xml
res/a3/f_.xml
res/a3/fa.xml
res/a3/fb.xml
res/a3/fc.xml
res/a3/fd.xml
res/a3/fe.xml
res/a3/ff.xml
res/a3/fg.xml
res/a3/fh.xml
res/a3/fi.xml
res/a3/fj.xml
res/a3/fk.xml
res/a3/fl.xml
res/a3/fm.xml
res/a3/fn.xml
res/a3/fo.xml
res/a3/fp.xml
res/a3/fq.xml
res/a3/fr.xml
res/a3/fs.xml
res/a3/ft.xml
res/a3/fu.xml
res/a3/fv.xml
res/a3/fw.xml
res/a3/fx.xml
res/a3/fy.xml
res/a3/fz.xml
res/a3/g.xml
res/a3/g0.xml
res/a3/g1.xml
res/a3/g2.xml
res/a3/g3.xml
res/a3/g4.xml
res/a3/g5.xml
res/a3/g6.xml
res/a3/g7.xml
res/a3/g8.xml
res/a3/g9.xml
res/a3/g_.xml
res/a3/ga.xml
res/a3/gb.xml
res/a3/gc.xml
res/a3/gd.xml
res/a3/ge.xml
res/a3/gf.xml
res/a3/gg.xml
res/a3/gh.xml
res/a3/gi.xml
res/a3/gj.xml
res/a3/gk.xml
res/a3/gl.xml
res/a3/gm.xml
res/a3/gn.xml
res/a3/go.xml
res/a3/gp.xml
res/a3/gq.xml
res/a3/gr.xml
res/a3/gs.xml
res/a3/gt.xml
res/a3/gu.xml
res/a3/gv.xml
res/a3/gw.xml
res/a3/gx.xml
res/a3/gy.xml
res/a3/gz.xml
res/a3/h.xml
res/a3/h0.xml
res/a3/h1.xml
res/a3/h2.xml
res/a3/h3.xml
res/a3/h4.xml
res/a3/h5.xml
res/a3/h6.xml
res/a3/h7.xml
res/a3/h8.xml
res/a3/h9.xml
res/a3/h_.xml
res/a3/ha.xml
res/a3/hb.xml
res/a3/hc.xml
res/a3/hd.xml
res/a3/he.xml
res/a3/hf.xml
res/a3/hg.xml
res/a3/hh.xml
res/a3/hi.xml
res/a3/hj.xml
res/a3/hk.xml
res/a3/hl.xml
res/a3/hm.xml
res/a3/hn.xml
res/a3/ho.xml
res/a3/hp.xml
res/a3/hq.xml
res/a3/hr.xml
res/a3/hs.xml
res/a3/ht.xml
res/a3/hu.xml
res/a3/hv.xml
res/a3/hw.xml
res/a3/hx.xml
res/a3/hy.xml
res/a3/i.xml
res/a3/j.xml
res/a3/k.xml
res/a3/l.xml
res/a3/m.xml
res/a3/n.xml
res/a3/o.xml
res/a3/p.xml
res/a3/q.xml
res/a3/r.xml
res/a3/s.xml
res/a3/t.xml
res/a3/u.xml
res/a3/v.xml
res/a3/w.xml
res/a3/x.xml
res/a3/y.xml
res/a3/z.xml
res/a4/a.xml
res/a4/b.xml
res/a5/a.xml
res/a5/b.xml
res/a5/c.xml
res/a5/d.xml
res/a5/e.xml
res/a5/f.xml
res/a5/g.xml
res/a5/h.xml
res/a5/i.xml
res/a5/j.xml
res/a5/k.xml
res/a5/l.xml
res/a5/m.xml
res/a5/n.xml
res/a5/o.xml
res/a5/p.xml
res/a6/a.xml
res/a6/b.xml
res/a7/a.xml
res/a7/b.xml
res/a8/a.xml
res/a8/b.xml
res/a8/c.xml
res/a9/a.xml
res/a_/a.xml
res/a_/b.xml
res/a_/c.xml
res/a_/d.xml
res/aa/a.xml
res/aa/b.xml
res/ab/a.xml
res/ac/a.xml
res/ad/a.xml
res/ad/b.xml
res/ad/c.xml
res/ad/d.xml
res/ad/e.xml
res/ad/f.xml
res/ad/g.xml
res/ad/h.xml
res/ad/i.xml
res/ad/j.xml
res/b/a.xml
res/b/b.xml
res/b/c.xml
res/c/a.xml
res/c/a0.xml
res/c/a1.xml
res/c/a2.xml
res/c/a3.xml
res/c/a4.xml
res/c/a5.xml
res/c/a6.xml
res/c/a7.xml
res/c/a8.xml
res/c/a9.xml
res/c/a_.xml
res/c/aa.xml
res/c/ab.xml
res/c/ac.xml
res/c/ad.xml
res/c/ae.xml
res/c/af.xml
res/c/ag.xml
res/c/ah.xml
res/c/ai.xml
res/c/aj.xml
res/c/ak.xml
res/c/al.xml
res/c/am.xml
res/c/an.xml
res/c/ao.xml
res/c/ap.xml
res/c/aq.xml
res/c/ar.xml
res/c/as.xml
res/c/at.xml
res/c/au.xml
res/c/av.xml
res/c/aw.xml
res/c/ax.xml
res/c/ay.xml
res/c/az.xml
res/c/b.xml
res/c/b1.xml
res/c/b2.xml
res/c/b3.xml
res/c/b4.xml
res/c/b5.xml
res/c/b6.xml
res/c/b7.xml
res/c/b8.xml
res/c/b9.xml
res/c/b_.xml
res/c/ba.xml
res/c/bc.xml
res/c/bd.xml
res/c/be.xml
res/c/bf.xml
res/c/bg.xml
res/c/bh.xml
res/c/bi.xml
res/c/bj.xml
res/c/bk.xml
res/c/bl.xml
res/c/bm.xml
res/c/bn.xml
res/c/bo.xml
res/c/bp.xml
res/c/bq.xml
res/c/br.xml
res/c/bs.xml
res/c/bt.xml
res/c/bu.xml
res/c/bv.xml
res/c/bw.xml
res/c/bx.xml
res/c/by.xml
res/c/bz.xml
res/c/c.xml
res/c/c0.xml
res/c/c1.xml
res/c/c2.xml
res/c/c3.xml
res/c/c4.xml
res/c/c5.xml
res/c/c6.xml
res/c/c7.xml
res/c/c8.xml
res/c/c9.xml
res/c/c_.xml
res/c/ca.xml
res/c/cb.xml
res/c/cc.xml
res/c/cd.xml
res/c/ce.xml
res/c/cf.xml
res/c/cg.xml
res/c/ch.xml
res/c/ci.xml
res/c/cj.xml
res/c/ck.xml
res/c/cl.xml
res/c/cm.xml
res/c/cn.xml
res/c/co.xml
res/c/cp.xml
res/c/cq.xml
res/c/cr.xml
res/c/cs.xml
res/c/ct.xml
res/c/cu.xml
res/c/cv.xml
res/c/cw.xml
res/c/cx.xml
res/c/cy.xml
res/c/cz.xml
res/c/d.xml
res/c/d0.xml
res/c/d1.xml
res/c/d2.xml
res/c/d3.xml
res/c/d4.xml
res/c/d5.xml
res/c/d6.xml
res/c/d7.xml
res/c/d8.xml
res/c/d9.xml
res/c/d_.xml
res/c/da.xml
res/c/db.xml
res/c/dc.xml
res/c/dd.xml
res/c/de.xml
res/c/df.xml
res/c/dg.xml
res/c/dh.xml
res/c/di.xml
res/c/dj.xml
res/c/dk.xml
res/c/dl.xml
res/c/dm.xml
res/c/dn.xml
res/c/do.xml
res/c/dp.xml
res/c/dq.xml
res/c/dr.xml
res/c/ds.xml
res/c/dt.png
res/c/du.xml
res/c/dv.xml
res/c/dw.xml
res/c/dx.xml
res/c/dy.xml
res/c/dz.xml
res/c/e.xml
res/c/e0.xml
res/c/e1.xml
res/c/e2.xml
res/c/e3.xml
res/c/e4.xml
res/c/e5.xml
res/c/e6.xml
res/c/e7.xml
res/c/e8.xml
res/c/e9.xml
res/c/e_.xml
res/c/ea.xml
res/c/eb.xml
res/c/ec.xml
res/c/ed.xml
res/c/ee.xml
res/c/ef.xml
res/c/eg.xml
res/c/eh.xml
res/c/ei.xml
res/c/ej.xml
res/c/ek.xml
res/c/el.xml
res/c/em.xml
res/c/en.xml
res/c/eo.xml
res/c/ep.xml
res/c/eq.xml
res/c/er.xml
res/c/es.xml
res/c/et.xml
res/c/eu.xml
res/c/ev.xml
res/c/ew.xml
res/c/ex.xml
res/c/ey.xml
res/c/ez.xml
res/c/f.xml
res/c/f0.xml
res/c/f1.xml
res/c/f2.xml
res/c/f3.xml
res/c/f4.xml
res/c/f5.xml
res/c/f6.xml
res/c/f7.xml
res/c/f8.xml
res/c/f9.xml
res/c/f_.xml
res/c/fa.xml
res/c/fb.xml
res/c/fc.xml
res/c/fd.xml
res/c/fe.xml
res/c/ff.xml
res/c/fg.xml
res/c/fh.xml
res/c/fi.xml
res/c/fj.xml
res/c/fk.xml
res/c/fl.xml
res/c/fm.xml
res/c/fn.xml
res/c/fo.xml
res/c/fp.xml
res/c/fq.xml
res/c/fr.xml
res/c/fs.xml
res/c/ft.xml
res/c/fu.xml
res/c/fv.xml
res/c/fw.xml
res/c/fx.xml
res/c/fy.xml
res/c/fz.xml
res/c/g.xml
res/c/g0.xml
res/c/g1.xml
res/c/g2.xml
res/c/g3.xml
res/c/g4.xml
res/c/g5.xml
res/c/g7.xml
res/c/g8.xml
res/c/g9.xml
res/c/g_.xml
res/c/ga.xml
res/c/gb.xml
res/c/gc.xml
res/c/gd.xml
res/c/ge.xml
res/c/gf.xml
res/c/gg.xml
res/c/gi.xml
res/c/h.xml
res/c/i.xml
res/c/j.xml
res/c/k.xml
res/c/l.xml
res/c/m.xml
res/c/n.xml
res/c/o.xml
res/c/p.xml
res/c/q.xml
res/c/r.xml
res/c/s.xml
res/c/t.xml
res/c/u.xml
res/c/v.xml
res/c/w.xml
res/c/x.xml
res/c/y.xml
res/c/z.xml
res/d/a.xml
res/e/a.xml
res/e/b.xml
res/e/c.xml
res/e/d.xml
res/e/e.xml
res/e/f.xml
res/e/g.xml
res/e/h.xml
res/e/i.xml
res/e/j.xml
res/e/k.xml
res/e/l.xml
res/e/m.xml
res/e/n.xml
res/e/o.xml
res/e/p.xml
res/e/q.xml
res/e/r.xml
res/e/s.xml
res/e/t.xml
res/e/u.xml
res/e/v.xml
res/e/w.xml
res/e/x.xml
res/f/a.xml
res/f/a0.xml
res/f/a1.xml
res/f/a2.xml
res/f/a3.xml
res/f/a4.xml
res/f/a5.xml
res/f/a6.xml
res/f/a7.xml
res/f/a8.xml
res/f/a9.xml
res/f/a_.xml
res/f/aa.xml
res/f/ab.xml
res/f/ac.xml
res/f/ad.xml
res/f/ae.xml
res/f/af.xml
res/f/ag.xml
res/f/ah.xml
res/f/ai.xml
res/f/aj.xml
res/f/ak.xml
res/f/al.xml
res/f/am.xml
res/f/an.xml
res/f/ao.xml
res/f/ap.xml
res/f/aq.xml
res/f/ar.xml
res/f/as.xml
res/f/at.xml
res/f/au.xml
res/f/av.xml
res/f/aw.xml
res/f/ax.xml
res/f/ay.xml
res/f/az.xml
res/f/b.xml
res/f/b0.xml
res/f/b1.xml
res/f/b2.xml
res/f/b3.xml
res/f/b4.xml
res/f/b5.xml
res/f/b6.xml
res/f/b7.xml
res/f/b8.xml
res/f/b9.xml
res/f/b_.xml
res/f/ba.xml
res/f/bb.xml
res/f/bc.xml
res/f/bd.xml
res/f/be.xml
res/f/bf.xml
res/f/bg.xml
res/f/bh.xml
res/f/bi.xml
res/f/bj.xml
res/f/c.xml
res/f/d.xml
res/f/e.xml
res/f/f.xml
res/f/g.xml
res/f/h.xml
res/f/i.xml
res/f/j.xml
res/f/k.xml
res/f/l.xml
res/f/m.xml
res/f/n.xml
res/f/o.xml
res/f/p.xml
res/f/q.xml
res/f/r.xml
res/f/s.xml
res/f/t.xml
res/f/u.xml
res/f/v.xml
res/f/w.xml
res/f/x.xml
res/f/y.xml
res/f/z.xml
res/g/a.xml
res/h/a.xml
res/h/b.xml
res/h/c.xml
res/h/d.xml
res/h/e.xml
res/h/f.xml
res/h/g.xml
res/h/h.xml
res/i/a.xml
res/i/b.xml
res/i/c.xml
res/j/a.xml
res/j/a0.xml
res/j/a1.xml
res/j/a2.xml
res/j/a3.xml
res/j/a4.xml
res/j/a5.xml
res/j/a6.xml
res/j/a7.xml
res/j/a8.xml
res/j/a9.xml
res/j/a_.xml
res/j/aa.xml
res/j/ab.xml
res/j/ac.xml
res/j/ad.xml
res/j/ae.xml
res/j/af.xml
res/j/ag.xml
res/j/ah.xml
res/j/ai.xml
res/j/aj.xml
res/j/ak.xml
res/j/al.xml
res/j/am.xml
res/j/an.xml
res/j/ao.xml
res/j/ap.xml
res/j/aq.xml
res/j/ar.xml
res/j/as.xml
res/j/at.xml
res/j/au.xml
res/j/av.xml
res/j/aw.xml
res/j/ax.xml
res/j/ay.xml
res/j/az.xml
res/j/b.xml
res/j/b0.xml
res/j/b1.xml
res/j/b2.xml
res/j/b3.xml
res/j/b4.xml
res/j/b5.xml
res/j/b6.xml
res/j/b7.xml
res/j/b8.xml
res/j/b9.xml
res/j/b_.xml
res/j/ba.xml
res/j/bb.xml
res/j/c.xml
res/j/d.xml
res/j/e.xml
res/j/f.xml
res/j/g.xml
res/j/h.xml
res/j/i.xml
res/j/j.xml
res/j/k.xml
res/j/l.xml
res/j/m.xml
res/j/n.xml
res/j/o.xml
res/j/p.xml
res/j/q.xml
res/j/r.xml
res/j/s.xml
res/j/t.xml
res/j/u.xml
res/j/v.xml
res/j/w.xml
res/j/x.xml
res/j/y.xml
res/j/z.xml
res/k/a1.9.png
res/k/a3.png
res/k/a5.9.png
res/k/ah.9.png
res/k/am.png
res/k/ao.9.png
res/k/as.png
res/k/au.9.png
res/k/b9.png
res/k/ba.9.png
res/k/bb.9.png
res/k/bf.9.png
res/k/bl.9.png
res/k/bu.9.png
res/k/bv.9.png
res/k/bx.9.png
res/k/c.9.png
res/k/cc.9.png
res/k/cp.9.png
res/l/g.webp
res/l/t.9.png
res/m/a.png
res/m/ak.png
res/m/at.png
res/m/b2.png
res/m/c6.png
res/m/c9.png
res/m/cu.png
res/m/i.png
res/n/a2.webp
res/n/a4.webp
res/n/a7.webp
res/n/a_.webp
res/n/ab.webp
res/n/ak.webp
res/n/ao.webp
res/n/aq.webp
res/n/at.png
res/n/au.webp
res/n/b0.webp
res/n/b2.png
res/n/b6.webp
res/n/b9.webp
res/n/b_.png
res/n/bf.webp
res/n/bm.webp
res/n/bp.png
res/n/br.webp
res/n/bs.webp
res/n/bz.webp
res/n/c3.webp
res/n/c4.webp
res/n/c8.png
res/n/c_.png
res/n/cb.webp
res/n/cm.webp
res/n/cn.png
res/n/co.webp
res/n/cs.webp
res/n/cu.webp
res/n/cv.png
res/n/cz.webp
res/n/d1.webp
res/n/d3.png
res/n/d_.png
res/n/m.png
res/n/o.png
res/n/q.png
res/n/u.webp
res/n/x.webp
res/o/a.xml
res/o/b.xml
res/o/c.xml
res/o/d.xml
res/o/e.xml
res/o/f.xml
res/o/g.xml
res/o/h.xml
res/o/i.xml
res/p/a6.xml
res/p/j.xml
res/q/a.xml
res/r/a.xml
res/x/ab.png
res/x/d.png
res/xml/splits0.xml
res/y/a.mp4
res/y/b.webm
resources.arsc
transport-api.properties
transport-backend-cct.properties
transport-runtime.properties
user-messaging-platform.properties
stamp-cert-sha256
META-INF/BNDLTOOL.SF
META-INF/BNDLTOOL.RSA
META-INF/MANIFEST.MF

污点分析

当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
规则名称 描述信息 操作
病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析