Threat level
Analyzed on 2021-12-21T02:22:52.173728
MD5 | 6b21d67138638084b59b0beaad64bb35 | |
SHA1 | 13f1017221f46bc35c8ebd267adde33585c0529d | |
SHA256 | 691b02f853ffc14ee2e2abd3a7cf6afddf01685c190af9651b07fb1ebd898737 | |
Size | 7.23MB |
Information computed with APKiD.
/tmp/tmpai9ut16t!classes.dex | |
anti_vm |
|
compiler |
|
/tmp/tmpai9ut16t!classes2.dex | |
anti_vm |
|
compiler |
|
Information computed with ssdeep.
APK file | 98304:uPSRM6d2kigjss197xpJcSwbYTvtLjykH6OxAkBNX4ZTHpdjv7eHIV2EWN0UU26M:PKnG11aOnj5x5f2djaONW5Y85HhS8rH | |
Manifest | 384:NZKd+NTP5UQtu1TE7Oe9TVTyGBa9g5hVhnYVWTRAisciCSLWunghAULGM:Od+NTP5… | |
classes.dex | 49152:JlVgIfBRMflcRcvdaD6o7oJL+cYcIEaHfd7NK9FK629s23Lck13giW489rB:JgI… | |
classes2.dex | 49152:d5IPEAK2JHX/pRkAdPAJE9gFDLDe8a4waIXbXxH8:dBg/pndcFDLDfIL6 |
Information computed with Dexofuzzy.
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
Low | App has a Network Security Configuration[android:networkSecurityConfig=@xml/network_security_config] The Network Security Configuration feature lets apps customize their network security settings in a safe, declarative configuration file without modifying app code. These settings can be configured for specific domains and for a specific app. |
Medium | Application Data can be Backed up[android:allowBackup=true] This flag allows anyone to backup your application data via adb. It allows users who have enabled USB debugging to copy application data off of the device. |
High | Broadcast Receiver (cn.app.lib.version.download.DownloadPauseReceiver) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
High | Service (com.xiaomi.mipush.sdk.PushMessageHandler) is not Protected. [android:exported=true] A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Broadcast Receiver (com.xiaomi.push.service.receivers.NetworkStatusReceiver) is not Protected. [android:exported=true] A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Broadcast Receiver (cn.bidsun.lib.push.receiver.MessageReceiver) is not Protected. [android:exported=true] A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Activity (cn.app.lib.umeng.wxapi.WXEntryActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Activity (com.tencent.tauth.AuthActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
Information computed with MobSF.
com.glodon.appproduct.splash.NativeSplashActivity |
Hosts: virtual Schemes: open.app.gzhjy:// |
com.tencent.tauth.AuthActivity |
Schemes: \ 1110850219:// |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['network connectivity', 'camera']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_CKM.1.1(1) | The application generate asymmetric cryptographic keys not in accordance with FCS_CKM.1.1(1) using key generation algorithm RSA schemes and cryptographic key sizes of 1024-bit or lower. Cryptographic Asymmetric Key Generation |
FCS_COP.1.1(1) | The application perform encryption/decryption in accordance with a specified cryptographic algorithm AES-CBC (as defined in NIST SP 800-38A) mode or AES-GCM (as defined in NIST SP 800-38D) and cryptographic key sizes 256-bit/128-bit. Cryptographic Operation - Encryption/Decryption |
FCS_COP.1.1(2) | The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5. Cryptographic Operation - Hashing |
FCS_COP.1.1(4) | The application perform keyed-hash message authentication with cryptographic algorithm ['HMAC-SHA1'] . Cryptographic Operation - Keyed-Hash Message Authentication |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FCS_HTTPS_EXT.1.3 | The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid. HTTPS Protocol |
FIA_X509_EXT.1.1 | The application invoked platform-provided functionality to validate certificates in accordance with the following rules: ['The certificate path must terminate with a trusted CA certificate']. X.509 Certificate Validation |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
FPT_TUD_EXT.2.1 | The application shall be distributed using the format of the platform-supported package manager. Integrity for Installation and Update |
FCS_CKM.1.1(2) | The application shall generate symmetric cryptographic keys using a Random Bit Generator as specified in FCS_RBG_EXT.1 and specified cryptographic key sizes 128 bit or 256 bit. Cryptographic Symmetric Key Generation |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
High | Base config is insecurely configured to permit clear text traffic to all domains. Scope: ['*'] |
Information computed with MobSF.
Information computed with MobSF.
http://xmlpull.org/v1/doc/features.html#indent-output Defined in com/c/a/c/a/e.java |
|
http://xmlpull.org/v1/doc/features.html#indent-output Defined in com/c/a/c/a/a.java |
|
http://hydra.alibaba.com/ Defined in com/c/a/a/b.java |
|
https://api.xmpush.xiaomi.com/upload/xmsf_log?file= https://api.xmpush.xiaomi.com/upload/app_log?file= Defined in com/xiaomi/mipush/sdk/bo.java |
|
https://api.xmpush.xiaomi.com/upload/xmsf_log?file= https://api.xmpush.xiaomi.com/upload/app_log?file= Defined in com/xiaomi/mipush/sdk/bo.java |
|
https://api.xmpush.xiaomi.com/upload/crash_log?file= Defined in com/xiaomi/mipush/sdk/bq.java |
|
http://xmlpull.org/v1/doc/features.html#process-namespaces Defined in com/xiaomi/push/ey.java |
|
http://new.api.ad.xiaomi.com/logNotificationAdActions Defined in com/xiaomi/push/bw.java |
|
http://xmlpull.org/v1/doc/features.html#process-namespaces Defined in com/xiaomi/push/gb.java |
|
http://xmlpull.org/v1/doc/features.html#process-namespaces Defined in com/xiaomi/push/fj.java |
|
http://xmlpull.org/v1/doc/features.html#process-namespaces Defined in com/xiaomi/push/gc.java |
|
http://www.jivesoftware.com/xmlns/xmpp/properties Defined in com/xiaomi/push/fu.java |
|
https://cn.register.xmpush.xiaomi.com https://register.xmpush.global.xiaomi.com https://fr.register.xmpush.global.xiaomi.com https://ru.register.xmpush.global.xiaomi.com https://idmb.register.xmpush.global.xiaomi.com Defined in com/xiaomi/push/service/bj.java |
|
https://cn.register.xmpush.xiaomi.com https://register.xmpush.global.xiaomi.com https://fr.register.xmpush.global.xiaomi.com https://ru.register.xmpush.global.xiaomi.com https://idmb.register.xmpush.global.xiaomi.com Defined in com/xiaomi/push/service/bj.java |
|
https://cn.register.xmpush.xiaomi.com https://register.xmpush.global.xiaomi.com https://fr.register.xmpush.global.xiaomi.com https://ru.register.xmpush.global.xiaomi.com https://idmb.register.xmpush.global.xiaomi.com Defined in com/xiaomi/push/service/bj.java |
|
https://cn.register.xmpush.xiaomi.com https://register.xmpush.global.xiaomi.com https://fr.register.xmpush.global.xiaomi.com https://ru.register.xmpush.global.xiaomi.com https://idmb.register.xmpush.global.xiaomi.com Defined in com/xiaomi/push/service/bj.java |
|
https://cn.register.xmpush.xiaomi.com https://register.xmpush.global.xiaomi.com https://fr.register.xmpush.global.xiaomi.com https://ru.register.xmpush.global.xiaomi.com https://idmb.register.xmpush.global.xiaomi.com Defined in com/xiaomi/push/service/bj.java |
|
http://resolver.msg.xiaomi.net/psc/?t=a Defined in com/xiaomi/push/service/ai.java |
|
https://api.weixin.qq.com/sns/userinfo?access_token= https://api.weixin.qq.com/sns/oauth2/access_token? https://api.weixin.qq.com/sns/oauth2/refresh_token? https://api.weixin.qq.com/sns/oauth2/refresh_token?appid= Defined in com/umeng/weixin/handler/UmengWXHandler.java |
|
https://api.weixin.qq.com/sns/userinfo?access_token= https://api.weixin.qq.com/sns/oauth2/access_token? https://api.weixin.qq.com/sns/oauth2/refresh_token? https://api.weixin.qq.com/sns/oauth2/refresh_token?appid= Defined in com/umeng/weixin/handler/UmengWXHandler.java |
|
https://api.weixin.qq.com/sns/userinfo?access_token= https://api.weixin.qq.com/sns/oauth2/access_token? https://api.weixin.qq.com/sns/oauth2/refresh_token? https://api.weixin.qq.com/sns/oauth2/refresh_token?appid= Defined in com/umeng/weixin/handler/UmengWXHandler.java |
|
https://api.weixin.qq.com/sns/userinfo?access_token= https://api.weixin.qq.com/sns/oauth2/access_token? https://api.weixin.qq.com/sns/oauth2/refresh_token? https://api.weixin.qq.com/sns/oauth2/refresh_token?appid= Defined in com/umeng/weixin/handler/UmengWXHandler.java |
|
https://ulogs.umeng.com/unify_logs https://alogus.umeng.com/unify_logs https://alogsus.umeng.com/unify_logs https://ulogs.umengcloud.com/unify_logs Defined in com/umeng/commonsdk/statistics/UMServerURL.java |
|
https://ulogs.umeng.com/unify_logs https://alogus.umeng.com/unify_logs https://alogsus.umeng.com/unify_logs https://ulogs.umengcloud.com/unify_logs Defined in com/umeng/commonsdk/statistics/UMServerURL.java |
|
https://ulogs.umeng.com/unify_logs https://alogus.umeng.com/unify_logs https://alogsus.umeng.com/unify_logs https://ulogs.umengcloud.com/unify_logs Defined in com/umeng/commonsdk/statistics/UMServerURL.java |
|
https://ulogs.umeng.com/unify_logs https://alogus.umeng.com/unify_logs https://alogsus.umeng.com/unify_logs https://ulogs.umengcloud.com/unify_logs Defined in com/umeng/commonsdk/statistics/UMServerURL.java |
|
https://cmnsguider.yunos.com:443/genDeviceToken Defined in com/umeng/commonsdk/statistics/idtracking/s.java |
|
https://plbslog.umeng.com https://ouplog.umeng.com Defined in com/umeng/commonsdk/stateless/a.java |
|
https://plbslog.umeng.com https://ouplog.umeng.com Defined in com/umeng/commonsdk/stateless/a.java |
|
https://developer.umeng.com/docs/66632/detail/ Defined in com/umeng/commonsdk/debug/UMLogUtils.java |
|
https://graph.qq.com/oauth2.0/me?access_token= http://log.umsns.com/link/qq/download/ https://openmobile.qq.com/user/get_simple_userinfo?status_os= Defined in com/umeng/qq/handler/UmengQQHandler.java |
|
https://graph.qq.com/oauth2.0/me?access_token= http://log.umsns.com/link/qq/download/ https://openmobile.qq.com/user/get_simple_userinfo?status_os= Defined in com/umeng/qq/handler/UmengQQHandler.java |
|
https://graph.qq.com/oauth2.0/me?access_token= http://log.umsns.com/link/qq/download/ https://openmobile.qq.com/user/get_simple_userinfo?status_os= Defined in com/umeng/qq/handler/UmengQQHandler.java |
|
http://developer.umeng.com/docs/66650/cate/66650 Defined in com/umeng/analytics/pro/h.java |
|
https://log.umsns.com/ Defined in com/umeng/socialize/view/OauthDialog.java |
|
https://log.umsns.com/ https://log.umsns.com/link/qq/download/ https://log.umsns.com/link/weixin/download/ http://www.umeng.com/social Defined in com/umeng/socialize/common/SocializeConstants.java |
|
https://log.umsns.com/ https://log.umsns.com/link/qq/download/ https://log.umsns.com/link/weixin/download/ http://www.umeng.com/social Defined in com/umeng/socialize/common/SocializeConstants.java |
|
https://log.umsns.com/ https://log.umsns.com/link/qq/download/ https://log.umsns.com/link/weixin/download/ http://www.umeng.com/social Defined in com/umeng/socialize/common/SocializeConstants.java |
|
https://log.umsns.com/ https://log.umsns.com/link/qq/download/ https://log.umsns.com/link/weixin/download/ http://www.umeng.com/social Defined in com/umeng/socialize/common/SocializeConstants.java |
|
https://mobile.umeng.com/images/pic/home/social/img-1.png Defined in com/umeng/socialize/net/LinkcardRequest.java |
|
https://log.umsns.com/ Defined in com/umeng/socialize/net/base/SocializeRequest.java |
|
https://developer.umeng.com/docs/66632/detail/ Defined in com/umeng/socialize/utils/UrlUtil.java |
|
https://github.com/lingochamp/FileDownloader/wiki/filedownloader.properties Defined in com/liulishuo/filedownloader/services/a.java |
|
http://117.187.131.86:10010/venues/webApi/gtv-portal/queryNoticeCalendar?name=bohong&pwd=e10adc3949ba59abbe56e057f20f883e http://58.42.231.109:55539/venues/webApi/gtv-portal/queryNoticeCalendar?name=bohong&pwd=e10adc3949ba59abbe56e057f20f883e http://ggzy.guizhou.gov.cn/igs/front/search/list.html?filter Defined in com/glodon/appproduct/frament/HomeFrament.java |
|
javascript:document.getElementsByTagName('HEAD').item(0).removeChild(document.getElementById('QQBrowserSDKNightMode')); javascript:var http://debugtbs.qq.com http://debugx5.qq.com http://debugtbs.qq.com?10000 Defined in com/tencent/smtt/sdk/WebView.java |
|
javascript:document.getElementsByTagName('HEAD').item(0).removeChild(document.getElementById('QQBrowserSDKNightMode')); javascript:var http://debugtbs.qq.com http://debugx5.qq.com http://debugtbs.qq.com?10000 Defined in com/tencent/smtt/sdk/WebView.java |
|
javascript:document.getElementsByTagName('HEAD').item(0).removeChild(document.getElementById('QQBrowserSDKNightMode')); javascript:var http://debugtbs.qq.com http://debugx5.qq.com http://debugtbs.qq.com?10000 Defined in com/tencent/smtt/sdk/WebView.java |
|
www.qq.com http://pms.mb.qq.com/rsp204 Defined in com/tencent/smtt/sdk/i.java |
|
http://mdc.html5.qq.com/d/directdown.jsp?channel_id=11047 http://mdc.html5.qq.com/d/directdown.jsp?channel_id=11041 Defined in com/tencent/smtt/sdk/b/a/a.java |
|
http://mdc.html5.qq.com/d/directdown.jsp?channel_id=11047 http://mdc.html5.qq.com/d/directdown.jsp?channel_id=11041 Defined in com/tencent/smtt/sdk/b/a/a.java |
|
http://mdc.html5.qq.com/mh?channel_id=50079&u= Defined in com/tencent/smtt/sdk/a/c.java |
|
http://soft.tbs.imtt.qq.com/17421/tbs_res_imtt_tbs_DebugPlugin_DebugPlugin.tbs Defined in com/tencent/smtt/utils/d.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://log.tbs.qq.com/ajax?c=pu&v=2&k= http://log.tbs.qq.com/ajax?c=pu&tk= http://wup.imtt.qq.com:8080 http://log.tbs.qq.com/ajax?c=dl&k= http://cfg.imtt.qq.com/tbs?v=2&mk= http://log.tbs.qq.com/ajax?c=ul&v=2&k= http://mqqad.html5.qq.com/adjs http://log.tbs.qq.com/ajax?c=ucfu&k= Defined in com/tencent/smtt/utils/n.java |
|
http://rqd.uu.qq.com/rqd/sync http://android.bugly.qq.com/rqd/async Defined in com/tencent/bugly/crashreport/common/strategy/StrategyBean.java |
|
http://rqd.uu.qq.com/rqd/sync http://android.bugly.qq.com/rqd/async Defined in com/tencent/bugly/crashreport/common/strategy/StrategyBean.java |
|
http://schemas.android.com/apk/res/android Defined in pl/droidsonroids/gif/k.java |
|
http://schemas.android.com/apk/res/android Defined in pl/droidsonroids/gif/GifTextureView.java |
|
http://schemas.android.com/apk/res/android Defined in pl/droidsonroids/gif/GifTextView.java |
|
http://www.w3.org/2000/xmlns/ Defined in org/mozilla/javascript/xmlimpl/XmlNode.java |
Information computed with MobSF.