温馨提示:APP静态检测会有结果不完整的现象,如有疑问或建议, 可加入我们的微信群讨论
文件信息
文件名 com.oneworld.onepay_c7fd5e1d.apk文件大小 16.41MB
MD5值 b60a3ccce764f3d1683a1c9fd1490525
SHA1值 e91f8277121194264b21678894031b8a7877f3ce
SHA256值 75242162482280c28f68b9af5c58ebb59d966fac8a22f4489cd23fa98d1d54f6
APK信息
APK名称 OKPAY包名 com.oneworld.onepay
主活动 com.leo.okp.MainActivity
安卓版本名称 2.0.0
域名线索
域名 | 查询域名 | ip | 地区 | 查询地区 |
---|---|---|---|---|
ulogs.umengcloud.com | 223.109.148.179 | China - Jiangsu | ||
www.google-analytics.com | 58.254.149.161 | China - Guangdong | ||
www.jivesoftware.com | 23.235.209.143 | United States of America - Virginia | ||
norma-external-collect.meizu.com | 122.13.76.176 | China - Guangdong | ||
dashif.org | 185.199.109.153 | United States of America - Pennsylvania | ||
store-drru.hispace.hicloud.com | 159.138.202.186 | Russian Federation - Sverdlovskaya oblast' | ||
plbslog.umeng.com | 36.156.202.78 | China - Jiangsu | ||
oss20231101.okfy8899.com | 172.66.43.44 | United States of America - California | ||
idmb.register.xmpush.global.xiaomi.com | 13.233.242.220 | India - Maharashtra | ||
pagead2.googlesyndication.com | 58.254.137.166 | China - Guangdong | ||
store3.hispace.hicloud.com | 23.55.129.49 | Australia - New South Wales | ||
alogsus.umeng.com | 223.109.148.179 | China - Jiangsu | ||
www.w3.org | 104.18.22.19 | United States of America - California | ||
xml.org | 104.239.240.11 | United States of America - Texas | ||
appgallery.cloud.huawei.com | 49.4.35.16 | China - Guangdong | ||
flutter.dev | 199.36.158.100 | United States of America - California | ||
developer.apple.com | 17.253.87.206 | Hong Kong - Hong Kong | ||
metrics-dra.dt.hicloud.com | 94.74.88.100 | Singapore - Singapore | ||
developer.android.com | 172.217.163.46 | United States of America - California | ||
ulogs.umeng.com | 223.109.148.130 | China - Jiangsu | ||
www.jsdelivr.com | 104.21.23.24 | United States of America - California | ||
data-drcn.push.dbankcloud.com | 49.4.40.58 | China - Guangdong | ||
store-at-dre.hispace.dbankcloud.com | 没有ip信息 | 没有地区信息 | ||
resolver.msg.global.xiaomi.net | 47.241.174.254 | Singapore - Singapore | ||
store1.hispace.hicloud.com | 49.4.47.241 | China - Guangdong | ||
metrics2.data.hicloud.com | 80.158.2.190 | Germany - Schleswig-Holstein | ||
fr.register.xmpush.global.xiaomi.com | 35.157.188.46 | Germany - Hessen | ||
grs.dbankcloud.eu | 没有ip信息 | 没有地区信息 | ||
ssl.google-analytics.com | 58.254.149.233 | China - Guangdong | ||
data-dre.push.dbankcloud.com | 80.158.49.244 | Germany - Schleswig-Holstein | ||
developer.mozilla.org | 34.111.97.67 | United States of America - Missouri | ||
cn.register.xmpush.xiaomi.com | 111.202.1.240 | China - Beijing | ||
www.ibm.com | 23.13.189.250 | Hong Kong - Hong Kong | ||
www.okpay777.com | 35.220.164.170 | Hong Kong - Hong Kong | ||
aomedia.org | 185.199.111.153 | United States of America - Pennsylvania | ||
github.com | 20.205.243.166 | Singapore - Singapore | ||
ru.register.xmpush.global.xiaomi.com | 107.155.52.56 | Russian Federation - Moskva | ||
api.flutter.dev | 199.36.158.100 | United States of America - California | ||
schemas.microsoft.com | 13.107.246.74 | United States of America - Washington | ||
api-push.in.meizu.com | 206.161.233.191 | United States of America - Virginia | ||
adash.man.aliyuncs.com | 59.82.40.77 | China - Shanghai | ||
alogus.umeng.com | 223.109.148.141 | China - Jiangsu | ||
register.xmpush.global.xiaomi.com | 47.88.199.5 | Singapore - Singapore | ||
storage.googleapis.com | 142.251.42.251 | United States of America - California | ||
pslog.umeng.com | 59.82.31.210 | China - Zhejiang | ||
resolver.msg.xiaomi.net | 123.125.102.48 | China - Beijing | ||
plus.google.com | 157.240.16.50 | India - Maharashtra | ||
store2.hispace.hicloud.com | 13.225.183.110 | Japan - Tokyo | ||
ok1112817899.oss-cn-hangzhou.aliyuncs.com | 118.178.29.145 | China - Zhejiang | ||
api-push.meizu.com | 221.5.93.66 | China - Guangdong | ||
grs.dbankcloud.cn | 121.36.116.8 | China - Beijing | ||
data-drru.push.dbankcloud.com | 159.138.202.31 | Russian Federation - Sverdlovskaya oblast' | ||
xmlpull.org | 185.199.109.153 | United States of America - Pennsylvania | ||
grs.dbankcloud.com | 113.201.107.54 | China - Shaanxi | ||
developer.umeng.com | 59.82.112.112 | China - Zhejiang | ||
okzuixin1118899.oss-cn-beijing.aliyuncs.com | 59.110.190.158 | China - Beijing | ||
exoplayer.dev | 185.199.111.153 | United States of America - Pennsylvania | ||
metrics5.data.hicloud.com | 159.138.203.215 | Russian Federation - Sverdlovskaya oblast' | ||
metrics1.data.hicloud.com | 218.12.91.83 | China - Hebei | ||
play.google.com | 59.24.3.174 | Korea (Republic of) - Gyeonggi-do | ||
data-dra.push.dbankcloud.com | 119.8.163.189 | Singapore - Singapore | ||
aaid.umeng.com | 112.85.139.75 | China - Jiangsu | ||
store.hispace.hicloud.com | 49.4.47.241 | China - Guangdong | ||
goo.gl | 142.251.42.238 | United States of America - California | ||
grs.dbankcloud.asia | 119.8.176.197 | Singapore - Singapore | ||
ns.adobe.com | 没有ip信息 | 没有地区信息 | ||
ouplog.umeng.com | 47.246.110.93 | Singapore - Singapore |
URL线索
邮箱线索
邮箱地址 | 所在文件 |
---|---|
u0013android@android.com0 |
l/e/a/b/d/c0.java |
u0013android@android.com |
l/e/a/b/d/c0.java |
_httpparser@13463476.responsepa |
lib/armeabi-v7a/libapp.so |
storationinformation@751124995.fromserial |
lib/armeabi-v7a/libapp.so |
_double@0150898.fromintege |
lib/armeabi-v7a/libapp.so |
._future@4048458.immediate |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal |
lib/armeabi-v7a/libapp.so |
_link@14069316.fromrawpat |
lib/armeabi-v7a/libapp.so |
c_growablelist@0150898.withcapaci |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal6 |
lib/armeabi-v7a/libapp.so |
_receiveportimpl@1026248.fromrawrec |
lib/armeabi-v7a/libapp.so |
-_list@0150898._ofarray |
lib/armeabi-v7a/libapp.so |
z_timer@1026248.periodic |
lib/armeabi-v7a/libapp.so |
m_growablelist@0150898._literal2 |
lib/armeabi-v7a/libapp.so |
g_bigintimpl@0150898.from |
lib/armeabi-v7a/libapp.so |
_list@0150898.empty |
lib/armeabi-v7a/libapp.so |
_directory@14069316.fromrawpat |
lib/armeabi-v7a/libapp.so |
_casterror@0150898._create |
lib/armeabi-v7a/libapp.so |
l_invocationmirror@0150898._withtype |
lib/armeabi-v7a/libapp.so |
_colorfilter@16065589.mode |
lib/armeabi-v7a/libapp.so |
_colorfilter@16065589.srgbtoline |
lib/armeabi-v7a/libapp.so |
i_rawsocket@14069316._writepipe |
lib/armeabi-v7a/libapp.so |
4_uri@0150898.file |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal1 |
lib/armeabi-v7a/libapp.so |
q_imagefilter@16065589.blur |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal4 |
lib/armeabi-v7a/libapp.so |
bb_growablelist@0150898._ofgrowabl |
lib/armeabi-v7a/libapp.so |
x_growablelist@0150898.of |
lib/armeabi-v7a/libapp.so |
8n_routedata@1188504625.ofroute |
lib/armeabi-v7a/libapp.so |
k_colorfilter@16065589.lineartosr |
lib/armeabi-v7a/libapp.so |
_nativesocket@14069316.pipe |
lib/armeabi-v7a/libapp.so |
_cookie@13463476.fromsetcoo |
lib/armeabi-v7a/libapp.so |
authenticationscheme@13463476.fromstring |
lib/armeabi-v7a/libapp.so |
_list@0150898.of |
lib/armeabi-v7a/libapp.so |
_list@0150898.generate |
lib/armeabi-v7a/libapp.so |
n_typeerror@0150898._create |
lib/armeabi-v7a/libapp.so |
lectiontoolbarbutton@348392285.text |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofgrowabl |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofefficie |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._ofarray |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal3 |
lib/armeabi-v7a/libapp.so |
u_growablelist@0150898._ofother |
lib/armeabi-v7a/libapp.so |
_timer@1026248._internal |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal5 |
lib/armeabi-v7a/libapp.so |
_rawsocket@14069316._readpipe |
lib/armeabi-v7a/libapp.so |
_socket@14069316._readpipe |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofother |
lib/armeabi-v7a/libapp.so |
eo_bytebuffer@7027147._new |
lib/armeabi-v7a/libapp.so |
lectiontoolbarbutton@470113492.text |
lib/armeabi-v7a/libapp.so |
ngstreamsubscription@4048458.zoned |
lib/armeabi-v7a/libapp.so |
_assertionerror@0150898._create |
lib/armeabi-v7a/libapp.so |
av_nativesocket@14069316.normal |
lib/armeabi-v7a/libapp.so |
j_filestream@14069316.forstdin |
lib/armeabi-v7a/libapp.so |
_uri@0150898.directory |
lib/armeabi-v7a/libapp.so |
qd_growablelist@0150898._literal8 |
lib/armeabi-v7a/libapp.so |
v_file@14069316.fromrawpat |
lib/armeabi-v7a/libapp.so |
gh_growablelist@0150898.generate |
lib/armeabi-v7a/libapp.so |
_uri@0150898.notsimple |
lib/armeabi-v7a/libapp.so |
7u_growablelist@0150898._literal7 |
lib/armeabi-v7a/libapp.so |
__growablelist@0150898._ofefficie |
lib/armeabi-v7a/libapp.so |
_future@4048458.immediatee |
lib/armeabi-v7a/libapp.so |
手机线索
手机号 | 所在文件 |
---|---|
17512775099 |
l/e/b/c/a.java |
签名证书
APK已签名
v1 签名: True
v2 签名: True
v3 签名: False
找到 1 个唯一证书
主题: C=cn, ST=sh, L=sh, O=sh, OU=abcd, CN=abc
签名算法: rsassa_pkcs1v15
有效期自: 2023-08-10 09:53:37+00:00
有效期至: 2050-12-26 09:53:37+00:00
发行人: C=cn, ST=sh, L=sh, O=sh, OU=abcd, CN=abc
序列号: 0x24eca69b
哈希算法: sha256
md5值: 58ccd18a2db451a6e30a5a558ba6f411
sha1值: a1642cd220a1b4cb897bc4fb61badfb04fe7c830
sha256值: 43517a6e9910c71168fc67b82f4a8f09371e490dcf79a8cd2cb8b1303747efc1
sha512值: 2a4410385863183f1d287c633a540d90b0fbadd5356ca6cc85a42a32626ac44ec3dcc895246b75afd20111b7a9cc31b18523caf24f9a3cc96448ce52ffca9ca6
公钥算法: rsa
密钥长度: 2048
指纹: 859401e99c78efb60c1194e001bb1ec1b4decd5d2195587c98a2fb8dbe2f37ce
硬编码敏感信息
加壳分析
第三方插件
危险动作
向手机申请的权限 | 是否危险 | 类型 | 详细情况 |
---|---|---|---|
android.permission.INTERNET | 正常 | 互联网接入 | 允许应用程序创建网络套接字 |
android.permission.ACCESS_NETWORK_STATE | 正常 | 查看网络状态 | 允许应用程序查看所有网络的状态 |
android.permission.ACCESS_WIFI_STATE | 正常 | 查看Wi-Fi状态 | 允许应用程序查看有关 Wi-Fi 状态的信息 |
android.permission.WAKE_LOCK | 正常 | 防止手机睡眠 | 允许应用程序防止手机进入睡眠状态 |
android.permission.READ_PHONE_STATE | 危险 | 读取电话状态和身份 | 允许应用访问设备的电话功能。具有此权限的应用程序可以确定此电话的电话号码和序列号,呼叫是否处于活动状态,呼叫所连接的号码等 |
android.permission.RECORD_AUDIO | 危险 | 录音 | 允许应用程序访问音频记录路径 |
android.permission.CAMERA | 危险 | 拍照和录像 | 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像 |
android.permission.MODIFY_AUDIO_SETTINGS | 正常 | 更改您的音频设置 | 允许应用程序修改全局音频设置,例如音量和路由 |
android.permission.WRITE_EXTERNAL_STORAGE | 危险 | 读取/修改/删除外部存储内容 | 允许应用程序写入外部存储 |
android.permission.ACCESS_FINE_LOCATION | 危险 | 精细定位(GPS) | 访问精细位置源,例如手机上的全球定位系统,如果可用。恶意应用程序可以使用它来确定您的位置,并可能消耗额外的电池电量 |
android.permission.ACCESS_COARSE_LOCATION | 危险 | 粗定位 | 访问粗略位置源,例如移动网络数据库,以确定大概的电话位置(如果可用)。恶意应用程序可以使用它来确定您的大致位置 |
android.permission.ACCESS_GPS | 未知 | 调用了未知的操作 | |
android.permission.ACCESS_ASSISTED_GPS | 未知 | 调用了未知的操作 | |
android.permission.ACCESS_LOCATION | 未知 | 调用了未知的操作 | |
android.permission.FLASHLIGHT | 正常 | 控制手电筒 | 允许应用程序控制手电筒 |
android.permission.RECEIVE_BOOT_COMPLETED | 正常 | 开机时自动启动 | 允许应用程序在系统完成启动后立即启动。这可能会使启动手机需要更长的时间,并允许应用程序通过始终运行来减慢整个手机的速度 |
android.permission.VIBRATE | 正常 | 可控震源 | 允许应用程序控制振动器 |
android.permission.USE_FULL_SCREEN_INTENT | 正常 | 针对想要使用通知全屏意图的 Build.VERSION_CODES.Q 的应用程序是必需的 | |
android.permission.SCHEDULE_EXACT_ALARM | 正常 | 允许应用程序使用精确的警报调度 API 来执行对时间敏感的后台工作 | |
com.oneworld.onepay.permission.MIPUSH_RECEIVE | 未知 | 调用了未知的操作 | |
android.permission.READ_EXTERNAL_STORAGE | 危险 | 读取外部存储器内容 | 允许应用程序从外部存储读取 |
com.oneworld.onepay.permission.PROCESS_PUSH_MSG | 未知 | 调用了未知的操作 | |
com.oneworld.onepay.permission.PUSH_PROVIDER | 未知 | 调用了未知的操作 | |
android.permission.FOREGROUND_SERVICE | 正常 | 允许常规应用程序使用 Service.startForeground。 | |
com.meizu.flyme.push.permission.RECEIVE | 未知 | 调用了未知的操作 | |
com.oneworld.onepay.push.permission.MESSAGE | 未知 | 调用了未知的操作 | |
com.meizu.c2dm.permission.RECEIVE | 未知 | 调用了未知的操作 | |
com.oneworld.onepay.permission.C2D_MESSAGE | 未知 | 调用了未知的操作 | |
com.meizu.flyme.permission.PUSH | 未知 | 调用了未知的操作 | |
com.coloros.mcs.permission.RECIEVE_MCS_MESSAGE | 未知 | 调用了未知的操作 | |
com.heytap.mcs.permission.RECIEVE_MCS_MESSAGE | 未知 | 调用了未知的操作 | |
com.vivo.notification.permission.BADGE_ICON | 未知 | 调用了未知的操作 | |
android.permission.CHANGE_WIFI_STATE | 正常 | 更改Wi-Fi状态 | 允许应用程序连接和断开 Wi-Fi 接入点,并对配置的 Wi-Fi 网络进行更改 |
android.permission.CALL_PHONE | 危险 | 直接拨打电话号码 | 允许应用程序在没有您干预的情况下拨打电话号码。恶意应用程序可能会导致您的电话账单出现意外呼叫。请注意,这不允许应用程序拨打紧急电话号码 |
android.permission.REQUEST_INSTALL_PACKAGES | 危险 | 允许应用程序请求安装包。 | 恶意应用程序可以利用它来尝试诱骗用户安装其他恶意软件包。 |
com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA | 未知 | 调用了未知的操作 |