文件基本信息
应用基础信息
文件基本信息
应用基础信息
文件结构与资源列表
应用签名证书信息
二进制文件已签名
v1 签名: False
v2 签名: True
v3 签名: True
v4 签名: False
主题: C=UZ, ST=hrsocmnyvzgbroj, L=dfqparr, O=ajoeclyu, OU=hxibamqisu, CN=vyqhyirocpxyj
签名算法: rsassa_pkcs1v15
有效期自: 2025-04-04 14:00:00+00:00
有效期至: 2052-08-20 14:00:00+00:00
发行人: C=UZ, ST=hrsocmnyvzgbroj, L=dfqparr, O=ajoeclyu, OU=hxibamqisu, CN=vyqhyirocpxyj
序列号: 0x9366796cb188def5
哈希算法: sha384
证书MD5: c36b835c7a0c1a1ece20b75ee7a1c0ee
证书SHA1: 70e9155487e250c13560e292cf4e9ccfaa90ce6c
证书SHA256: b01ad57c90a97e9e9ce2771b377f6ed8f8a9bd7331a34bbff2a5def761ee8b98
证书SHA512: 7765d046b0cbaa2fcf4acc5919eb89eb077987f332a51b997b39be6721b665d6310a3b71e5d4fe41a3e5b9c4251f4a8996e2aec81b270934efcb209ebf6e44cb
公钥算法: rsa
密钥长度: 2048
指纹: d5f87eb0b8389ed919c626a9db41addbc62651a9b421e2122eab95363e444e52
找到 1 个唯一证书
权限声明与风险分级
证书安全合规分析
标题 | 严重程度 | 描述信息 |
---|---|---|
已签名应用 | 信息 | 应用程序使用代码签名证书进行签名 |
Manifest 配置安全分析
序号 | 问题 | 严重程度 | 描述信息 | 操作 |
---|---|---|---|---|
1 |
应用程序已启用明文网络流量 [android:usesCleartextTraffic=true] |
警告 | 应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。 | |
2 |
应用程序数据存在被泄露的风险 未设置[android:allowBackup]标志 |
警告 | 这个标志 [android:allowBackup]应该设置为false。默认情况下它被设置为true,允许任何人通过adb备份你的应用程序数据。它允许已经启用了USB调试的用户从设备上复制应用程序数据。 | |
3 |
Service (org.lrsiwlpgruyd.roxiloaiz.Service) 未被保护。 [android:exported=true] |
警告 | 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。 | |
4 |
Broadcast Receiver (org.lrsiwlpgruyd.roxiloaiz.Receiver) 受权限保护, 但是应该检查权限的保护级别。 Permission: android.permission.BROADCAST_SMS [android:exported=true] |
警告 | 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。 | |
5 |
Activity-Alias (org.lrsiwlpgruyd.roxiloaiz.CatInWonderland) 未被保护。 [android:exported=true] |
警告 | 发现 Activity-Alias与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。 | |
6 |
Service (androidx.work.impl.background.systemjob.SystemJobService) 受权限保护, 但是应该检查权限的保护级别。 Permission: android.permission.BIND_JOB_SERVICE [android:exported=true] |
警告 | 发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。 | |
7 |
Broadcast Receiver (androidx.work.impl.diagnostics.DiagnosticsReceiver) 受权限保护, 但是应该检查权限的保护级别。 Permission: android.permission.DUMP [android:exported=true] |
警告 | 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。 | |
8 |
Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) 受权限保护, 但是应该检查权限的保护级别。 Permission: android.permission.DUMP [android:exported=true] |
警告 | 发现一个 Broadcast Receiver被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。 | |
9 |
高优先级的Intent (1000) - {1} 个命中 [android:priority] |
警告 | 通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。 |
可浏览 Activity 组件分析
ACTIVITY | INTENT |
---|
网络通信安全风险分析
序号 | 范围 | 严重级别 | 描述 |
---|
API调用分析
安全漏洞检测
序号 | 问题 | 等级 | 参考标准 | 文件位置 | 操作 |
---|---|---|---|---|---|
1 | 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 | 警告 |
CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
OWASP Top 10: M7: Client Code Quality |
升级会员:解锁高级权限 | |
2 | 应用程序记录日志信息,不得记录敏感信息 | 信息 |
CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3 |
升级会员:解锁高级权限 | |
3 | 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 | 安全 |
OWASP MASVS: MSTG-NETWORK-4 |
升级会员:解锁高级权限 | |
4 | 应用程序使用不安全的随机数生成器 | 警告 |
CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography OWASP MASVS: MSTG-CRYPTO-6 |
升级会员:解锁高级权限 | |
5 | 应用程序创建临时文件。敏感信息永远不应该被写进临时文件 | 警告 |
CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage OWASP MASVS: MSTG-STORAGE-2 |
升级会员:解锁高级权限 |
Native库安全分析
序号 | 动态库 | NX(堆栈禁止执行) | PIE | STACK CANARY(栈保护) | RELRO | RPATH(指定SO搜索路径) | RUNPATH(指定SO搜索路径) | FORTIFY(常用函数加强检查) | SYMBOLS STRIPPED(裁剪符号表) |
---|
文件分析
序号 | 问题 | 文件 |
---|
行为分析
编号 | 行为 | 标签 | 文件 |
---|---|---|---|
00013 | 读取文件并将其放入流中 |
文件 |
升级会员:解锁高级权限 |
00162 | 创建 InetSocketAddress 对象并连接到它 |
socket |
升级会员:解锁高级权限 |
00163 | 创建新的 Socket 并连接到它 |
socket |
升级会员:解锁高级权限 |
00022 | 从给定的文件绝对路径打开文件 |
文件 |
升级会员:解锁高级权限 |
00091 | 从广播中检索数据 |
信息收集 |
升级会员:解锁高级权限 |
00025 | 监视要执行的一般操作 |
反射 |
升级会员:解锁高级权限 |
00046 | 方法反射 |
反射 |
升级会员:解锁高级权限 |
00026 | 方法反射 |
反射 |
升级会员:解锁高级权限 |
00075 | 获取设备的位置 |
信息收集 位置 |
升级会员:解锁高级权限 |
00137 | 获取设备的最后已知位置 |
位置 信息收集 |
升级会员:解锁高级权限 |
00024 | Base64解码后写入文件 |
反射 文件 |
升级会员:解锁高级权限 |
00104 | 检查给定路径是否是目录 |
文件 |
升级会员:解锁高级权限 |
敏感权限分析
恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。
IP地理位置
手机号提取
URL链接分析
URL信息 | 源码文件 |
---|---|
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/a22222a222a2aaaa2a2aa2aa2aa2aa2aaaa2a2a2aa222.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/iii6iii6ii6iiiiii66i66ii66i6ii666666iii6ii6iiiii6666ii6i66.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n |
u4u44uuu4u44444444uuuuuuu4u44uuu4/s999ss9s9s999sss999s9s999s999ss9999ss9sss9sss9ss99s99ss99ss9ss99s9.java |
www00.v1v1vvvv11vv11v1v1v1111111vv1vvv1v1v11v11vv1vv www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/j55jj5555jjjj55555j55j5jjj55j55j5jjj5555j.java |
www00.r4r44444rr4r44r4rr4r4r44r4rr444r444r44r4rrr4rr |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/i99ii9i9999i999i9999iiii99999i999i9ii9i9i9999i999i9ii99ii9i99.java |
www00.r0r0r00rrr0r0rrrrrrrrr0000rrr0r00r0rrrr0r0r00r00rr0r00rr000r0000r0r0rr www00.r4r44444rr4r44r4rr4r4r44r4rr444r444r44r4rrr4rr |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.r4r44444rr4r44r4rr4r4r44r4rr444r444r44r4rrr4rr |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/x88888x8xxxx8x888888x.java |
www00.s999ss9s9s999sss999s9s999s999ss9999ss9sss9sss9ss99s99ss99ss9ss99s9 www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.f6213x3b4c089a www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.pp00pp0ppppp0ppppp00p00p0p000pp0p00ppppp0p0p0p0p0000 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a www00.pp00pp0ppppp0ppppp00p00p0p000pp0p00ppppp0p0p0p0p0000 www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
u4u44uuu4u44444444uuuuuuu4u44uuu4/rr44rr44r4rr4rr4rr444r44r444rr4r4r44rr44rrr.java |
www00.r0r0r00rrr0r0rrrrrrrrr0000rrr0r00r0rrrr0r0r00r00rr0r00rr000r0000r0r0rr www00.r4r44444rr4r44r4rr4r4r44r4rr444r444r44r4rrr4rr |
llll77ll77l77l77ll777ll7l7l777ll77llll77lllllll77lllll77l77l7777ll77777l7/x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
u4u44uuu4u44444444uuuuuuu4u44uuu4/x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9.java |
www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.f6213x3b4c089a www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.pp00pp0ppppp0ppppp00p00p0p000pp0p00ppppp0p0p0p0p0000 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.java |
www00.x88888x8xxxx8x888888x www00.v1v1vvvv11vv11v1v1v1111111vv1vvv1v1v11v11vv1vv www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
f4fff4ff4ff44444f4fffff4f44fffffff4444ff4f4444f444/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/r0r0r00rrr0r0rrrrrrrrr0000rrr0r00r0rrrr0r0r00r00rr0r00rr000r0000r0r0rr.java |
www00.ll6l6l66l66lll66l6l6ll6l6666 |
f4fff4ff4ff44444f4fffff4f44fffffff4444ff4f4444f444/m222mm22mm2mmm2m2m222m2mm2222m222.java |
www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.f6208xea98305a www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/s999ss9s9s999sss999s9s999s999ss9999ss9sss9sss9ss99s99ss99ss9ss99s9.java |
www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n |
u5uu55uu5u5uu555u5u5uuuuu5uuuuu5u55uu55u5uu555u55u55uu55u5u/x88888x8xxxx8x888888x.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
uu7uuuuuu7uu7u7u777u/a22222a222a2aaaa2a2aa2aa2aa2aa2aaaa2a2a2aa222.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/q99qqqqq999qqqqqq9qq99qq99q9q999q99q9q99q9q99q9qq99q9q9q999q9q9q9q99.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
uu7uuuuuu7uu7u7u777u/x88888x8xxxx8x888888x.java |
www00.v1v1vvvv11vv11v1v1v1111111vv1vvv1v1v11v11vv1vv www00.r0r0r00rrr0r0rrrrrrrrr0000rrr0r00r0rrrr0r0r00r00rr0r00rr000r0000r0r0rr www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.ll6l6l66l66lll66l6l6ll6l6666 www00.iii6iii6ii6iiiiii66i66ii66i6ii666666iii6ii6iiiii6666ii6i66 |
ee2e2222e22eeeeeee2222ee2e2ee2e222e22ee2eeee22eeee2e22eee22e2e2e2222eeee2ee222/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/i99ii9i9999i999i9999iiii99999i999i9ii9i9i9999i999i9ii99ii9i99.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
sss0s00sss0ss00s0sss0s0s/rr44rr44r4rr4rr4rr444r44r444rr4r4r44rr44rrr.java |
www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9.java |
www00.v1v1vvvv11vv11v1v1v1111111vv1vvv1v1v11v11vv1vv www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
s1s1s111ss11s1s/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.hhh5h55hhhh5h5hhhh55h5h5hh5hh55h55hh5h5hh55hhh5hh5hhh5555hh5h5hh5hh www00.x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9 www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.rr44rr44r4rr4rr4rr444r44r444rr4r4r44rr44rrr www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/j55jj5555jjjj55555j55j5jjj55j55j5jjj5555j.java |
www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/rr00rr0rrr0rrrr000r0000rrrrr0r00rr0r00r00rrr00000r0r00rr0r0r0.java |
www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/m222mm22mm2mmm2m2m222m2mm2222m222.java |
www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
i99ii9i9999i999i9999iiii99999i999i9ii9i9i9999i999i9ii99ii9i99/rr00rr0rrr0rrrr000r0000rrrrr0r00rr0r00r00rrr00000r0r00rr0r0r0.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n |
s1s1s111ss11s1s/i99ii9i9999i999i9999iiii99999i999i9ii9i9i9999i999i9ii99ii9i99.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.t999t99t9tttt9t9tt9t999999tt www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/a22222a222a2aaaa2a2aa2aa2aa2aa2aaaa2a2a2aa222.java |
www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
s1s1s111ss11s1s/j55jj5555jjjj55555j55j5jjj55j55j5jjj5555j.java |
www00.t999t99t9tttt9t9tt9t999999tt www00.v1v1vvvv11vv11v1v1v1111111vv1vvv1v1v11v11vv1vv www00.r4r44444rr4r44r4rr4r4r44r4rr444r444r44r4rrr4rr www00.r0r0r00rrr0r0rrrrrrrrr0000rrr0r00r0rrrr0r0r00r00rr0r00rr000r0000r0r0rr www00.hhh5h55hhhh5h5hhhh55h5h5hh5hh55h55hh5h5hh55hhh5hh5hhh5555hh5h5hh5hh www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
e99ee9eeeee99e9ee999e9e9e99e9ee999999e9e9999eeee9e9e999e9e99e9999e9e99e9e9e9e999999eee/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.iii6iii6ii6iiiiii66i66ii66i6ii666666iii6ii6iiiii6666ii6i66.class |
aaaaa9aaa9999999aa9a/x88888x8xxxx8x888888x.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
u4u44uuu4u44444444uuuuuuu4u44uuu4/aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a.java |
www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n www00.r1rr11r11r1rr1111111111r1rrr11r1r11rrr1r1rr111rrrr1r11rr1r111r111r11r11111rrrr1r1rr11 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
u4u44uuu4u44444444uuuuuuu4u44uuu4/e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00.java |
www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.ll6l6l66l66lll66l6l6ll6l6666 |
u4u44uuu4u44444444uuuuuuu4u44uuu4/j55jj5555jjjj55555j55j5jjj55j55j5jjj5555j.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 |
ww0wwwww0ww000w000ww00ww000w0ww00wwww0w00ww0www0ww0wwwww00/rr44rr44r4rr4rr4rr444r44r444rr4r4r44rr44rrr.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 www00.iii6iii6ii6iiiiii66i66ii66i6ii666666iii6ii6iiiii6666ii6i66 |
u4u44uuu4u44444444uuuuuuu4u44uuu4/q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
u4u44uuu4u44444444uuuuuuu4u44uuu4/nnn2nn2nn2nn22n2nn22.java |
www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n |
s5555s55s5s55s5ss5ssssssss55555/x88888x8xxxx8x888888x.java |
www00.nnn2nn2nn2nn22n2nn22 www00.ll6l6l66l66lll66l6l6ll6l6666 www00.nnnn2n2n2n22n2n22222n2n2nn2n22n2nn22nnnn2n22n2nn2222n2222nn222n2222nnn2nnn2nnn2nnn22n222n22n2222n |
u4u44uuu4u44444444uuuuuuu4u44uuu4/m222mm22mm2mmm2m2m222m2mm2222m222.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a |
u4u44uuu4u44444444uuuuuuu4u44uuu4/hhh5h55hhhh5h5hhhh55h5h5hh5hh55h55hh5h5hh55hhh5hh5hhh5555hh5h5hh5hh.java |
www00.x88888x8xxxx8x888888x |
ww0wwwww0ww000w000ww00ww000w0ww00wwww0w00ww0www0ww0wwwww00/x88888x8xxxx8x888888x.java |
www00.q55q5q5qqq5qq55q55qqq555q5qqqqq55q55qqqq5 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a |
u4u44uuu4u44444444uuuuuuu4u44uuu4/p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.java |
www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.f6211rr00rr0rrr0rrrr000r0000rrrrr0r00rr0r00r00rrr00000r0r00rr0r0r0.getclass www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp.f6214t999t99t9tttt9t9tt9t999999tt www00.x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9 www00.p55p55p5p555p55555p55pp555p5pp55555555ppp5p55p55pp555p5p5pp55pppppppppp5555pp5p55pp www00.x9xx9x9xx999xxx9xx9xx9999xxx9xx99x9x99999xxxxx99xx99x9xx999x99xx99xxx9x9.f6271x88888x8xxxx8x888888x www00.a9aaaa999a9a9999aa99a9a9aaa9a9a9a9999aaa9aaaa99a9a9a99999999a999a99999a9999a9a9aa9a www00.rr00rr0rrr0rrrr000r0000rrrrr0r00rr0r00r00rrr00000r0r00rr0r0r0 www00.aa666a6a6a6aa6aaa6a6aa6a6aaa66a6a66aa666666a6aaaa6666aa66a666a666aa6a6a6aaaa6aa6a www00.a22222a222a2aaaa2a2aa2aa2aa2aa2aaaa2a2a2aa222.f6085x88888x8xxxx8x888888x www00.ll6l6l66l66lll66l6l6ll6l6666 www00.pp00pp0ppppp0ppppp00p00p0p000pp0p00ppppp0p0p0p0p0000 www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 www00.b11bbbbb11b11b1bb1b1b111b11b1b11b1bb111b11b1bbb11b |
u4u44uuu4u44444444uuuuuuu4u44uuu4/i99ii9i9999i999i9999iiii99999i999i9ii9i9i9999i999i9ii99ii9i99.java |
www00.e000e0e0e00ee000e000eeee0ee00ee00e0000ee0e0e000e00ee00eeeeee0000e0ee0ee0e00e0ee00 |
p1ppppp1p1pppp111pp11pp111111p1p1pp1111p1pp11111pp1ppp1ppp1pp11p11p11p111ppp1pp11p/ll6l6l66l66lll66l6l6ll6l6666.java |
Firebase配置检测
邮箱地址提取
第三方追踪器
名称 | 类别 | 网址 |
---|
敏感凭证泄露
活动列表
显示所有 183 个 activities
广播接收者列表
显示 10 个 receivers
内容提供者列表
显示 1 个 providers
第三方SDK
SDK名称 | 开发者 | 描述信息 |
---|---|---|
Jetpack App Startup | App Startup 库提供了一种直接,高效的方法来在应用程序启动时初始化组件。库开发人员和应用程序开发人员都可以使用 App Startup 来简化启动顺序并显式设置初始化顺序。App Startup 允许您定义共享单个内容提供程序的组件初始化程序,而不必为需要初始化的每个组件定义单独的内容提供程序。这可以大大缩短应用启动时间。 | |
Jetpack WorkManager | 使用 WorkManager API 可以轻松地调度即使在应用退出或设备重启时仍应运行的可延迟异步任务。 | |
Jetpack ProfileInstaller | 让库能够提前预填充要由 ART 读取的编译轨迹。 | |
Jetpack Room | Room 持久性库在 SQLite 的基础上提供了一个抽象层,让用户能够在充分利用 SQLite 的强大功能的同时,获享更强健的数据库访问机制。 |
污点分析
当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……规则名称 | 描述信息 | 操作 |
---|---|---|
病毒分析 | 使用安卓恶意软件常用的API进行污点分析 | 开始分析 |
漏洞挖掘 | 漏洞挖掘场景下的污点分析 | 开始分析 |
隐私合规 | 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 | 开始分析 |
密码分析 | 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 | 开始分析 |
Callback | 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 | 开始分析 |