温馨提示:本平台仅供研究软件风险、安全评估,禁止用于非法用途。由于展示的数据过于全面,请耐心等待加载完成。如有疑问或建议, 可加入我们的微信群讨论

APP评分

病毒检测 19 个厂商报毒

安全评分

文件信息

文件名称 com.kawaii.kawaiiheroines.off.apk
文件大小 20.49MB
MD5 489113555ba62046e3fbb4bbe3b82f4f
SHA1 5c625b9b04455d72e4b663329c240695213acc81
SHA256 e055e141883a95af3565e23e1cea4f2977cf475df555853c10d327148ad24033

应用信息

应用名称 可爱就是正义
包名 com.kawaii.kawaiiheroines.off
主活动 com.was.api.WasActivity
目标SDK 28     最小SDK 16
版本号 1.2     子版本号 3
加固信息 360加固 加固

组件导出信息

反编译代码

Manifest文件 查看
APK文件 下载
Java源代码 查看 -- 下载

证书信息

二进制文件已签名
v1 签名: True
v2 签名: False
v3 签名: False
v4 签名: False
主题: C=10, ST=asdas, L=asdasd, O=asdas, OU=adas, CN=asda
签名算法: rsassa_pkcs1v15
有效期自: 2017-06-22 02:27:31+00:00
有效期至: 3016-10-23 02:27:31+00:00
发行人: C=10, ST=asdas, L=asdasd, O=asdas, OU=adas, CN=asda
序列号: 0x7f6c9026
哈希算法: sha256
证书MD5: b8b25021f83c780d613d86732ae6b9e3
证书SHA1: f1b75a2b0b53690c2781d185ecf76a23997d36c7
证书SHA256: d6aa94df7016a6d04d5de179c688943fa29727f898c9097814c7754dfb946bd1
证书SHA512: 45f54f6be3d55ab331db0417b62d2559313fd09f75289b97966c760828365d237ab399c3f61f8c7c9f9f782d98800e01dfcef2b967b6b9f84c68b656c571a005
找到 1 个唯一证书

应用程序权限

权限名称 安全等级 权限内容 权限描述 关联代码
android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
com.android.vending.BILLING 普通 应用程序具有应用内购买 允许应用程序从 Google Play 进行应用内购买。
android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
android.permission.ACCESS_WIFI_STATE 普通 查看Wi-Fi状态 允许应用程序查看有关Wi-Fi状态的信息。
android.permission.ACCESS_COARSE_LOCATION 危险 获取粗略位置 通过WiFi或移动基站的方式获取用户错略的经纬度信息,定位精度大概误差在30~1500米。恶意程序可以用它来确定您的大概位置。
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
android.permission.READ_PHONE_STATE 危险 读取手机状态和标识 允许应用程序访问设备的手机功能。有此权限的应用程序可确定此手机的号码和序列号,是否正在通话,以及对方的号码等。
android.permission.WAKE_LOCK 危险 防止手机休眠 允许应用程序防止手机休眠,在手机屏幕关闭后后台进程仍然运行。
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE 普通 Google 定义的权限 由 Google 定义的自定义权限。
android.permission.READ_EXTERNAL_STORAGE 危险 读取SD卡内容 允许应用程序从SD卡读取信息。
com.android.vending.CHECK_LICENSE 未知 未知权限 来自 android 引用的未知权限。
android.permission.GET_TASKS 危险 检索当前运行的应用程序 允许应用程序检索有关当前和最近运行的任务的信息。恶意应用程序可借此发现有关其他应用程序的保密信息。
android.permission.ACCESS_COARSE_UPDATES 未知 未知权限 来自 android 引用的未知权限。
android.permission.WRITE_SETTINGS 危险 修改全局系统设置 允许应用程序修改系统设置方面的数据。恶意应用程序可借此破坏您的系统配置。
android.permission.CHANGE_WIFI_STATE 危险 改变Wi-Fi状态 允许应用程序改变Wi-Fi状态。
android.permission.VIBRATE 普通 控制振动器 允许应用程序控制振动器,用于消息通知振动功能。
android.permission.SYSTEM_ALERT_WINDOW 危险 弹窗 允许应用程序弹窗。 恶意程序可以接管手机的整个屏幕。
com.android.browser.permission.READ_HISTORY_BOOKMARKS 危险 获取自带浏览器上网记录 恶意代码可有利用此权限窃取用户的上网记录和书签。
android.permission.LOCAL_MAC_ADDRESS 未知 未知权限 来自 android 引用的未知权限。
android.permission.SEND_DOWNLOAD_COMPLETED_INTENTS 未知 未知权限 来自 android 引用的未知权限。
android.permission.DOWNLOAD_WITHOUT_NOTIFICATION 普通 后台下载文件 这个权限是允许应用通过下载管理器下载文件,且不对用户进行任何提示。
android.permission.REQUEST_INSTALL_PACKAGES 危险 允许安装应用程序 Android8.0 以上系统允许安装未知来源应用程序权限。
android.permission.ACCESS_FINE_LOCATION 危险 获取精确位置 通过GPS芯片接收卫星的定位信息,定位精度达10米以内。恶意程序可以用它来确定您所在的位置。

证书分析

高危
1
警告
0
信息
1
标题 严重程度 描述信息
已签名应用 信息 应用程序已使用代码签名证书进行签名
应用程序存在Janus漏洞 高危 应用程序使用了v1签名方案进行签名,如果只使用v1签名方案,那么它就容易受到安卓5.0-8.0上的Janus漏洞的攻击。在安卓5.0-7.0上运行的使用了v1签名方案的应用程序,以及同时使用了v2/v3签名方案的应用程序也同样存在漏洞。

MANIFEST分析

高危
1
警告
5
信息
0
屏蔽
0
序号 问题 严重程度 描述信息 操作
1 应用程序可以安装在有漏洞的已更新 Android 版本上
Android 4.1-4.1.2, [minSdk=16]
信息 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
2 应用程序已启用明文网络流量
[android:usesCleartextTraffic=true]
警告 应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。
3 应用程序数据可以被备份
[android:allowBackup=true]
警告 这个标志允许任何人通过adb备份你的应用程序数据。它允许已经启用了USB调试的用户从设备上复制应用程序数据。
4 Activity (com.kawaii.kawaiiheroines.PTPlayer) 未被保护。
存在一个intent-filter。
警告 发现 Activity与设备上的其他应用程序共享,因此让它可以被设备上的任何其他应用程序访问。intent-filter的存在表明这个Activity是显式导出的。
5 Service (com.google.android.gms.auth.api.signin.RevocationBoundService) 受权限保护, 但是应该检查权限的保护级别。
Permission: com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION
[android:exported=true]
警告 发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。
6 Activity (com.facebook.CustomTabActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
7 Activity (com.facebook.CustomTabActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。

可浏览的ACTIVITIES

ACTIVITY INTENT
com.facebook.CustomTabActivity Schemes: fbconnect://,
Hosts: cct.com.kawaii.kawaiiheroines,

网络安全配置

序号 范围 严重级别 描述

API调用分析

API功能 源码文件
调用java反射机制
bolts/MeasurementEvent.java
com/common/busi/CustomView.java
com/jg/ids/h/a.java
com/miui/zeus/utils/a.java
com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/b/b.java
com/miui/zeus/utils/b/e.java
com/miui/zeus/utils/b/f.java
com/miui/zeus/utils/j.java
com/miui/zeus/utils/p.java
com/nineoldandroids/animation/PropertyValuesHolder.java
com/nineoldandroids/util/ReflectiveProperty.java
com/qihoo/jiagutracker/ViewInfo.java
com/stub/StubApp.java
com/stub/plugin/MyLog.java
com/stub/plugin/ReflectionUtil.java
com/stub/plugin/Stub01.java
com/stub/plugin/Stub02.java
com/stub/plugin/Stub03.java
com/stub/plugin/Stub04.java
com/stub/stub07/Stub01.java
com/was/api/CoreBridge.java
com/was/api/DexUtils.java
com/was/api/RefUtil.java
com/was/api/Vqqq.java
com/was/api/xm/XMInterstital.java
com/was/api/xm/XMReward.java
com/was/m/GoogleAdsRewardListener.java
com/was/m/GoogleAdsUnityRewardListener.java
com/was/m/IronsourceRewardListener.java
com/was/m/MopubRewardListener.java
com/was/m/RewardController.java
com/was/m/RewardManager.java
com/was/m/UnitySendUtils.java
com/was/m/WrapRewardListener.java
com/xiaomi/ad/c/a/c.java
com/xiaomi/analytics/a/a/c.java
com/xiaomi/analytics/a/b/d.java
com/xiaomi/analytics/a/b/i.java
com/xiaomi/analytics/a/b/l.java
grm/gz/MultiDex.java
grm/gz/MultiDexExtractor.java
rna/oz/v4/app/ActionBarDrawerToggleHoneycomb.java
rna/oz/v4/app/NotificationCompatJellybean.java
rna/oz/v4/graphics/drawable/DrawableCompatJellybeanMr1.java
rna/oz/v4/media/routing/MediaRouterJellybean.java
rna/oz/v4/media/routing/MediaRouterJellybeanMr1.java
rna/oz/v4/text/ICUCompatApi23.java
rna/oz/v4/text/ICUCompatIcs.java
rna/oz/v4/view/LayoutInflaterCompatHC.java
rna/oz/v4/view/ViewCompat.java
rna/oz/v4/view/ViewCompatBase.java
rna/oz/v4/view/ViewCompatEclairMr1.java
rna/oz/v4/view/ViewPager.java
rna/oz/v4/widget/CompoundButtonCompatDonut.java
rna/oz/v4/widget/PopupWindowCompatApi21.java
rna/oz/v4/widget/PopupWindowCompatGingerbread.java
rna/oz/v4/widget/SlidingPaneLayout.java
一般功能-> IPC通信
bolts/AppLinkNavigation.java
bolts/AppLinks.java
bolts/MeasurementEvent.java
com/common/busi/f.java
com/jg/ids/a/a.java
com/jg/ids/a/c.java
com/jg/ids/a/d.java
com/jg/ids/b/a.java
com/jg/ids/b/c.java
com/jg/ids/c/b.java
com/jg/ids/c/c.java
com/jg/ids/c/d.java
com/jg/ids/e/b.java
com/jg/ids/e/c.java
com/jg/ids/e/d.java
com/jg/ids/f/b.java
com/jg/ids/f/c.java
com/jg/ids/f/d.java
com/jg/ids/g.java
com/jg/ids/h.java
com/jg/ids/meizu/MeiZuReceiver.java
com/jg/ids/meizu/a.java
com/kawaii/kawaiiheroines/PTPlayer.java
com/miui/analytics/ICore.java
com/miui/zeus/pm/manager/PluginManager.java
com/miui/zeus/utils/a.java
com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/clientInfo/utils/AdvertisingIdHelper.java
com/miui/zeus/utils/clientInfo/utils/b.java
com/miui/zeus/utils/i/a.java
com/miui/zeus/utils/i/b.java
com/miui/zeus/utils/i/d.java
com/qihoo/jiagutracker/Instrument/CustomInstrumentation.java
com/qihoo/jiagutracker/Instrument/InstrumentCallback.java
com/secrethq/store/util/IabHelper.java
com/secrethq/utils/PTServicesBridge.java
com/stub/plugin/Stub01.java
com/stub/plugin/Stub02.java
com/stub/plugin/Stub03.java
com/stub/stub07/Stub01.java
com/was/api/PermissionChecker.java
com/was/api/dym/Xj3sb.java
com/was/m/RewardManager.java
com/xiaomi/ad/a/a.java
com/xiaomi/ad/a/b.java
com/xiaomi/ad/a/c.java
com/xiaomi/ad/common/Debugger.java
com/xiaomi/ad/common/app/DownloadInstallManager.java
com/xiaomi/ad/common/app/DownloadInstallReceiver.java
com/xiaomi/ad/common/pojo/AdIntent.java
com/xiaomi/analytics/Analytics.java
com/xiaomi/analytics/a/a/c.java
com/xiaomi/analytics/a/b.java
com/xiaomi/analytics/a/c.java
rna/oz/v4/app/ActivityCompat.java
rna/oz/v4/app/ActivityCompatJB.java
rna/oz/v4/app/Fragment.java
rna/oz/v4/app/FragmentActivity.java
rna/oz/v4/app/FragmentHostCallback.java
rna/oz/v4/app/INotificationSideChannel.java
rna/oz/v4/app/NavUtils.java
rna/oz/v4/app/NavUtilsJB.java
rna/oz/v4/app/NotificationCompat.java
rna/oz/v4/app/NotificationCompatApi20.java
rna/oz/v4/app/NotificationCompatApi21.java
rna/oz/v4/app/NotificationCompatBase.java
rna/oz/v4/app/NotificationCompatGingerbread.java
rna/oz/v4/app/NotificationCompatHoneycomb.java
rna/oz/v4/app/NotificationCompatIceCreamSandwich.java
rna/oz/v4/app/NotificationCompatJellybean.java
rna/oz/v4/app/NotificationCompatKitKat.java
rna/oz/v4/app/NotificationCompatSideChannelService.java
rna/oz/v4/app/NotificationManagerCompat.java
rna/oz/v4/app/RemoteInput.java
rna/oz/v4/app/RemoteInputCompatApi20.java
rna/oz/v4/app/RemoteInputCompatJellybean.java
rna/oz/v4/app/ShareCompat.java
rna/oz/v4/app/ShareCompatICS.java
rna/oz/v4/app/TaskStackBuilder.java
rna/oz/v4/app/TaskStackBuilderHoneycomb.java
rna/oz/v4/app/TaskStackBuilderJellybean.java
rna/oz/v4/content/ContextCompat.java
rna/oz/v4/content/ContextCompatHoneycomb.java
rna/oz/v4/content/ContextCompatJellybean.java
rna/oz/v4/content/IntentCompat.java
rna/oz/v4/content/IntentCompatHoneycomb.java
rna/oz/v4/content/IntentCompatIcsMr1.java
rna/oz/v4/content/LocalBroadcastManager.java
rna/oz/v4/content/WakefulBroadcastReceiver.java
rna/oz/v4/media/TransportMediatorJellybeanMR2.java
rna/oz/v4/media/session/IMediaControllerCallback.java
rna/oz/v4/media/session/IMediaSession.java
rna/oz/v4/media/session/MediaControllerCompat.java
rna/oz/v4/media/session/MediaControllerCompatApi21.java
rna/oz/v4/media/session/MediaSessionCompat.java
rna/oz/v4/media/session/MediaSessionCompatApi14.java
rna/oz/v4/media/session/MediaSessionCompatApi18.java
rna/oz/v4/media/session/MediaSessionCompatApi21.java
rna/oz/v4/net/ConnectivityManagerCompat.java
加密解密-> 信息摘要算法
DEX-> 动态加载
一般功能-> 获取系统服务(getSystemService)
com/common/busi/CustomView.java
com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/f/c.java
com/miui/zeus/utils/j/c.java
com/secrethq/utils/PTServicesBridge.java
com/stub/stub07/Stub01.java
com/was/api/WasTools.java
com/xiaomi/ad/common/app/DownloadInstallManager.java
com/xiaomi/ad/common/app/DownloadInstallTaskStore.java
com/xiaomi/analytics/a/b/c.java
com/xiaomi/analytics/a/b/j.java
com/xiaomi/analytics/a/b/k.java
org/cocos2dx/lib/Cocos2dxAccelerometer.java
org/cocos2dx/lib/Cocos2dxEditBoxDialog.java
org/cocos2dx/lib/Cocos2dxGLSurfaceView.java
org/cocos2dx/lib/Cocos2dxTextInputWraper.java
rna/oz/v4/app/AppOpsManagerCompat23.java
rna/oz/v4/app/DialogFragment.java
rna/oz/v4/app/FragmentHostCallback.java
rna/oz/v4/app/NotificationManagerCompat.java
rna/oz/v4/content/WakefulBroadcastReceiver.java
rna/oz/v4/hardware/display/DisplayManagerCompat.java
rna/oz/v4/hardware/display/DisplayManagerJellybeanMr1.java
rna/oz/v4/hardware/fingerprint/FingerprintManagerCompatApi23.java
rna/oz/v4/media/TransportMediator.java
rna/oz/v4/media/routing/MediaRouterJellybean.java
rna/oz/v4/media/routing/MediaRouterJellybeanMr1.java
rna/oz/v4/media/session/MediaSessionCompat.java
rna/oz/v4/media/session/MediaSessionCompatApi14.java
rna/oz/v4/media/session/MediaSessionCompatApi18.java
rna/oz/v4/media/session/MediaSessionCompatApi8.java
rna/oz/v4/print/PrintHelperKitkat.java
rna/oz/v4/view/ViewParentCompat.java
rna/oz/v4/widget/ExploreByTouchHelper.java
rna/oz/v4/widget/ResourceCursorAdapter.java
rna/oz/v4/widget/SearchViewCompatHoneycomb.java
辅助功能accessibility相关 rna/oz/v4/view/accessibility/AccessibilityNodeInfoCompatIcs.java
rna/oz/v4/view/accessibility/AccessibilityNodeInfoCompatJellybeanMr2.java
网络通信-> TCP套接字 com/miui/zeus/utils/g/j.java
rna/oz/v4/net/TrafficStatsCompat.java
rna/oz/v4/net/TrafficStatsCompatIcs.java
一般功能-> 文件操作
bolts/AggregateException.java
bolts/CancellationTokenRegistration.java
bolts/CancellationTokenSource.java
bolts/WebViewAppLinkResolver.java
com/common/busi/a.java
com/common/busi/d.java
com/fakeu/FakeURL.java
com/fakeu/OnlyHttpClient.java
com/jg/ids/l.java
com/kawaii/kawaiiheroines/PTPlayer.java
com/miui/zeus/a/a.java
com/miui/zeus/a/b.java
com/miui/zeus/b/a/d.java
com/miui/zeus/b/a/e.java
com/miui/zeus/b/c.java
com/miui/zeus/c/a/a.java
com/miui/zeus/c/a/b.java
com/miui/zeus/c/a/c.java
com/miui/zeus/pm/manager/ApkPluginBase.java
com/miui/zeus/pm/manager/AssetApkPlugin.java
com/miui/zeus/pm/manager/DownloadApkPlugin.java
com/miui/zeus/pm/manager/PluginManager.java
com/miui/zeus/utils/a.java
com/miui/zeus/utils/b.java
com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/b/c.java
com/miui/zeus/utils/b/g.java
com/miui/zeus/utils/c/a.java
com/miui/zeus/utils/c/b.java
com/miui/zeus/utils/c/c.java
com/miui/zeus/utils/c/f.java
com/miui/zeus/utils/c/g.java
com/miui/zeus/utils/c/l.java
com/miui/zeus/utils/c/n.java
com/miui/zeus/utils/c/q.java
com/miui/zeus/utils/g/c.java
com/miui/zeus/utils/g/e.java
com/miui/zeus/utils/g/j.java
com/miui/zeus/utils/h.java
com/miui/zeus/utils/h/a.java
com/miui/zeus/utils/h/b.java
com/miui/zeus/utils/o.java
com/nineoldandroids/animation/AnimatorInflater.java
com/secrethq/utils/PTServicesBridge.java
com/stub/StubApp.java
com/was/api/DexUtils.java
com/was/api/Dir.java
com/was/api/WasActivity.java
com/was/api/WasDexLoader.java
com/was/api/WasTools.java
com/was/api/dym/Zy2sb.java
com/xiaomi/ad/c/a/a.java
com/xiaomi/ad/c/a/d.java
com/xiaomi/ad/common/app/DownloadInstallTaskStore.java
com/xiaomi/analytics/a/b/c.java
com/xiaomi/analytics/a/b/e.java
com/xiaomi/analytics/a/b/g.java
com/xiaomi/analytics/a/b/h.java
com/xiaomi/analytics/a/b/k.java
com/xiaomi/analytics/a/c.java
com/xiaomi/analytics/a/d.java
grm/gz/MultiDex.java
grm/gz/MultiDexExtractor.java
grm/gz/ZipUtil.java
org/cocos2dx/lib/Cocos2dxETCLoader.java
org/cocos2dx/lib/Cocos2dxHelper.java
org/cocos2dx/lib/Cocos2dxMusic.java
rna/oz/v4/app/ActivityCompatHoneycomb.java
rna/oz/v4/app/BackStackRecord.java
rna/oz/v4/app/Fragment.java
rna/oz/v4/app/FragmentActivity.java
rna/oz/v4/app/FragmentController.java
rna/oz/v4/app/FragmentHostCallback.java
rna/oz/v4/app/FragmentManager.java
rna/oz/v4/app/FragmentManagerImpl.java
rna/oz/v4/app/LoaderManager.java
rna/oz/v4/app/LoaderManagerImpl.java
rna/oz/v4/content/AsyncTaskLoader.java
rna/oz/v4/content/ContextCompat.java
rna/oz/v4/content/ContextCompatApi21.java
rna/oz/v4/content/ContextCompatFroyo.java
rna/oz/v4/content/ContextCompatHoneycomb.java
rna/oz/v4/content/ContextCompatKitKat.java
rna/oz/v4/content/CursorLoader.java
rna/oz/v4/content/EditorCompatGingerbread.java
rna/oz/v4/content/FileProvider.java
rna/oz/v4/content/Loader.java
rna/oz/v4/content/SharedPreferencesCompat.java
rna/oz/v4/graphics/drawable/RoundedBitmapDrawableFactory.java
rna/oz/v4/os/EnvironmentCompat.java
rna/oz/v4/os/EnvironmentCompatKitKat.java
rna/oz/v4/print/PrintHelper.java
rna/oz/v4/print/PrintHelperKitkat.java
rna/oz/v4/provider/DocumentFile.java
rna/oz/v4/provider/RawDocumentFile.java
rna/oz/v4/util/AtomicFile.java
rna/oz/v4/util/LogWriter.java
rna/oz/v4/util/TimeUtils.java
网络通信-> HTTP请求、连接和会话 com/fakeu/OnlyHttpClient.java
网络通信-> HTTP建立连接
进程操作-> 杀死进程
进程操作-> 获取进程pid
组件-> ContentProvider com/jg/ids/d/a.java
com/stub/plugin/Stub04.java
rna/oz/v4/content/FileProvider.java
加密解密-> Base64 加密 com/miui/zeus/utils/h.java
一般功能-> 传感器相关操作 org/cocos2dx/lib/Cocos2dxAccelerometer.java
一般功能-> 查看\修改Android系统属性 com/miui/zeus/utils/b/f.java
com/xiaomi/analytics/a/b/l.java
加密解密-> Crypto加解密组件
组件-> 启动 Activity
组件-> 发送广播
设备指纹-> 查看本机IMSI com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/j/c.java
一般功能-> 获取网络接口信息 com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/j/c.java
一般功能-> 获取活动网路信息
一般功能-> 设置手机铃声,媒体音量 rna/oz/v4/media/session/MediaSessionCompat.java
组件-> 启动 Service
隐私数据-> 屏幕截图,截取自己应用内部界面 rna/oz/v4/print/PrintHelperKitkat.java
网络通信-> URLConnection bolts/WebViewAppLinkResolver.java
com/fakeu/FakeURL.java
网络通信-> WebView JavaScript接口 bolts/WebViewAppLinkResolver.java
com/xiaomi/analytics/Analytics.java
网络通信-> WebView GET请求 bolts/WebViewAppLinkResolver.java
JavaScript 接口方法 bolts/WebViewAppLinkResolver.java
com/xiaomi/analytics/Analytics.java
网络通信-> WebView 相关 bolts/WebViewAppLinkResolver.java
隐私数据-> 获取已安装的应用程序 com/miui/zeus/utils/b/a.java
com/miui/zeus/utils/i/b.java
进程操作-> 获取运行的进程\服务 com/miui/zeus/utils/b/a.java
com/xiaomi/analytics/a/b/c.java
一般功能-> Android通知 rna/oz/v4/app/NotificationManagerCompat.java
rna/oz/v4/app/NotificationManagerCompatEclair.java
一般功能-> 获取WiFi相关信息 com/miui/zeus/utils/b/a.java
com/xiaomi/analytics/a/b/k.java
网络通信-> HTTPS建立连接 com/miui/zeus/utils/g/j.java
com/was/api/WasActivity.java
DEX-> 加载和操作Dex文件 com/stub/StubApp.java
com/was/api/Vqqq.java
grm/gz/MultiDex.java
网络通信-> SSL证书处理 com/miui/zeus/utils/g/j.java
一般功能-> 加载so文件 com/jg/ce/Interface2.java
com/kawaii/kawaiiheroines/PTPlayer.java
com/stub/StubApp.java
组件-> Provider openFile rna/oz/v4/content/FileProvider.java

源代码分析

高危
4
警告
8
信息
1
安全
0
屏蔽
0
序号 问题 等级 参考标准 文件位置 操作
1 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
com/jg/ids/e/d.java
com/miui/zeus/a/b.java
com/secrethq/utils/PTServicesBridge.java
2 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3
bolts/MeasurementEvent.java
com/buildbox/AdIntegrator.java
com/kawaii/kawaiiheroines/PTPlayer.java
com/miui/zeus/b/a/d.java
com/miui/zeus/b/a/e.java
com/miui/zeus/b/e.java
com/miui/zeus/pm/manager/PluginManager.java
com/miui/zeus/utils/a/c.java
com/miui/zeus/utils/b/e.java
com/miui/zeus/utils/c/n.java
com/miui/zeus/utils/f/c.java
com/nineoldandroids/animation/PropertyValuesHolder.java
com/secrethq/ads/PTAdAdMobBridge.java
com/secrethq/ads/PTAdChartboostBridge.java
com/secrethq/ads/PTAdInMobiBridge.java
com/secrethq/store/PTStoreBridge.java
com/secrethq/store/util/IabHelper.java
com/secrethq/store/util/Security.java
com/secrethq/utils/PTServicesBridge.java
com/stub/plugin/MyLog.java
com/was/api/PermissionChecker.java
com/was/api/WasTools.java
com/was/api/dym/Hlwdsb.java
com/was/api/dym/Xj3sb.java
com/was/api/dym/Zy2sb.java
com/was/api/xm/XMBanner.java
com/was/api/xm/XMFloatAD.java
com/was/api/xm/XMInterstital.java
com/was/api/xm/XMReward.java
com/was/api/xm/XMRewardVideo.java
com/was/api/xm/XiaomiFeed.java
com/was/m/ApplovinFacadeRewardListener.java
com/was/m/ApplovinRewardListener.java
com/was/m/ChartboostAdsUnityRewardListener.java
com/was/m/GoogleAdsRewardListener.java
com/was/m/GoogleAdsUnityRewardListener.java
com/was/m/HeyzapRewardListener.java
com/was/m/InappsettingsRewardListener.java
com/was/m/IronsourceRewardListener.java
com/was/m/MaxUnityRewardListener.java
com/was/m/MopubRewardListener.java
com/was/m/RewardController.java
com/was/m/StubRewardListener.java
com/was/m/UnitySendUtils.java
com/was/m/VideoRewardListener.java
com/was/m/WrapRewardListener.java
com/xiaomi/analytics/Action.java
com/xiaomi/analytics/Analytics.java
com/xiaomi/analytics/EventAction.java
com/xiaomi/analytics/LogEvent.java
com/xiaomi/analytics/LoggerFactory.java
com/xiaomi/analytics/a/a/b.java
com/xiaomi/analytics/a/a/c.java
com/xiaomi/analytics/a/b.java
com/xiaomi/analytics/a/b/b.java
com/xiaomi/analytics/a/b/e.java
com/xiaomi/analytics/a/b/h.java
com/xiaomi/analytics/a/b/k.java
com/xiaomi/analytics/a/b/l.java
com/xiaomi/analytics/a/b/m.java
com/xiaomi/analytics/a/c.java
com/xiaomi/analytics/a/d.java
grm/gz/MultiDex.java
grm/gz/MultiDexExtractor.java
org/cocos2dx/lib/Cocos2dxActivity.java
org/cocos2dx/lib/Cocos2dxBitmap.java
org/cocos2dx/lib/Cocos2dxETCLoader.java
org/cocos2dx/lib/Cocos2dxGLSurfaceView.java
org/cocos2dx/lib/Cocos2dxLocalStorage.java
org/cocos2dx/lib/Cocos2dxMusic.java
org/cocos2dx/lib/Cocos2dxReflectionHelper.java
org/cocos2dx/lib/Cocos2dxRenderer.java
org/cocos2dx/lib/Cocos2dxSound.java
rna/oz/v4/app/ActionBarDrawerToggleHoneycomb.java
rna/oz/v4/app/BackStackRecord.java
rna/oz/v4/app/BackStackState.java
rna/oz/v4/app/FragmentActivity.java
rna/oz/v4/app/FragmentManagerImpl.java
rna/oz/v4/app/FragmentState.java
rna/oz/v4/app/FragmentStatePagerAdapter.java
rna/oz/v4/app/LoaderManagerImpl.java
rna/oz/v4/app/NavUtils.java
rna/oz/v4/app/NotificationCompatJellybean.java
rna/oz/v4/app/NotificationManagerCompat.java
rna/oz/v4/app/RemoteInput.java
rna/oz/v4/app/ShareCompat.java
rna/oz/v4/app/TaskStackBuilder.java
rna/oz/v4/content/ContextCompat.java
rna/oz/v4/content/LocalBroadcastManager.java
rna/oz/v4/content/ModernAsyncTask.java
rna/oz/v4/content/WakefulBroadcastReceiver.java
rna/oz/v4/graphics/drawable/DrawableCompatJellybeanMr1.java
rna/oz/v4/graphics/drawable/RoundedBitmapDrawableFactory.java
rna/oz/v4/media/MediaMetadataCompat.java
rna/oz/v4/media/RatingCompat.java
rna/oz/v4/media/TransportMediatorJellybeanMR2.java
rna/oz/v4/media/routing/MediaRouterJellybean.java
rna/oz/v4/media/routing/MediaRouterJellybeanMr1.java
rna/oz/v4/media/session/MediaControllerCompat.java
rna/oz/v4/os/EnvironmentCompat.java
rna/oz/v4/print/PrintHelperKitkat.java
rna/oz/v4/provider/DocumentsContractApi19.java
rna/oz/v4/provider/DocumentsContractApi21.java
rna/oz/v4/provider/RawDocumentFile.java
rna/oz/v4/speech/tts/TextToSpeechICS.java
rna/oz/v4/text/ICUCompatApi23.java
rna/oz/v4/text/ICUCompatIcs.java
rna/oz/v4/util/AtomicFile.java
rna/oz/v4/util/LogWriter.java
rna/oz/v4/view/ActionProvider.java
rna/oz/v4/view/LayoutInflaterCompatHC.java
rna/oz/v4/view/MenuItemCompat.java
rna/oz/v4/view/ViewCompat.java
rna/oz/v4/view/ViewCompatEclairMr1.java
rna/oz/v4/view/ViewPager.java
rna/oz/v4/view/ViewParentCompatLollipop.java
rna/oz/v4/widget/CompoundButtonCompatDonut.java
rna/oz/v4/widget/NestedScrollView.java
rna/oz/v4/widget/PopupWindowCompatApi21.java
rna/oz/v4/widget/SlidingPaneLayout.java
rna/oz/v4/widget/SwipeRefreshLayout.java
3 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
4 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
5 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-6
com/miui/zeus/utils/k.java
com/xiaomi/analytics/a/d.java
6 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 警告 CWE: CWE-312: 明文存储敏感信息
OWASP Top 10: M9: Reverse Engineering
OWASP MASVS: MSTG-STORAGE-14
7 该文件是World Writable。任何应用程序都可以写入文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
org/cocos2dx/lib/Cocos2dxHelper.java
8 应用程序创建临时文件。敏感信息永远不应该被写进临时文件 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
com/secrethq/utils/PTServicesBridge.java
grm/gz/MultiDexExtractor.java
9 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 警告 CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
OWASP Top 10: M7: Client Code Quality
org/cocos2dx/lib/Cocos2dxLocalStorage.java
10 不安全的Web视图实现。可能存在WebView任意代码执行漏洞 警告 CWE: CWE-749: 暴露危险方法或函数
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-7
bolts/WebViewAppLinkResolver.java
11 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击 高危 CWE: CWE-79: 在Web页面生成时对输入的转义处理不恰当('跨站脚本')
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-6
bolts/WebViewAppLinkResolver.java
12 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。 高危 CWE: CWE-649: 依赖于混淆或加密安全相关输入而不进行完整性检查
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-3
com/was/api/WasTools.java
13 该文件是World Readable。任何应用程序都可以读取文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
com/xiaomi/ad/c/a/d.java

动态库分析

No Shared Objects found.
序号 动态库 NX(堆栈禁止执行) STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)

文件分析

序号 问题 文件

VIRUSTOTAL扫描

  检出率: 19 / 65       完整报告

反病毒引擎 检出结果
AhnLab-V3 PUP/Android.Adload.1107517
Alibaba AdWare:Android/Agent.e071324b
Antiy-AVL Trojan/Generic.ASMalwAD.C
Avira ADWARE/ANDR.Ewind.FRGC.Gen
BitDefenderFalx Android.Adware.GingerMaster.GE
Cynet Malicious (score: 99)
ESET-NOD32 a variant of Android/Packed.Jiagu.D potentially unsafe
F-Secure Adware.ADWARE/ANDR.Ewind.FRGC.Gen
Ikarus Trojan-Dropper.AndroidOS.Agent
Jiangmin Trojan.Generic.gwsjy
K7GW Trojan ( 0052d2661 )
Kaspersky not-a-virus:HEUR:AdWare.AndroidOS.Agent.ev
Lionic Adware.AndroidOS.Ewind.A!c
MaxSecure Android.WIN32.Robtes.dc
NANO-Antivirus Riskware.Android.Ewind.ilzxjh
SymantecMobileInsight AppRisk:Generisk
Trustlook Android.PUA.Adware
Xcitium ApplicUnwnt@#1v9arstz4sjkb
ZoneAlarm not-a-virus:HEUR:AdWare.AndroidOS.Agent.ev

滥用权限

恶意软件常用权限 9/30
android.permission.ACCESS_COARSE_LOCATION
android.permission.READ_PHONE_STATE
android.permission.WAKE_LOCK
android.permission.GET_TASKS
android.permission.WRITE_SETTINGS
android.permission.VIBRATE
android.permission.SYSTEM_ALERT_WINDOW
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.ACCESS_FINE_LOCATION
其它常用权限 7/46
android.permission.INTERNET
android.permission.ACCESS_NETWORK_STATE
android.permission.ACCESS_WIFI_STATE
android.permission.WRITE_EXTERNAL_STORAGE
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
android.permission.READ_EXTERNAL_STORAGE
android.permission.CHANGE_WIFI_STATE

恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。

IP地图

域名检测

域名 状态 中国境内 位置信息 解析
test.zeus.ad.xiaomi.com 安全
没有可用的地理位置信息。




zeus.ad.xiaomi.com 安全
IP地址: 111.13.141.27
国家: 中国
地区: 北京
城市: 北京
查看: 高德地图





sdkconfig.ad.intl.xiaomi.com 安全
IP地址: 8.219.6.100
国家: 新加坡
地区: 新加坡
城市: 新加坡
查看: Google 地图





a.dan665.com 安全
IP地址: 8.219.6.100
国家: 中国
地区: 广东
城市: 深圳
查看: 高德地图





sdkconfig.ad.xiaomi.com 安全
IP地址: 111.13.141.27
国家: 中国
地区: 北京
城市: 北京
查看: 高德地图





手机号码

网址

网址信息 源码文件
http://39.108.85.226:8080/a/lk?m=
com/was/api/WasActivity.java
http://a.dan665.com:9127/ll/gs
com/was/api/dym/Zy2sb.java
https://test.zeus.ad.xiaomi.com/client/upgrade/mimo/v1
https://zeus.ad.xiaomi.com/client/upgrade/mimo/v1
com/xiaomi/ad/common/MimoSdkConfig.java
https://sdkconfig.ad.xiaomi.com/api/checkupdate/lastusefulversion2?
https://sdkconfig.ad.intl.xiaomi.com/api/checkupdate/lastusefulversion2?
com/xiaomi/analytics/a/d.java

FIREBASE实例

邮箱

密钥凭证

已显示 17 个secrets
1、 友盟统计的=> "UMENG_APPKEY" : "fd4b8f30fba54a8094e34e20a6c31c26"
2、 友盟统计的=> "UMENG_CHANNEL" : "xmtok"
3、 AdMob广告平台的=> "com.google.android.gms.ads.APPLICATION_ID" : "ca-app-pub-1785290411592283~4082375772"
4、 凭证信息=> "com.google.android.gms.games.APP_ID" : "@string/app_id"
5、 5e8f16062ea3cd2c4a0d547876baa6f38cabf625
6、 3082046c30820354a003020102020900e552a8ecb9011b7c300d06092a864886f70d0101050500308180310b300906035504061302434e3110300e060355040813074265696a696e673110300e060355040713074265696a696e67310f300d060355040a13065869616f6d69310d300b060355040b13044d495549310d300b060355040313044d495549311e301c06092a864886f70d010901160f6d697569407869616f6d692e636f6d301e170d3131313230363033323632365a170d3339303432333033323632365a308180310b300906035504061302434e3110300e060355040813074265696a696e673110300e060355040713074265696a696e67310f300d060355040a13065869616f6d69310d300b060355040b13044d495549310d300b060355040313044d495549311e301c06092a864886f70d010901160f6d697569407869616f6d692e636f6d30820120300d06092a864886f70d01010105000382010d00308201080282010100c786568a9aff253ad74c5d3e6fbffa12fed44cd3244f18960ec5511bb551e413115197234845112cc3df9bbacd3e0f4b3528cd87ed397d577dc9008e9cbc6a25fc0664d3a3f440243786db8b250d40f6f148c9a3cd6fbc2dd8d24039bd6a8972a1bdee28c308798bfa9bb3b549877b10f98e265f118c05f264537d95e29339157b9d2a31485e0c823521cca6d0b721a8432600076d669e20ac43aa588b52c11c2a51f04c6bb31ad6ae8573991afe8e4957d549591fcb83ec62d1da35b1727dc6b63001a5ef387b5a7186c1e68da1325772b5307b1bc739ef236b9efe06d52dcaf1e32768e3403e55e3ec56028cf5680cfb33971ccf7870572bc47d3e3affa385020103a381e83081e5301d0603551d0e0416041491ae2f8c72e305f92aa9f7452e2a3160b841a15c3081b50603551d230481ad3081aa801491ae2f8c72e305f92aa9f7452e2a3160b841a15ca18186a48183308180310b300906035504061302434e3110300e060355040813074265696a696e673110300e060355040713074265696a696e67310f300d060355040a13065869616f6d69310d300b060355040b13044d495549310d300b060355040313044d495549311e301c06092a864886f70d010901160f6d697569407869616f6d692e636f6d820900e552a8ecb9011b7c300c0603551d13040530030101ff300d06092a864886f70d010105050003820101003b3a699ceb497300f2ab86cbd41c513440bf60aa5c43984eb1da140ef30544d9fbbb3733df24b26f2703d7ffc645bf598a5e6023596a947e91731542f2c269d0816a69c92df9bfe8b1c9bc3c54c46c12355bb4629fe6020ca9d15f8d6155dc5586f5616db806ecea2d06bd83e32b5f13f5a04fe3e5aa514f05df3d555526c63d3d62acf00adee894b923c2698dc571bc52c756ffa7a2221d834d10cb7175c864c30872fe217c31442dff0040a67a2fb1c8ba63eac2d5ba3d8e76b4ff2a49b0db8a33ef4ae0dd0a840dd2a8714cb5531a56b786819ec9eb1051d91b23fde06bd9d0708f150c4f9efe6a416ca4a5e0c23a952af931ad3579fb4a8b19de98f64bd9
7、 17853953c5adafd100f24cd747edd6b7
8、 2438bce1ddb7bd026d5ff89f598b3b5e5bb824b3
9、 c14544e18450a763c7f009cc9b892ad7
10、 6d089fcf31523ea73ca94138571ed31e
11、 9b8f518b086098de3d77736f9458a3d2f6f95a37
12、 cc2751449a350f668590264ed76692694a80308a
13、 701478a1e3b4b7e3978ea69469410f13
14、 308204a830820390a003020102020900b3998086d056cffa300d06092a864886f70d0101040500308194310b3009060355040613025553311330110603550408130a43616c69666f726e6961311630140603550407130d4d6f756e7461696e20566965773110300e060355040a1307416e64726f69643110300e060355040b1307416e64726f69643110300e06035504031307416e64726f69643122302006092a864886f70d0109011613616e64726f696440616e64726f69642e636f6d301e170d3038303431353232343035305a170d3335303930313232343035305a308194310b3009060355040613025553311330110603550408130a43616c69666f726e6961311630140603550407130d4d6f756e7461696e20566965773110300e060355040a1307416e64726f69643110300e060355040b1307416e64726f69643110300e06035504031307416e64726f69643122302006092a864886f70d0109011613616e64726f696440616e64726f69642e636f6d30820120300d06092a864886f70d01010105000382010d003082010802820101009c780592ac0d5d381cdeaa65ecc8a6006e36480c6d7207b12011be50863aabe2b55d009adf7146d6f2202280c7cd4d7bdb26243b8a806c26b34b137523a49268224904dc01493e7c0acf1a05c874f69b037b60309d9074d24280e16bad2a8734361951eaf72a482d09b204b1875e12ac98c1aa773d6800b9eafde56d58bed8e8da16f9a360099c37a834a6dfedb7b6b44a049e07a269fccf2c5496f2cf36d64df90a3b8d8f34a3baab4cf53371ab27719b3ba58754ad0c53fc14e1db45d51e234fbbe93c9ba4edf9ce54261350ec535607bf69a2ff4aa07db5f7ea200d09a6c1b49e21402f89ed1190893aab5a9180f152e82f85a45753cf5fc19071c5eec827020103a381fc3081f9301d0603551d0e041604144fe4a0b3dd9cba29f71d7287c4e7c38f2086c2993081c90603551d230481c13081be80144fe4a0b3dd9cba29f71d7287c4e7c38f2086c299a1819aa48197308194310b3009060355040613025553311330110603550408130a43616c69666f726e6961311630140603550407130d4d6f756e7461696e20566965773110300e060355040a1307416e64726f69643110300e060355040b1307416e64726f69643110300e06035504031307416e64726f69643122302006092a864886f70d0109011613616e64726f696440616e64726f69642e636f6d820900b3998086d056cffa300c0603551d13040530030101ff300d06092a864886f70d01010405000382010100572551b8d93a1f73de0f6d469f86dad6701400293c88a0cd7cd778b73dafcc197fab76e6212e56c1c761cfc42fd733de52c50ae08814cefc0a3b5a1a4346054d829f1d82b42b2048bf88b5d14929ef85f60edd12d72d55657e22e3e85d04c831d613d19938bb8982247fa321256ba12d1d6a8f92ea1db1c373317ba0c037f0d1aff645aef224979fba6e7a14bc025c71b98138cef3ddfc059617cf24845cf7b40d6382f7275ed738495ab6e5931b9421765c491b72fb68e080dbdb58c2029d347c8b328ce43ef6a8b15533edfbe989bd6a48dd4b202eda94c6ab8dd5b8399203daae2ed446232e4fe9bd961394c6300e5138e3cfd285e6e4e483538cb8b1b357
15、 8a3c4b262d721acd49a4bf97d5213199c86fa2b9
16、 df6b721c8b4d3b6eb44c861d4415007e5a35fc95
17、 a4b7452e2ed8f5f191058ca7bbfd26b0d3214bfc

字符串列表

建议导出为TXT,方便查看。

活动列表

已显示 14 个activities
1、 com.kawaii.kawaiiheroines.PTPlayer
2、 com.google.android.gms.auth.api.signin.internal.SignInHubActivity
3、 com.google.android.gms.common.api.GoogleApiActivity
4、 com.facebook.FacebookActivity
5、 com.facebook.CustomTabMainActivity
6、 com.facebook.CustomTabActivity
7、 com.was.api.WasActivity
8、 com.was.ff.NdnzdActivity
9、 com.was.ff.WycghzActivity
10、 com.was.ff.SuseActivity
11、 com.was.ff.WsjyActivity
12、 com.zxing.ScancodeActivity
13、 com.miui.zeus.mimo.sdk.activityProxy.ProxyActivity
14、 com.miui.zeus.mimo.sdk.activityProxy.FullScreenProxyActivity

服务列表

已显示 2 个services
1、 com.google.android.gms.auth.api.signin.RevocationBoundService
2、 com.virtu.UnionLoginService

广播接收者列表

已显示 1 个receivers
1、 com.facebook.CurrentAccessTokenExpirationBroadcastReceiver

内容提供者列表

已显示 3 个providers
1、 com.google.android.gms.ads.MobileAdsInitProvider
2、 com.facebook.internal.FacebookInitProvider
3、 android.support.v4.content.FileProvider

第三方SDK

SDK名称 开发者 描述信息
360 加固 360 360 加固保是基于 360 核心加密技术,给安卓应用进行深度加密、加壳保护的安全技术产品,可保护应用远离恶意破解、反编译、二次打包,内存抓取等威胁。
Google Sign-In Google 提供使用 Google 登录的 API。
Google Play Service Google 借助 Google Play 服务,您的应用可以利用由 Google 提供的最新功能,例如地图,Google+ 等,并通过 Google Play 商店以 APK 的形式分发自动平台更新。 这样一来,您的用户可以更快地接收更新,并且可以更轻松地集成 Google 必须提供的最新信息。
File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。

文件列表

AndroidManifest.xml
androidsupportmultidexversion.txt
assets/.appkey
assets/data/atlases/atlas_ID107.plist
assets/data/atlases/atlas_ID107.png
assets/data/atlases/atlas_ID14275.plist
assets/data/atlases/atlas_ID14275.png
assets/data/atlases/atlas_ID15071.plist
assets/data/atlases/atlas_ID15071.png
assets/data/atlases/atlas_ID2952.plist
assets/data/atlases/atlas_ID2952.png
assets/data/data.pkg
assets/data/fonts/PTModelFont_ID10538.fnt
assets/data/fonts/PTModelFont_ID10538.png
assets/data/fonts/PTModelFont_ID10633.fnt
assets/data/fonts/PTModelFont_ID10633.png
assets/data/fonts/PTModelFont_ID11005.fnt
assets/data/fonts/PTModelFont_ID11005.png
assets/data/fonts/PTModelFont_ID11100.fnt
assets/data/fonts/PTModelFont_ID11100.png
assets/data/fonts/PTModelFont_ID13588.fnt
assets/data/fonts/PTModelFont_ID13588.png
assets/data/fonts/PTModelFont_ID2.fnt
assets/data/fonts/PTModelFont_ID2.png
assets/data/fonts/PTModelFont_ID38592.fnt
assets/data/fonts/PTModelFont_ID38592.png
assets/data/fx/flagMap.png
assets/data/fx/lightMap.png
assets/data/fx/trailMap.png
assets/data/images/PTModelSprite_ID26933.png
assets/data/images/PTModelSprite_ID35565.png
assets/data/images/PTModelSprite_ID3559.png
assets/data/images/PTModelSprite_ID35614.png
assets/data/images/PTModelSprite_ID36225.png
assets/data/images/PTModelSprite_ID36228.png
assets/data/images/PTModelSprite_ID36231.png
assets/data/shaders/WaterReflection.fsh
assets/data/sounds/PTModelSound_ID35201.mp3
assets/data/sounds/PTModelSound_ID42306.mp3
assets/data/sounds/PTModelSound_ID42307.mp3
assets/data/sounds/PTModelSound_ID42308.mp3
assets/data/sounds/PTModelSound_ID42311.mp3
assets/data/sounds/PTModelSound_ID42314.mp3
assets/data/sounds/PTModelSound_ID42318.mp3
assets/data/sounds/PTModelSound_ID42322.mp3
assets/default.png
assets/heyzap.bin
assets/libjiagu.so
assets/libjiagu_x86.so
assets/mimo_asset.apk
assets/qih.bundle
assets/unity.action
classes.dex
lib/armeabi-v7a/libplayer.so
org/cocos2dx/DISCLAIMER
play-services-ads-base.properties
play-services-ads-identifier.properties
play-services-ads-lite.properties
play-services-ads.properties
play-services-auth-api-phone.properties
play-services-auth-base.properties
play-services-auth.properties
play-services-base.properties
play-services-basement.properties
play-services-drive.properties
play-services-games.properties
play-services-gass.properties
play-services-measurement-base.properties
play-services-measurement-sdk-api.properties
play-services-tasks.properties
res/anim/abc_fade_in.xml
res/anim/abc_fade_out.xml
res/anim/abc_grow_fade_in_from_bottom.xml
res/anim/abc_popup_enter.xml
res/anim/abc_popup_exit.xml
res/anim/abc_shrink_fade_out_from_bottom.xml
res/anim/abc_slide_in_bottom.xml
res/anim/abc_slide_in_top.xml
res/anim/abc_slide_out_bottom.xml
res/anim/abc_slide_out_top.xml
res/anim/tooltip_enter.xml
res/anim/tooltip_exit.xml
res/color-v21/abc_btn_colored_borderless_text_material.xml
res/color-v23/abc_btn_colored_borderless_text_material.xml
res/color-v23/abc_btn_colored_text_material.xml
res/color-v23/abc_color_highlight_material.xml
res/color-v23/abc_tint_btn_checkable.xml
res/color-v23/abc_tint_default.xml
res/color-v23/abc_tint_edittext.xml
res/color-v23/abc_tint_seek_thumb.xml
res/color-v23/abc_tint_spinner.xml
res/color-v23/abc_tint_switch_track.xml
res/color/abc_background_cache_hint_selector_material_dark.xml
res/color/abc_background_cache_hint_selector_material_light.xml
res/color/abc_btn_colored_borderless_text_material.xml
res/color/abc_btn_colored_text_material.xml
res/color/abc_hint_foreground_material_dark.xml
res/color/abc_hint_foreground_material_light.xml
res/color/abc_primary_text_disable_only_material_dark.xml
res/color/abc_primary_text_disable_only_material_light.xml
res/color/abc_primary_text_material_dark.xml
res/color/abc_primary_text_material_light.xml
res/color/abc_search_url_text.xml
res/color/abc_secondary_text_material_dark.xml
res/color/abc_secondary_text_material_light.xml
res/color/abc_tint_btn_checkable.xml
res/color/abc_tint_default.xml
res/color/abc_tint_edittext.xml
res/color/abc_tint_seek_thumb.xml
res/color/abc_tint_spinner.xml
res/color/abc_tint_switch_track.xml
res/color/com_facebook_button_text_color.xml
res/color/com_facebook_send_button_text_color.xml
res/color/common_google_signin_btn_text_dark.xml
res/color/common_google_signin_btn_text_light.xml
res/color/common_google_signin_btn_tint.xml
res/color/switch_thumb_material_dark.xml
res/color/switch_thumb_material_light.xml
res/drawable-hdpi/icon.png
res/drawable-mdpi/com_facebook_profile_picture_blank_portrait.png
res/drawable-mdpi/com_facebook_profile_picture_blank_square.png
res/drawable-mdpi/icon.png
res/drawable-v21/abc_action_bar_item_background_material.xml
res/drawable-v21/abc_btn_colored_material.xml
res/drawable-v21/abc_edit_text_material.xml
res/drawable-v21/abc_ratingbar_indicator_material.xml
res/drawable-v21/abc_ratingbar_material.xml
res/drawable-v21/abc_ratingbar_small_material.xml
res/drawable-v21/notification_action_background.xml
res/drawable-v23/abc_control_background_material.xml
res/drawable-watch-v20/common_google_signin_btn_text_dark_normal.xml
res/drawable-watch-v20/common_google_signin_btn_text_disabled.xml
res/drawable-watch-v20/common_google_signin_btn_text_light_normal.xml
res/drawable-xhdpi/icon.png
res/drawable-xxhdpi/icon.png
res/drawable-xxxhdpi/icon.png
res/drawable/abc_btn_borderless_material.xml
res/drawable/abc_btn_check_material.xml
res/drawable/abc_btn_colored_material.xml
res/drawable/abc_btn_default_mtrl_shape.xml
res/drawable/abc_btn_radio_material.xml
res/drawable/abc_cab_background_internal_bg.xml
res/drawable/abc_cab_background_top_material.xml
res/drawable/abc_dialog_material_background.xml
res/drawable/abc_edit_text_material.xml
res/drawable/abc_ic_ab_back_material.xml
res/drawable/abc_ic_arrow_drop_right_black_24dp.xml
res/drawable/abc_ic_clear_material.xml
res/drawable/abc_ic_go_search_api_material.xml
res/drawable/abc_ic_menu_overflow_material.xml
res/drawable/abc_ic_search_api_material.xml
res/drawable/abc_ic_voice_search_api_material.xml
res/drawable/abc_item_background_holo_dark.xml
res/drawable/abc_item_background_holo_light.xml
res/drawable/abc_list_selector_background_transition_holo_dark.xml
res/drawable/abc_list_selector_background_transition_holo_light.xml
res/drawable/abc_list_selector_holo_dark.xml
res/drawable/abc_list_selector_holo_light.xml
res/drawable/abc_ratingbar_indicator_material.xml
res/drawable/abc_ratingbar_material.xml
res/drawable/abc_ratingbar_small_material.xml
res/drawable/abc_seekbar_thumb_material.xml
res/drawable/abc_seekbar_tick_mark_material.xml
res/drawable/abc_seekbar_track_material.xml
res/drawable/abc_spinner_textfield_background_material.xml
res/drawable/abc_switch_thumb_material.xml
res/drawable/abc_tab_indicator_material.xml
res/drawable/abc_text_cursor_material.xml
res/drawable/abc_textfield_search_material.xml
res/drawable/abc_vector_test.xml
res/drawable/com_facebook_auth_dialog_background.xml
res/drawable/com_facebook_auth_dialog_cancel_background.xml
res/drawable/com_facebook_auth_dialog_header_background.xml
res/drawable/com_facebook_button_background.xml
res/drawable/com_facebook_button_icon.xml
res/drawable/com_facebook_button_like_background.xml
res/drawable/com_facebook_button_send_background.xml
res/drawable/com_facebook_favicon_blue.xml
res/drawable/com_facebook_send_button_icon.xml
res/drawable/common_google_signin_btn_icon_dark.xml
res/drawable/common_google_signin_btn_icon_dark_focused.xml
res/drawable/common_google_signin_btn_icon_dark_normal.xml
res/drawable/common_google_signin_btn_icon_disabled.xml
res/drawable/common_google_signin_btn_icon_light.xml
res/drawable/common_google_signin_btn_icon_light_focused.xml
res/drawable/common_google_signin_btn_icon_light_normal.xml
res/drawable/common_google_signin_btn_text_dark.xml
res/drawable/common_google_signin_btn_text_dark_focused.xml
res/drawable/common_google_signin_btn_text_dark_normal.xml
res/drawable/common_google_signin_btn_text_disabled.xml
res/drawable/common_google_signin_btn_text_light.xml
res/drawable/common_google_signin_btn_text_light_focused.xml
res/drawable/common_google_signin_btn_text_light_normal.xml
res/drawable/icon.png
res/drawable/messenger_button_blue_bg_round.xml
res/drawable/messenger_button_blue_bg_selector.xml
res/drawable/messenger_button_white_bg_round.xml
res/drawable/messenger_button_white_bg_selector.xml
res/drawable/notification_bg.xml
res/drawable/notification_bg_low.xml
res/drawable/notification_icon_background.xml
res/drawable/notification_tile_bg.xml
res/drawable/spacer.png
res/drawable/tooltip_frame_dark.xml
res/drawable/tooltip_frame_light.xml
res/layout-v17/abc_action_mode_close_item_material.xml
res/layout-v17/abc_alert_dialog_button_bar_material.xml
res/layout-v17/abc_alert_dialog_title_material.xml
res/layout-v17/abc_dialog_title_material.xml
res/layout-v17/abc_popup_menu_header_item_layout.xml
res/layout-v17/abc_popup_menu_item_layout.xml
res/layout-v17/abc_search_view.xml
res/layout-v17/abc_select_dialog_material.xml
res/layout-v17/com_facebook_device_auth_dialog_fragment.xml
res/layout-v17/com_facebook_smart_device_dialog_fragment.xml
res/layout-v17/notification_action.xml
res/layout-v17/notification_action_tombstone.xml
res/layout-v17/notification_template_big_media.xml
res/layout-v17/notification_template_big_media_custom.xml
res/layout-v17/notification_template_big_media_narrow.xml
res/layout-v17/notification_template_big_media_narrow_custom.xml
res/layout-v17/notification_template_custom_big.xml
res/layout-v17/notification_template_lines_media.xml
res/layout-v17/notification_template_media.xml
res/layout-v17/notification_template_media_custom.xml
res/layout-v17/select_dialog_multichoice_material.xml
res/layout-v17/select_dialog_singlechoice_material.xml
res/layout-v17/tooltip.xml
res/layout-v21/abc_screen_toolbar.xml
res/layout-v21/notification_action.xml
res/layout-v21/notification_action_tombstone.xml
res/layout-v21/notification_template_custom_big.xml
res/layout-v21/notification_template_icon_group.xml
res/layout-v22/abc_alert_dialog_button_bar_material.xml
res/layout-v26/abc_screen_toolbar.xml
res/layout/abc_action_bar_title_item.xml
res/layout/abc_action_bar_up_container.xml
res/layout/abc_action_menu_item_layout.xml
res/layout/abc_action_menu_layout.xml
res/layout/abc_action_mode_bar.xml
res/layout/abc_action_mode_close_item_material.xml
res/layout/abc_activity_chooser_view.xml
res/layout/abc_activity_chooser_view_list_item.xml
res/layout/abc_alert_dialog_button_bar_material.xml
res/layout/abc_alert_dialog_material.xml
res/layout/abc_alert_dialog_title_material.xml
res/layout/abc_dialog_title_material.xml
res/layout/abc_expanded_menu_layout.xml
res/layout/abc_list_menu_item_checkbox.xml
res/layout/abc_list_menu_item_icon.xml
res/layout/abc_list_menu_item_layout.xml
res/layout/abc_list_menu_item_radio.xml
res/layout/abc_popup_menu_header_item_layout.xml
res/layout/abc_popup_menu_item_layout.xml
res/layout/abc_screen_content_include.xml
res/layout/abc_screen_simple.xml
res/layout/abc_screen_simple_overlay_action_mode.xml
res/layout/abc_screen_toolbar.xml
res/layout/abc_search_dropdown_item_icons_2line.xml
res/layout/abc_search_view.xml
res/layout/abc_select_dialog_material.xml
res/layout/com_facebook_activity_layout.xml
res/layout/com_facebook_device_auth_dialog_fragment.xml
res/layout/com_facebook_login_fragment.xml
res/layout/com_facebook_smart_device_dialog_fragment.xml
res/layout/com_facebook_tooltip_bubble.xml
res/layout/main.xml
res/layout/messenger_button_send_blue_large.xml
res/layout/messenger_button_send_blue_round.xml
res/layout/messenger_button_send_blue_small.xml
res/layout/messenger_button_send_white_large.xml
res/layout/messenger_button_send_white_round.xml
res/layout/messenger_button_send_white_small.xml
res/layout/notification_action.xml
res/layout/notification_action_tombstone.xml
res/layout/notification_media_action.xml
res/layout/notification_media_cancel_action.xml
res/layout/notification_template_big_media.xml
res/layout/notification_template_big_media_custom.xml
res/layout/notification_template_big_media_narrow.xml
res/layout/notification_template_big_media_narrow_custom.xml
res/layout/notification_template_custom_big.xml
res/layout/notification_template_icon_group.xml
res/layout/notification_template_lines_media.xml
res/layout/notification_template_media.xml
res/layout/notification_template_media_custom.xml
res/layout/notification_template_part_chronometer.xml
res/layout/notification_template_part_time.xml
res/layout/select_dialog_item_material.xml
res/layout/select_dialog_multichoice_material.xml
res/layout/select_dialog_singlechoice_material.xml
res/layout/support_simple_spinner_dropdown_item.xml
res/layout/tooltip.xml
res/xml/file_paths.xml
res/xml/splits0.xml
resources.arsc
META-INF/CERT.SF
META-INF/CERT.RSA
META-INF/MANIFEST.MF

污点分析

当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
规则名称 描述信息 操作
病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析