Reminder: The static detection of the APP may result in incomplete findings. If you have any doubts or suggestions, contact us.
File Information
File name bgzs.apkSize 40.49MB
MD5 7f3a095027021d5530d83dc2549daac0
SHA1 8c8be9205635726d41b5b49ad367fec9042900f2
SHA256 3fce4c14a14091e6c48a93a8b1011e5438de6e152303ae66048c7bbfc2349ae6
APK Information
App name Ai办公助手Package name com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv
Main activity com.KzfOoQjGKhb.DLFzKPMYoR.rliwfpActivity
Version null
Domain Clues
67 records
View
URL Clues
73 records
View
Email Clues
3 records
View
Phone Clues
4 records
View
Domain Clues
Domain | Domain query | IP | Location | Location query |
---|---|---|---|---|
cfg.imtt.qq.com | 60.28.172.238 | China - Tianjin | ||
ru.register.xmpush.global.xiaomi.com | 107.155.52.56 | Russian Federation - Moskva | ||
p.bmob.cn | No information | No locations | ||
resolver.msg.global.xiaomi.net | 8.219.211.108 | Singapore - Singapore | ||
imtest6.netease.im | No information | No locations | ||
file.bmob.cn | No information | No locations | ||
debugx5.qq.com | 60.29.240.122 | China - Tianjin | ||
resolver.msg.xiaomi.net | 111.206.174.194 | China - Beijing | ||
long.open.weixin.qq.com | 112.65.193.170 | China - Shanghai | ||
register.xmpush.global.xiaomi.com | 47.88.199.5 | Singapore - Singapore | ||
dr.netease.im | 101.71.139.136 | China - Zhejiang | ||
io.codenow.cn | 106.75.70.127 | China - Shanghai | ||
app.bmob.iwyttc.com | No information | No locations | ||
open3.bmob.cn | No information | No locations | ||
soft.tbs.imtt.qq.com | 119.167.147.86 | China - Shandong | ||
play.google.com | 93.46.8.90 | Italy - Lombardia | ||
cn.register.xmpush.xiaomi.com | 123.125.102.39 | China - Beijing | ||
nrtc.netease.im | 45.254.48.99 | China - Guangdong | ||
opentest.bmob.cn | No information | No locations | ||
59.111.110.241 | 59.111.110.241 | China - Zhejiang | ||
wannos.127.net | 223.252.196.42 | China - Guangdong | ||
m0.api.upyun.com | 218.28.104.157 | China - Henan | ||
imtest.netease.im | 111.124.202.79 | China - Guizhou | ||
www.baidu.com | 110.242.68.3 | China - Hebei | ||
ns.adobe.com | No information | No locations | ||
mdc.html5.qq.com | 116.130.223.178 | China - Beijing | ||
github.com | 20.205.243.166 | Singapore - Singapore | ||
debugtbs.qq.com | 60.29.240.122 | China - Tianjin | ||
fr.register.xmpush.global.xiaomi.com | 98.64.182.160 | Netherlands - Noord-Holland | ||
api-push.in.meizu.com | 206.161.233.191 | United States of America - Virginia | ||
pms.mb.qq.com | 60.29.240.17 | China - Tianjin | ||
h.trace.qq.com | 113.56.189.162 | China - Hubei | ||
open.weixin.qq.com | 220.196.154.28 | China - Jiangsu | ||
log.tbs.qq.com | 124.95.224.248 | China - Liaoning | ||
qyqa.netease.com | 59.111.96.241 | China - Zhejiang | ||
astat.bugly.qcloud.com | 119.28.121.133 | Singapore - Singapore | ||
www.bjtime.cn | 192.168.0.1 | - - - | ||
ip-api.com | 208.95.112.1 | United States of America - North Carolina | ||
maps.google.cn | 114.250.70.34 | China - Beijing | ||
roomserver.netease.im | 47.96.10.89 | China - Zhejiang | ||
wup.imtt.qq.com | 125.39.196.183 | China - Tianjin | ||
m.toutiao.com | 27.221.96.225 | China - Shandong | ||
nosup-hz1.127.net | 45.127.129.9 | China - Guangdong | ||
www.taobao.com | 183.204.244.141 | China - Henan | ||
127.0.0.1 | 127.0.0.1 | - - - | ||
www.qq.com | 221.198.70.47 | China - Tianjin | ||
imtest4.netease.im | 59.111.241.163 | China - Guangdong | ||
api-push.meizu.com | 221.5.93.66 | China - Guangdong | ||
schemas.android.com | No information | No locations | ||
xml.apache.org | 151.101.2.132 | United States of America - California | ||
goo.gl | 142.251.42.238 | United States of America - California | ||
idmb.register.xmpush.global.xiaomi.com | 20.219.205.9 | India - Maharashtra | ||
mqqad.html5.qq.com | 0.0.0.1 | - - - | ||
v0.api.upyun.com | 218.28.104.157 | China - Henan | ||
statistic.live.126.net | 101.71.139.161 | China - Zhejiang | ||
lbs.netease.im | 45.254.49.32 | China - Guangdong | ||
astat.bugly.cros.wr.pvp.net | 170.106.118.26 | United States of America - California | ||
p0.api.upyun.com | 101.251.144.15 | China - Zhejiang | ||
www.jivesoftware.com | 23.235.209.143 | United States of America - Virginia | ||
www.bouncycastle.org | 203.32.61.103 | Australia - Victoria | ||
www.time.ac.cn | 210.72.145.8 | China - Beijing | ||
android.bugly.qq.com | 124.95.225.146 | China - Liaoning | ||
xmlpull.org | 185.199.111.153 | United States of America - Pennsylvania | ||
www.jd.com | 60.9.5.193 | China - Hebei | ||
api.weixin.qq.com | 116.128.184.169 | China - Shanghai | ||
www.ntsc.ac.cn | 159.226.242.43 | China - Beijing | ||
norma-external-collect.meizu.com | 183.60.176.112 | China - Guangdong |
URL Clues
Email Clues
Phone Clues
Signature Certificate
APK已签名
v1 签名: False
v2 签名: True
v3 签名: False
找到 1 个唯一证书
主题: C=TG@apksigner, ST=TG@apksigner, L=TG@apksigner, O=gb1723628374706, OU=gb1723628374706, CN=dqtk
签名算法: rsassa_pkcs1v15
有效期自: 2024-08-14 09:39:34+00:00
有效期至: 2074-08-02 09:39:34+00:00
发行人: C=TG@apksigner, ST=TG@apksigner, L=TG@apksigner, O=gb1723628374706, OU=gb1723628374706, CN=dqtk
序列号: 0x61f90146
哈希算法: sha1
md5值: 16457bea4d2e9d8d7cc661bc3d40f9b1
sha1值: 9c7f1302d917bf123d868ec82266e288153653bd
sha256值: 3f19d476f2ae4bd7329863fc3c5bed8acf677a45689e5b4dc707b5bb57d0bc4d
sha512值: 191aca9e3144bd83981010aa08230e8c13b101598ac9915ed89cc2cc81e9d1cf8189ce8872d531a93134c983eba872b5505834df059de7c74da71cf49d84841a
公钥算法: rsa
密钥长度: 1024
指纹: 5a559793d96d0b7bc00d076b657297bcb7f101f47e6fea58ab84e914c8d38036
Leaked Information
Shells Analysis
Plugins Analysis
Dangerous Actions
Permissions | Is Dangerous | Category | Information |
---|---|---|---|
android.permission.GET_TASKS | Dangerous | 检索正在运行的应用程序 | 允许应用程序检索有关当前和最近运行的任务的信息。可能允许恶意应用程序发现有关其他应用程序的私人信息 |
android.permission.INTERNET | Normal | 互联网接入 | 允许应用程序创建网络套接字 |
android.permission.ACCESS_NETWORK_STATE | Normal | 查看网络状态 | 允许应用程序查看所有网络的状态 |
android.permission.ACCESS_WIFI_STATE | Normal | 查看Wi-Fi状态 | 允许应用程序查看有关 Wi-Fi 状态的信息 |
android.permission.CHANGE_WIFI_STATE | Normal | 更改Wi-Fi状态 | 允许应用程序连接和断开 Wi-Fi 接入点,并对配置的 Wi-Fi 网络进行更改 |
android.permission.READ_EXTERNAL_STORAGE | Dangerous | 读取外部存储器内容 | 允许应用程序从外部存储读取 |
android.permission.WRITE_EXTERNAL_STORAGE | Dangerous | 读取/修改/删除外部存储内容 | 允许应用程序写入外部存储 |
android.permission.ACCESS_LOCATION_EXTRA_COMMANDS | Normal | 访问额外的位置提供程序命令 | 访问额外的位置提供程序命令,恶意应用程序可能会使用它来干扰 GPS 或其他位置源的操作 |
android.permission.CAMERA | Dangerous | 拍照和录像 | 允许应用程序用相机拍照和录像。这允许应用程序收集相机随时看到的图像 |
android.permission.RECORD_AUDIO | Dangerous | 录音 | 允许应用程序访问音频记录路径 |
android.permission.FLASHLIGHT | Normal | 控制手电筒 | 允许应用程序控制手电筒 |
android.permission.VIBRATE | Normal | 可控震源 | 允许应用程序控制振动器 |
android.permission.CHANGE_CONFIGURATION | System Needs | 更改您的 UI 设置 | 允许应用程序更改当前配置,例如语言环境或整体字体大小 |
android.permission.MODIFY_AUDIO_SETTINGS | Normal | 更改您的音频设置 | 允许应用程序修改全局音频设置,例如音量和路由 |
android.permission.WRITE_SETTINGS | Dangerous | 修改全局系统设置 | 允许应用程序修改系统设定数据。恶意应用可能会损坏你的系统的配置。 |
android.permission.DISABLE_KEYGUARD | Normal | 如果键盘不安全,允许应用程序禁用它。 | |
android.permission.WAKE_LOCK | Normal | 防止手机睡眠 | 允许应用程序防止手机进入睡眠状态 |
android.permission.FOREGROUND_SERVICE | Normal | 允许常规应用程序使用 Service.startForeground。 | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.permission.RECEIVE_MSG | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.permission.MIPUSH_RECEIVE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.permission.C2D_MESSAGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.coloros.mcs.permission.RECIEVE_MCS_MESSAGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.heytap.mcs.permission.RECIEVE_MCS_MESSAGE | unknown | unknown | |
android.permission.SYSTEM_ALERT_WINDOW | Dangerous | 显示系统级警报 | 允许应用程序显示系统警报窗口。恶意应用程序可以接管手机的整个屏幕 |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.meizu.flyme.push.permission.RECEIVE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.push.permission.MESSAGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.meizu.c2dm.permission.RECEIVE | unknown | unknown | |
android.permission.PROCESS_OUTGOING_CALLS | Dangerous | 拦截拨出电话 | 允许应用程序处理拨出电话并更改要拨打的号码。恶意应用程序可能会监控,重定向或阻止拨出电话 |
android.permission.CALL_PHONE | Dangerous | 直接拨打电话号码 | 允许应用程序在没有您干预的情况下拨打电话号码。恶意应用程序可能会导致您的电话账单出现意外呼叫。请注意,这不允许应用程序拨打紧急电话号码 |
android.permission.READ_PHONE_STATE | Dangerous | 读取电话状态和身份 | 允许应用访问设备的电话功能。具有此权限的应用程序可以确定此电话的电话号码和序列号,呼叫是否处于活动状态,呼叫所连接的号码等 |
android.permission.ANSWER_PHONE_CALLS | Dangerous | 允许应用接听来电。 | |
android.permission.READ_CALL_LOG | Dangerous | 允许应用程序读取用户的通话日志 | |
android.permission.WRITE_CALL_LOG | Dangerous | 允许应用程序写入(但不读取)用户号召日志数据。 | |
android.permission.MOUNT_UNMOUNT_FILESYSTEMS | Dangerous | 装载和卸载文件系统 | 允许应用程序为可移动存储安装和卸载文件系统 |
android.permission.KILL_BACKGROUND_PROCESSES | Normal | 杀死后台进程 | 允许应用程序杀死其他应用程序的后台进程,即使内存不低 |
android.permission.READ_PRIVILEGED_PHONE_STATE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.sec.android.provider.badge.permission.READ | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.sec.android.provider.badge.permission.WRITE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.htc.launcher.permission.READ_SETTINGS | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.htc.launcher.permission.UPDATE_SHORTCUT | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.sonyericsson.home.permission.BROADCAST_BADGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.sonymobile.home.permission.PROVIDER_INSERT_BADGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.anddoes.launcher.permission.UPDATE_COUNT | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.majeur.launcher.permission.UPDATE_BADGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.huawei.android.launcher.permission.CHANGE_BADGE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.huawei.android.launcher.permission.READ_SETTINGS | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.huawei.android.launcher.permission.WRITE_SETTINGS | unknown | unknown | |
android.permission.READ_APP_BADGE | Normal | 显示应用程序通知 | 允许应用程序显示应用程序图标徽章 |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.oppo.launcher.permission.READ_SETTINGS | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.oppo.launcher.permission.WRITE_SETTINGS | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_me.everything.badger.permission.BADGE_COUNT_READ | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_me.everything.badger.permission.BADGE_COUNT_WRITE | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.permission.PROCESS_PUSH_MSG | unknown | unknown | |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv.permission.PUSH_PROVIDER | unknown | unknown | |
android.permission.REQUEST_INSTALL_PACKAGES | Dangerous | 允许应用程序请求安装包。 | 恶意应用程序可以利用它来尝试诱骗用户安装其他恶意软件包。 |
com.KzfugghhfOoQjGKhb.DLFzKPMYoSbbgghhv_com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA | unknown | unknown |