温馨提示:本平台仅供研究软件风险、安全评估,禁止用于非法用途。由于展示的数据过于全面,请耐心等待加载完成。如有疑问或建议, 可加入我们的微信群讨论

应用图标

应用评分

文件信息

文件名称 com.apicloud.a6981894597784a.apk
文件大小 12.21MB
MD5 f7abb9ca00cf3272f3b9b59019d1beb4
SHA1 a23958517440046b9351e6ff5c3a51a755d6b68a
SHA256 5c097baebd047d66e0522edc934c868db6fd4bec516bb48c3eb3da01976fc6a6
病毒检测 ⚠️ 4 个厂商报毒⚠️

应用信息

应用名称 宝宝很忙
包名 com.apicloud.A6981894597784
主活动 com.uzmap.pkg.LauncherUI
目标SDK 28 最小SDK 19
版本号 2.8.8 子版本号 288
加固信息 未加壳

非法应用检测 (该功能即将上线,识别赌博、诈骗、色情和黑产等类型应用)

组件导出信息

反编译代码

Manifest文件 查看
Java源代码 查看 -- 下载

证书信息

二进制文件已签名
v1 签名: True
v2 签名: True
v3 签名: False
v4 签名: False
主题: C=(zh), ST=(beijing), L=(), O=(beijing), OU=(liu_meng2000@163.com), CN=(liu_meng2000@163.com)
签名算法: rsassa_pkcs1v15
有效期自: 2015-09-16 10:21:34+00:00
有效期至: 2115-08-23 10:21:34+00:00
发行人: C=(zh), ST=(beijing), L=(), O=(beijing), OU=(liu_meng2000@163.com), CN=(liu_meng2000@163.com)
序列号: 0x21504dda
哈希算法: sha256
证书MD5: 8a9e920748ead57a745858dde4c5ec9d
证书SHA1: 7bbb813fef652dbedefdc4e51cd964004bb81414
证书SHA256: 35e93295c3f34a299637b57592168ddbe4969010c66cfeb9743a14f13f60e87c
证书SHA512: bf67fbdd9005b9f6e655d0cdc62e8563b0c0117b1c83899d74d43ed18919812faa455b55334ef19e6d1f28fa43458dcdf4355f4f3a521b474db0933356f18b54
公钥算法: rsa
密钥长度: 1024
指纹: 81a7c387c648acf30f74d46bfa87e8c01f8a79cde8fdac312a15867b3a253ac5
找到 1 个唯一证书

应用程序权限

权限名称 安全等级 权限内容 权限描述 关联代码
android.permission.INTERNET 危险 完全互联网访问 允许应用程序创建网络套接字。
com/apicloud/a/a/c.java
com/apicloud/fileBrowser/Utils/ImageUtil.java
com/apicloud/glide/load/data/HttpUrlFetcher.java
com/deepe/c/j/d/g.java
com/deepe/c/j/e/c.java
com/deepe/c/j/k.java
com/deepe/c/l/a/b.java
com/eclipsesource/v8/debug/V8DebugServer.java
com/gprinter/io/EthernetPort.java
com/lidroid/xutils/HttpUtils.java
com/lidroid/xutils/bitmap/download/DefaultDownloader.java
com/lidroid/xutils/http/RequestParams.java
com/lidroid/xutils/http/ResponseInfo.java
com/lidroid/xutils/http/ResponseStream.java
com/lidroid/xutils/http/SyncHttpHandler.java
com/lidroid/xutils/http/callback/DefaultHttpRedirectHandler.java
com/lidroid/xutils/http/callback/FileDownloadHandler.java
com/lidroid/xutils/http/callback/StringDownloadHandler.java
com/lidroid/xutils/http/client/HttpRequest.java
com/lidroid/xutils/http/client/entity/BodyParamsEntity.java
com/lidroid/xutils/http/client/entity/DecompressingEntity.java
com/lidroid/xutils/http/client/entity/GZipDecompressingEntity.java
com/lidroid/xutils/http/client/entity/InputStreamUploadEntity.java
com/lidroid/xutils/http/client/multipart/HttpMultipart.java
com/lidroid/xutils/http/client/multipart/MultipartEntity.java
com/unionpay/a/c.java
com/uzmap/pkg/b/c/o.java
com/uzmap/pkg/uzcore/i/b/a.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageDownLoader.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/AsyncImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/utils/ImageDownLoader.java
com.huawei.android.launcher.permission.CHANGE_BADGE 普通 在应用程序上显示通知计数 在华为手机的应用程序启动图标上显示通知计数或徽章。
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储。
com/apicloud/a/i/a/d/g.java
com/apicloud/devlop/FNImageClip/SaveUtil.java
com/apicloud/fileBrowser/Utils/LogUtil.java
com/apicloud/fileBrowser/Utils/MouleUtil.java
com/apicloud/fileBrowser/fileexplorer/Util.java
com/apicloud/glide/disklrucache/DiskLruCache.java
com/apicloud/glide/gifencoder/AnimatedGifEncoder.java
com/apicloud/glide/load/engine/DecodeJob.java
com/apicloud/wxphotopicker/Utils/ImageUtil.java
com/apicloud/wxphotopicker/Utils/LogUtil.java
com/apicloud/wxphotopicker/Utils/MouleUtil.java
com/apicloud/wxphotopicker/Utils/UriUtils.java
com/deepe/a/c/f.java
com/deepe/b/e.java
com/deepe/b/f/a.java
com/deepe/b/f/b.java
com/deepe/c/c/j.java
com/deepe/c/c/t.java
com/deepe/c/i/g.java
com/deepe/c/j/d/c.java
com/deepe/f/b.java
com/deepe/sdk/StringStream.java
com/eclipsesource/v8/LibraryLoader.java
com/gprinter/command/GpUtils.java
com/gprinter/utils/SerialPortControl.java
com/lidroid/xutils/cache/LruDiskCache.java
com/lidroid/xutils/http/ResponseStream.java
com/lidroid/xutils/http/callback/FileDownloadHandler.java
com/open/apicloud/jpush/JPushNotification.java
com/unionpay/UPPayAssistEx.java
com/unionpay/a.java
com/unionpay/utils/j.java
com/uzmap/pkg/b/c/o.java
com/uzmap/pkg/uzapp/b.java
com/uzmap/pkg/uzcore/g/e.java
com/uzmap/pkg/uzcore/uzmodule/a/c.java
com/uzmap/pkg/uzkit/UZUtility.java
com/uzmap/pkg/uzkit/request/HttpDownload.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageBrowserAdapter.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageDownLoader.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzFNScanner/UzFNScanner.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/ScanUtil.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/UriUtils.java
com/uzmap/pkg/uzmodules/uzTabBarMenu/UzTabBarMenu.java
com/uzmap/pkg/uzmodules/uzUIChatBox/BitmapUtils.java
com/uzmap/pkg/uzmodules/uzUnionPay/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/GalleryActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/ImageActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/utils/ImageDownLoader.java
com/uzmap/pkg/uzmodules/uzimageFilter/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageFilter/compress/ImageUtil.java
com/uzmap/pkg/uzmodules/uzimageFilter/uzimageFilter.java
com/uzmap/pkg/uzmodules/uzinputField/UzInputField.java
com/uzmap/pkg/uzmodules/uztimeSelector/NumberPicker.java
net/apicloud/selector/uis/SelectorActivity.java
top/zibin/luban/Engine.java
android.permission.ACCESS_COARSE_LOCATION 危险 获取粗略位置 通过WiFi或移动基站的方式获取用户错略的经纬度信息,定位精度大概误差在30~1500米。恶意程序可以用它来确定您的大概位置。
android.permission.ACCESS_FINE_LOCATION 危险 获取精确位置 通过GPS芯片接收卫星的定位信息,定位精度达10米以内。恶意程序可以用它来确定您所在的位置。
android.permission.ACCESS_NETWORK_STATE 普通 获取网络状态 允许应用程序查看所有网络的状态。
android.permission.ACCESS_WIFI_STATE 普通 查看Wi-Fi状态 允许应用程序查看有关Wi-Fi状态的信息。
android.permission.WAKE_LOCK 危险 防止手机休眠 允许应用程序防止手机休眠,在手机屏幕关闭后后台进程仍然运行。
android.permission.VIBRATE 普通 控制振动器 允许应用程序控制振动器,用于消息通知振动功能。
android.permission.CAMERA 危险 拍照和录制视频 允许应用程序拍摄照片和视频,且允许应用程序收集相机在任何时候拍到的图像。
android.permission.FLASHLIGHT 普通 控制闪光灯 允许应用程序控制闪光灯。
android.permission.BLUETOOTH_ADMIN 危险 管理蓝牙 允许程序发现和配对新的蓝牙设备。
android.permission.BLUETOOTH 危险 创建蓝牙连接 允许应用程序查看或创建蓝牙连接。
android.permission.FOREGROUND_SERVICE 普通 创建前台Service Android 9.0以上允许常规应用程序使用 Service.startForeground,用于podcast播放(推送悬浮播放,锁屏播放)
org.simalliance.openmobileapi.SMARTCARD 未知 未知权限 来自 android 引用的未知权限。
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 危险 装载和卸载文件系统 允许应用程序装载和卸载可移动存储器的文件系统。
android.permission.NFC 危险 控制nfc功能 允许应用程序与支持nfc的物体交互。
android.permission.WRITE_MEDIA_STORAGE 签名(系统) 获取外置SD卡的写权限 允许应用程序在外置SD卡中进行写入操作。
android.permission.CHANGE_NETWORK_STATE 危险 改变网络连通性 允许应用程序改变网络连通性。
android.permission.READ_EXTERNAL_STORAGE 危险 读取SD卡内容 允许应用程序从SD卡读取信息。
cn/smssdk/gui/SearchEngine.java
com/apicloud/a/c/c.java
com/apicloud/fileBrowser/Utils/MouleUtil.java
com/apicloud/fileBrowser/fileexplorer/MimeUtils.java
com/apicloud/fileBrowser/fileexplorer/Util.java
com/apicloud/glide/disklrucache/DiskLruCache.java
com/apicloud/glide/load/resource/file/FileToStreamDecoder.java
com/apicloud/wxphotopicker/Utils/MouleUtil.java
com/deepe/a/c/e.java
com/deepe/a/c/f.java
com/deepe/c/c/aa.java
com/deepe/c/i/g.java
com/deepe/c/j/d/c.java
com/deepe/c/j/e/a/g.java
com/eclipsesource/v8/PlatformDetector.java
com/gprinter/utils/SerialPortControl.java
com/lidroid/xutils/bitmap/download/DefaultDownloader.java
com/lidroid/xutils/cache/LruDiskCache.java
com/lidroid/xutils/http/client/entity/FileUploadEntity.java
com/lidroid/xutils/http/client/multipart/content/FileBody.java
com/unionpay/a.java
com/unionpay/utils/b.java
com/uzmap/pkg/uzapp/DataProvider.java
com/uzmap/pkg/uzcore/b/f.java
com/uzmap/pkg/uzcore/e/c.java
com/uzmap/pkg/uzkit/request/HttpParams.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzUIChatBox/BitmapUtils.java
com/uzmap/pkg/uzmodules/uzUnionPay/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageBrowser/AsyncImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/ImageActivity.java
com/uzmap/pkg/uzmodules/uzimageFilter/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageFilter/uzimageFilter.java
net/apicloud/selector/uis/SelectorActivity.java
top/zibin/luban/io/ArrayPoolProvide.java
android.permission.ACCESS_MOCK_LOCATION 危险 获取模拟定位信息 获取模拟定位信息,一般用于帮助开发者调试应用。恶意程序可以用它来覆盖真实位置信息源。
android.permission.RECEIVE_SMS 危险 接收短信 允许应用程序接收短信。 恶意程序会在用户未知的情况下监视或删除。
android.permission.BLUETOOTH_SCAN 危险 新蓝牙运行时权限 Android 12 系统引入了新的运行时权限,需要能够发现和配对附近的蓝牙设备。
android.permission.BLUETOOTH_ADVERTISE 危险 新蓝牙运行时权限 Android 12 系统引入了新的运行时权限,需要能够向附近的蓝牙设备进行广告。
android.permission.BLUETOOTH_CONNECT 危险 新蓝牙运行时权限 Android 12 系统引入了新的运行时权限,需要能够连接到配对的蓝牙设备。
com.apicloud.A6981894597784.permission.JPUSH_MESSAGE 未知 未知权限 来自 android 引用的未知权限。
android.permission.POST_NOTIFICATIONS 危险 发送通知的运行时权限 允许应用发布通知,Android 13 引入的新权限。
com.vivo.notification.permission.BADGE_ICON 普通 桌面图标角标 vivo平台桌面图标角标,接入vivo平台后需要用户手动开启,开启完成后收到新消息时,在已安装的应用桌面图标右上角显示“数字角标”。
android.permission.ACCESS_BACKGROUND_LOCATION 危险 获取后台定位权限 允许应用程序访问后台位置。如果您正在请求此权限,则还必须请求ACCESS COARSE LOCATION或ACCESS FINE LOCATION。单独请求此权限不会授予您位置访问权限。
android.permission.QUERY_ALL_PACKAGES 普通 获取已安装应用程序列表 Android 11引入与包可见性相关的权限,允许查询设备上的任何普通应用程序,而不考虑清单声明。
android.permission.GET_TASKS 危险 检索当前运行的应用程序 允许应用程序检索有关当前和最近运行的任务的信息。恶意应用程序可借此发现有关其他应用程序的保密信息。
com.apicloud.A6981894597784.permission.MIPUSH_RECEIVE 未知 未知权限 来自 android 引用的未知权限。
com.coloros.mcs.permission.RECIEVE_MCS_MESSAGE 未知 未知权限 来自 android 引用的未知权限。
com.heytap.mcs.permission.RECIEVE_MCS_MESSAGE 未知 未知权限 来自 android 引用的未知权限。
com.meizu.flyme.permission.PUSH 未知 未知权限 来自 android 引用的未知权限。
android.permission.CHANGE_WIFI_STATE 危险 改变Wi-Fi状态 允许应用程序改变Wi-Fi状态。
android.permission.INSTALL_PACKAGES 签名(系统) 请求安装APP 允许应用程序安装全新的或更新的 Android 包。恶意应用程序可能会借此添加其具有任意权限的新应用程序。
android.permission.DELETE_PACKAGES 签名(系统) 删除应用程序 允许应用程序删除 Android 包。恶意应用程序可借此删除重要的应用程序。
android.permission.MANAGE_EXTERNAL_STORAGE 危险 文件列表访问权限 Android11新增权限,读取本地文件,如简历,聊天图片。

证书安全分析

高危
0
警告
1
信息
1
标题 严重程度 描述信息
已签名应用 信息 应用程序已使用代码签名证书进行签名

MANIFEST分析

高危
11
警告
16
信息
0
屏蔽
0
序号 问题 严重程度 描述信息 操作
1 应用程序可以安装在有漏洞的已更新 Android 版本上
Android 4.4-4.4.4, [minSdk=19]
信息 该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。
2 应用程序已启用明文网络流量
[android:usesCleartextTraffic=true]
警告 应用程序打算使用明文网络流量,例如明文HTTP,FTP协议,DownloadManager和MediaPlayer。针对API级别27或更低的应用程序,默认值为“true”。针对API级别28或更高的应用程序,默认值为“false”。避免使用明文流量的主要原因是缺乏机密性,真实性和防篡改保护;网络攻击者可以窃听传输的数据,并且可以在不被检测到的情况下修改它。
3 Activity (com.uzmap.pkg.LauncherUI) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
4 Activity (com.uzmap.pkg.EntranceActivity) 的启动模式不是standard模式 高危 Activity 不应将启动模式属性设置为 "singleTask/singleInstance",因为这会使其成为根 Activity,并可能导致其他应用程序读取调用 Intent 的内容。因此,当 Intent 包含敏感信息时,需要使用 "standard" 启动模式属性。
5 Service (com.mob.MobACService) 未被保护。
[android:exported=true]
警告 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
6 Activity (com.mob.id.MobIDActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
7 Activity (com.mob.id.MobIDActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
8 Activity (com.mob.id.MobIDSYActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
9 Activity (com.mob.id.MobIDSYActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
10 Service (com.mob.id.MobIDService) 未被保护。
[android:exported=true]
警告 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
11 Activity (com.mob.guard.MobTranPullUpActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
12 Activity (com.mob.guard.MobTranPullUpActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
13 Activity (com.mob.guard.MobTranPullLockActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
14 Activity (com.mob.guard.MobTranPullLockActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
15 Service (com.mob.guard.MobGuardPullUpService) 未被保护。
[android:exported=true]
警告 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
16 Activity (cn.jpush.android.ui.PopWinActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
17 Activity (cn.jpush.android.ui.PopWinActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
18 Activity (cn.jpush.android.ui.PushActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
19 Activity (cn.jpush.android.ui.PushActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
20 Content Provider (cn.jpush.android.service.DownloadProvider) 未被保护。
[android:exported=true]
警告 发现 Content Provider与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
21 Activity (cn.jpush.android.service.JNotifyActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
22 Activity (cn.jpush.android.service.JNotifyActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
23 Activity (cn.android.service.JTransitActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
24 Activity (cn.android.service.JTransitActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
25 Service (cn.jpush.android.service.DaemonService) 未被保护。
[android:exported=true]
警告 发现 Service与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
26 Activity (cn.jpush.android.service.DActivity) is vulnerable to StrandHogg 2.0 高危 已发现活动存在 StrandHogg 2.0 栈劫持漏洞的风险。漏洞利用时,其他应用程序可以将恶意活动放置在易受攻击的应用程序的活动栈顶部,从而使应用程序成为网络钓鱼攻击的易受攻击目标。可以通过将启动模式属性设置为“singleInstance”并设置空 taskAffinity (taskAffinity="") 来修复此漏洞。您还可以将应用的目标 SDK 版本 (28) 更新到 29 或更高版本以在平台级别修复此问题。
27 Activity (cn.jpush.android.service.DActivity) 未被保护。
[android:exported=true]
警告 发现 Activity与设备上的其他应用程序共享,因此可被设备上的任何其他应用程序访问。
28 高优先级的Intent (1000)
[android:priority]
警告 通过设置一个比另一个Intent更高的优先级,应用程序有效地覆盖了其他请求。

可浏览的Activity组件

ACTIVITY INTENT

网络通信安全

序号 范围 严重级别 描述

API调用分析

API功能 源码文件
一般功能-> 文件操作
cn/smssdk/entity/BaseEntity.java
cn/smssdk/gui/SearchEngine.java
cn/smssdk/gui/entity/Profile.java
cn/smssdk/net/HttpResponseCallbackImp.java
cn/smssdk/net/c.java
cn/smssdk/net/h/e.java
cn/smssdk/utils/f.java
com/apicloud/DVTorch/DVTorch.java
com/apicloud/a/a/b.java
com/apicloud/a/a/c.java
com/apicloud/a/a/e.java
com/apicloud/a/c/c.java
com/apicloud/a/d/g.java
com/apicloud/a/g/a/i.java
com/apicloud/a/i/a/ah/a/i.java
com/apicloud/a/i/a/ah/a/j.java
com/apicloud/a/i/a/d/a/b.java
com/apicloud/a/i/a/d/a/c.java
com/apicloud/a/i/a/d/a/e.java
com/apicloud/a/i/a/d/a/f.java
com/apicloud/a/i/a/d/a/o.java
com/apicloud/a/i/a/d/a/p.java
com/apicloud/a/i/a/d/a/q.java
com/apicloud/a/i/a/d/a/r.java
com/apicloud/a/i/a/d/b.java
com/apicloud/a/i/a/d/g.java
com/apicloud/a/i/a/e/c/d.java
com/apicloud/a/i/a/e/e.java
com/apicloud/a/i/a/y/a/h.java
com/apicloud/devlop/FNImageClip/JsParmasUtil.java
com/apicloud/devlop/FNImageClip/SaveUtil.java
com/apicloud/fileBrowser/FileBrowserModule.java
com/apicloud/fileBrowser/Utils/ImageUtil.java
com/apicloud/fileBrowser/Utils/LogUtil.java
com/apicloud/fileBrowser/Utils/MouleUtil.java
com/apicloud/fileBrowser/fileexplorer/FileCategoryHelper.java
com/apicloud/fileBrowser/fileexplorer/FileIconHelper.java
com/apicloud/fileBrowser/fileexplorer/FileListAdapter.java
com/apicloud/fileBrowser/fileexplorer/FileListItem.java
com/apicloud/fileBrowser/fileexplorer/FileOperationHelper.java
com/apicloud/fileBrowser/fileexplorer/FileViewActivity.java
com/apicloud/fileBrowser/fileexplorer/FileViewInteractionHub.java
com/apicloud/fileBrowser/fileexplorer/FilenameExtFilter.java
com/apicloud/fileBrowser/fileexplorer/IntentBuilder.java
com/apicloud/fileBrowser/fileexplorer/MimeUtils.java
com/apicloud/fileBrowser/fileexplorer/Util.java
com/apicloud/glide/BitmapRequestBuilder.java
com/apicloud/glide/BitmapTypeRequest.java
com/apicloud/glide/DownloadOptions.java
com/apicloud/glide/DrawableRequestBuilder.java
com/apicloud/glide/DrawableTypeRequest.java
com/apicloud/glide/GenericRequestBuilder.java
com/apicloud/glide/GenericTranscodeRequest.java
com/apicloud/glide/GifRequestBuilder.java
com/apicloud/glide/GifTypeRequest.java
com/apicloud/glide/Glide.java
com/apicloud/glide/RequestManager.java
com/apicloud/glide/disklrucache/DiskLruCache.java
com/apicloud/glide/disklrucache/StrictLineReader.java
com/apicloud/glide/disklrucache/Util.java
com/apicloud/glide/gifdecoder/GifDecoder.java
com/apicloud/glide/gifencoder/AnimatedGifEncoder.java
com/apicloud/glide/gifencoder/LZWEncoder.java
com/apicloud/glide/load/Encoder.java
com/apicloud/glide/load/Key.java
com/apicloud/glide/load/ResourceDecoder.java
com/apicloud/glide/load/data/AssetPathFetcher.java
com/apicloud/glide/load/data/ByteArrayFetcher.java
com/apicloud/glide/load/data/ExifOrientationStream.java
com/apicloud/glide/load/data/FileDescriptorAssetPathFetcher.java
com/apicloud/glide/load/data/FileDescriptorLocalUriFetcher.java
com/apicloud/glide/load/data/HttpUrlFetcher.java
com/apicloud/glide/load/data/LocalUriFetcher.java
com/apicloud/glide/load/data/MediaStoreThumbFetcher.java
com/apicloud/glide/load/data/StreamAssetPathFetcher.java
com/apicloud/glide/load/data/StreamLocalUriFetcher.java
com/apicloud/glide/load/engine/CacheLoader.java
com/apicloud/glide/load/engine/DecodeJob.java
com/apicloud/glide/load/engine/EngineKey.java
com/apicloud/glide/load/engine/OriginalKey.java
com/apicloud/glide/load/engine/cache/DiskCache.java
com/apicloud/glide/load/engine/cache/DiskCacheAdapter.java
com/apicloud/glide/load/engine/cache/DiskLruCacheFactory.java
com/apicloud/glide/load/engine/cache/DiskLruCacheWrapper.java
com/apicloud/glide/load/engine/cache/ExternalCacheDiskCacheFactory.java
com/apicloud/glide/load/engine/cache/InternalCacheDiskCacheFactory.java
com/apicloud/glide/load/engine/cache/SafeKeyGenerator.java
com/apicloud/glide/load/engine/prefill/BitmapPreFillRunner.java
com/apicloud/glide/load/model/FileLoader.java
com/apicloud/glide/load/model/ImageVideoModelLoader.java
com/apicloud/glide/load/model/ImageVideoWrapper.java
com/apicloud/glide/load/model/ImageVideoWrapperEncoder.java
com/apicloud/glide/load/model/StreamEncoder.java
com/apicloud/glide/load/model/StringLoader.java
com/apicloud/glide/load/model/file_descriptor/FileDescriptorFileLoader.java
com/apicloud/glide/load/model/stream/BaseGlideUrlLoader.java
com/apicloud/glide/load/model/stream/HttpUrlGlideUrlLoader.java
com/apicloud/glide/load/model/stream/MediaStoreStreamLoader.java
com/apicloud/glide/load/model/stream/StreamByteArrayLoader.java
com/apicloud/glide/load/model/stream/StreamFileLoader.java
com/apicloud/glide/load/model/stream/StreamModelLoader.java
com/apicloud/glide/load/model/stream/StreamResourceLoader.java
com/apicloud/glide/load/model/stream/StreamStringLoader.java
com/apicloud/glide/load/model/stream/StreamUriLoader.java
com/apicloud/glide/load/model/stream/StreamUrlLoader.java
com/apicloud/glide/load/resource/NullEncoder.java
com/apicloud/glide/load/resource/NullResourceEncoder.java
com/apicloud/glide/load/resource/bitmap/BitmapEncoder.java
com/apicloud/glide/load/resource/bitmap/Downsampler.java
com/apicloud/glide/load/resource/bitmap/FileDescriptorBitmapDataLoadProvider.java
com/apicloud/glide/load/resource/bitmap/FileDescriptorBitmapDecoder.java
com/apicloud/glide/load/resource/bitmap/ImageHeaderParser.java
com/apicloud/glide/load/resource/bitmap/ImageVideoBitmapDecoder.java
com/apicloud/glide/load/resource/bitmap/ImageVideoDataLoadProvider.java
com/apicloud/glide/load/resource/bitmap/RecyclableBufferedInputStream.java
com/apicloud/glide/load/resource/bitmap/StreamBitmapDataLoadProvider.java
com/apicloud/glide/load/resource/bitmap/StreamBitmapDecoder.java
com/apicloud/glide/load/resource/bitmap/VideoBitmapDecoder.java
com/apicloud/glide/load/resource/file/FileDecoder.java
com/apicloud/glide/load/resource/file/FileResource.java
com/apicloud/glide/load/resource/file/FileToStreamDecoder.java
com/apicloud/glide/load/resource/file/StreamFileDataLoadProvider.java
com/apicloud/glide/load/resource/gif/GifDrawableLoadProvider.java
com/apicloud/glide/load/resource/gif/GifFrameLoader.java
com/apicloud/glide/load/resource/gif/GifResourceDecoder.java
com/apicloud/glide/load/resource/gif/GifResourceEncoder.java
com/apicloud/glide/load/resource/gifbitmap/GifBitmapWrapperResourceDecoder.java
com/apicloud/glide/load/resource/gifbitmap/GifBitmapWrapperResourceEncoder.java
com/apicloud/glide/load/resource/gifbitmap/GifBitmapWrapperStreamResourceDecoder.java
com/apicloud/glide/load/resource/gifbitmap/ImageVideoGifDrawableLoadProvider.java
com/apicloud/glide/load/resource/transcode/BitmapBytesTranscoder.java
com/apicloud/glide/provider/ChildLoadProvider.java
com/apicloud/glide/provider/DataLoadProvider.java
com/apicloud/glide/provider/EmptyDataLoadProvider.java
com/apicloud/glide/provider/FixedLoadProvider.java
com/apicloud/glide/signature/EmptySignature.java
com/apicloud/glide/signature/MediaStoreSignature.java
com/apicloud/glide/signature/StringSignature.java
com/apicloud/glide/util/ContentLengthInputStream.java
com/apicloud/glide/util/ExceptionCatchingInputStream.java
com/apicloud/glide/util/MarkEnforcingInputStream.java
com/apicloud/third/gif/GifAnimationMetaData.java
com/apicloud/third/gif/GifDecoder.java
com/apicloud/third/gif/GifDrawable.java
com/apicloud/third/gif/GifDrawableInit.java
com/apicloud/third/gif/GifIOException.java
com/apicloud/third/gif/GifInfoHandle.java
com/apicloud/third/gif/GifTexImage2D.java
com/apicloud/third/gif/GifTextView.java
com/apicloud/third/gif/GifTextureView.java
com/apicloud/third/gif/GifViewUtils.java
com/apicloud/third/gif/InputSource.java
com/apicloud/wxphotopicker/Utils/ImageUtil.java
com/apicloud/wxphotopicker/Utils/LogUtil.java
com/apicloud/wxphotopicker/Utils/MouleUtil.java
com/apicloud/wxphotopicker/Utils/UriUtils.java
com/apicloud/wxphotopicker/loader/ImageModel.java
com/apicloud/wxphotopicker/paramete/OpenParam.java
com/apicloud/zhaofei/xprinterplus/CheckWifiConnThread.java
com/apicloud/zhaofei/xprinterplus/DeviceConnFactoryManager.java
com/apicloud/zhaofei/xprinterplus/SharedPreferencesUtil.java
com/deepe/a/a/b.java
com/deepe/a/c/c.java
com/deepe/a/c/d.java
com/deepe/a/c/e.java
com/deepe/a/c/f.java
com/deepe/a/d/a/a.java
com/deepe/a/e/a.java
com/deepe/b/a/c.java
com/deepe/b/c/a.java
com/deepe/b/d.java
com/deepe/b/d/a.java
com/deepe/b/d/b.java
com/deepe/b/e.java
com/deepe/b/f.java
com/deepe/b/f/a.java
com/deepe/b/f/b.java
com/deepe/c/a/b.java
com/deepe/c/a/c.java
com/deepe/c/a/d.java
com/deepe/c/a/j.java
com/deepe/c/c/aa.java
com/deepe/c/c/b.java
com/deepe/c/c/e.java
com/deepe/c/c/f.java
com/deepe/c/c/h.java
com/deepe/c/c/j.java
com/deepe/c/c/t.java
com/deepe/c/c/v.java
com/deepe/c/c/w.java
com/deepe/c/f/b.java
com/deepe/c/i/a.java
com/deepe/c/i/g.java
com/deepe/c/j/c/b.java
com/deepe/c/j/c/c.java
com/deepe/c/j/d/a.java
com/deepe/c/j/d/c.java
com/deepe/c/j/d/f.java
com/deepe/c/j/d/g.java
com/deepe/c/j/d/i.java
com/deepe/c/j/d/k.java
com/deepe/c/j/e.java
com/deepe/c/j/e/a/a.java
com/deepe/c/j/e/a/b.java
com/deepe/c/j/e/a/c.java
com/deepe/c/j/e/a/d.java
com/deepe/c/j/e/a/f.java
com/deepe/c/j/e/a/g.java
com/deepe/c/j/e/a/h.java
com/deepe/c/j/e/a/i.java
com/deepe/c/j/e/a/j.java
com/deepe/c/j/e/a/k.java
com/deepe/c/j/e/j.java
com/deepe/c/j/f.java
com/deepe/c/j/j.java
com/deepe/c/j/k.java
com/deepe/c/k/g.java
com/deepe/c/l/a/b.java
com/deepe/c/l/d.java
com/deepe/c/l/i/a.java
com/deepe/f/a/f.java
com/deepe/f/b.java
com/deepe/f/c.java
com/deepe/sdk/RESResponse.java
com/deepe/sdk/StringStream.java
com/eclipsesource/v8/LibraryLoader.java
com/eclipsesource/v8/NodeJS.java
com/eclipsesource/v8/PlatformDetector.java
com/eclipsesource/v8/Releasable.java
com/eclipsesource/v8/debug/V8DebugServer.java
com/gprinter/command/CpclCommand.java
com/gprinter/command/EscCommand.java
com/gprinter/command/GpUtils.java
com/gprinter/command/GsCommand.java
com/gprinter/command/LabelCommand.java
com/gprinter/io/BluetoothPort.java
com/gprinter/io/EthernetPort.java
com/gprinter/io/NfcPort.java
com/gprinter/io/PortManager.java
com/gprinter/io/SerialPort.java
com/gprinter/io/UsbPort.java
com/gprinter/utils/SerialPortControl.java
com/gprinter/utils/SerialPortFinder.java
com/gprinter/utils/ZLibUtils.java
com/jcraft/jzlib/DeflaterOutputStream.java
com/jcraft/jzlib/GZIPException.java
com/jcraft/jzlib/GZIPHeader.java
com/jcraft/jzlib/GZIPInputStream.java
com/jcraft/jzlib/GZIPOutputStream.java
com/jcraft/jzlib/Inflate.java
com/jcraft/jzlib/InflaterInputStream.java
com/jcraft/jzlib/ZInputStream.java
com/jcraft/jzlib/ZOutputStream.java
com/jcraft/jzlib/ZStreamException.java
com/lidroid/xutils/BitmapUtils.java
com/lidroid/xutils/DbUtils.java
com/lidroid/xutils/HttpUtils.java
com/lidroid/xutils/bitmap/core/BitmapCache.java
com/lidroid/xutils/bitmap/core/BitmapDecoder.java
com/lidroid/xutils/bitmap/download/DefaultDownloader.java
com/lidroid/xutils/bitmap/download/Downloader.java
com/lidroid/xutils/cache/LruDiskCache.java
com/lidroid/xutils/http/HttpHandler.java
com/lidroid/xutils/http/RequestParams.java
com/lidroid/xutils/http/ResponseStream.java
com/lidroid/xutils/http/SyncHttpHandler.java
com/lidroid/xutils/http/callback/FileDownloadHandler.java
com/lidroid/xutils/http/callback/StringDownloadHandler.java
com/lidroid/xutils/http/client/DefaultSSLSocketFactory.java
com/lidroid/xutils/http/client/RetryHandler.java
com/lidroid/xutils/http/client/entity/BodyParamsEntity.java
com/lidroid/xutils/http/client/entity/DecompressingEntity.java
com/lidroid/xutils/http/client/entity/FileUploadEntity.java
com/lidroid/xutils/http/client/entity/GZipDecompressingEntity.java
com/lidroid/xutils/http/client/entity/InputStreamUploadEntity.java
com/lidroid/xutils/http/client/multipart/HttpMultipart.java
com/lidroid/xutils/http/client/multipart/MultipartEntity.java
com/lidroid/xutils/http/client/multipart/content/ByteArrayBody.java
com/lidroid/xutils/http/client/multipart/content/ContentBody.java
com/lidroid/xutils/http/client/multipart/content/FileBody.java
com/lidroid/xutils/http/client/multipart/content/InputStreamBody.java
com/lidroid/xutils/http/client/multipart/content/StringBody.java
com/lidroid/xutils/http/client/util/URLEncodedUtils.java
com/lidroid/xutils/task/PriorityObjectBlockingQueue.java
com/lidroid/xutils/util/IOUtils.java
com/lidroid/xutils/util/OtherUtils.java
com/lidroid/xutils/util/PreferencesCookieStore.java
com/open/apicloud/jpush/JPushNotification.java
com/open/apicloud/jpush/SharedPrefe.java
com/unionpay/UPPayAssistEx.java
com/unionpay/WebViewJavascriptBridge.java
com/unionpay/a.java
com/unionpay/a/a.java
com/unionpay/a/c.java
com/unionpay/utils/UPUtils.java
com/unionpay/utils/b.java
com/unionpay/utils/g.java
com/unionpay/utils/j.java
com/uzmap/pkg/b/a/g.java
com/uzmap/pkg/b/a/h.java
com/uzmap/pkg/b/c/d.java
com/uzmap/pkg/b/c/j.java
com/uzmap/pkg/b/c/o.java
com/uzmap/pkg/openapi/FileSystem.java
com/uzmap/pkg/uzapp/DataProvider.java
com/uzmap/pkg/uzapp/UPExtraBridge.java
com/uzmap/pkg/uzapp/b.java
com/uzmap/pkg/uzcore/UZCoreUtil.java
com/uzmap/pkg/uzcore/b/f.java
com/uzmap/pkg/uzcore/b/j.java
com/uzmap/pkg/uzcore/e/c.java
com/uzmap/pkg/uzcore/f/c.java
com/uzmap/pkg/uzcore/g/b.java
com/uzmap/pkg/uzcore/g/c.java
com/uzmap/pkg/uzcore/g/d.java
com/uzmap/pkg/uzcore/g/e.java
com/uzmap/pkg/uzcore/g/f.java
com/uzmap/pkg/uzcore/g/g.java
com/uzmap/pkg/uzcore/g/h.java
com/uzmap/pkg/uzcore/i/a/b.java
com/uzmap/pkg/uzcore/i/a/c.java
com/uzmap/pkg/uzcore/i/b/a.java
com/uzmap/pkg/uzcore/i/b/g.java
com/uzmap/pkg/uzcore/m.java
com/uzmap/pkg/uzcore/uzmodule/a/c.java
com/uzmap/pkg/uzcore/uzmodule/a/f.java
com/uzmap/pkg/uzkit/UZUtility.java
com/uzmap/pkg/uzkit/data/UZWidgetInfo.java
com/uzmap/pkg/uzkit/request/APICloudHttpClient.java
com/uzmap/pkg/uzkit/request/HttpDownload.java
com/uzmap/pkg/uzkit/request/HttpParams.java
com/uzmap/pkg/uzkit/request/HttpPost.java
com/uzmap/pkg/uzmodules/UICalendar/Config.java
com/uzmap/pkg/uzmodules/UICalendar/UICalendar.java
com/uzmap/pkg/uzmodules/photoBrowser/BitmapToolkit.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageBrowserAdapter.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageDownLoader.java
com/uzmap/pkg/uzmodules/photoBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/photoBrowser/PhotoBrowser.java
com/uzmap/pkg/uzmodules/photoBrowser/view/largeImage/factory/BitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/photoBrowser/view/largeImage/factory/FileBitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/photoBrowser/view/largeImage/factory/InputStreamBitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/uzFNScanner/UzFNScanner.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureActivity.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureView.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/camera/CameraManager.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/RGBLuminanceSource.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/JsParamsUtil.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/ScanUtil.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/UriUtils.java
com/uzmap/pkg/uzmodules/uzTabBarMenu/UzTabBarMenu.java
com/uzmap/pkg/uzmodules/uzUIChatBox/BitmapUtils.java
com/uzmap/pkg/uzmodules/uzUIChatBox/JsParamsUtil.java
com/uzmap/pkg/uzmodules/uzUnionPay/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageBrowser/AsyncImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/ImageLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/BaseActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/GalleryActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/ImageActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/utils/ImageDownLoader.java
com/uzmap/pkg/uzmodules/uzimageBrowser/view/largeimage/factory/BitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/uzimageBrowser/view/largeimage/factory/FileBitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/uzimageBrowser/view/largeimage/factory/InputStreamBitmapDecoderFactory.java
com/uzmap/pkg/uzmodules/uzimageFilter/MouleUtil.java
com/uzmap/pkg/uzmodules/uzimageFilter/compress/Compressor.java
com/uzmap/pkg/uzmodules/uzimageFilter/compress/ImageUtil.java
com/uzmap/pkg/uzmodules/uzimageFilter/utils/BitmapToolkit.java
com/uzmap/pkg/uzmodules/uzimageFilter/uzimageFilter.java
com/uzmap/pkg/uzmodules/uzinputField/UzInputField.java
com/uzmap/pkg/uzmodules/uzpush/UPush.java
com/uzmap/pkg/uzmodules/uztimeSelector/NumberPicker.java
net/apicloud/selector/uis/SelectorActivity.java
net/apicloud/selector/utils/TakePhotoUtil.java
top/zibin/luban/Checker.java
top/zibin/luban/Engine.java
top/zibin/luban/InputStreamAdapter.java
top/zibin/luban/InputStreamProvider.java
top/zibin/luban/Luban.java
top/zibin/luban/OnCompressListener.java
top/zibin/luban/OnNewCompressListener.java
top/zibin/luban/io/ArrayPoolProvide.java
top/zibin/luban/io/BufferedInputStreamWrap.java
隐私数据-> 读取短信 cn/smssdk/d/a.java
cn/smssdk/gui/SMSReceiver.java
组件-> 发送广播
一般功能-> IPC通信
cn/android/service/JTransitActivity.java
cn/gov/pbc/tsm/client/mobile/android/bank/service/a.java
cn/smssdk/gui/AvatarPage.java
cn/smssdk/gui/AvatarPickerPage.java
cn/smssdk/gui/ContactDetailPage.java
cn/smssdk/gui/ContactsPage.java
cn/smssdk/gui/IdentifyNumPage.java
cn/smssdk/gui/SMSReceiver.java
com/apicloud/a/a.java
com/apicloud/a/a/a.java
com/apicloud/a/b.java
com/apicloud/a/d/a.java
com/apicloud/a/d/b.java
com/apicloud/a/i/a/ah/f.java
com/apicloud/a/i/a/d/b.java
com/apicloud/a/i/a/y/a/a/f.java
com/apicloud/fileBrowser/FileBrowserModule.java
com/apicloud/fileBrowser/fileexplorer/FileViewActivity.java
com/apicloud/fileBrowser/fileexplorer/FileViewInteractionHub.java
com/apicloud/fileBrowser/fileexplorer/IFileInteractionListener.java
com/apicloud/fileBrowser/fileexplorer/IntentBuilder.java
com/apicloud/glide/manager/DefaultConnectivityMonitor.java
com/apicloud/wxphotopicker/WXPhotoPickerModule.java
com/apicloud/zhaofei/xprinterplus/BluetoothDeviceList.java
com/apicloud/zhaofei/xprinterplus/ConnMoreDevicesActivity.java
com/apicloud/zhaofei/xprinterplus/DeviceConnFactoryManager.java
com/apicloud/zhaofei/xprinterplus/SerialPortList.java
com/apicloud/zhaofei/xprinterplus/UsbDeviceList.java
com/apicloud/zhaofei/xprinterplus/XPrinterPlusModule.java
com/deepe/a/b/a.java
com/deepe/c/a/d.java
com/deepe/c/f/a/c.java
com/deepe/c/f/d.java
com/deepe/c/j/a/a.java
com/deepe/f/a/f.java
com/deepe/f/b/a.java
com/gprinter/io/NfcPort.java
com/gprinter/io/UsbPort.java
com/open/apicloud/jpush/JPushNotification.java
com/open/apicloud/jpush/JPushReceiver.java
com/open/apicloud/jpush/PushMessageReceiver.java
com/unionpay/UPPayAssistEx.java
com/unionpay/UPPayWapActivity.java
com/unionpay/a.java
com/unionpay/client3/tsm/ITsmConnection.java
com/unionpay/client3/tsm/ITsmConnectionCallback.java
com/unionpay/m.java
com/unionpay/mobile/tsm/connect/IInitCallback.java
com/unionpay/mobile/tsm/connect/IRemoteApdu.java
com/unionpay/tsmservice/ITsmActivityCallback.java
com/unionpay/tsmservice/ITsmCallback.java
com/unionpay/tsmservice/ITsmProgressCallback.java
com/unionpay/tsmservice/ITsmService.java
com/unionpay/tsmservice/OnSafetyKeyboardCallback.java
com/unionpay/tsmservice/UPTsmAddon.java
com/unionpay/tsmservice/a.java
com/unionpay/tsmservice/mi/ITsmActivityCallback.java
com/unionpay/tsmservice/mi/ITsmCallback.java
com/unionpay/tsmservice/mi/ITsmProgressCallback.java
com/unionpay/tsmservice/mi/ITsmService.java
com/unionpay/tsmservice/mi/OnSafetyKeyboardCallback.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
com/unionpay/tsmservice/mi/a.java
com/uzmap/pkg/LauncherUI.java
com/uzmap/pkg/b/a/a.java
com/uzmap/pkg/b/a/g.java
com/uzmap/pkg/b/c/i.java
com/uzmap/pkg/b/c/m.java
com/uzmap/pkg/b/f/a.java
com/uzmap/pkg/openapi/SuperWebview.java
com/uzmap/pkg/openapi/ViewClient.java
com/uzmap/pkg/uzapp/DataProvider.java
com/uzmap/pkg/uzapp/UPExtraBridge.java
com/uzmap/pkg/uzapp/b.java
com/uzmap/pkg/uzcore/UZAppActivity.java
com/uzmap/pkg/uzcore/UZCoreUtil.java
com/uzmap/pkg/uzcore/UZPlatformBridge.java
com/uzmap/pkg/uzcore/ad.java
com/uzmap/pkg/uzcore/aj.java
com/uzmap/pkg/uzcore/d/c.java
com/uzmap/pkg/uzcore/external/j.java
com/uzmap/pkg/uzcore/f.java
com/uzmap/pkg/uzcore/g/e.java
com/uzmap/pkg/uzcore/h.java
com/uzmap/pkg/uzcore/h/m.java
com/uzmap/pkg/uzcore/i.java
com/uzmap/pkg/uzcore/i/a.java
com/uzmap/pkg/uzcore/i/b/a.java
com/uzmap/pkg/uzcore/i/b/g.java
com/uzmap/pkg/uzcore/i/b/h.java
com/uzmap/pkg/uzcore/i/b/i.java
com/uzmap/pkg/uzcore/k.java
com/uzmap/pkg/uzcore/l.java
com/uzmap/pkg/uzcore/o.java
com/uzmap/pkg/uzcore/uzmodule/ActivityResult.java
com/uzmap/pkg/uzcore/uzmodule/UZModule.java
com/uzmap/pkg/uzcore/uzmodule/a.java
com/uzmap/pkg/uzcore/uzmodule/a/a.java
com/uzmap/pkg/uzcore/uzmodule/a/c.java
com/uzmap/pkg/uzcore/uzmodule/a/f.java
com/uzmap/pkg/uzmodules/uzFNScanner/UzFNScanner.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureActivity.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/camera/FlashlightManager.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/CaptureActivityHandler.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/CaptureActivityHandlerView.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/DecodeFormatManager.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/Intents.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/ScanUtil.java
com/uzmap/pkg/uzmodules/uzUnionPay/BaseUnionModule.java
com/uzmap/pkg/uzmodules/uzUnionPay/TransActivity.java
com/uzmap/pkg/uzmodules/uzUnionPay/UzUnionPay.java
com/uzmap/pkg/uzmodules/uzimageBrowser/UZImageBrowser.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/BaseActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/GalleryActivity.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/ImageActivity.java
com/uzmap/pkg/uzmodules/uzimageFilter/uzimageFilter.java
com/uzmap/pkg/uzsocket/UPnsService.java
com/uzmap/pkg/uzsocket/api/Receiver.java
com/uzmap/pkg/uzsocket/b/c.java
net/apicloud/selector/SelectorHelper.java
net/apicloud/selector/uis/SelectorActivity.java
net/apicloud/selector/utils/AnimUtil.java
net/apicloud/selector/utils/PSUtil.java
net/apicloud/selector/utils/TakePhotoUtil.java
网络通信-> TCP套接字
网络通信-> SSL证书处理
加密解密-> 信息摘要算法
隐私数据-> 拍照摄像 com/apicloud/DVTorch/DVTorch.java
com/apicloud/a/i/a/d/a/b.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/camera/CameraManager.java
组件-> 启动 Activity
cn/smssdk/gui/ContactDetailPage.java
com/apicloud/a/i/a/y/a/a/f.java
com/apicloud/fileBrowser/FileBrowserModule.java
com/apicloud/fileBrowser/fileexplorer/IFileInteractionListener.java
com/apicloud/wxphotopicker/WXPhotoPickerModule.java
com/apicloud/zhaofei/xprinterplus/BluetoothDeviceList.java
com/apicloud/zhaofei/xprinterplus/ConnMoreDevicesActivity.java
com/apicloud/zhaofei/xprinterplus/XPrinterPlusModule.java
com/deepe/c/a/d.java
com/deepe/c/f/a/c.java
com/deepe/c/f/l.java
com/open/apicloud/jpush/JPushReceiver.java
com/unionpay/UPPayAssistEx.java
com/unionpay/a.java
com/unionpay/m.java
com/unionpay/tsmservice/ITsmActivityCallback.java
com/unionpay/tsmservice/UPTsmAddon.java
com/unionpay/tsmservice/a.java
com/unionpay/tsmservice/mi/ITsmActivityCallback.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
com/unionpay/tsmservice/mi/a.java
com/uzmap/pkg/LauncherUI.java
com/uzmap/pkg/b/a/g.java
com/uzmap/pkg/b/c/i.java
com/uzmap/pkg/openapi/ViewClient.java
com/uzmap/pkg/uzapp/UPExtraBridge.java
com/uzmap/pkg/uzapp/b.java
com/uzmap/pkg/uzcore/UZAppActivity.java
com/uzmap/pkg/uzcore/h/m.java
com/uzmap/pkg/uzcore/i/b/a.java
com/uzmap/pkg/uzcore/i/b/i.java
com/uzmap/pkg/uzcore/uzmodule/UZModule.java
com/uzmap/pkg/uzcore/uzmodule/a/c.java
com/uzmap/pkg/uzcore/uzmodule/a/f.java
com/uzmap/pkg/uzmodules/uzFNScanner/UzFNScanner.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureActivity.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/decoding/CaptureActivityHandler.java
com/uzmap/pkg/uzmodules/uzUnionPay/UzUnionPay.java
com/uzmap/pkg/uzmodules/uzimageBrowser/UZImageBrowser.java
com/uzmap/pkg/uzmodules/uzimageBrowser/activity/GalleryActivity.java
net/apicloud/selector/SelectorHelper.java
net/apicloud/selector/utils/AnimUtil.java
net/apicloud/selector/utils/PSUtil.java
加密解密-> Base64 加密 cn/smssdk/net/c.java
com/unionpay/tsmservice/UPTsmAddon.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
加密解密-> Base64 解密
调用java反射机制
cn/smssdk/c/b.java
cn/smssdk/gui/PopupDialog.java
cn/smssdk/utils/f.java
com/apicloud/a/i/a/aa/h.java
com/apicloud/a/i/a/aa/j.java
com/apicloud/a/i/a/ad/a/h.java
com/apicloud/a/i/a/v/a.java
com/apicloud/a/i/a/v/g.java
com/apicloud/fileBrowser/Utils/ViewUtil.java
com/apicloud/glide/module/ManifestParser.java
com/apicloud/third/gif/LibraryLoader.java
com/apicloud/wxphotopicker/Utils/ViewUtil.java
com/deepe/a/b/d.java
com/deepe/c/b/b/a.java
com/deepe/c/b/i.java
com/deepe/c/f/a/c.java
com/deepe/c/f/d.java
com/deepe/c/f/g.java
com/deepe/c/i/l.java
com/deepe/c/i/o.java
com/deepe/c/j/d/g.java
com/deepe/f/b/a.java
com/eclipsesource/v8/V8.java
com/eclipsesource/v8/V8Object.java
com/lidroid/xutils/ViewUtils.java
com/lidroid/xutils/bitmap/BitmapCommonUtils.java
com/lidroid/xutils/bitmap/callback/DefaultBitmapLoadCallBack.java
com/lidroid/xutils/db/table/Column.java
com/lidroid/xutils/db/table/ColumnUtils.java
com/lidroid/xutils/db/table/Finder.java
com/lidroid/xutils/db/table/Foreign.java
com/lidroid/xutils/db/table/Id.java
com/lidroid/xutils/db/table/TableUtils.java
com/lidroid/xutils/util/OtherUtils.java
com/lidroid/xutils/view/EventListenerManager.java
com/unionpay/UPPayAssistEx.java
com/unionpay/tsmservice/mi/widget/UPSaftyKeyboard.java
com/unionpay/tsmservice/widget/UPSaftyKeyboard.java
com/uzmap/pkg/b/a/b.java
com/uzmap/pkg/b/a/i.java
com/uzmap/pkg/b/f/b.java
com/uzmap/pkg/uzcore/i/b/j.java
com/uzmap/pkg/uzcore/uzmodule/c.java
com/uzmap/pkg/uzcore/uzmodule/e.java
com/uzmap/pkg/uzmodules/photoBrowser/ViewUtil.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/camera/CameraConfigurationManager.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/camera/FlashlightManager.java
org/simple/eventbus/SubsciberMethodHunter.java
org/simple/eventbus/Subscription.java
org/simple/eventbus/TargetMethod.java
隐私数据-> 录制视频 com/apicloud/a/i/a/d/a/q.java
com/apicloud/a/i/a/d/a/r.java
com/deepe/a/c/d.java
命令执行-> getRuntime.exec()
一般功能-> 获取系统服务(getSystemService)
cn/smssdk/c/b.java
cn/smssdk/gui/PopupDialog.java
cn/smssdk/gui/RegisterPage.java
cn/smssdk/utils/f.java
com/apicloud/c/a/a/j.java
com/apicloud/fileBrowser/Utils/ViewUtil.java
com/apicloud/glide/load/engine/cache/MemorySizeCalculator.java
com/apicloud/glide/manager/DefaultConnectivityMonitor.java
com/apicloud/glide/request/target/NotificationTarget.java
com/apicloud/glide/request/target/ViewTarget.java
com/apicloud/wxphotopicker/Utils/ViewUtil.java
com/apicloud/zhaofei/xprinterplus/ConnMoreDevicesActivity.java
com/apicloud/zhaofei/xprinterplus/UsbDeviceList.java
com/apicloud/zhaofei/xprinterplus/Utils.java
com/apicloud/zhaofei/xprinterplus/XPrinterPlusModule.java
com/deepe/b/a.java
com/deepe/c/a/i.java
com/gprinter/io/UsbPort.java
com/lidroid/xutils/bitmap/BitmapGlobalConfig.java
com/open/apicloud/jpush/JPushNotification.java
com/unionpay/UPPayAssistEx.java
com/unionpay/a.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
com/unionpay/utils/e.java
com/uzmap/pkg/uzcore/i/b/a.java
com/uzmap/pkg/uzmodules/UICalendar/GridAdapter.java
com/uzmap/pkg/uzmodules/UICalendar/Utils.java
com/uzmap/pkg/uzmodules/photoBrowser/ViewUtil.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureActivity.java
com/uzmap/pkg/uzmodules/uzFNScanner/Zxing/CaptureView.java
com/uzmap/pkg/uzmodules/uzFNScanner/utlis/BeepUtil.java
com/uzmap/pkg/uzmodules/uzTabBarMenu/UzTabBarMenu.java
com/uzmap/pkg/uzmodules/uzUIChatBox/GridAdapter.java
com/uzmap/pkg/uzmodules/uzUIChatBox/UzUIChatBox.java
com/uzmap/pkg/uzmodules/uzclipboard/UzClipBoard.java
com/uzmap/pkg/uzmodules/uzinputField/UzInputField.java
com/uzmap/pkg/uzmodules/uztimeSelector/NumberPicker.java
com/uzmap/pkg/uzmodules/uztimeSelector/TimePicker.java
net/apicloud/selector/utils/UiUtil.java
隐私数据-> 获取已安装的应用程序 com/deepe/c/f/a/c.java
com/uzmap/pkg/uzcore/UZCoreUtil.java
进程操作-> 获取进程pid
网络通信-> WebView 相关
组件-> ContentProvider com/uzmap/pkg/uzapp/DataProvider.java
com/uzmap/pkg/uzapp/UProvider.java
组件-> Provider openFile com/uzmap/pkg/uzapp/DataProvider.java
网络通信-> WebView GET请求
辅助功能accessibility相关 com/uzmap/pkg/uzmodules/uztimeSelector/NumberPicker.java
com/uzmap/pkg/uzmodules/uztimeSelector/TimePicker.java
一般功能-> 加载so文件
隐私数据-> 获取GPS位置信息 com/unionpay/UPPayAssistEx.java
com/unionpay/utils/e.java
com/uzmap/pkg/b/a/e.java
一般功能-> 获取活动网路信息 com/apicloud/glide/manager/DefaultConnectivityMonitor.java
com/unionpay/UPPayAssistEx.java
网络通信-> HTTP建立连接
网络通信-> HTTPS建立连接
一般功能-> 查看\修改Android系统属性
JavaScript 接口方法
进程操作-> 获取运行的进程\服务 com/deepe/c/i/l.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
加密解密-> Crypto加解密组件 cn/smssdk/net/h/c.java
com/deepe/c/g/b.java
com/unionpay/utils/d.java
一般功能-> Android通知 com/apicloud/glide/request/target/NotificationTarget.java
com/open/apicloud/jpush/JPushNotification.java
com/uzmap/pkg/b/a/g.java
网络通信-> WebView JavaScript接口
隐私数据-> 剪贴板数据读写操作 com/deepe/a/b/c.java
com/deepe/c/a/i.java
com/uzmap/pkg/uzmodules/uzclipboard/UzClipBoard.java
网络通信-> HTTP请求、连接和会话 com/lidroid/xutils/HttpUtils.java
com/lidroid/xutils/http/HttpHandler.java
com/lidroid/xutils/http/SyncHttpHandler.java
网络通信-> URLConnection
组件-> 启动 Service com/unionpay/tsmservice/UPTsmAddon.java
com/unionpay/tsmservice/mi/UPTsmAddon.java
com/uzmap/pkg/uzsocket/b/c.java
一般功能-> 传感器相关操作 com/deepe/a/b/j.java
com/deepe/c/a/i.java
com/uzmap/pkg/b/a/j.java
隐私数据-> 屏幕截图,截取自己应用内部界面 com/uzmap/pkg/uzmodules/uzFNScanner/utlis/ScanUtil.java
进程操作-> 杀死进程 com/uzmap/pkg/uzcore/UZAppActivity.java
设备指纹-> getSimOperator cn/smssdk/gui/RegisterPage.java
com/deepe/f/a.java
设备指纹-> 查看运营商信息 com/deepe/f/a.java
设备指纹-> 查看本机IMSI com/unionpay/utils/e.java
设备指纹-> 查看本机号码 com/unionpay/utils/e.java
一般功能-> 获取WiFi相关信息 com/unionpay/utils/e.java
网络通信-> WebView POST请求 com/uzmap/pkg/openapi/SuperWebview.java
网络通信-> DefaultHttpClient Connection com/lidroid/xutils/HttpUtils.java
隐私数据-> 读写通讯录 com/deepe/c/a/b.java
隐私数据-> 屏幕截图,截取自己应用内部界面 com/apicloud/devlop/FNImageClip/ScreenShot.java
网络通信-> TCP服务器套接字 com/eclipsesource/v8/debug/V8DebugServer.java
网络通信-> NFC连接 com/gprinter/io/NfcPort.java
网络通信-> 蓝牙连接 com/apicloud/zhaofei/xprinterplus/BluetoothDeviceList.java
com/gprinter/io/BluetoothPort.java
隐私数据-> 录制音频行为 com/deepe/a/c/f.java

安全漏洞检测

高危
7
警告
9
信息
2
安全
2
屏蔽
0
序号 问题 等级 参考标准 文件位置 操作
1 应用程序记录日志信息,不得记录敏感信息 信息 CWE: CWE-532: 通过日志文件的信息暴露
OWASP MASVS: MSTG-STORAGE-3
升级会员:解锁高级权限
2 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
升级会员:解锁高级权限
3 应用程序使用不安全的随机数生成器 警告 CWE: CWE-330: 使用不充分的随机数
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-6
升级会员:解锁高级权限
4 MD5是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
升级会员:解锁高级权限
5 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
OWASP Top 10: M3: Insecure Communication
OWASP MASVS: MSTG-NETWORK-3
升级会员:解锁高级权限
6 SHA-1是已知存在哈希冲突的弱哈希 警告 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
升级会员:解锁高级权限
7 该文件是World Readable。任何应用程序都可以读取文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
升级会员:解锁高级权限
8 此应用程序可能具有Root检测功能 安全
OWASP MASVS: MSTG-RESILIENCE-1
升级会员:解锁高级权限
9 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击 高危 CWE: CWE-79: 在Web页面生成时对输入的转义处理不恰当('跨站脚本')
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-6
升级会员:解锁高级权限
10 该文件是World Writable。任何应用程序都可以写入文件 高危 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
升级会员:解锁高级权限
11 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库 警告 CWE: CWE-89: SQL命令中使用的特殊元素转义处理不恰当('SQL 注入')
OWASP Top 10: M7: Client Code Quality
升级会员:解锁高级权限
12 使用弱加密算法 高危 CWE: CWE-327: 使用已被攻破或存在风险的密码学算法
OWASP Top 10: M5: Insufficient Cryptography
OWASP MASVS: MSTG-CRYPTO-4
升级会员:解锁高级权限
13 应用程序创建临时文件。敏感信息永远不应该被写进临时文件 警告 CWE: CWE-276: 默认权限不正确
OWASP Top 10: M2: Insecure Data Storage
OWASP MASVS: MSTG-STORAGE-2
升级会员:解锁高级权限
14 启用了调试配置。生产版本不能是可调试的 高危 CWE: CWE-919: 移动应用程序中的弱点
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-RESILIENCE-2
升级会员:解锁高级权限
15 此应用侦听剪贴板更改。一些恶意软件也会监听剪贴板更改 信息
OWASP MASVS: MSTG-PLATFORM-4
升级会员:解锁高级权限
16 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等 警告 CWE: CWE-312: 明文存储敏感信息
OWASP Top 10: M9: Reverse Engineering
OWASP MASVS: MSTG-STORAGE-14
升级会员:解锁高级权限
17 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击 安全
OWASP MASVS: MSTG-NETWORK-4
升级会员:解锁高级权限
18 SSL的不安全实现。信任所有证书或接受自签名证书是一个关键的安全漏洞。此应用程序易受MITM攻击 高危 CWE: CWE-295: 证书验证不恰当
OWASP Top 10: M3: Insecure Communication
OWASP MASVS: MSTG-NETWORK-3
升级会员:解锁高级权限
19 IP地址泄露 警告 CWE: CWE-200: 信息泄露
OWASP MASVS: MSTG-CODE-2
升级会员:解锁高级权限
20 不安全的Web视图实现。可能存在WebView任意代码执行漏洞 警告 CWE: CWE-749: 暴露危险方法或函数
OWASP Top 10: M1: Improper Platform Usage
OWASP MASVS: MSTG-PLATFORM-7
升级会员:解锁高级权限

Native库安全分析

序号 动态库 NX(堆栈禁止执行) PIE STACK CANARY(栈保护) RELRO RPATH(指定SO搜索路径) RUNPATH(指定SO搜索路径) FORTIFY(常用函数加强检查) SYMBOLS STRIPPED(裁剪符号表)
1 armeabi/libsec.so
True
info
二进制文件设置了 NX 位。这标志着内存页面不可执行,使得攻击者注入的 shellcode 不可执行。


True
info
这个二进制文件在栈上添加了一个栈哨兵值,以便它会被溢出返回地址的栈缓冲区覆盖。这样可以通过在函数返回之前验证栈哨兵的完整性来检测溢出
Full RELRO
info
此共享对象已完全启用 RELRO。 RELRO 确保 GOT 不会在易受攻击的 ELF 二进制文件中被覆盖。在完整 RELRO 中,整个 GOT(.got 和 .got.plt 两者)被标记为只读。
None
info
二进制文件没有设置运行时搜索路径或RPATH
None
info
二进制文件没有设置 RUNPATH
False
warning
二进制文件没有任何加固函数。加固函数提供了针对 glibc 的常见不安全函数(如 strcpy,gets 等)的缓冲区溢出检查。使用编译选项 -D_FORTIFY_SOURCE=2 来加固函数。这个检查对于 Dart/Flutter 库不适用
False
warning
符号可用
2 armeabi/libserial_port.so
True
info
二进制文件设置了 NX 位。这标志着内存页面不可执行,使得攻击者注入的 shellcode 不可执行。


True
info
这个二进制文件在栈上添加了一个栈哨兵值,以便它会被溢出返回地址的栈缓冲区覆盖。这样可以通过在函数返回之前验证栈哨兵的完整性来检测溢出
Full RELRO
info
此共享对象已完全启用 RELRO。 RELRO 确保 GOT 不会在易受攻击的 ELF 二进制文件中被覆盖。在完整 RELRO 中,整个 GOT(.got 和 .got.plt 两者)被标记为只读。
None
info
二进制文件没有设置运行时搜索路径或RPATH
None
info
二进制文件没有设置 RUNPATH
False
warning
二进制文件没有任何加固函数。加固函数提供了针对 glibc 的常见不安全函数(如 strcpy,gets 等)的缓冲区溢出检查。使用编译选项 -D_FORTIFY_SOURCE=2 来加固函数。这个检查对于 Dart/Flutter 库不适用
False
warning
符号可用

文件分析

序号 问题 文件

敏感权限分析

恶意软件常用权限 7/30
android.permission.ACCESS_COARSE_LOCATION
android.permission.ACCESS_FINE_LOCATION
android.permission.WAKE_LOCK
android.permission.VIBRATE
android.permission.CAMERA
android.permission.RECEIVE_SMS
android.permission.GET_TASKS
其它常用权限 13/46
android.permission.INTERNET
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.ACCESS_NETWORK_STATE
android.permission.ACCESS_WIFI_STATE
android.permission.FLASHLIGHT
android.permission.BLUETOOTH_ADMIN
android.permission.BLUETOOTH
android.permission.FOREGROUND_SERVICE
android.permission.CHANGE_NETWORK_STATE
android.permission.READ_EXTERNAL_STORAGE
android.permission.ACCESS_MOCK_LOCATION
android.permission.ACCESS_BACKGROUND_LOCATION
android.permission.CHANGE_WIFI_STATE

恶意软件常用权限 是被已知恶意软件广泛滥用的权限。
其它常用权限 是已知恶意软件经常滥用的权限。

IP地理位置

恶意域名检测

域名 状态 中国境内 位置信息 解析
p.app3c.cn 安全
没有可用的地理位置信息。
www.ccil.org 安全
IP地址: 142.251.42.211
国家: 日本
地区: 东京
城市: 东京
查看: Google 地图

d.app3c.cn 安全
没有可用的地理位置信息。
download.sdk.mob.com 安全
IP地址: 45.113.201.237
国家: 中国
地区: 江苏
城市: 扬州
查看: 高德地图

as.app3c.com 安全
没有可用的地理位置信息。
identify.verify.mob.com 安全
IP地址: 59.110.247.93
国家: 中国
地区: 北京
城市: 北京
查看: 高德地图

s.app3c.com 安全
没有可用的地理位置信息。
init.sms.mob.com 安全
IP地址: 59.110.247.93
国家: 中国
地区: 北京
城市: 北京
查看: 高德地图

mobile.unionpay.com 安全
没有可用的地理位置信息。
www.mob.com 安全
IP地址: 45.113.201.237
国家: 中国
地区: 江苏
城市: 扬州
查看: 高德地图

iuap-yonbuilder-mamservice.yyuap.com 安全
IP地址: 59.110.247.93
国家: 中国
地区: 北京
城市: 北京
查看: 高德地图

手机号提取

URL链接分析

URL信息 源码文件
http://sms.mob.com
http://www.cnblogs.com/iamlilinfeng/p/4239957.html
http://hzhls01.ys7.com:7886/hcnp/472637161_1_1_1_0_www.ys7.com_6500.m3u8?d4ed820bd1f74c12b04873a24d2c0471
http://faceservice.mangbaobao.com
https://community.apicloud.com/bbs/forum.php?mod=viewthread&tid=110959&highlight=%E5%8A%A8%E6%80%81%E6%9D%83%E9%99%90
http://zichan.mangbaobao.com
http://i.ys7.com/static/images/64f874091341499eba92ca0e029dd433/0a003d50c31ac0b1e589937720eaa93a/1_web.jpeg
http://www.auicss.com
http://appservice.mangbaobao.com
https://github.com/olado/doT
http://hammerjs.github.io/
http://hammerjs.github.io/getting-started/
http://appservice.mangbaobao.com/MobilApp/Images/
http://chufang.mangbaobao.com
http://www.apicloud.com
http://www.cnblogs.com/vajoy/p/4011723.html
http://img1.3lian.com/gif/more/11/201206/a5194ba8c27b17def4a7c5495aba5e32.jpg
自研引擎-A
https://mobile.unionpay.com/getclient?platform=android&type=securepayplugin
http://mobile.unionpay.com/getclient?platform=android&type=securepayplugin
com/unionpay/UPPayAssistEx.java
https://github.com/tootallnate/java-websocket/wiki/lost-connection-detection
com/deepe/c/l/a.java
http://download.sdk.mob.com/7d7/e2b/91d898dfde6fb787ab3d926f9d.png
http://download.sdk.mob.com/e72/83d/e247e8b45bd557f70ac6dcc0cb.png
http://download.sdk.mob.com/167/bc4/38197ca7950aec7020d516fbb2.png
http://download.sdk.mob.com/d33/6f9/c15ee2d2f01aba51d33985e6c5.png
http://download.sdk.mob.com/cc3/00e/dedc8bf1514d6c6a5e456fba74.png
http://download.sdk.mob.com/f57/a5e/72ecd0c6ca96361c7f3bcd7144.png
http://download.sdk.mob.com/a0b/7d0/0520d3554a69ad50a3b87d1760.png
http://download.sdk.mob.com/bbd/480/d993f23339944e4de27e4b0a12.png
http://download.sdk.mob.com/29f/06f/e6a941cd02e3f29465cd438d16.png
http://download.sdk.mob.com/047/a51/38cfad789e9808443d11f2f9be.png
http://download.sdk.mob.com/3a6/b11/ba6a81f2c13fb0ba3b96d99619.png
http://download.sdk.mob.com/e31/c6e/315fdfa6abc4b17d8c139605de.png
http://download.sdk.mob.com/f22/154/e27eaf3fc3e24047bd5d4ec3a8.png
http://download.sdk.mob.com/7b6/264/2c4a9fef9ffa03e5deb5973ab9.png
http://download.sdk.mob.com/510/deb/0c0731ac543eb71311c482a2e2.png
http://download.sdk.mob.com/cc6/115/2628761069dd35867eda68fe2a.png
cn/smssdk/gui/util/Const.java
http://www.ccil.org/~cowan/tagsoup/properties/schema
com/deepe/c/i/o.java
http://identify.verify.mob.com/auth/verify/mobile
cn/smssdk/net/h/e.java
192.168.123.100
com/apicloud/zhaofei/xprinterplus/Constant.java
http://init.sms.mob.com/v3/sdk/init
cn/smssdk/utils/a.java
http://www.mob.com/about/policy
cn/smssdk/utils/b.java
192.168.2.227
com/apicloud/zhaofei/xprinterplus/XPrinterPlusModule.java
https://s.app3c.com
https://as.app3c.com
https://p.app3c.cn
https://d.app3c.cn
https://iuap-yonbuilder-mamservice.yyuap.com/iuap-yonbuilder-mobile/v2
compile/Properties.java
https://github.com/tootallnate/java-websocket/wiki/lost-connection-detection
http://download.sdk.mob.com/167/bc4/38197ca7950aec7020d516fbb2.png
http://download.sdk.mob.com/29f/06f/e6a941cd02e3f29465cd438d16.png
http://www.mob.com/about/policy
https://d.app3c.cn
10.0.2.15
http://www.mob.com
https://iuap-yonbuilder-mamservice.yyuap.com/iuap-yonbuilder-mobile/v2
http://download.sdk.mob.com/e72/83d/e247e8b45bd557f70ac6dcc0cb.png
http://download.sdk.mob.com/cc6/115/2628761069dd35867eda68fe2a.png
http://download.sdk.mob.com/d33/6f9/c15ee2d2f01aba51d33985e6c5.png
192.168.2.227
http://download.sdk.mob.com/cc3/00e/dedc8bf1514d6c6a5e456fba74.png
http://download.sdk.mob.com/f57/a5e/72ecd0c6ca96361c7f3bcd7144.png
https://s.app3c.com
http://download.sdk.mob.com/3a6/b11/ba6a81f2c13fb0ba3b96d99619.png
https://mobile.unionpay.com/getclient?platform=android&type=securepayplugin
http://download.sdk.mob.com/7d7/e2b/91d898dfde6fb787ab3d926f9d.png
http://download.sdk.mob.com/a0b/7d0/0520d3554a69ad50a3b87d1760.png
http://identify.verify.mob.com/auth/verify/mobile
http://mobile.unionpay.com/getclient?platform=android&type=securepayplugin
http://download.sdk.mob.com/047/a51/38cfad789e9808443d11f2f9be.png
http://init.sms.mob.com/v3/sdk/init
https://p.app3c.cn
http://www.ccil.org/~cowan/tagsoup/properties/schema
http://download.sdk.mob.com/bbd/480/d993f23339944e4de27e4b0a12.png
https://as.app3c.com
http://download.sdk.mob.com/e31/c6e/315fdfa6abc4b17d8c139605de.png
192.168.123.100
http://download.sdk.mob.com/f22/154/e27eaf3fc3e24047bd5d4ec3a8.png
http://download.sdk.mob.com/7b6/264/2c4a9fef9ffa03e5deb5973ab9.png
http://download.sdk.mob.com/510/deb/0c0731ac543eb71311c482a2e2.png
127.0.0.1
自研引擎-S

Firebase配置检测

邮箱地址提取

第三方追踪器

名称 类别 网址
JiGuang Aurora Mobile JPush Analytics https://reports.exodus-privacy.eu.org/trackers/343

敏感凭证泄露

已显示 52 个secrets
1、 MobTech(袤博科技) 推送SDK的=> "Mob-AppKey" : "327cbd5bba87b"
2、 MobTech(袤博科技) 推送SDK的=> "Mob-AppSecret" : "0103f5423865fb98e695f04961bf5e0c"
3、 "smssdk_authorize_dialog_reject" : "Disagree"
4、 "smssdk_authorize_dialog_accept" : "Agree"
5、 ba6a81f2c13fb0ba3b96d99619
6、 f6e50617931173015060355040b130e4368696e6120556e696
7、 aHR0cHM6Ly93d3cuZ29vZ2xlLWFuYWx5dGljcy5jb20vYmF0Y2g=
8、 YW5kcm9pZC50ZWxlcGhvbnkuU21zTWFuYWdlcg==
9、 64c2f89fdffa16729c9779f99562bc189d2ce4722ba0faedb11aa22d0d9db228fda
10、 38cfad789e9808443d11f2f9be
11、 62587239-AD3C-8190-47B4-37DE080D7E9D
12、 1001a3e74c601e3beb1b7ae4f9ab2872a0aaf1dbc2cba89c7528cd
13、 2c4a9fef9ffa03e5deb5973ab9
14、 2628761069dd35867eda68fe2a
15、 54aa526e7a37d8ba2311a1d3d2ab79b3fbeaf3ebb9e7da9e7cdd9be1ae5a53595f47
16、 ZGlzdC9iYXNlL2FwaWJhc2UuanM=
17、 0c0731ac543eb71311c482a2e2
18、 c15ee2d2f01aba51d33985e6c5
19、 d993f23339944e4de27e4b0a12
20、 15060355040a130e4368696e6120556e696f6e50617931173015060355040b130e4
21、 Um6KcRJbF1vsF/zTJLvpHYey5Cam3apb9vgw5B2hRjmuQKQr
22、 861693111300f060355040713085368616e67686169311730
23、 38197ca7950aec7020d516fbb2
24、 1ef570e1013109c50df8f8c2015faed71e4cf7c53ca9195a99c574ca046aeefdf70bc5fd69f04b0eadf63398698f776cf1ef0db5134efddc3aa4825b69aee94b55356a15d2a50a325ef7bd2d9efe15f3ac5d2303e0bdf5147b3d0fb5fa4fd1d5ea07fe1b45912ff9d7fe472136ff49cb1176f039219bc737ec7ccad132a5ce57
25、 fa3acdf1b118fc26668bf72a70d60aa024a2667254c5f0bb8f082bc384b38a4e6d3d1b672467a19793c8f770c63f48b409e87f5787371789af40b95eae9867b9
26、 6e696f6e5061793111300f06035504031308556e696f6e5061
27、 d9255940da7b6cd07483f4b4243fd1825b2705
28、 0520d3554a69ad50a3b87d1760
29、 D75BB2802E61738A9A03BF014F927D9A
30、 aHR0cHM6Ly93d3cuZ29vZ2xlLWFuYWx5dGljcy5jb20vY29sbGVjdA==
31、 91d898dfde6fb787ab3d926f9d
32、 08eb9b5c67474d027fa03ce35109b11604083ab6bb4df2c46240f879f
33、 8cc1d6ed5e1b2cc00489215aec3fc2eac008e767b0215981cb5e
34、 e247e8b45bd557f70ac6dcc0cb
35、 0000000023456789abcdef12123456786789abcd
36、 11300f060355040813085368616e67686169311130
37、 b1fdf62b0f540fca5458b063af9354925a6c3505a18ff164b6b195f6e517eaee1fb783
38、 3015060355040a130e4368696e6120556e696
39、 72ecd0c6ca96361c7f3bcd7144
40、 92a864886f70d010101050003818d0030818902818100c42e6236d5054ffccaa
41、 e27eaf3fc3e24047bd5d4ec3a8
42、 0f060355040713085368616e676861693117
43、 e94ddc285669ec06b8a405dd4341eac4ea7030203010001300d06092a864886f70d010105050003818
44、 e6a941cd02e3f29465cd438d16
45、 dedc8bf1514d6c6a5e456fba74
46、 f6e5061793111300f06035504031308556e696f6e50617930819f300d060
47、 536C79B93ACFBEA950AE365D8CE1AEF91FEA9535
48、 89504e470d0a1a0a0000000d49484452000000210000003c0806000000e8acd32a000000097048597300000b1300000b1301009a9c1800000a4d6943435050686f746f73686f70204943432070726f66696c65000078da9d53775893f7163edff7650f5642d8f0b1976c81002223ac08c81059a21092006184101240c585880a561415119c4855c482d50a489d88e2a028b867418a885a8b555c38ee1fdca7b57d7aefededfbd7fbbce79ce7fcce79cf0f8011122691e6a26a003952853c3ad81f8f4f48c4c9bd80021548e0042010e6cbc26705c50000f00379787e74b03ffc01af6f00020070d52e2412c7e1ff83ba50265700209100e02212e70b01905200c82e54c81400c81800b053b3640a009400006c797c422200aa0d00ecf4493e0500d8a993dc1700d8a21ca908008d0100992847240240bb00605581522c02c0c200a0ac40222e04c0ae018059b632470280bd0500768e58900f4060008099422ccc0020380200431e13cd03204c03a030d2bfe0a95f7085b8480100c0cb95cd974bd23314b895d01a77f2f0e0e221e2c26cb142611729106609e4229c979b231348e7034cce0c00001af9d1c1fe383f90e7e6e4e1e666e76ceff4c5a2fe6bf06f223e21f1dffebc8c020400104ecfefda5fe5e5d60370c701b075bf6ba95b00da560068dff95d33db09a05a0ad07af98b7938fc401e9ea150c83c1d1c0a0b0bed2562a1bd30e38b3eff33e16fe08b7ef6fc401efedb7af000719a4099adc0a383fd71616e76ae528ee7cb0442316ef7e723fec7857ffd8e29d1e234b15c2c158af15889b850224dc779b952914421c995e212e97f32f11f96fd0993770d00ac864fc04eb607b5cb6cc07eee01028b0e58d27600407ef32d8c1a0b91001067343279f7000093bff98f402b0100cd97a4e30000bce8185ca894174cc608000044a0812ab041070cc114acc00e9cc11dbcc01702610644400c24c03c104206e4801c0aa11896411954c03ad804b5b0031aa0119ae110b4c131380de7e0125c81eb70170660189ec218bc86090441c8081361213a8811628ed822ce0817998e04226148349280a420e988145122c5c872a402a9426a915d4823f22d7214398d5c40fa90dbc820328afc8abc47319481b25103d4027540b9a81f1a8ac6a073d174340f5d8096a26bd11ab41e3d80b6a2a7d14be87574007d8a8e6380d1310e668cd9615c8c87456089581a26c71663e55835568f35631d583776151bc09e61ef0824028b8013ec085e8410c26c82909047584c5843a825ec23b412ba085709838431c2272293a84fb4257a12f9c478623ab1905846ac26ee211e219e255e270e135f9348240ec992e44e0a21259032490b496b48db482da453a43ed210699c4c26eb906dc9dee408b280ac209791b7900f904f92fbc9c3e4b7143ac588e24c09a22452a494124a35653fe504a59f324299a0aa51cda99ed408aa883a9f5a496da076502f5387a91334759a25cd9b1643cba42da3d5d09a696769f7682fe974ba09dd831e4597d097d26be807e9e7e983f4770c0d860d83c7486228196b197b19a718b7192f994ca605d39799c85430d7321b9967980f986f55582af62a7c1591ca12953a9556957e95e7aa545573553fd579aa0b54ab550fab5e567da64655b350e3a909d416abd5a91d55bba936aece5277528f50cf515fa3be5ffd82fa630db2868546a08648a35463b7c6198d2116c63265f15842d6725603eb2c6b984d625bb2f9ec4c7605fb1b762f7b4c534373aa66ac6691669de671cd010ec6b1e0f039d99c4ace21ce0dce7b2d032d3f2db1d66aad66ad7ead37da7adabeda62ed72ed16edebdaef75709d409d2c9df53a6d3af77509ba36ba51ba85badb75cfea3ed363eb79e909f5caf50ee9ddd147f56df4a3f517eaefd6efd11f373034083690196c313863f0cc9063e86b9869b8d1f084e1a811cb68ba91c468a3d149a327b826ee8767e33578173e66ac6f1c62ac34de65dc6b3c61626932dba4c4a4c5e4be29cd946b9a66bad1b4d374ccccc82cdcacd8acc9ec8e39d59c6b9e61bed9bcdbfc8d85a5459cc54a8b368bc796da967ccb05964d96f7ac98563e567956f556d7ac49d65ceb2ceb6dd6576c501b579b0c9b3a9bcbb6a8ad9badc4769b6ddf14e2148f29d229f5536eda31ecfcec0aec9aec06ed39f661f625f66df6cf1dcc1c121dd63b743b7c727475cc766c70bceba4e134c3a9c4a9c3e957671b67a1739df33517a64b90cb1297769717536da78aa76e9f7acb95e51aeebad2b5d3f5a39bbb9bdcadd96dd4ddcc3dc57dabfb4d2e9b1bc95dc33def41f4f0f758e271cce39da79ba7c2f390e72f5e765e595efbbd1e4fb39c269ed6306dc8dbc45be0bdcb7b603a3e3d65facee9033ec63e029f7a9f87bea6be22df3dbe237ed67e997e07fc9efb3bfacbfd8ff8bfe179f216f14e056001c101e501bd811a81b3036b031f049904a50735058d05bb062f0c3e15420c090d591f72936fc017f21bf96333dc672c9ad115ca089d155a1bfa30cc264c1ed6118e86cf08df107e6fa6f94ce9ccb60888e0476c88b81f69199917f97d14292a32aa2eea51b453747174f72cd6ace459fb67bd8ef18fa98cb93bdb6ab6727667ac6a6c526c63ec9bb880b8aab8817887f845f1971274132409ed89e4c4d8c43d89e37302e76c9a339ce49a54967463aee5dca2b917e6e9cecb9e773c593559907c3885981297b23fe5832042502f184fe5a76e4d1d13f2849b854f45bea28da251b1b7b84a3c92e69d5695f638dd3b7d43fa68864f4675c633094f522b79911992b923f34d5644d6deaccfd971d92d39949c949ca3520d6996b42bd730b728b74f662b2b930de479e66dca1b9387caf7e423f973f3db156c854cd1a3b452ae500e164c2fa82b785b185b78b848bd485ad433df66feeaf9230b82167cbd90b050b8b0b3d8b87859f1e022bf45bb16238b5317772e315d52ba647869f0d27dcb68cbb296fd50e2585255f26a79dcf28e5283d2a5a5432b82573495a994c9cb6eaef45ab9631561956455ef6a97d55b567f2a17955fac70aca8aef8b046b8e6e2574e5fd57cf5796ddadade4ab7caedeb48eba4eb6eacf759bfaf4abd6a41d5d086f00dad1bf18de51b5f6d4ade74a17a6af58ecdb4cdcacd03356135ed5bccb6acdbf2a136a3f67a9d7f5dcb56fdadabb7bed926dad6bfdd777bf30e831d153bdeef94ecbcb52b78576bbd457df56ed2ee82dd8f1a621bbabfe67eddb847774fc59e8f7ba57b07f645efeb6a746f6cdcafbfbfb2096d52368d1e483a70e59b806fda9bed9a77b5705a2a0ec241e5c127dfa67c7be350e8a1cec3dcc3cddf997fb7f508eb48792bd23abf75ac2da36da03da1bdefe88ca39d1d5e1d47beb7ff7eef31e36375c7358f579ea09d283df1f9e48293e3a764a79e9d4e3f3dd499dc79f74cfc996b5d515dbd6743cf9e3f1774ee4cb75ff7c9f3dee78f5df0bc70f422f762db25b74bad3dae3d477e70fde148af5b6feb65f7cbed573cae74f44deb3bd1efd37ffa6ac0d573d7f8d72e5d9f79bdefc6ec1bb76e26dd1cb825baf5f876f6ed17770aee4cdc5d7a8f78affcbedafdea07fa0fea7fb4feb165c06de0f860c060cfc3590fef0e09879efe94ffd387e1d247cc47d52346238d8f9d1f1f1b0d1abdf264ce93e1a7b2a713cfca7e56ff79eb73abe7dffde2fb4bcf58fcd8f00bf98bcfbfae79a9f372efaba9af3ac723c71fbcce793df1a6fcadcedb7defb8efbadfc7bd1f9928fc40fe50f3d1fa63c7a7d04ff73ee77cfefc2ff784f3fb25d29f33000000206348524d00007a25000080830000f9ff000080e9000075300000ea6000003a980000176f925fc546000002744944415478dabcd9c96b145110c7f1d734b6c9b8ef8a0b2e410cfe77826741100441c48324a006040f8a08828a8a102689c11d238a3b8a0b060feaf7e8e979e9816178f57a7b5587390df47c86ee7e55f52b0738c3cf3ae01af00f580226bdf7ce1af010f0439fbe25622db03802f0c02f2bc41a602100f0c094056215302f00ee0063da881ed01700f78071c069227ac0ac00b85f7eef3411bdf2874280d9618016621cb82b00faa3000dc4caf2610b01e6cb87d469220ae0b60058285f53a78928809b0260b13c299d26a2006e0880475580148802b82e009ed4017445ac28ab6108f014585ff75a6d11397055003c073636b95e1b440e5c11002f804d4dff5453440e5c16004bc09636b7b60922072e0980576d014d10393023005e035bbbbce6751019704100bc01b6753decaa1019705e00bc0576a438f263880c981200ef819da90a9f84c8807302e003b02b65f90f2132e0ac00f804ec4edd0485106704c067608f462b388a382d00be007bb51ae261c42901f015d8a739160c104705c037e080f6703440fc0900be03131623e200f137342302872d114784dbb10c4c5a211c704c80fc040e59211c705c80fc000e5a211c704280a83da852ed3869f9cac6aa68ecf0da6f85303bc6eb7456ea05ad6e7ba75adaeb36bab126e763d726a749cb9f01d31aed5ed3e127d6f8be6bdbf8b6190333e0626404d86e81483e0c758906928d855d4392d880fcb22e24455c5415156cb640740e4d524688b1f8e819b0c102d13a48d388956391e2e310442b602f805b75c355cd55432c667e50aea3d4110e18ab08dc575b20aa560f7340cf6a11175bc24c5bae24a575d4b2f57236b4989bb3460c569433c0ef1234e1bd77ff070038285c304da61b3c0000000049454e44ae426082
49、 315fdfa6abc4b17d8c139605de
50、 b1ff56cef0e21c87260c63ce3ca868bf5974c14
51、 3634385a3078310b300906035504061302383631
52、 258EAFA5-E914-47DA-95CA-C5AB0DC85B11

字符串信息

建议导出为TXT,方便查看。

第三方SDK

SDK名称 开发者 描述信息
银联 SDK 银联 银联在线支付网关是中国银联联合各商业银行为持卡人提供的集成化、综合性互联网支付工具,主要支持输入卡号付款、用户登录支付、网银支付、迷你付(IC 卡支付)等多种支付方式,为持卡人提供境内外网上购物、水电煤缴费、商旅预订等支付服务。
RenderScript Android RenderScript 是用于在 Android 上以高性能运行计算密集型任务的框架。RenderScript 主要用于数据并行计算,不过串行工作负载也可以从中受益。RenderScript 运行时可在设备上提供的多个处理器(如多核 CPU 和 GPU)间并行调度工作。这样您就能够专注于表达算法而不是调度工作。RenderScript 对于执行图像处理、计算摄影或计算机视觉的应用来说尤其有用。
极光推送 极光 JPush 是经过考验的大规模 App 推送平台,每天推送消息数超过 5 亿条。 开发者集成 SDK 后,可以通过调用 API 推送消息。同时,JPush 提供可视化的 web 端控制台发送通知,统计分析推送效果。 JPush 全面支持 Android, iOS, Winphone 三大手机平台。
File Provider Android FileProvider 是 ContentProvider 的特殊子类,它通过创建 content://Uri 代替 file:///Uri 以促进安全分享与应用程序关联的文件。

文件列表

    污点分析

    当apk较大时,代码量会很大,造成数据流图(ICFG)呈现爆炸式增长,所以该功能比较耗时,请先喝杯咖啡,耐心等待……
    规则名称 描述信息 操作
    病毒分析 使用安卓恶意软件常用的API进行污点分析 开始分析  
    漏洞挖掘 漏洞挖掘场景下的污点分析 开始分析  
    隐私合规 隐私合规场景下的污点分析:组件内污点传播、组件间污点传播、组件与库函数之间的污点传播 开始分析  
    密码分析 分析加密算法是否使用常量密钥、静态初始化的向量(IV)、加密模式是否使用ECB等 开始分析  
    Callback 因为Android中系统级的Callback并不会出现显式地进行回调方法的调用,所以如果需要分析Callback方法需要在声明文件中将其声明,这里提供一份AndroidCallbacks.txt文件,里面是一些常见的原生回调接口或类,如果有特殊接口需求,可以联系管理员 开始分析