0/61
Threat
Analyzed on 2021-02-22T03:36:47.364897
MD5 | 06bf993c2c181b98e3a8e754b827b2c4 | |
SHA1 | fa64221202925224f42a8fda94c6a8e6c0fbcb27 | |
SHA256 | 4fde9a4c1ac63935e14d5170f01761a6b8dfe9aea2102ca1210b8bff32f59c32 | |
Size | 9.32MB |
Information computed with APKiD.
/tmp/tmpgcc4shfv!classes.dex | |
anti_vm |
|
compiler |
|
/tmp/tmpgcc4shfv!classes2.dex | |
anti_vm |
|
compiler |
|
Information computed with ssdeep.
APK file | 196608:9EKW7umONLi8/zBh9OkZL6LzgI7slzpBqj:9EKWIu8rBh9HNzIgtn6 | |
Manifest | 384:4nx+5nU5UQt9oO3hgLm3c3KJITyNMAavEgRpcKHDkCx/2+0Sx9xh9NRpNtlhBx9+:… | |
classes.dex | 196608:0LdkMQistil4hNoKVhCmkflSZZNvDxDe+ZZfgKZ5vJCjtLO1t:0LuMQis+4hNo… | |
classes2.dex | 49152:sIwjJ4PfXnx/DeVVN8vO9CNoKVhCmkflSZCo59n9uKCNvDxDe+ZZfgKZ5vJ8eLA… |
Information computed with Dexofuzzy.
Information computed with AndroGuard and Pithus.
Package | com.oneplus.bbs | |
App name | 一加社区 | |
Version name | 3.7.3.0.200331121646.4d54f5b | |
Version code | 150 | |
SDK | 24 - 28 | |
UAID | f4bc41bed2043e68aa60748599fb2ad9bc38032d | |
Signature | Signature V1 | |
Frosting | Not frosted |
Information computed with AndroGuard.
Information computed with MobSF.
Findings | Files |
---|---|
Certificate/Key files hardcoded inside the app. |
okhttp3/internal/publicsuffix/NOTICE |
Information computed with MobSF.
Low | App has a Network Security Configuration[android:networkSecurityConfig=@xml/network_security_config] The Network Security Configuration feature lets apps customize their network security settings in a safe, declarative configuration file without modifying app code. These settings can be configured for specific domains and for a specific app. |
High | Activity (com.oneplus.bbs.ui.activity.ThreadsActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Activity (com.oneplus.bbs.ui.activity.ChooseThreadsActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Broadcast Receiver (com.oneplus.bbs.receiver.UserFeedbackReceiverEx) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
High | Activity (com.oneplus.bbs.ui.activity.PushWebBrowserActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Activity (com.mob.tools.MobUIShell) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Activity (cn.sharesdk.share.demo.wxapi.WXEntryActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
Information computed with MobSF.
com.oneplus.bbs.ui.activity.ChooseThreadsActivity |
Schemes: com.oneplus.bbs.ui.activity:// |
com.oneplus.bbs.ui.activity.PreStartActivity |
Hosts: www.oneplusbbs.com Schemes: oneplusbbsapp:// |
com.mob.tools.MobUIShell |
Schemes: tencent100371282:// |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Certificate valid not before | July 2, 2014, 1:31 p.m. |
Oldest file found in APK | July 2, 2014, 10:31 p.m. |
Latest file found in APK | July 2, 2014, 10:31 p.m. |
First submission on VT | April 20, 2020, 2:11 a.m. |
Upload on Pithus | Feb. 22, 2021, 3:36 a.m. |
Last submission on VT | March 27, 2021, 9:42 a.m. |
Certificate valid not after | June 26, 2039, 1:31 p.m. |
Score | 0/61 |
Report | https://www.virustotal.com/gui/file/4fde9a4c1ac63935e14d5170f01761a6b8dfe9aea2102ca1210b8bff32f59c32/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application implement DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['bluetooth', 'network connectivity', 'location']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_COP.1.1(1) | The application perform encryption/decryption not in accordance with FCS_COP.1.1(1), AES-ECB mode is being used. Cryptographic Operation - Encryption/Decryption |
FCS_COP.1.1(2) | The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5. Cryptographic Operation - Hashing |
FCS_COP.1.1(4) | The application perform keyed-hash message authentication with cryptographic algorithm ['HMAC-SHA1'] . Cryptographic Operation - Keyed-Hash Message Authentication |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FCS_HTTPS_EXT.1.3 | The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid. HTTPS Protocol |
FIA_X509_EXT.1.1 | The application invoked platform-provided functionality to validate certificates in accordance with the following rules: ['The certificate path must terminate with a trusted CA certificate', 'RFC 5280 certificate validation and certificate path validation']. X.509 Certificate Validation |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
FPT_TUD_EXT.2.1 | The application shall be distributed using the format of the platform-supported package manager. Integrity for Installation and Update |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
High | Base config is insecurely configured to permit clear text traffic to all domains. Scope: ['*'] |
Information computed with MobSF.
Information computed with MobSF.
www.oneplusbbs.com Defined in io/ganguo/library/util/f.java |
|
http://api.share.mob.com:80 http://up.sharesdk.cn/upload/image http://l.mob.com/url/ShareSdkMapping.do Defined in cn/sharesdk/framework/b/c.java |
|
https://){1} Defined in cn/sharesdk/framework/b/a.java |
|
https://api.weibo.com/2/friendships/create.json https://open.weibo.cn/oauth2/authorize? https://api.weibo.com/oauth2/default.html https://api.weibo.com/2/users/show.json https://api.weibo.com/2/friendships/followers.json https://api.weibo.com/2/statuses/upload.json https://api.weibo.com/2/friendships/friends/bilateral.json https://api.weibo.com/oauth2/access_token https://api.weibo.com/2/friendships/friends.json https://api.weibo.com/2/statuses/upload_url_text.json https://api.weibo.com/2/statuses/update.json https://api.weibo.com/2/statuses/user_timeline.json Defined in cn/sharesdk/sina/weibo/d.java |
|
http://weibo.com/ Defined in cn/sharesdk/sina/weibo/SinaWeibo.java |
|
https://api.weixin.qq.com/sns/oauth2/access_token https://api.weixin.qq.com/sns/oauth2/refresh_token https://api.weixin.qq.com/sns/userinfo Defined in cn/sharesdk/wechat/utils/g.java |
|
https://www.douban.com/service/auth2/token https://api.douban.com https://www.douban.com https://api.douban.com/shuo/v2/statuses/ Defined in cn/sharesdk/douban/a.java |
|
http://www.myapp.com/down/ Defined in cn/sharesdk/tencent/qq/f.java |
|
https://graph.qq.com/oauth2.0/me https://graph.qq.com/user/get_simple_userinfo https://graph.qq.com/oauth2.0/m_authorize?response_type=token&client_id= https://graph.qq.com http://openmobile.qq.com/api/check? Defined in cn/sharesdk/tencent/qq/b.java |
|
https://graph.qq.com/user/get_simple_userinfo https://graph.qq.com/oauth2.0/me https://graph.qq.com/oauth2.0/m_authorize?response_type=token&client_id= https://graph.qq.com/photo/upload_pic https://graph.qq.com Defined in cn/sharesdk/tencent/qzone/b.java |
|
http://xmlpull.org/v1/doc/features.html#indent-output Defined in com/ta/utdid2/c/a/e.java |
|
http://xmlpull.org/v1/doc/features.html#indent-output Defined in com/ta/utdid2/c/a/a.java |
|
http://hydra.alibaba.com/ Defined in com/ta/utdid2/a/b.java |
|
https://172.17.100.23:18806 https://api.open.oppomobile.com https://intlapi.cdo.oppomobile.com https://cn-store-test.wanyol.com https://awsstore.wanyol.com https://oppo-sea.store-test.wanyol.com Defined in com/heytap/upgrade/util/Constants.java |
|
https://ulogs.umeng.com/unify_logs https://alogus.umeng.com/unify_logs https://alogsus.umeng.com/unify_logs https://ulogs.umengcloud.com/unify_logs Defined in com/umeng/commonsdk/statistics/UMServerURL.java |
|
https://lark.alipay.com/yj131525/byt0wl/ufnf3i#A10200 Defined in com/umeng/commonsdk/statistics/internal/c.java |
|
https://cmnsguider.yunos.com:443/genDeviceToken Defined in com/umeng/commonsdk/statistics/idtracking/s.java |
|
https://plbslog.umeng.com https://ouplog.umeng.com Defined in com/umeng/commonsdk/stateless/a.java |
|
https://developer.umeng.com/docs/66632/detail/ Defined in com/umeng/commonsdk/debug/UMLogUtils.java |
|
http://alog.umeng.com/app_logs http://alog.umeng.co/app_logs http://oc.umeng.com/check_config_update http://oc.umeng.co/check_config_update Defined in com/umeng/analytics/a.java |
|
http://log.umsns.com/ http://log.umsns.com/share/api/ Defined in com/umeng/analytics/social/e.java |
|
http://log.umsns.com/share/api/ Defined in com/umeng/analytics/social/f.java |
|
https://opendev8.oneplus.cn https://open.oneplus.cn https://cf.1plus.io/ https://wwwtest13.oneplusbbs.com https://www.oneplusbbs.com https://apitest13.oneplusbbs.com https://api.oneplusbbs.com Defined in com/oneplus/bbs/bean/APIConstants.java |
|
https://account.oneplus.com/cn/login/forget Defined in com/oneplus/bbs/ui/activity/RedirectActivity.java |
|
file:///android_asset/privacy_policy.html file:///android_asset/privacy_policy_night.html file:///android_asset/user_agreement.html file:///android_asset/user_agreement_night.html https://www.oneplus.com https://account.oneplus.com/cn/agreement_privacy https://account.oneplus.com/cn/agreement Defined in com/oneplus/bbs/ui/activity/AboutUsActivity.java |
|
https://store.oneplus.com/cn/order/pay https://store.oneplus.com/cn https://storetest32.oneplus.com/cn javascript:COMMUNITY_APP_BACK() https://mapi.alipay.com javascript:COMMUNITY_APP_ACCOUNT_LOGIN_SUCCESS() Defined in com/oneplus/bbs/ui/fragment/StoreFragment.java |
|
http://player.youku.com/embed/%s http://player.youku.com https://player.youku.com http://v.youku.com https://v.youku.com file:///android_res/mipmap/emoji_ file:///android_asset/loading_failed.png'; Defined in com/oneplus/bbs/ui/fragment/ThreadsDetailFragment.java |
|
https://www https://www.oneplusbbs.com/static/image/smiley/wanzai2/ http://www https://apitest11 https://static Defined in com/oneplus/bbs/ui/adapter/MessageAdapter.java |
|
https://image01.oneplus.cn/user/201405/30/1016/521849aafd8fbf02edb41c5b6f6ac0b5.jpg http://pan.baidu.com/ Defined in com/oneplus/bbs/ui/adapter/DefLoadOperation.java |
|
file:///android_res/mipmap/emoji_%s.png Defined in com/oneplus/platform/library/c/a.java |
|
https://www.oneplus.com/global/legal/privacy-policy Defined in com/oneplus/lib/app/AboutActivity.java |
|
http://schemas.android.com/apk/res/android Defined in com/oneplus/support/core/content/d/b.java |
|
http://example.com/ Defined in cz/msebera/android/httpclient/impl/client/cache/CacheKeyGenerator.java |
|
http://c.data.mob.com/v2/cdata Defined in a/b/a/g.java |
|
http://m.data.mob.com/v2/cconf Defined in a/b/a/c.java |
|
http://api.exc.mob.com:80 Defined in a/b/a/n/d.java |
|
http://devs.data.mob.com:80/dinfo http://devs.data.mob.com:80/dsign Defined in a/b/a/e/b.java |
|
www.oneplus.com Defined in Android String Resource |
Information computed with MobSF.
Information computed with Exodus-core.
Umeng Analytics | https://reports.exodus-privacy.eu.org/fr/trackers/119 |
Information computed with Quark-Engine.
Confidence:
|
Write HTTP input stream into a file |
Confidence:
|
Get the current WiFi id |
Confidence:
|
Get location of the current GSM and put it into JSON |
Confidence:
|
Get the network operator name and IMSI |
Confidence:
|
Load external class |
Confidence:
|
Run shell script programmably |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) |
Confidence:
|
Query the list of the installed packages |
Confidence:
|
Get absolute path of file and put it to JSON object |
Confidence:
|
Find a method from given class name, usually for reflection |
Confidence:
|
Write the IMSI number into a file |
Confidence:
|
Check the active network type |
Confidence:
|
Connect to a URL and receive input stream from the server |
Confidence:
|
Method reflection |
Confidence:
|
Install other APKs from file |
Confidence:
|
Get the network operator name |
Confidence:
|
Connect to a URL and read data from it |
Confidence:
|
Save the response to JSON after connecting to the remote server |
Confidence:
|
Load class from given class name |
Confidence:
|
Retrieve data from broadcast |
Confidence:
|
Write the IMEI number into a file |
Confidence:
|
Read sensitive data(SMS, CALLLOG, etc) |
Confidence:
|
Open a file from given absolute path of the file |
Confidence:
|
Check the current network type |
Confidence:
|
Put data in cursor to JSON object |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) via setData |
Confidence:
|
Connect to a URL and get the response code |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Get the current WiFi id and put it into JSON. |
Confidence:
|