温馨提示:APP静态检测会有结果不完整的现象,如有疑问或建议, 可加入我们的微信群讨论

APP图标



下载APP

文件信息

文件名 com.mhzf.apk
文件大小 17.08MB
MD5值 fc0544f018b43a4d8e2ce84b11fa1f25
SHA1值 24e8c98181f1b908c4f333a04eab32fdd87e4824
SHA256值 9f7abc72cdb6f2568ba37055e4c6b6425c9f53960b669a876cbd5b779f8e470b

APK信息

APK名称 魔盒Pay
包名 uni.UNIAEFE394
主活动 io.dcloud.PandoraEntry
安卓版本名称 1.6.1
域名线索 60 条
查看
URL线索 30 条
查看
邮箱线索 1 条
查看
手机号线索 2 条
查看

域名线索

域名 查询域名 ip 地区 查询地区
drafts.csswg.org 45.79.94.155 United States of America - California
popscan.blogspot.fr 202.160.128.210 Singapore - Singapore
bit.ly 67.199.248.10 United States of America - New York
bugs.chromium.org 142.251.43.19 United States of America - California
inspirit.ru 176.31.179.191 France - Hauts-de-France
github.com 20.205.243.166 Singapore - Singapore
beian.miit.gov.cn 119.39.205.85 China - Hunan
bugs.jquery.com 104.131.8.164 United States of America - New Jersey
api.next.bspapp.com 203.107.60.33 China - Zhejiang
stitchpanorama.sourceforge.net 172.64.150.145 United States of America - California
jsonlib.appspot.com 31.13.86.21 Italy - Lombardia
bugzilla.mozilla.org 34.110.178.183 United States of America - Missouri
stackoverflow.com 104.18.32.7 United States of America - California
davidbau.com 216.92.235.213 United States of America - Pennsylvania
web.archive.org 182.50.139.56 Singapore - Singapore
next.vuex.vuejs.org 13.124.181.114 Korea (Republic of) - Gyeonggi-do
www.mohepay.com 175.178.211.223 China - Beijing
connect.microsoft.com 20.236.44.162 United States of America - Washington
er.dcloud.net.cn 118.89.168.191 China - Beijing
er.dcloud.io 没有ip信息 没有地区信息
www.apache.org 151.101.2.132 United States of America - California
ask.dcloud.net.cn 221.204.43.242 China - Shanxi
www.github.com 20.205.243.166 Singapore - Singapore
html.spec.whatwg.org 165.227.248.76 United States of America - New Jersey
jsperf.com 104.16.227.18 United States of America - California
vuejs.org 54.177.145.149 United States of America - California
msdn.microsoft.com 13.107.253.39 Germany - Hessen
api.bspapp.com 39.96.249.142 China - Beijing
cdn.uviewui.com 101.73.101.238 China - Hebei
lame.sf.net 104.18.34.154 United States of America - California
ns.adobe.com 没有ip信息 没有地区信息
bugs.webkit.org 17.253.85.201 Hong Kong - Hong Kong
www.google.com 199.59.148.229 United States of America - California
cnx.org 143.204.126.124 Japan - Tokyo
uniapp.dcloud.net.cn 124.163.196.191 China - Shanxi
www.rsa.com 23.185.0.253 United States of America - California
m3w.cn 119.188.174.59 China - Shandong
jquery.com 104.18.155.119 United States of America - California
www.tu-darmstadt.de 130.83.47.181 Germany - Hessen
images.apple.com 23.77.214.197 Hong Kong - Hong Kong
quilljs.com 172.66.40.163 United States of America - California
developer.mozilla.org 34.111.97.67 United States of America - Missouri
www.inf.fu-berlin.de 160.45.117.200 Germany - Berlin
sizzlejs.com 104.17.98.190 United States of America - California
service.dcloud.net.cn 110.40.181.119 China - Beijing
www.ti.com 218.58.100.33 China - Shandong
liuliu.me 72.14.178.109 United States of America - Texas
cvlab.epfl.ch 128.178.222.83 Switzerland - Vaud
www.w3.org 104.18.22.19 United States of America - California
schemas.android.com 没有ip信息 没有地区信息
jquery.org 104.17.176.200 United States of America - California
apis.map.qq.com 116.130.223.114 China - Beijing
promisesaplus.com 104.21.93.212 United States of America - California
js.foundation 104.131.8.164 United States of America - New Jersey
www-cs-students.stanford.edu 171.64.66.201 United States of America - California
example.com 93.184.215.14 United States of America - California
crbug.com 216.239.32.29 United States of America - California
101.34.23.153 101.34.23.153 China - Beijing
oapi.yeahka.cn 120.78.0.128 China - Zhejiang
infra.spec.whatwg.org 165.227.248.76 United States of America - New Jersey

URL线索

URL信息 Url所在文件
http://schemas.android.com/apk/res/android
com/hjq/permissions/AndroidManifestParser.java
https://ask.dcloud.net.cn/article/282
io/dcloud/common/constant/DOMException.java
http://localhost
io/dcloud/common/util/PdrUtil.java
https://localhost
io/dcloud/common/util/PdrUtil.java
https://m3w.cn/s/
io/dcloud/common/util/ShortCutUtil.java
http://ns.adobe.com/xap/1.0/\u0000
io/dcloud/common/util/ExifInterface.java
https://ask.dcloud.net.cn/article/35627
io/dcloud/e/b/a.java
https://ask.dcloud.net.cn/article/35877
io/dcloud/e/b/a.java
http://localhost
io/dcloud/e/b/e.java
https://er.dcloud.io/rv
io/dcloud/e/c/h/c.java
https://er.dcloud.net.cn/rv
io/dcloud/e/c/h/c.java
https://ask.dcloud.net.cn/article/35058
io/dcloud/feature/audio/AudioRecorderMgr.java
https://er.dcloud.io/sc
io/dcloud/feature/gg/dcloud/ADHandler.java
https://er.dcloud.net.cn/sc
io/dcloud/feature/gg/dcloud/ADHandler.java
https://ask.dcloud.net.cn/article/283
io/dcloud/feature/utsplugin/ProxyModule.java
http://localhost
io/dcloud/feature/weex/adapter/DefaultWebSocketAdapter.java
https://ask.dcloud.net.cn/article/283
io/dcloud/g/b.java
https://ask.dcloud.net.cn/article/287
io/dcloud/share/IFShareApi.java
http://schemas.android.com/apk/res/android
pl/droidsonroids/gif/GifViewUtils.java
http://schemas.android.com/apk/res/android
pl/droidsonroids/gif/GifTextView.java
http://schemas.android.com/apk/res/android
pl/droidsonroids/gif/GifTextureView.java
https://ask.dcloud.net.cn/article/36199
Mogua Engine V1
http://www.w3.org/2000/svg
Mogua Engine V2
https://next.vuex.vuejs.org/
Mogua Engine V2
https://vuejs.org/images/icons/favicon-96x96.png
Mogua Engine V2
https://www.mohepay.com/
Mogua Engine V2
https://github.com/emn178/js-md5
Mogua Engine V2
http://www-cs-students.stanford.edu/
Mogua Engine V2
https://github.com/bitcoinjs/bitcoinjs-lib
Mogua Engine V2
https://beian.miit.gov.cn/
Mogua Engine V2
http://101.34.23.153/20230327chen/com.mhzf.apk
Mogua Engine V2
http://101.34.23.153/20230327chen/com.mohe.mobileconfig
Mogua Engine V2
https://api.next.bspapp.com
Mogua Engine V2
https://api.bspapp.com
Mogua Engine V2
https://$
Mogua Engine V2
https://uniapp.dcloud.net.cn/uniCloud/secure-network.html
Mogua Engine V2
https://uniapp.dcloud.net.cn/uniCloud/faq?id=promise
Mogua Engine V2
https://oapi.yeahka.cn/common/upload
Mogua Engine V2
http://cdn.uviewui.com/uview/empty/data.png
Mogua Engine V2
http://cdn.uviewui.com/uview/empty/history.png
Mogua Engine V2
http://cdn.uviewui.com/uview/empty/search.png
Mogua Engine V2
https://oapi.yeahka.cn/merchant/willfaceurl?merchant_id=$
Mogua Engine V2
https://vuejs.org/error-reference/
Mogua Engine V2
http://www.w3.org/2000/svg
Mogua Engine V2
http://www.w3.org/1998/Math/MathML
Mogua Engine V2
http://www.w3.org/1999/xlink
Mogua Engine V2
https://service.dcloud.net.cn/uniapp/feedback.html
Mogua Engine V2
https://github.com/uuidjs/uuid
Mogua Engine V2
https://apis.map.qq.com/jsapi?qt=translate&type=1&points=$
Mogua Engine V2
https://apis.map.qq.com/uri/v1/routeplan?type=drive&to=
Mogua Engine V2
https://www.google.com/maps/?daddr=
Mogua Engine V2
https://www.google.com/maps/
Mogua Engine V2
https://quilljs.com/
Mogua Engine V2
https://quilljs.com
Mogua Engine V2
http://davidbau.com/encode/seedrandom-min.js></script>
Mogua Engine V2
http://bit.ly/srandom-512
Mogua Engine V2
https://jsonlib.appspot.com/urandom?callback=Math.seedrandom
Mogua Engine V2
http://www.rsa.com/rsalabs/node.asp?id=2009
Mogua Engine V2
http://stitchpanorama.sourceforge.net/Python/svd.py
Mogua Engine V2
https://github.com/promises-aplus/promises-spec
Mogua Engine V2
https://github.com/wellflat/jslib
Mogua Engine V2
http://inspirit.ru/
Mogua Engine V2
http://popscan.blogspot.fr/2012/08/skin-detection-in-digital-images.html
Mogua Engine V2
http://cvlab.epfl.ch/
Mogua Engine V2
https://github.com/mtschirs/js-objectdetect
Mogua Engine V2
http://www.tu-darmstadt.de/
Mogua Engine V2
https://github.com/liuliu/ccv
Mogua Engine V2
http://liuliu.me/
Mogua Engine V2
https://github.com/wellflat/javascript-labs
Mogua Engine V2
http://www.inf.fu-berlin.de/lehre/SS12/SP-Par/download/fft1.pdf
Mogua Engine V2
http://cnx.org/content/m12021/latest/
Mogua Engine V2
http://images.apple.com/acg/pdf/g4fft.pdf
Mogua Engine V2
http://www.ti.com/lit/an/spra291/spra291.pdf
Mogua Engine V2
http://stackoverflow.com/questions/9882716/packing-float-into-vec4-how-does-this-code-work',
Mogua Engine V2
http://stackoverflow.com/questions/9882716/packing-float-into-vec4-how-does-this-code-work
Mogua Engine V2
https://www.github.com/auduno/clmtrackr/)
Mogua Engine V2
https://jquery.com/
Mogua Engine V2
https://sizzlejs.com/
Mogua Engine V2
https://jquery.org/license
Mogua Engine V2
https://github.com/whatwg/html/issues/2369
Mogua Engine V2
https://html.spec.whatwg.org/
Mogua Engine V2
https://js.foundation/
Mogua Engine V2
https://jsperf.com/thor-indexof-vs-for/5
Mogua Engine V2
http://www.w3.org/TR/css3-selectors/
Mogua Engine V2
https://www.w3.org/TR/css-syntax-3/
Mogua Engine V2
http://www.w3.org/TR/selectors/
Mogua Engine V2
http://www.w3.org/TR/CSS21/syndata.html
Mogua Engine V2
https://drafts.csswg.org/cssom/
Mogua Engine V2
https://html.spec.whatwg.org/multipage/scripting.html
Mogua Engine V2
https://html.spec.whatwg.org/multipage/forms.html
Mogua Engine V2
https://bugs.jquery.com/ticket/4833
Mogua Engine V2
https://bugs.jquery.com/ticket/13378
Mogua Engine V2
https://bugs.jquery.com/ticket/12359
Mogua Engine V2
https://msdn.microsoft.com/en-us/library/ie/hh465388.aspx
Mogua Engine V2
http://www.w3.org/TR/2011/REC-css3-selectors-20110929/
Mogua Engine V2
https://bugs.webkit.org/show_bug.cgi?id=136851
Mogua Engine V2
https://github.com/jquery/sizzle/pull/225
Mogua Engine V2
https://msdn.microsoft.com/en-us/library/ms536429%28VS.85%29.aspx
Mogua Engine V2
https://promisesaplus.com/
Mogua Engine V2
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
Mogua Engine V2
https://bugs.jquery.com/ticket/13393
Mogua Engine V2
https://www.w3.org/TR/DOM-Level-3-Events/
Mogua Engine V2
https://www.w3.org/TR/2003/WD-DOM-Level-3-Events-20030331/ecma-script-binding.html
Mogua Engine V2
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
Mogua Engine V2
https://connect.microsoft.com/IE/feedback/details/1736512/
Mogua Engine V2
https://jsperf.com/getall-vs-sizzle/2
Mogua Engine V2
https://developer.mozilla.org/en-US/docs/CSS/display
Mogua Engine V2
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
Mogua Engine V2
https://html.spec.whatwg.org/multipage/syntax.html
Mogua Engine V2
https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-and-removing-tabindex-values-with-javascript/
Mogua Engine V2
https://infra.spec.whatwg.org/
Mogua Engine V2
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
Mogua Engine V2
http://www.w3.org/TR/DOM-Level-3-Events/
Mogua Engine V2
https://bugs.chromium.org/p/chromium/issues/detail?id=449857
Mogua Engine V2
http://example.com:80x/
Mogua Engine V2
https://bugs.webkit.org/show_bug.cgi?id=137337
Mogua Engine V2
https://bugs.webkit.org/show_bug.cgi?id=29084
Mogua Engine V2
https://bugs.chromium.org/p/chromium/issues/detail?id=589347
Mogua Engine V2
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries
Mogua Engine V2
https://github.com/jquery/jquery/pull/557)
Mogua Engine V2
http://www.apache.org/licenses/LICENSE-2.0
Mogua Engine V2
http://www.w3.org/1999/xlink
Mogua Engine V2
http://www.w3.org/2000/svg
Mogua Engine V2
http://lame.sf.net
lib/armeabi-v7a/liblamemp3.so
http://ns.adobe.com/xap/1.0/
lib/armeabi-v7a/libnative-imagetranscoder.so
http://ns.adobe.com/xap/1.0/
lib/armeabi-v7a/libstatic-webp.so
https://crbug.com/v8/8520
lib/armeabi-v7a/libweexjss.so

邮箱线索

邮箱地址 所在文件
emn178@gmail.com
Mogua Engine V2
jhruby.web@gmail.com
Mogua Engine V2

手机线索

手机号 所在文件
18422112222
Mogua Engine V2
14120000111
Mogua Engine V2
19743644256
Mogua Engine V2
18095010153
Mogua Engine V2
16252827678
Mogua Engine V2

代码反编译

AndroidManifest配置 查看
Java源代码 查看 -- 下载

签名证书

APK已签名
v1 签名: True
v2 签名: True
v3 签名: True
找到 1 个唯一证书
主题: C=CN, ST=BJ, L=HD, O=Android, OU=Android, CN=Android Debug
签名算法: rsassa_pkcs1v15
有效期自: 2021-04-12 08:27:53+00:00
有效期至: 2121-03-19 08:27:53+00:00
发行人: C=CN, ST=BJ, L=HD, O=Android, OU=Android, CN=Android Debug
序列号: 0x363bc393
哈希算法: sha256
md5值: 06838cc840093b9d4689fc419ba1a3f3
sha1值: 97c84101b9141c130dd75d7428a2922518c36dcd
sha256值: b01d06180d003e79c7b9088993b8e5ae7a19b0da1161aa097c7f398a6f514fa7
sha512值: 67720eb20639d1f5f9c8b7b201b185ea4364f6a89bedd35aa1d273002c16d65a7739f59679510d3b96c1f2c3dd3136d9a34451cb679251a86ff4cafdc18314bf
公钥算法: rsa
密钥长度: 2048
指纹: b27ac6d7a4586417c251be6e44179616262379e57da2d1e19db0995be0ddf509

硬编码敏感信息

"dcloud_common_user_refuse_api" : "the user denies access to the API"
"dcloud_io_without_authorization" : "not authorized"
"dcloud_oauth_authentication_failed" : "failed to obtain authorization to log in to the authentication service"
"dcloud_oauth_empower_failed" : "the Authentication Service operation to obtain authorized logon failed"
"dcloud_oauth_logout_tips" : "not logged in or logged out"
"dcloud_oauth_oauth_not_empower" : "oAuth authorization has not been obtained"
"dcloud_oauth_token_failed" : "failed to get token"
"dcloud_permissions_reauthorization" : "reauthorize"
"dcloud_tips_certificate" : "certificate"
"dcloud_common_user_refuse_api" : "用户拒绝该API访问"
"dcloud_io_without_authorization" : "没有获得授权"
"dcloud_oauth_authentication_failed" : "获取授权登录认证服务操作失败"
"dcloud_oauth_empower_failed" : "获取授权登录认证服务操作失败"
"dcloud_oauth_logout_tips" : "未登录或登录已注销"
"dcloud_oauth_oauth_not_empower" : "尚未获取oauth授权"
"dcloud_oauth_token_failed" : "获取token失败"
"dcloud_permissions_reauthorization" : "重新授权"
"dcloud_tips_certificate" : "证书"

加壳分析

第三方插件

危险动作

向手机申请的权限 是否危险 类型 详细情况
android.permission.INTERNET 正常 互联网接入 允许应用程序创建网络套接字
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储
android.permission.ACCESS_NETWORK_STATE 正常 查看网络状态 允许应用程序查看所有网络的状态
android.permission.ACCESS_WIFI_STATE 正常 查看Wi-Fi状态 允许应用程序查看有关 Wi-Fi 状态的信息
android.permission.INSTALL_PACKAGES 系统需要 直接安装应用程序 允许应用程序安装新的或更新的 Android 包。恶意应用程序可以使用它来添加具有任意强大权限的新应用程序
android.permission.REQUEST_INSTALL_PACKAGES 危险 允许应用程序请求安装包。 恶意应用程序可以利用它来尝试诱骗用户安装其他恶意软件包。
android.permission.CAMERA 危险 拍照和录像 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像
android.permission.CHANGE_NETWORK_STATE 正常 更改网络连接 允许应用程序更改网络连接状态。
android.permission.CHANGE_WIFI_STATE 正常 更改Wi-Fi状态 允许应用程序连接和断开 Wi-Fi 接入点,并对配置的 Wi-Fi 网络进行更改
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 危险 装载和卸载文件系统 允许应用程序为可移动存储安装和卸载文件系统
android.permission.READ_LOGS 危险 读取敏感日志数据 允许应用程序从系统读小号各种日志文件。这使它能够发现有关您使用手机做什么的一般信息,可能包括个人或私人信息
android.permission.READ_PHONE_STATE 危险 读取电话状态和身份 允许应用访问设备的电话功能。具有此权限的应用程序可以确定此电话的电话号码和序列号,呼叫是否处于活动状态,呼叫所连接的号码等
android.permission.VIBRATE 正常 可控震源 允许应用程序控制振动器
android.permission.WAKE_LOCK 正常 防止手机睡眠 允许应用程序防止手机进入睡眠状态
android.permission.WRITE_SETTINGS 危险 修改全局系统设置 允许应用程序修改系统设定数据。恶意应用可能会损坏你的系统的配置。
android.permission.READ_EXTERNAL_STORAGE 危险 读取外部存储器内容 允许应用程序从外部存储读取
com.asus.msa.SupplementaryDID.ACCESS 未知 调用了未知的操作
android.permission.READ_MEDIA_IMAGES 未知 调用了未知的操作
android.permission.READ_MEDIA_VIDEO 未知 调用了未知的操作
android.permission.READ_MEDIA_VISUAL_USER_SELECTED 未知 调用了未知的操作
com.huawei.android.launcher.permission.CHANGE_BADGE 正常 在应用程序上显示通知计数 在华为手机的应用程序启动图标上显示通知计数或徽章。
com.vivo.notification.permission.BADGE_ICON 未知 调用了未知的操作