温馨提示:APP静态检测会有结果不完整的现象,如有疑问或建议, 可加入我们的微信群讨论

APP图标



下载APP

文件信息

文件名 TOKENBUFF1.0.1.apk
文件大小 81.84MB
MD5值 89e31c232d3b7bf324c08f82c3916e7e
SHA1值 c140c16cc7d55596e58d983f2b3899e23139428b
SHA256值 e0cede65a5f01bf6f727460fafe1131d5f6cd0b5c0f23059b5c4f76517bf3e40

APK信息

APK名称 TOKENBUFF
包名 com.tokenbuff.wallet
主活动 com.tokenbuff.wallet.MainActivity
安卓版本名称 1.0.1
域名线索 58 条
查看
URL线索 41 条
查看
邮箱线索 15 条
查看
手机号线索 2 条
查看

域名线索

域名 查询域名 ip 地区 查询地区
grs.dbankcloud.com 60.28.193.195 China - Tianjin
cn.register.xmpush.xiaomi.com 123.125.102.39 China - Beijing
issuetracker.google.com 142.250.217.78 United States of America - California
10.38.162.35 10.38.162.35 - - -
api.etherscan.io 199.59.148.247 United States of America - California
api-push.in.meizu.com 206.161.233.191 United States of America - Virginia
crbug.com 216.239.32.29 United States of America - California
api.testnet.solana.com 103.56.16.112 Hong Kong - Hong Kong
www.webrtc.org 142.250.217.110 United States of America - California
journeyapps.com 18.155.68.86 Singapore - Singapore
infura.io 65.9.42.46 Japan - Tokyo
resolver.msg.xiaomi.net 110.43.0.169 China - Beijing
metrics5.dt.dbankcloud.ru 159.138.203.215 Russian Federation - Sverdlovskaya oblast'
developer.android.com 142.250.217.78 United States of America - California
api.flutter.dev 199.36.158.100 United States of America - California
aomediacodec.github.io 185.199.108.153 United States of America - Pennsylvania
feross.org 50.116.11.184 United States of America - California
data-drru.push.dbankcloud.com 159.138.202.31 Russian Federation - Sverdlovskaya oblast'
www.jsdelivr.com 172.67.208.113 United States of America - California
www.w3.org 104.18.22.19 United States of America - California
play.google.com 93.46.8.90 Italy - Lombardia
xml.org 104.239.240.11 United States of America - Texas
grs.dbankcloud.eu 没有ip信息 没有地区信息
www.unicode.org 64.182.27.164 United States of America - Texas
api-kovan.etherscan.io 103.214.168.106 Japan - Tokyo
dartbug.com 216.239.32.21 United States of America - California
docs.flutter.dev 199.36.158.100 United States of America - California
web3.gastracker.io 没有ip信息 没有地区信息
www.ietf.org 104.16.44.99 United States of America - California
links.ethers.org 13.35.238.59 India - Telangana
grs.platform.dbankcloud.ru 没有ip信息 没有地区信息
api-push.meizu.com 221.5.93.66 China - Guangdong
grs.dbankcloud.cn 49.4.35.251 China - Guangdong
developer.apple.com 17.253.87.198 Hong Kong - Hong Kong
g.co 127.0.0.1 - - -
api.mainnet-beta.solana.com 162.125.32.12 United States of America - California
grs.dbankcloud.asia 121.36.117.149 China - Beijing
api-goerli.etherscan.io 210.56.51.192 Hong Kong - Hong Kong
xmlpull.org 185.199.108.153 United States of America - Pennsylvania
norma-external-collect.meizu.com 183.60.176.112 China - Guangdong
metrics-dra.dt.hicloud.com 94.74.88.100 Singapore - Singapore
metrics2.data.hicloud.com 80.158.38.48 Germany - Schleswig-Holstein
api-ropsten.etherscan.io 208.31.254.33 United States of America - District of Columbia
default.url 没有ip信息 没有地区信息
api-rinkeby.etherscan.io 65.49.26.97 United States of America - Missouri
data-dra.push.dbankcloud.com 119.8.163.189 Singapore - Singapore
docs.rs 13.33.88.114 Singapore - Singapore
data-drcn.push.dbankcloud.com 49.4.40.58 China - Guangdong
github.com 20.205.243.166 Singapore - Singapore
webrtc.googlesource.com 74.125.197.82 United States of America - California
metrics5.data.hicloud.com 159.138.203.215 Russian Federation - Sverdlovskaya oblast'
schemas.microsoft.com 13.107.246.73 United States of America - Washington
metrics1.data.hicloud.com 111.202.16.252 China - Beijing
data-dre.push.dbankcloud.com 80.158.49.244 Germany - Schleswig-Holstein
api.devnet.solana.com 108.160.165.212 United States of America - California
goo.gle 67.199.248.12 United States of America - New York
dashif.org 185.199.108.153 United States of America - Pennsylvania
ns.adobe.com 没有ip信息 没有地区信息

URL线索

URL信息 Url所在文件
https://)([\\s\\S]+)
com/huawei/hms/scankit/p/C0233bd.java
http://xml.org/sax/features/namespaces
com/huawei/secure/android/common/xml/DocumentBuilderFactorySecurity.java
http://xml.org/sax/features/validation
com/huawei/secure/android/common/xml/DocumentBuilderFactorySecurity.java
http://xml.org/sax/features/namespaces
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xml.org/sax/features/namespace-prefixes
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xml.org/sax/features/validation
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xml.org/sax/features/external-general-entities
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xml.org/sax/features/external-parameter-entities
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xml.org/sax/features/string-interning
com/huawei/secure/android/common/xml/SAXParserFactorySecurity.java
http://xmlpull.org/v1/doc/features.html
com/huawei/secure/android/common/xml/XmlPullParserFactorySecurity.java
https://api-push.meizu.com/garcia/api/server/getPublicKey
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://api-push.meizu.com/garcia/api/server/getPushConf
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://api-push.in.meizu.com
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://api-push.meizu.com
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://norma-external-collect.meizu.com/android/exchange/getpublickey.do
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://norma-external-collect.meizu.com/push/android/external/add.do
com/meizu/cloud/pushsdk/constants/PushConstants.java
https://api-push.meizu.com/garcia/api/client/
com/meizu/cloud/pushsdk/platform/c/a.java
https://api-push.in.meizu.com/garcia/api/client/
com/meizu/cloud/pushsdk/platform/c/a.java
https://api-push.meizu.com/garcia/api/client/log/upload
com/meizu/cloud/pushsdk/platform/c/a.java
http://xmlpull.org/v1/doc/features.html
com/xiaomi/push/fh.java
http://xmlpull.org/v1/doc/features.html
com/xiaomi/push/fw.java
https://%1$s/gslb/?ver=5.0
com/xiaomi/push/ch.java
http://xmlpull.org/v1/doc/features.html
com/xiaomi/push/fx.java
http://xmlpull.org/v1/doc/features.html
com/xiaomi/push/ex.java
http://10.38.162.35:9085
com/xiaomi/push/service/q.java
https://cn.register.xmpush.xiaomi.com
com/xiaomi/push/service/q.java
https://resolver.msg.xiaomi.net/psc/?t=a
com/xiaomi/push/service/ax.java
http://ns.adobe.com/xap/1.0/\u0000
defpackage/op0.java
https://developer.apple.com/streaming/emsg-id3
defpackage/to0.java
https://developer.android.com/guide/topics/media/issues/cleartext-not-permitted
defpackage/b71.java
https://play.google.com/store/apps/details?id=
defpackage/oe1.java
https://github.com/Baseflow/flutter-permission-handler/issues
defpackage/c62.java
http://g.co/dev/packagevisibility.
defpackage/sk2.java
http://ns.adobe.com/xap/1.0/
defpackage/ld1.java
https://goo.gle/compose-feedback
defpackage/gw.java
https://x</LA_URL>
defpackage/x21.java
https://default.url
defpackage/x21.java
http://schemas.microsoft.com/DRM/2007/03/protocols/AcquireLicense
defpackage/i71.java
https://issuetracker.google.com/issues/new?component=907884&template=1466542
defpackage/u03.java
http://dashif.org/guidelines/last-segment-number
defpackage/c20.java
http://dashif.org/guidelines/trickmode
defpackage/c20.java
http://dashif.org/thumbnail_tile
defpackage/c20.java
http://dashif.org/guidelines/thumbnail_tile
defpackage/c20.java
https://developer.android.com/guide/topics/media/issues/player-accessed-on-wrong-thread
defpackage/as0.java
https://developer.android.com/guide/topics/permissions/overview
io/flutter/plugin/platform/PlatformPlugin.java
https://docs.flutter.dev/deployment/android
io/flutter/embedding/engine/loader/FlutterLoader.java
https://journeyapps.com/
摸瓜V1引擎
https://github.com/journeyapps/zxing-android-embedded
摸瓜V1引擎
https://data-drcn.push.dbankcloud.com
摸瓜V2引擎
https://data-dra.push.dbankcloud.com
摸瓜V2引擎
https://data-dre.push.dbankcloud.com
摸瓜V2引擎
https://data-drru.push.dbankcloud.com
摸瓜V2引擎
https://metrics1.data.hicloud.com:6447
摸瓜V2引擎
https://metrics-dra.dt.hicloud.com:6447
摸瓜V2引擎
https://metrics2.data.hicloud.com:6447
摸瓜V2引擎
https://metrics5.data.hicloud.com:6447
摸瓜V2引擎
https://metrics5.dt.dbankcloud.ru:6447
摸瓜V2引擎
https://grs.dbankcloud.com
摸瓜V2引擎
https://grs.dbankcloud.cn
摸瓜V2引擎
https://grs.dbankcloud.asia
摸瓜V2引擎
https://grs.platform.dbankcloud.ru
摸瓜V2引擎
https://grs.dbankcloud.eu
摸瓜V2引擎
https://api.etherscan.io
摸瓜V2引擎
https://api-ropsten.etherscan.io
摸瓜V2引擎
https://api-rinkeby.etherscan.io
摸瓜V2引擎
https://api-kovan.etherscan.io
摸瓜V2引擎
https://api-goerli.etherscan.io
摸瓜V2引擎
https://infura.io)
摸瓜V2引擎
http://localhost:8545
摸瓜V2引擎
https://web3.gastracker.io
摸瓜V2引擎
https://web3.gastracker.io/morden
摸瓜V2引擎
http://feross.org>
摸瓜V2引擎
https://feross.org>
摸瓜V2引擎
https://github.com/indutny/elliptic/issues
摸瓜V2引擎
https://github.com/indutny/elliptic
摸瓜V2引擎
https://links.ethers.org/v5-errors-
摸瓜V2引擎
http://api.devnet.solana.com
摸瓜V2引擎
http://api.testnet.solana.com
摸瓜V2引擎
http://api.mainnet-beta.solana.com/
摸瓜V2引擎
https://api.devnet.solana.com
摸瓜V2引擎
https://api.testnet.solana.com
摸瓜V2引擎
https://api.mainnet-beta.solana.com/
摸瓜V2引擎
https://github.com/indutny/elliptic/issues
摸瓜V2引擎
https://github.com/indutny/elliptic
摸瓜V2引擎
https://github.com/uuidjs/uuid
摸瓜V2引擎
https://github.com/nodeca/pica
摸瓜V2引擎
https://www.jsdelivr.com/using-sri-with-dynamic-files
摸瓜V2引擎
https://github.com/apvarun/toastify-js
摸瓜V2引擎
http://agoratest
lib/arm64-v8a/libagora-rtc-sdk.so
http://s?
lib/arm64-v8a/libagora-rtc-sdk.so
http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time
lib/arm64-v8a/libagora-rtc-sdk.so
http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor
lib/arm64-v8a/libagora-rtc-sdk.so
https://api.flutter.dev/flutter/material/Scaffold/of.html
lib/arm64-v8a/libapp.so
http://www.unicode.org/copyright.html
lib/arm64-v8a/libflutter.so
https://docs.flutter.dev/release/breaking-changes/android-surface-plugins
lib/arm64-v8a/libflutter.so
https://github.com/flutter/flutter/issues.
lib/arm64-v8a/libflutter.so
https://dartbug.com/52121.
lib/arm64-v8a/libflutter.so
https://crbug.com/1053756
lib/arm64-v8a/libjingle_peerconnection_so.so
https://webrtc.googlesource.com/src/+/refs/heads/main/docs/native-code/rtp-hdrext/playout-delay/,
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00
lib/arm64-v8a/libjingle_peerconnection_so.so
https://aomediacodec.github.io/av1-rtp-spec/
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/video-content-type
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/video-timing
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/playout-delay
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/color-space
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id
lib/arm64-v8a/libjingle_peerconnection_so.so
http://www.webrtc.org/experiments/rtp-hdrext/inband-cn
lib/arm64-v8a/libjingle_peerconnection_so.so
https://docs.rs/getrandom
lib/arm64-v8a/librust_bdk_ffi.so
http://scheme
lib/arm64-v8a/librust_bdk_ffi.so

邮箱线索

邮箱地址 所在文件
feross@feross.org
摸瓜V2引擎
git@github.com
摸瓜V2引擎
fedor@indutny.com
摸瓜V2引擎
git@github.com
摸瓜V2引擎
fedor@indutny.com
摸瓜V2引擎
superstruct@0.11
摸瓜V2引擎
appro@openssl.org
lib/arm64-v8a/libagora-ffmpeg.so
appro@openssl.org
lib/arm64-v8a/libagora-rtc-sdk.so
appro@openssl.org
lib/arm64-v8a/libagora_face_capture_extension.so
appro@openssl.org
lib/arm64-v8a/libagora_lip_sync_extension.so
appro@openssl.org
lib/arm64-v8a/libagora_video_av1_decoder_extension.so
appro@openssl.org
lib/arm64-v8a/libagora_video_av1_encoder_extension.so
appro@openssl.org
lib/arm64-v8a/libagora_video_decoder_extension.so
appro@openssl.org
lib/arm64-v8a/libagora_video_encoder_extension.so
appro@openssl.org
lib/arm64-v8a/libflutter.so
appro@openssl.org
lib/arm64-v8a/libjingle_peerconnection_so.so
appro@openssl.org
lib/arm64-v8a/librust_bdk_ffi.so
nf@xpfr6ktsre6gbytuwtg.tgmq6k3flf
lib/arm64-v8a/libvideo_dec.so
dshu7immlpkc@mbst14hc.dwicgkl
lib/arm64-v8a/libvideo_dec.so
nf@xpfr6ktsre6gbytuwtg.tgmq6k3flf
lib/arm64-v8a/libvideo_enc.so
dshu7immlpkc@mbst14hc.dwicgkl
lib/arm64-v8a/libvideo_enc.so

手机线索

手机号 所在文件
19919152923
摸瓜V2引擎
19919152923
摸瓜V2引擎

代码反编译

AndroidManifest配置 查看
Java源代码 查看 -- 下载

签名证书

APK已签名
v1 签名: False
v2 签名: True
v3 签名: False
找到 1 个唯一证书
主题: C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown
签名算法: rsassa_pkcs1v15
有效期自: 2024-12-19 16:22:28+00:00
有效期至: 2124-11-25 16:22:28+00:00
发行人: C=Unknown, ST=Unknown, L=Unknown, O=Unknown, OU=Unknown, CN=Unknown
序列号: 0x1c1f1e8e
哈希算法: sha256
md5值: 4f399aa03366630029494df4ff9f3bd5
sha1值: e7b91643b6cecb8fa58e0fa8e6a90e0c511817c1
sha256值: f80e368e946c8d24c8f5ff194264d5d3f96fe89ea1105d2d4f30f72570213fc5
sha512值: bfdbc392a4aab081c0149a876d137611612cd2ad31000a12b405758b7719568783ab957bf05a1642034275792775997a7e6b6b10a3323621bf56cf6fd0c3c7fe
公钥算法: rsa
密钥长度: 2048
指纹: 9f2e58413555b3d756aea8714bc711ce5c583aa3005a95a097b33823d190237c

硬编码敏感信息

"ENGAGELAB_PRIVATES_CHANNEL_high" : "HIGH"
"ENGAGELAB_PRIVATES_CHANNEL_low" : "LOW"
"ENGAGELAB_PRIVATES_CHANNEL_normal" : "NORMAL"
"ENGAGELAB_PRIVATES_CHANNEL_silence" : "SILENCE"
"library_zxingandroidembedded_author" : "JourneyApps"
"library_zxingandroidembedded_authorWebsite" : "https://journeyapps.com/"
"ENGAGELAB_PRIVATES_CHANNEL_high" : "重要"
"ENGAGELAB_PRIVATES_CHANNEL_low" : "不重要"
"ENGAGELAB_PRIVATES_CHANNEL_normal" : "普通"
"ENGAGELAB_PRIVATES_CHANNEL_silence" : "静默"

加壳分析

第三方插件

危险动作

向手机申请的权限 是否危险 类型 详细情况
android.permission.ACCESS_FINE_LOCATION 危险 精细定位(GPS) 访问精细位置源,例如手机上的全球定位系统,如果可用。恶意应用程序可以使用它来确定您的位置,并可能消耗额外的电池电量
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储
android.permission.CAMERA 危险 拍照和录像 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像
android.permission.INTERNET 正常 互联网接入 允许应用程序创建网络套接字
android.permission.USE_BIOMETRIC 正常 允许应用使用设备支持的生物识别模式。
android.permission.RECORD_AUDIO 危险 录音 允许应用程序访问音频记录路径
android.permission.ACCESS_NETWORK_STATE 正常 查看网络状态 允许应用程序查看所有网络的状态
android.permission.CHANGE_NETWORK_STATE 正常 更改网络连接 允许应用程序更改网络连接状态。
android.permission.MODIFY_AUDIO_SETTINGS 正常 更改您的音频设置 允许应用程序修改全局音频设置,例如音量和路由
android.permission.WAKE_LOCK 正常 防止手机睡眠 允许应用程序防止手机进入睡眠状态
android.permission.RECEIVE_BOOT_COMPLETED 正常 开机时自动启动 允许应用程序在系统完成启动后立即启动。这可能会使启动手机需要更长的时间,并允许应用程序通过始终运行来减慢整个手机的速度
android.permission.READ_MEDIA_IMAGES 未知 调用了未知的操作
android.permission.READ_MEDIA_VIDEO 未知 调用了未知的操作
android.permission.BLUETOOTH 正常 创建蓝牙连接 允许应用程序连接到配对的蓝牙设备
android.permission.BLUETOOTH_ADMIN 正常 蓝牙管理 允许应用程序发现和配对蓝牙设备。
android.permission.FOREGROUND_SERVICE 正常 允许常规应用程序使用 Service.startForeground。
android.permission.SCHEDULE_EXACT_ALARM 正常 允许应用程序使用精确的警报调度 API 来执行对时间敏感的后台工作
com.google.android.c2dm.permission.RECEIVE 合法 C2DM 权限 云到设备消息传递的权限
android.permission.READ_EXTERNAL_STORAGE 危险 读取外部存储器内容 允许应用程序从外部存储读取
com.huawei.android.launcher.permission.CHANGE_BADGE 正常 在应用程序上显示通知计数 在华为手机的应用程序启动图标上显示通知计数或徽章。
com.tokenbuff.wallet.permission.PROCESS_PUSH_MSG 未知 调用了未知的操作
com.tokenbuff.wallet.permission.PUSH_PROVIDER 未知 调用了未知的操作
com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA 未知 调用了未知的操作
android.permission.ACCESS_WIFI_STATE 正常 查看Wi-Fi状态 允许应用程序查看有关 Wi-Fi 状态的信息
android.permission.VIBRATE 正常 可控震源 允许应用程序控制振动器
com.meizu.flyme.permission.PUSH 未知 调用了未知的操作
android.permission.READ_PHONE_STATE 危险 读取电话状态和身份 允许应用访问设备的电话功能。具有此权限的应用程序可以确定此电话的电话号码和序列号,呼叫是否处于活动状态,呼叫所连接的号码等
com.meizu.flyme.push.permission.RECEIVE 未知 调用了未知的操作
com.tokenbuff.wallet.push.permission.MESSAGE 未知 调用了未知的操作
com.coloros.mcs.permission.RECIEVE_MCS_MESSAGE 未知 调用了未知的操作
com.heytap.mcs.permission.RECIEVE_MCS_MESSAGE 未知 调用了未知的操作
com.push.permission.UPSTAGESERVICE 未知 调用了未知的操作
com.hihonor.android.launcher.permission.CHANGE_BADGE 未知 调用了未知的操作
android.permission.BLUETOOTH_CONNECT 未知 调用了未知的操作
android.permission.POST_NOTIFICATIONS 未知 调用了未知的操作
android.permission.READ_MEDIA_AUDIO 未知 调用了未知的操作
android.permission.USE_FINGERPRINT 正常 allow use of指纹 该常量在 API 级别 28 中已被弃用。应用程序应改为请求 USE_BIOMETRIC
com.tokenbuff.wallet.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION 未知 调用了未知的操作
com.hihonor.push.permission.READ_PUSH_NOTIFICATION_INFO 未知 调用了未知的操作
com.tokenbuff.wallet.permission.MIPUSH_RECEIVE 未知 调用了未知的操作
com.meizu.c2dm.permission.RECEIVE 未知 调用了未知的操作
com.tokenbuff.wallet.permission.C2D_MESSAGE 未知 调用了未知的操作