温馨提示:APP静态检测会有结果不完整的现象,如有疑问或建议, 可加入我们的微信群讨论
文件信息
文件名 base.apk文件大小 144.17MB
MD5值 f7dd58113ded10761330aa3ab465b168
SHA1值 dc5c72fb8119e68641915125207ef7fcce496b4f
SHA256值 26e9fb783f91b686fef9501e2faf8d68d3c8341d6b803a2317ebd83ef07c0793
APK信息
APK名称 久赢恒丰包名 com.txcf.cronuss
主活动 com.txcf.cronuss.MainActivity
安卓版本名称 1.3.6
域名线索
域名 | 查询域名 | ip | 地区 | 查询地区 |
---|---|---|---|---|
loggw-exsdk.alipay.com | 110.76.6.68 | China - Zhejiang | ||
www.example.com | 125.56.201.98 | Japan - Tokyo | ||
long.open.weixin.qq.com | 112.65.193.150 | China - Shanghai | ||
dns.alidns.com | 223.6.6.6 | China - Zhejiang | ||
xmlpull.org | 185.199.110.153 | United States of America - Pennsylvania | ||
xml.org | 104.239.240.11 | United States of America - Texas | ||
data-dre.push.dbankcloud.com | 80.158.49.244 | Germany - Schleswig-Holstein | ||
umc.danuoyi.alicdn.com | 101.37.12.98 | China - Zhejiang | ||
gw.rtn.aliyuncs.com | 60.205.93.126 | China - Beijing | ||
grs.dbankcloud.asia | 49.4.35.251 | China - Guangdong | ||
mobilegw.alipaydev.com | 110.75.132.131 | China - Zhejiang | ||
vpp-license-proxy.aliyuncs.com | 106.15.100.116 | China - Zhejiang | ||
mcgw.alipay.com | 123.125.216.191 | China - Beijing | ||
cn.register.xmpush.xiaomi.com | 123.125.102.39 | China - Beijing | ||
work.weixin.qq.com | 106.55.127.35 | China - Beijing | ||
www.alibaba.com | 203.119.238.116 | China - Zhejiang | ||
beian.miit.gov.cn | 119.39.205.85 | China - Hunan | ||
alivc-player.oss-cn-shanghai.aliyuncs.com | 140.206.110.65 | China - Shanghai | ||
cloud-config-service-pre.rtc.aliyuncs.com | 47.93.95.208 | China - Zhejiang | ||
wappaygw.alipay.com | 123.125.216.192 | China - Beijing | ||
metrics5.dt.dbankcloud.ru | 159.138.203.215 | Russian Federation - Sverdlovskaya oblast' | ||
render.alipay.com | 221.207.101.98 | China - Heilongjiang | ||
slsrole.alicdn.com | 218.11.15.235 | China - Hebei | ||
cloud-config-service.rtc.aliyuncs.com | 47.93.95.208 | China - Zhejiang | ||
metrics1-drcn.dt.dbankcloud.cn | 111.202.16.252 | China - Beijing | ||
www.w3.org | 104.18.22.19 | United States of America - California | ||
log-global-cn-shenzhen.aliyuncs.com | 没有ip信息 | 没有地区信息 | ||
10.38.162.35 | 10.38.162.35 | - - - | ||
schemas.android.com | 没有ip信息 | 没有地区信息 | ||
app.txcfgl.com | 47.99.190.68 | China - Zhejiang | ||
flutter.dev | 199.36.158.100 | United States of America - California | ||
grs.platform.dbankcloud.ru | 没有ip信息 | 没有地区信息 | ||
mobilegwpre.alipay.com | 110.75.138.35 | China - Zhejiang | ||
open.weixin.qq.com | 116.128.169.212 | China - Shanghai | ||
www.ietf.org | 104.16.44.99 | United States of America - California | ||
miniapp.guniuniu.com | 47.99.190.68 | China - Zhejiang | ||
purl.org | 207.241.225.157 | United States of America - California | ||
grs.dbankcloud.cn | 121.36.117.149 | China - Beijing | ||
mclient.alipay.com | 1.28.232.212 | China - Nei Mongol | ||
www.unicode.org | 64.182.27.164 | United States of America - Texas | ||
data-dra.push.dbankcloud.com | 119.8.163.189 | Singapore - Singapore | ||
vod-license-proxy-pre.aliyun-inc.com | 100.64.26.218 | - - - | ||
ns.adobe.com | 没有ip信息 | 没有地区信息 | ||
pgw.rtn.aliyuncs.com | 47.93.47.144 | China - Zhejiang | ||
resolver.msg.xiaomi.net | 39.102.218.17 | China - Zhejiang | ||
help.aliyun.com | 203.119.144.7 | China - Beijing | ||
live.aliyuncs.com | 59.82.44.229 | China - Shanghai | ||
vod-license.cn-shanghai.aliyuncs.com | 8.139.73.64 | China - Zhejiang | ||
metrics2.data.hicloud.com | 80.158.2.190 | Germany - Schleswig-Holstein | ||
data-drcn.push.dbankcloud.com | 118.194.33.160 | China - Shanghai | ||
dartbug.com | 216.239.32.21 | United States of America - California | ||
metrics-dra.dt.hicloud.com | 94.74.88.100 | Singapore - Singapore | ||
www.webrtc.org | 142.251.33.110 | Canada - Ontario | ||
github.com | 20.205.243.166 | Singapore - Singapore | ||
developer.mozilla.org | 34.111.97.67 | United States of America - Missouri | ||
www.alibabacloud.com | 47.241.205.194 | Singapore - Singapore | ||
dashif.org | 185.199.109.153 | United States of America - Pennsylvania | ||
mobilegw.dl.alipaydev.com | 110.75.132.25 | China - Zhejiang | ||
metrics5.data.hicloud.com | 159.138.203.215 | Russian Federation - Sverdlovskaya oblast' | ||
grs.dbankcloud.com | 60.28.193.195 | China - Tianjin | ||
www.ibm.com | 23.59.2.229 | Japan - Osaka | ||
mobilegw.alipay.com | 203.209.243.98 | China - Zhejiang | ||
mp.weixin.qq.com | 220.196.132.78 | China - Jiangsu | ||
h5.m.taobao.com | 125.38.11.130 | China - Tianjin | ||
cn-hangzhou.log.aliyuncs.com | 47.114.236.51 | China - Zhejiang | ||
grs.dbankcloud.eu | 没有ip信息 | 没有地区信息 | ||
videocloud.cn-hangzhou.log.aliyuncs.com | 47.96.32.228 | China - Zhejiang | ||
api.flutter.dev | 199.36.158.100 | United States of America - California | ||
docs.flutter.dev | 199.36.158.100 | United States of America - California | ||
data-drru.push.dbankcloud.com | 159.138.202.31 | Russian Federation - Sverdlovskaya oblast' | ||
developer.android.com | 142.251.33.110 | Canada - Ontario | ||
vpp-license-proxy.taobao.net | 没有ip信息 | 没有地区信息 |
URL线索
邮箱线索
邮箱地址 | 所在文件 |
---|---|
ftp@example.com |
lib/arm64-v8a/liball_in_one.so |
appro@openssl.org |
lib/arm64-v8a/libflutter.so |
ftp@example.com |
lib/armeabi-v7a/liball_in_one.so |
_httpparser@13463476.responsepa |
lib/armeabi-v7a/libapp.so |
storationinformation@153124995.fromserial |
lib/armeabi-v7a/libapp.so |
_internetaddress@14069316.fixed |
lib/armeabi-v7a/libapp.so |
_future@4048458.immediate |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal |
lib/armeabi-v7a/libapp.so |
_link@14069316.fromrawpat |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898.withcapaci |
lib/armeabi-v7a/libapp.so |
_receiveportimpl@1026248.fromrawrec |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal2 |
lib/armeabi-v7a/libapp.so |
_bigintimpl@0150898.from |
lib/armeabi-v7a/libapp.so |
_list@0150898.empty |
lib/armeabi-v7a/libapp.so |
_directory@14069316.fromrawpat |
lib/armeabi-v7a/libapp.so |
_colorfilter@15065589.lineartosr |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal4 |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898.of |
lib/armeabi-v7a/libapp.so |
_list@0150898.of |
lib/armeabi-v7a/libapp.so |
_list@0150898.generate |
lib/armeabi-v7a/libapp.so |
_typeerror@0150898._create |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofgrowabl |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofefficie |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._ofarray |
lib/armeabi-v7a/libapp.so |
_future@4048458.value |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofother |
lib/armeabi-v7a/libapp.so |
_bytebuffer@7027147._new |
lib/armeabi-v7a/libapp.so |
_nativesocket@14069316.normal |
lib/armeabi-v7a/libapp.so |
_colorfilter@15065589.srgbtoline |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal8 |
lib/armeabi-v7a/libapp.so |
_future@4048458.zonevalue |
lib/armeabi-v7a/libapp.so |
_nativesocket@14069316.listen |
lib/armeabi-v7a/libapp.so |
_pointerpanzoomdata@296213599.fromupdate |
lib/armeabi-v7a/libapp.so |
_double@0150898.fromintege |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal6 |
lib/armeabi-v7a/libapp.so |
_colorfilter@15065589.mode |
lib/armeabi-v7a/libapp.so |
_imagefilter@15065589.composed |
lib/armeabi-v7a/libapp.so |
_list@0150898._ofarray |
lib/armeabi-v7a/libapp.so |
_timer@1026248.periodic |
lib/armeabi-v7a/libapp.so |
_compressednode@54137193.single |
lib/armeabi-v7a/libapp.so |
_invocationmirror@0150898._withtype |
lib/armeabi-v7a/libapp.so |
_assetmanifestbin@62287047.fromstanda |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal1 |
lib/armeabi-v7a/libapp.so |
_uri@0150898.file |
lib/armeabi-v7a/libapp.so |
_imagefilter@15065589.blur |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._ofgrowabl |
lib/armeabi-v7a/libapp.so |
authenticationscheme@13463476.fromstring |
lib/armeabi-v7a/libapp.so |
_hashcollisionnode@54137193.fromcollis |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal3 |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._ofother |
lib/armeabi-v7a/libapp.so |
_timer@1026248._internal |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal5 |
lib/armeabi-v7a/libapp.so |
ngstreamsubscription@4048458.zoned |
lib/armeabi-v7a/libapp.so |
_assertionerror@0150898._create |
lib/armeabi-v7a/libapp.so |
_imagefilter@15065589.fromcolorf |
lib/armeabi-v7a/libapp.so |
_uri@0150898.directory |
lib/armeabi-v7a/libapp.so |
_httpparser@13463476.requestpar |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898.generate |
lib/armeabi-v7a/libapp.so |
_uri@0150898.notsimple |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._literal7 |
lib/armeabi-v7a/libapp.so |
_growablelist@0150898._ofefficie |
lib/armeabi-v7a/libapp.so |
_future@4048458.immediatee |
lib/armeabi-v7a/libapp.so |
appro@openssl.org |
lib/x86_64/libflutter.so |
手机线索
手机号 | 所在文件 |
---|---|
15724800000 |
cn/jiguang/am/a.java |
17512775099 |
ib/b.java |
18222222222 |
y8/e.java |
15838186836 |
摸瓜V1引擎 |
17874219618 |
摸瓜V1引擎 |
14702406825 |
摸瓜V2引擎 |
16725171731 |
摸瓜V2引擎 |
15864168224 |
摸瓜V2引擎 |
13794778293 |
摸瓜V2引擎 |
签名证书
APK已签名
v1 签名: True
v2 签名: True
v3 签名: False
找到 1 个唯一证书
主题: C=CN, ST=, L=, O=Android, OU=Android, CN=JnK7eshBRqfxocAdvh0r%2FUIQuXQbOFtK0%2B0obBkFaXAO%2BxWFs61H4mWsHx41FvvwU0zJbtUGkAlOxvhuCfrwXQ%3D%3D
签名算法: rsassa_pkcs1v15
有效期自: 2023-10-21 14:36:06+00:00
有效期至: 2123-09-27 14:36:06+00:00
发行人: C=CN, ST=, L=, O=Android, OU=Android, CN=JnK7eshBRqfxocAdvh0r%2FUIQuXQbOFtK0%2B0obBkFaXAO%2BxWFs61H4mWsHx41FvvwU0zJbtUGkAlOxvhuCfrwXQ%3D%3D
序列号: 0x17bd592
哈希算法: sha256
md5值: 088e6b2e1aa0c911f719cf74c1a189c1
sha1值: 8f46d051d1e345a89f860bd07669a39e83bfbccb
sha256值: f521e0d5ad2f4790588d6c4f48e6318220ebab00fcb35481c7a6973f967fbfba
sha512值: ba6e0bae69225988aa13fa89f0f5ac8468d5de696b6d70161c31b697e15e8362545dda7a183d710e5647cd9c794f17c4e79a65ad7c619e271a7f28de03c0241b
公钥算法: rsa
密钥长度: 2048
指纹: 762856b2ee78718579c035ca66efa400e44e20d41327b83629954c4c4fd75abf
硬编码敏感信息
加壳分析
第三方插件
危险动作
向手机申请的权限 | 是否危险 | 类型 | 详细情况 |
---|---|---|---|
android.permission.INTERNET | 正常 | 互联网接入 | 允许应用程序创建网络套接字 |
android.permission.ACCESS_NETWORK_STATE | 正常 | 查看网络状态 | 允许应用程序查看所有网络的状态 |
android.permission.ACCESS_WIFI_STATE | 正常 | 查看Wi-Fi状态 | 允许应用程序查看有关 Wi-Fi 状态的信息 |
android.permission.WRITE_EXTERNAL_STORAGE | 危险 | 读取/修改/删除外部存储内容 | 允许应用程序写入外部存储 |
android.permission.READ_EXTERNAL_STORAGE | 危险 | 读取外部存储器内容 | 允许应用程序从外部存储读取 |
android.permission.ACCESS_MEDIA_LOCATION | 危险 | 访问的任何地理位置 | 允许应用程序访问的任何地理位置持久保存在用户的共享集合 |
android.permission.RECORD_AUDIO | 危险 | 录音 | 允许应用程序访问音频记录路径 |
android.permission.SYSTEM_ALERT_WINDOW | 危险 | 显示系统级警报 | 允许应用程序显示系统警报窗口。恶意应用程序可以接管手机的整个屏幕 |
com.huawei.android.launcher.permission.CHANGE_BADGE | 未知 | 调用了未知的操作 | |
com.hihonor.android.launcher.permission.CHANGE_BADGE | 未知 | 调用了未知的操作 | |
android.permission.MODIFY_AUDIO_SETTINGS | 正常 | 更改您的音频设置 | 允许应用程序修改全局音频设置,例如音量和路由 |
android.permission.BLUETOOTH | 正常 | 创建蓝牙连接 | 允许应用程序连接到配对的蓝牙设备 |
android.permission.CAMERA | 危险 | 拍照和录像 | 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像 |
android.permission.READ_MEDIA_IMAGES | 未知 | 调用了未知的操作 | |
android.permission.READ_MEDIA_VIDEO | 未知 | 调用了未知的操作 | |
android.permission.WAKE_LOCK | 正常 | 防止手机睡眠 | 允许应用程序防止手机进入睡眠状态 |
android.permission.GET_TASKS | 危险 | 检索正在运行的应用程序 | 允许应用程序检索有关当前和最近运行的任务的信息。可能允许恶意应用程序发现有关其他应用程序的私人信息 |
android.permission.VIBRATE | 正常 | 可控震源 | 允许应用程序控制振动器 |
com.hihonor.push.permission.READ_PUSH_NOTIFICATION_INFO | 未知 | 调用了未知的操作 | |
com.huawei.android.launcher.permission.CHANGE_BADGE | 正常 | 在应用程序上显示通知计数 | 在华为手机的应用程序启动图标上显示通知计数或徽章。 |
com.txcf.cronuss.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | 未知 | 调用了未知的操作 | |
com.txcf.cronuss.permission.PROCESS_PUSH_MSG | 未知 | 调用了未知的操作 | |
com.txcf.cronuss.permission.PUSH_PROVIDER | 未知 | 调用了未知的操作 | |
com.txcf.cronuss.permission.MIPUSH_RECEIVE | 未知 | 调用了未知的操作 | |
com.coloros.mcs.permission.RECIEVE_MCS_MESSAGE | 未知 | 调用了未知的操作 | |
com.heytap.mcs.permission.RECIEVE_MCS_MESSAGE | 未知 | 调用了未知的操作 | |
com.android.vending.BILLING | 未知 | 调用了未知的操作 | |
android.permission.BLUETOOTH_ADMIN | 正常 | 蓝牙管理 | 允许应用程序发现和配对蓝牙设备。 |
android.permission.BLUETOOTH_CONNECT | 未知 | 调用了未知的操作 | |
android.permission.READ_PHONE_STATE | 危险 | 读取电话状态和身份 | 允许应用访问设备的电话功能。具有此权限的应用程序可以确定此电话的电话号码和序列号,呼叫是否处于活动状态,呼叫所连接的号码等 |
com.txcf.cronuss.permission.JPUSH_MESSAGE | 未知 | 调用了未知的操作 | |
android.permission.POST_NOTIFICATIONS | 未知 | 调用了未知的操作 | |
com.vivo.notification.permission.BADGE_ICON | 未知 | 调用了未知的操作 | |
android.permission.ACCESS_COARSE_LOCATION | 危险 | 粗定位 | 访问粗略位置源,例如移动网络数据库,以确定大概的电话位置(如果可用)。恶意应用程序可以使用它来确定您的大致位置 |
android.permission.ACCESS_FINE_LOCATION | 危险 | 精细定位(GPS) | 访问精细位置源,例如手机上的全球定位系统,如果可用。恶意应用程序可以使用它来确定您的位置,并可能消耗额外的电池电量 |
android.permission.ACCESS_BACKGROUND_LOCATION | 危险 | 后台访问位置 | 允许应用程序在后台访问位置 |
android.permission.QUERY_ALL_PACKAGES | 正常 | 允许查询设备上的任何普通应用程序,无论清单声明如何 |