温馨提示:APP静态检测会有结果不完整的现象,如有疑问或建议, 可加入我们的微信群讨论

APP图标



下载APP

文件信息

文件名 base.apk
文件大小 57.61MB
MD5值 b830f1c573090f102e13175fba2d5b44
SHA1值 b055b3b90c52ae1d3dd77064a29a7fe42cab0939
SHA256值 ba0b685700bbce7fc5e6bbe905421a3659ffb454ec088c7affab9259a21a0de7

APK信息

APK名称 Mattermost
包名 com.mattermost.rn
主活动 com.mattermost.rn.MainActivity
安卓版本名称 2.15.0
域名线索 39 条
查看
URL线索 44 条
查看
邮箱线索 0 条
查看
手机号线索 3 条
查看

域名线索

域名 查询域名 ip 地区 查询地区
www.whatwg.org 165.227.248.76 United States of America - New Jersey
www.mathjax.org 172.67.72.172 United States of America - California
www.example.com 93.184.215.14 United States of America - California
www.quirksmode.org 172.67.139.199 United States of America - California
code.google.com 172.217.163.46 United States of America - California
twitter.com 202.160.129.37 Singapore - Singapore
electronjs.org 104.21.49.33 United States of America - California
www.apache.org 151.101.2.132 United States of America - California
mathiasbynens.be 83.137.145.144 Netherlands - Groningen
www.w3.org 104.18.23.19 United States of America - California
www.andismith.com 13.215.144.61 Singapore - Singapore
html.spec.whatwg.org 165.227.248.76 United States of America - New Jersey
fb.me 157.240.7.35 Singapore - Singapore
xml.org 104.239.240.11 United States of America - Texas
github.com 20.205.243.166 Singapore - Singapore
api-7231322553409637977-752355.firebaseio.com 35.201.97.85 United States of America - Missouri
docs.swmansion.com 172.67.142.188 United States of America - California
w3c.github.io 185.199.109.153 United States of America - Pennsylvania
play.google.com 59.24.3.174 Korea (Republic of) - Gyeonggi-do
pinterest.com 157.240.10.36 United States of America - California
www.owasp.org 104.22.26.77 United States of America - California
xmlpull.org 185.199.111.153 United States of America - Pennsylvania
developer.mozilla.org 34.111.97.67 United States of America - Missouri
mths.be 83.137.145.144 Netherlands - Groningen
reactjs.org 76.76.21.21 United States of America - California
bugs.chromium.org 142.251.43.19 United States of America - California
modernizr.com 75.2.60.5 United States of America - Washington
developer.microsoft.com 60.210.8.162 China - Shandong
cdn.mathjax.org 172.67.72.172 United States of America - California
cdnjs.cloudflare.com 104.17.24.14 United States of America - California
www.facebook.com 199.96.62.75 United States of America - California
www.unix.org 170.39.106.9 United States of America - California
www.thespanner.co.uk 217.160.0.167 Germany - Nordrhein-Westfalen
www.slf4j.org 195.15.222.169 Switzerland - Geneve
tools.ietf.org 104.16.44.99 United States of America - California
bugzilla.mozilla.org 34.110.178.183 United States of America - Missouri
foo.com 34.206.39.153 United States of America - Virginia
plus.google.com 128.242.240.85 United States of America - Washington
logback.qos.ch 159.100.250.151 Switzerland - Zurich

URL线索

URL信息 Url所在文件
http://logback.qos.ch/css/classic.css
ch/qos/logback/classic/html/UrlCssBuilder.java
http://logback.qos.ch/codes.html
ch/qos/logback/classic/net/SocketReceiver.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/CoreConstants.java
http://logback.qos.ch/manual/
ch/qos/logback/core/CoreConstants.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/OutputStreamAppender.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/FileAppender.java
http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd\
ch/qos/logback/core/html/HTMLLayoutBase.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/joran/action/AppenderRefAction.java
http://xml.org/sax/features/validation
ch/qos/logback/core/joran/event/SaxEventRecorder.java
http://xml.org/sax/features/namespaces
ch/qos/logback/core/joran/event/SaxEventRecorder.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/net/AbstractSocketAppender.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/net/SyslogAppenderBase.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/net/SMTPAppenderBase.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/pattern/parser/Parser.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/SizeBasedTriggeringPolicy.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/TimeBasedRollingPolicy.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/RollingFileAppender.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/TimeBasedFileNamingAndTriggeringPolicyBase.java
http://logback.qos.ch/manual/appenders.html
ch/qos/logback/core/rolling/SizeAndTimeBasedFNATP.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/FixedWindowRollingPolicy.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/rolling/helper/RenameUtil.java
http://logback.qos.ch/codes.html
ch/qos/logback/core/sift/SiftingJoranConfiguratorBase.java
https://www.facebook.com/sharer/sharer.php?u=
cl/json/social/FacebookPagesManagerShare.java
https://www.facebook.com/sharer/sharer.php?u=
cl/json/social/FacebookShare.java
https://plus.google.com/share?url=
cl/json/social/GooglePlusShare.java
https://pinterest.com/pin/create/button/?url=
cl/json/social/PinterestShare.java
https://twitter.com/intent/tweet?text=
cl/json/social/TwitterShare.java
https://play.google.com/store/apps/details?id=com.instagram.android
cl/json/social/InstagramStoriesShare.java
https://play.google.com/store/apps/details?id=com.instagram.android
cl/json/social/InstagramShare.java
http://www.w3.org/TR/SVG11/feature
com/caverock/androidsvg/SVGParser.java
http://www.w3.org/2000/svg
com/caverock/androidsvg/SVGParser.java
http://www.w3.org/1999/xlink
com/caverock/androidsvg/SVGParser.java
http://xmlpull.org/v1/doc/features.html
com/caverock/androidsvg/SVGParser.java
http://xml.org/sax/features/external-general-entities
com/caverock/androidsvg/SVGParser.java
http://xml.org/sax/features/external-parameter-entities
com/caverock/androidsvg/SVGParser.java
http://xml.org/sax/properties/lexical-handler
com/caverock/androidsvg/SVGParser.java
https://).
com/reactnativecommunity/cookies/CookieManagerModule.java
https://docs.swmansion.com/react-native-gesture-handler/docs/guides/migrating-off-rnghenabledroot
com/swmansion/gesturehandler/react/RNGestureHandlerEnabledRootView.java
https://github.com/software-mansion/react-native-screens/issues/17
com/swmansion/rnscreens/ScreenStackFragment.java
https://github.com/software-mansion/react-native-screens/issues/17
com/swmansion/rnscreens/ScreenFragment.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
io/reactivex/rxjava3/core/Completable.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
io/reactivex/rxjava3/core/Maybe.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
io/reactivex/rxjava3/core/Single.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
io/reactivex/rxjava3/core/Flowable.java
https://github.com/ReactiveX/RxJava/wiki/Plugins
io/reactivex/rxjava3/core/Observable.java
https://github.com/ReactiveX/RxJava/wiki/Error-Handling
io/reactivex/rxjava3/exceptions/OnErrorNotImplementedException.java
https://github.com/ReactiveX/RxJava/wiki/What's-different-in-2.0
io/reactivex/rxjava3/exceptions/UndeliverableException.java
http://www.slf4j.org/codes.html
org/slf4j/MDC.java
https://www.slf4j.org/codes.html
org/slf4j/LoggerFactory.java
http://logback.qos.ch/codes.html
org/slf4j/impl/StaticLoggerBinder.java
https://api-7231322553409637977-752355.firebaseio.com
Mogua Engine V1
https://github.com/react-native-community/react-native-webview/blob/master/docs/Reference.md
Mogua Engine V2
http://www.apache.org/licenses/LICENSE-2.0
Mogua Engine V2
https://github.com/mathjax/MathJax-node/issues/299
Mogua Engine V2
https://cdnjs.cloudflare.com/ajax/libs/mathjax/'
Mogua Engine V2
http://www.w3.org/2000/svg
Mogua Engine V2
http://www.w3.org/1998/Math/MathML
Mogua Engine V2
http://www.unix.org/Public/UNIDATA/EastAsianWidth.txt
Mogua Engine V2
https://cdn.mathjax.org/mathjax/contrib
Mogua Engine V2
http://www.mathjax.org
Mogua Engine V2
http://www.w3.org/1999/xlink
Mogua Engine V2
https://bugs.chromium.org/p/v8/issues/detail?id=4118
Mogua Engine V2
https://bugs.chromium.org/p/v8/issues/detail?id=3056
Mogua Engine V2
https://mths.be/punycode
Mogua Engine V2
https://mathiasbynens.be/notes/javascript-encoding>
Mogua Engine V2
https://tools.ietf.org/html/rfc3492
Mogua Engine V2
https://github.com/joyent/node/issues/1707
Mogua Engine V2
https://github.com/facebookincubator/create-react-app/issues/3482
Mogua Engine V2
https://github.com/facebook/react/issues/13688
Mogua Engine V2
https://fb.me/react-crossorigin-error
Mogua Engine V2
https://github.com/facebook/react/issues/13610
Mogua Engine V2
http://www.w3.org/TR/DOM-Level-3-Events/
Mogua Engine V2
https://fb.me/react-event-pooling
Mogua Engine V2
http://www.w3.org/TR/2013/WD-DOM-Level-3-Events-20131105
Mogua Engine V2
https://code.google.com/p/chromium/issues/detail?id=355103
Mogua Engine V2
http://www.w3.org/TR/2013/WD-DOM-Level-3-Events-20131105/
Mogua Engine V2
https://github.com/facebook/react/issues/1698
Mogua Engine V2
http://www.whatwg.org/specs/web-apps/current-work/multipage/the-input-element.html
Mogua Engine V2
https://github.com/facebook/react/issues/12506
Mogua Engine V2
http://www.quirksmode.org/js/events_properties.html
Mogua Engine V2
https://github.com/facebook/react/issues/11768
Mogua Engine V2
http://www.w3.org/1999/xlink');
Mogua Engine V2
http://www.w3.org/XML/1998/namespace');
Mogua Engine V2
http://www.w3.org/TR/2012/WD-html5-20121025/the-input-element.html
Mogua Engine V2
https://fb.me/react-controlled-components',
Mogua Engine V2
https://bugs.chromium.org/p/chromium/issues/detail?id=608416
Mogua Engine V2
https://github.com/facebook/react/issues/7253
Mogua Engine V2
https://github.com/facebook/react/issues/708.
Mogua Engine V2
http://www.w3.org/TR/pointerevents/
Mogua Engine V2
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Object/is
Mogua Engine V2
http://www.w3.org/TR/css3-animations/
Mogua Engine V2
https://developer.mozilla.org/en-US/docs/Web/API/AnimationEvent
Mogua Engine V2
http://www.w3.org/TR/clipboard-apis/
Mogua Engine V2
https://developer.mozilla.org/en-US/docs/Web/API/KeyboardEvent
Mogua Engine V2
http://www.w3.org/TR/touch-events/
Mogua Engine V2
http://www.w3.org/TR/2009/WD-css3-transitions-20090320/
Mogua Engine V2
https://developer.mozilla.org/en-US/docs/Web/API/TransitionEvent
Mogua Engine V2
http://www.w3.org/TR/html5/index.html
Mogua Engine V2
http://www.quirksmode.org/blog/archives/2010/09/click_event_del.html
Mogua Engine V2
https://bugzilla.mozilla.org/show_bug.cgi?id=208427
Mogua Engine V2
https://html.spec.whatwg.org/multipage/browsers.html
Mogua Engine V2
https://html.spec.whatwg.org/
Mogua Engine V2
https://fb.me/react-controlled-components');
Mogua Engine V2
https://developer.microsoft.com/microsoft-edge/platform/issues/101525/
Mogua Engine V2
http://www.w3.org/1999/xhtml';
Mogua Engine V2
http://www.w3.org/1998/Math/MathML';
Mogua Engine V2
http://www.w3.org/2000/svg';
Mogua Engine V2
https://github.com/mozilla/gecko-dev/blob/4e638efc71/layout/style/test/property_database.js
Mogua Engine V2
https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet
Mogua Engine V2
http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/
Mogua Engine V2
http://modernizr.com/docs/
Mogua Engine V2
http://www.andismith.com/blog/2012/02/modernizr-prefixed/),
Mogua Engine V2
https://fb.me/react-invariant-dangerously-set-inner-html
Mogua Engine V2
https://w3c.github.io/webcomponents/spec/custom/
Mogua Engine V2
https://fb.me/invalid-aria-prop',
Mogua Engine V2
https://fb.me/react-attribute-behavior',
Mogua Engine V2
https://electronjs.org/docs/api/webview-tag
Mogua Engine V2
https://github.com/facebook/react/issues/11807
Mogua Engine V2
https://www.w3.org/TR/html5/single-page.html
Mogua Engine V2
https://github.com/facebook/react/pull/11157.
Mogua Engine V2
https://github.com/facebook/react/issues/6731
Mogua Engine V2
https://github.com/facebook/react/pull/6896
Mogua Engine V2
https://bugzilla.mozilla.org/show_bug.cgi?id=1276240
Mogua Engine V2
https://github.com/facebook/react/issues/13222
Mogua Engine V2
https://github.com/facebook/react/issues/14239
Mogua Engine V2
https://github.com/facebook/react/pull/10676.
Mogua Engine V2
https://html.spec.whatwg.org/multipage/syntax.html
Mogua Engine V2
https://html.spec.whatwg.org/multipage/semantics.html
Mogua Engine V2
https://github.com/facebook/react/issues/11918
Mogua Engine V2
https://github.com/facebook/react/issues/3877
Mogua Engine V2
https://fb.me/react-devtools');
Mogua Engine V2
https://github.com/rollup/rollup/issues/1771
Mogua Engine V2
https://github.com/facebook/react/issues/14365
Mogua Engine V2
https://bugs.chromium.org/p/v8/issues/detail?id=8538
Mogua Engine V2
https://github.com/facebook/react/issues/12502
Mogua Engine V2
https://github.com/facebook/fbjs/blob/e66ba20ad5be433eb54423f2b097d829324d9de6/packages/fbjs/src/__forks__/warning.js
Mogua Engine V2
https://fb.me/react-strict-mode-warnings',
Mogua Engine V2
https://fb.me/react-async-component-lifecycle-hooks',
Mogua Engine V2
https://github.com/facebook/react/pull/8033.
Mogua Engine V2
https://fb.me/react-warning-keys
Mogua Engine V2
https://fb.me/react-strict-mode-string-ref',
Mogua Engine V2
https://fb.me/react-refs-must-have-owner
Mogua Engine V2
https://github.com/facebook/react/issues/12995
Mogua Engine V2
https://fb.me/rules-of-hooks\n\n'
Mogua Engine V2
https://fb.me/react-invalid-hook-call
Mogua Engine V2
https://fb.me/rules-of-hooks');
Mogua Engine V2
https://github.com/facebook/react/pull/13384
Mogua Engine V2
https://fb.me/react-error-boundaries
Mogua Engine V2
https://github.com/facebook/react/issues/13188
Mogua Engine V2
https://fb.me/react-hooks-data-fetching';
Mogua Engine V2
http://fb.me/react-profiling')
Mogua Engine V2
https://github.com/facebook/react/issues/12449
Mogua Engine V2
https://fb.me/react-wrap-tests-with-act'
Mogua Engine V2
https://fb.me/react-strict-mode-find-node',
Mogua Engine V2
https://fb.me/react-polyfills');
Mogua Engine V2
https://fb.me/react-devtools'
Mogua Engine V2
https://fb.me/react-devtools-faq'
Mogua Engine V2
https://github.com/facebook/react/issues/3236).']
Mogua Engine V2
https://fb.me/react-special-props)',
Mogua Engine V2
https://reactjs.org/docs/react-api.html
Mogua Engine V2
https://fb.me/rules-of-hooks'
Mogua Engine V2
https://github.com/facebook/react/pull/13088
Mogua Engine V2
https://code.google.com/p/chromium/issues/detail?id=25916
Mogua Engine V2
http://foo.com
Mogua Engine V2
http://a@b@c/
Mogua Engine V2
http://a@b?@c
Mogua Engine V2
http://a@b/c@d
Mogua Engine V2
http://www.example.com
Mogua Engine V2

邮箱线索

代码反编译

AndroidManifest配置 查看
Java源代码 查看 -- 下载

签名证书

APK已签名
v1 签名: False
v2 签名: True
v3 签名: False
找到 1 个唯一证书
主题: C=US, ST=CA, L=Palo Alto, O=Mattermost, OU=IT, CN=Mattermost
签名算法: rsassa_pkcs1v15
有效期自: 2017-01-12 02:41:30+00:00
有效期至: 2044-05-30 02:41:30+00:00
发行人: C=US, ST=CA, L=Palo Alto, O=Mattermost, OU=IT, CN=Mattermost
序列号: 0x18cae1c3
哈希算法: sha256
md5值: 56dd47fc85163b01902a89bca72c4d95
sha1值: e3fb91ecb1a9c23acf6431fbaceb15ac68a21831
sha256值: 5ca732ab1f657dd9e4beff0840a8b9d19c59c30de3adcf4be6a2927226c11f4f
sha512值: c360222a6364c833e09e696636fc97e089a358342041bbb9d1c51225fe896189d62be1cd8def3024826dfa279c51d71950fddc4554ad19e54a576d2fe15408b9
公钥算法: rsa
密钥长度: 2048
指纹: 5e37cb7d5e79814713520a93f466b7866cb50c5364761b270ea7ed4a285f6dd2

硬编码敏感信息

"firebase_database_url" : "https://api-7231322553409637977-752355.firebaseio.com"
"google_api_key" : "AIzaSyCkZkU2ECVg-mmdCG5OoHHQXtKiENuvWPE"
"google_crash_reporting_api_key" : "AIzaSyCkZkU2ECVg-mmdCG5OoHHQXtKiENuvWPE"
"inAppSessionAuth_description" : "Instead of default flow from the mobile browser, enforce SSO with the WebView."
"inAppSessionAuth_title" : "In-App Session Auth"

加壳分析

第三方插件

危险动作

向手机申请的权限 是否危险 类型 详细情况
android.permission.INTERNET 正常 互联网接入 允许应用程序创建网络套接字
android.permission.VIBRATE 正常 可控震源 允许应用程序控制振动器
android.permission.RECEIVE_BOOT_COMPLETED 正常 开机时自动启动 允许应用程序在系统完成启动后立即启动。这可能会使启动手机需要更长的时间,并允许应用程序通过始终运行来减慢整个手机的速度
android.permission.CAMERA 危险 拍照和录像 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像
android.permission.READ_MEDIA_AUDIO 未知 调用了未知的操作
android.permission.READ_MEDIA_IMAGES 未知 调用了未知的操作
android.permission.READ_MEDIA_VIDEO 未知 调用了未知的操作
android.permission.WRITE_EXTERNAL_STORAGE 危险 读取/修改/删除外部存储内容 允许应用程序写入外部存储
android.permission.READ_EXTERNAL_STORAGE 危险 读取外部存储器内容 允许应用程序从外部存储读取
android.permission.ACCESS_NETWORK_STATE 正常 查看网络状态 允许应用程序查看所有网络的状态
android.permission.RECORD_AUDIO 危险 录音 允许应用程序访问音频记录路径
android.permission.MODIFY_AUDIO_SETTINGS 正常 更改您的音频设置 允许应用程序修改全局音频设置,例如音量和路由
android.permission.POST_NOTIFICATIONS 未知 调用了未知的操作
android.permission.FOREGROUND_SERVICE 正常 允许常规应用程序使用 Service.startForeground。
android.permission.BLUETOOTH 正常 创建蓝牙连接 允许应用程序连接到配对的蓝牙设备
android.permission.BLUETOOTH_ADMIN 正常 蓝牙管理 允许应用程序发现和配对蓝牙设备。
android.permission.BLUETOOTH_CONNECT 未知 调用了未知的操作
android.permission.WAKE_LOCK 正常 防止手机睡眠 允许应用程序防止手机进入睡眠状态
android.permission.ACCESS_WIFI_STATE 正常 查看Wi-Fi状态 允许应用程序查看有关 Wi-Fi 状态的信息
android.permission.USE_BIOMETRIC 正常 允许应用使用设备支持的生物识别模式。
android.permission.USE_FINGERPRINT 正常 allow use of指纹 该常量在 API 级别 28 中已被弃用。应用程序应改为请求 USE_BIOMETRIC
com.google.android.c2dm.permission.RECEIVE 合法 C2DM 权限 云到设备消息传递的权限
com.mattermost.rn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION 未知 调用了未知的操作
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE 未知 调用了未知的操作