VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

Scanner results
Scanner results:3%Antivirus software(1/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2015-09-29 12:37:03 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 0
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 0
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 0
clamav 19861 0.97.5 2014-12-31 Found nothing 0
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 0
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 0
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 0
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 0
gdata 25.3658 25.3658 2015-09-28 Android.Trojan.AutoSMS.BH 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 0
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 41
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 0
kingsoft 2.1 2.1 2013-09-22 Found nothing 4
mcafee 7638 5400.1158 2014-11-30 Found nothing 0
nod32 0920 3.0.21 2014-12-23 Found nothing 0
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 0
qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 0
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 0
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 0
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 12
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 0
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 0
权限列表
许可名称 信息
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.READ_CONTACTS 读取联系人信息
android.permission.WRITE_CONTACTS 写入联系人信息
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.ACCESS_FINE_LOCATION 获取精确的位置(通过GPS)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.INTERNET 连接网络(2G或3G)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 挂载、反挂载外部文件系统
android.permission.READ_LOGS 读取系统日志
android.permission.VIBRATE 允许设备震动
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:17c9247119bbfe4e99759612c25fdb34
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.gdut.systemmail
最低运行环境:Android 2.2.x
版权:poi
关键行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
MSCTF.MarshalInterface.FileMap.AKH..LGHJH
MSCTF.MarshalInterface.FileMap.AKH.B.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.C.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.D.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.E.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.F.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.G.LGHJH
MSCTF.Shared.SFM.AKH
MSCTF.MarshalInterface.FileMap.AKH.H.APMNH
MSCTF.MarshalInterface.FileMap.AKH.I.AANNH
MSCTF.MarshalInterface.FileMap.AKH.J.AANNH
MSCTF.MarshalInterface.FileMap.AKH.K.AANNH
MSCTF.MarshalInterface.FileMap.AKH.L.AANNH
MSCTF.MarshalInterface.FileMap.AKH.M.AANNH
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a0, Text = EasyBCD 2.3 Setup , ClassName = #32770.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [Copyright NeoSmart Technologies 2011,Static]
[Window,Class] = [Copyright NeoSmart Technologies 2011 ,Static]
[Window,Class] = [,Static]
进程行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
MSCTF.MarshalInterface.FileMap.AKH..LGHJH
MSCTF.MarshalInterface.FileMap.AKH.B.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.C.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.D.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.E.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.F.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.G.LGHJH
MSCTF.Shared.SFM.AKH
MSCTF.MarshalInterface.FileMap.AKH.H.APMNH
MSCTF.MarshalInterface.FileMap.AKH.I.AANNH
MSCTF.MarshalInterface.FileMap.AKH.J.AANNH
MSCTF.MarshalInterface.FileMap.AKH.K.AANNH
MSCTF.MarshalInterface.FileMap.AKH.L.AANNH
MSCTF.MarshalInterface.FileMap.AKH.M.AANNH
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a0, Text = EasyBCD 2.3 Setup , ClassName = #32770.
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [Copyright NeoSmart Technologies 2011,Static]
[Window,Class] = [Copyright NeoSmart Technologies 2011 ,Static]
[Window,Class] = [,Static]
文件行为
VirSCANVirSCAN
行为描述: 写权限映射文件
详情信息: CiceroSharedMemDefaultS-*
MSCTF.MarshalInterface.FileMap.AKH..LGHJH
MSCTF.MarshalInterface.FileMap.AKH.B.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.C.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.D.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.E.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.F.LGHJH
MSCTF.MarshalInterface.FileMap.AKH.G.LGHJH
MSCTF.Shared.SFM.AKH
MSCTF.MarshalInterface.FileMap.AKH.H.APMNH
MSCTF.MarshalInterface.FileMap.AKH.I.AANNH
MSCTF.MarshalInterface.FileMap.AKH.J.AANNH
MSCTF.MarshalInterface.FileMap.AKH.K.AANNH
MSCTF.MarshalInterface.FileMap.AKH.L.AANNH
MSCTF.MarshalInterface.FileMap.AKH.M.AANNH
行为描述: 创建可执行文件
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\InstallOptions.dll
行为描述: 修改文件内容
详情信息: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 0
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 36
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\modern-wizard.bmp---> Offset = 49152
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 124
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 33
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 43
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 60
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 277
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 323
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 378
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 386
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 398
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 225
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 347
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\ioSpecial.ini---> Offset = 714
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\Local Settings
FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1
FileName = C:\DOCUME~1\ADMINI~1
FileName = C:\DOCUME~1
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\*.*
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\InstallOptions.dll.AmBackup1
注册表行为
VirSCANVirSCAN
行为描述: 修改注册表
详情信息: \REGISTRY\MACHINE\SYSTEM\ControlSet002\Control\Session Manager\PendingFileRenameOperations
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.AKH
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,Button]
[Window,Class] = [Copyright NeoSmart Technologies 2011,Static]
[Window,Class] = [Copyright NeoSmart Technologies 2011 ,Static]
[Window,Class] = [,Static]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [#32770,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [OleMainThreadWndClass,]
行为描述: 获取系统权限
详情信息: SE_LOAD_DRIVER_PRIVILEGE
行为描述: 屏蔽窗口关闭消息
详情信息: hWnd = 0x000202a0, Text = EasyBCD 2.3 Setup , ClassName = #32770.
行为描述: 窗口信息
详情信息: Pid = 1628, Hwnd=0x202a6, Text = &Next >, ClassName = Button.
Pid = 1628, Hwnd=0x202a8, Text = Cancel, ClassName = Button.
Pid = 1628, Hwnd=0x202d4, Text = Copyright NeoSmart Technologies 2011 , ClassName = Static.
Pid = 1628, Hwnd=0x302dc, Text = Copyright NeoSmart Technologies 2011, ClassName = Static.
Pid = 1628, Hwnd=0x302da, Text = Welcome to the EasyBCD 2.3 Setup Wizard, ClassName = Static.
Pid = 1628, Hwnd=0x302b8, Text = This wizard will guide you through the installation of EasyBCD 2.3. It is recommended that you close all other applications be, ClassName = Static.
Pid = 1628, Hwnd=0x202a0, Text = EasyBCD 2.3 Setup, ClassName = #32770.
Pid = 1628, Hwnd=0x202a6, Text = I &Agree, ClassName = Button.
Pid = 1628, Hwnd=0x402b8, Text = Press Page Down to see the rest of the agreement., ClassName = Static.
Pid = 1628, Hwnd=0x402da, Text = Subject to the terms and conditions of this License, Licensor hereby grants You a worldwide, royalty-free, non-exclusive, perpetu, ClassName = RichEdit20A.
Pid = 1628, Hwnd=0x302c6, Text = If you accept the terms of the agreement, click I Agree to continue. You must accept the agreement to install EasyBCD 2.3., ClassName = Static.
Pid = 1628, Hwnd=0x10344, Text = 是(&Y), ClassName = Button.
Pid = 1628, Hwnd=0x10346, Text = 否(&N), ClassName = Button.
Pid = 1628, Hwnd=0x1034a, Text = Are you sure you want to quit EasyBCD 2.3 Setup?, ClassName = Static.
Pid = 1628, Hwnd=0x10342, Text = EasyBCD 2.3 Setup, ClassName = #32770.
行为描述: 打开图片文件
详情信息: \DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsk6.tmp\modern-wizard.bmp
危险行为
VirSCANVirSCAN
行为描述: 发送短信
详情信息: number:15555421256 data:message:phone info : sim : 89014103211118510720 device id : 357143040944263
动态列表行为
VirSCANVirSCAN
行为描述: 启动服务
详情信息: {"FLAG":0,"COMPONENT_NAME":"ComponentInfo{com.gdut.systemmail\/com.gdut.systemmail.service.EmailService}"}
{"FLAG":268435456,"COMPONENT_NAME":"ComponentInfo{com.gdut.systemmail\/com.gdut.systemmail.service.EmailService}"}
行为描述: 获取加密实例
详情信息: [u'AES/CBC/PKCS5Padding']
行为描述: 设置组件属性
详情信息: [u'ComponentInfo{com.gdut.systemmail/com.gdut.systemmail.MainActivity}', u'2', u'1']
行为描述: 读取URL数据
详情信息: []
[]
[]
行为描述: 访问网络
详情信息: host:10.0.0.172 port:80
行为描述: 创建数据库
详情信息: /mnt/sdcard/baidu/tempdata/ls.db
/data/data/com.gdut.systemmail/files/ofld/ofl_location.db
/data/data/com.gdut.systemmail/files/ofld/ofl_statistics.db
/mnt/sdcard/baidu/tempdata//ls.db
行为描述: 初始化IntentFilter
详情信息: [u'android.net.wifi.SCAN_RESULTS']
[u'android.intent.action.BATTERY_CHANGED']
行为描述: 读取文件
详情信息: path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:6
path:/system/build.prop length:5
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:69
path:/data/data/com.gdut.systemmail/shared_prefs/phoneInformation.xml length:167
path:unknown length:24
path:/data/app/com.gdut.systemmail-1.apk length:9
path:/data/app/com.gdut.systemmail-1.apk length:23
path:/data/app/com.gdut.systemmail-1.apk length:68
path:/data/app/com.gdut.systemmail-1.apk length:7
path:/proc/mounts length:69
path:/proc/mounts length:5
path:/system/etc/vold.fstab length:69
path:/system/etc/vold.fstab length:5
path:/data/data/com.gdut.systemmail/files/lldt/firll.dat length:5
path:/data/data/com.gdut.systemmail/files/lldt/firll.dat length:9
path:/data/data/com.gdut.systemmail/files/lldt/firll.dat length:13
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:69
行为描述: 写入系统设置
详情信息: [u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'bd_setting_i', u'357143040944263']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'C72E5823CAD38B88EA3C12201509DCFE', u'C9ACA71280E23AF7E85A80454FD70C37']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'com.baidu.deviceid', u'C9ACA71280E23AF7E85A80454FD70C37']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'bd_setting_i', u'357143040944263']
[u'android.app.ContextImpl$ApplicationContentResolver@4154d800', u'bd_setting_i', u'357143040944263']
[u'android.app.ContextImpl$ApplicationContentResolver@4154d800', u'bd_setting_i', u'357143040944263']
行为描述: 监听手机SIM卡或者移动网络信息
详情信息: [u'com.baidu.location.h.b$a@414d0740', u'272']
行为描述: 查询Wifi热点扫描结果
详情信息: []
[]
[]
[]
[]
行为描述: 注册广播接收器
详情信息: [u'com.gdut.systemmail.service.EmailService$2@414f5688', u'android.content.IntentFilter@414d4f00']
[u'com.baidu.location.h.e$a@41544ad8', u'android.content.IntentFilter@41508638']
[u'com.baidu.location.e.e$a@414eb348', u'android.content.IntentFilter@414eb360']
[u'com.baidu.location.e.i$a@41503968', u'android.content.IntentFilter@41503980']
[u'com.gdut.systemmail.service.EmailService$2@414f5688', u'android.content.IntentFilter@41513eb0']
[u'com.gdut.systemmail.service.EmailService$2@414f5688', u'android.content.IntentFilter@41534830']
行为描述: 初始化Intent
详情信息: []
[u'com.gdut.systemmail.LocationApplication@4150de78', u'class com.baidu.location.f']
[u'android.os.Parcel@414aec78']
[u'android.os.Parcel@414aec38']
[u'android.os.Parcel@414aec78']
[u'android.os.Parcel@414adfa8']
[u'android.os.Parcel@414ad1b8']
[u'android.app.ReceiverRestrictedContext@414c9ba8', u'class com.gdut.systemmail.service.EmailService']
[u'android.os.Parcel@414adf68']
[u'SEND_LOCATION_TO_EMAIL']
[u'android.os.Parcel@414adfa8']
行为描述: 定位移动终端
详情信息: null
null
null
null
null
null
null
null
行为描述: 传递附加信息
详情信息: debug_dev:false
cache_exception:false
kill_process:true
行为描述: 调用哈希算法
详情信息: MD5
SHA1
行为描述: 解析通用资源标识符
详情信息: content://sms/
content://com.android.contacts
content://sms
content://sms
content://sms
行为描述: 注册ContentObserver
详情信息: URI=content://sms/
行为描述: 读取系统设置
详情信息: [u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'bd_setting_i']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'com.baidu.deviceid']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'C72E5823CAD38B88EA3C12201509DCFE']
[u'android.app.ContextImpl$ApplicationContentResolver@41507f98', u'bd_setting_i']
[u'android.app.ContextImpl$ApplicationContentResolver@4154d800', u'bd_setting_i']
[u'android.app.ContextImpl$ApplicationContentResolver@4154d800', u'com.baidu.deviceid']
[u'android.app.ContextImpl$ApplicationContentResolver@4154d800', u'bd_setting_i']
行为描述: 读取sdcard
详情信息: path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
行为描述: 发送广播
详情信息: {"ACTION":"SEND_LOCATION_TO_EMAIL","FLAG":0}
行为描述: 发送短信
详情信息: number:15555421256 data:message:phone info : sim : 89014103211118510720 device id : 357143040944263
行为描述: 写入文件
详情信息: path:/data/data/com.gdut.systemmail/files/libjiagu.so length:69
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:68
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:68
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:69
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:68
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:69
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:62
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:60
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:61
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:61
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:67
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:67
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:67
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:62
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:62
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:68
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:63
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:68
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:66
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:65
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:63
path:/data/data/com.gdut.systemmail/files/libjiagu.so length:64
path:/data/data/com.gdut.systemmail/shared_prefs/phoneInformation.xml length:167
path:/mnt/sdcard/baidu/.cuid length:69
path:/mnt/sdcard/contact.txt length:100
path:/mnt/sdcard/sms.txt length:203
path:/data/data/com.gdut.systemmail/files/lldt/firll.dat length:9
path:/data/data/com.gdut.systemmail/files/lldt/firll.dat length:13
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
path:/mnt/sdcard/baidu/tempdata/ller.dat length:69
path:/mnt/sdcard/baidu/tempdata/ller.dat length:9
行为描述: 初始化URL
详情信息: [u'file', u'', u'-1', u'/data/app/com.gdut.systemmail-1.apk', u'null']
[u'jar:file:/data/app/com.gdut.systemmail-1.apk!/mailcap']
[u'file', u'', u'-1', u'/data/app/com.gdut.systemmail-1.apk', u'null']
[u'jar:file:/data/app/com.gdut.systemmail-1.apk!/mailcap']
[u'file', u'', u'-1', u'/data/app/com.gdut.systemmail-1.apk', u'null']
[u'jar:file:/data/app/com.gdut.systemmail-1.apk!/mimetypes.default']
行为描述: 获取设备ID
详情信息: 357143040944263
357143040944263
357143040944263
357143040944263
357143040944263
357143040944263
行为描述: 读取手机短信
详情信息: [u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
[u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
[u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
行为描述: 加载链接库文件
详情信息: /data/data/com.gdut.systemmail/files/libjiagu.so
行为描述: 隐藏桌面快捷图标
详情信息: [u'ComponentInfo{com.gdut.systemmail/com.gdut.systemmail.MainActivity}', u'2', u'1']
行为描述: 获取当前连接的Wifi热点信息
详情信息: []
[]
行为描述: 获取用户ID
详情信息: 460000043140572
460000043140572
行为描述: 缓冲区读取一行数据
详情信息: #
# @(#)mailcap 1.8 05/04/20
#
# Default mailcap file for the JavaMail System.
#
# JavaMail content-handlers:
#
text/plain;; x-java-content-handler=com.sun.mail.handlers.text_plain
text/html;; x-java-content-handler=com.sun.mail.handlers.text_html
text/xml;; x-java-content-handler=com.sun.mail.handlers.text_xml
#
multipart/*;; x-java-content-handler=com.sun.mail.handlers.multipart_mixed; x-java-fallback-entry=true
# @(#)mailcap 1.8 05/04/20
#
# Default mailcap file for the JavaMail System.
message/rfc822;; x-java-content-handler=com.sun.mail.handlers.message_rfc822
#
# JavaMail content-handlers:
#
text/plain;; x-java-content-handler=com.sun.mail.handlers.text_plain
#
# can't support image types because myjava.awt.Toolkit doesn't work on servers
text/html;; x-java-content-handler=com.sun.mail.handlers.text_html
text/xml;; x-java-content-handler=com.sun.mail.handlers.text_xml
#
#image/gif;; x-java-content-handler=com.sun.mail.handlers.image_gif
#image/jpeg;; x-java-content-handler=com.sun.mail.handlers.image_jpeg
null
multipart/*;; x-java-content-handler=com.sun.mail.handlers.multipart_mixed; x-java-fallback-entry=true
message/rfc822;; x-java-content-handler=com.sun.mail.handlers.message_rfc822
#
# can't support image types because myjava.awt.Toolkit doesn't work on servers
#
#image/gif;; x-java-content-handler=com.sun.mail.handlers.image_gif
#image/jpeg;; x-java-content-handler=com.sun.mail.handlers.image_jpeg
null
#
# A simple, old format, mime.types file
#
text/html html htm HTML HTM
text/plain txt text TXT TEXT
image/gif gif GIF
image/ief ief
image/jpeg jpeg jpg jpe JPG
image/tiff tiff tif
image/png png PNG
image/x-xwindowdump xwd
application/postscript ai eps ps
application/rtf rtf
application/x-tex tex
application/x-texinfo texinfo texi
行为描述: 查询App共享数据
详情信息: [u'content://com.android.contacts/data', u'[data1, raw_contact_id]', u'mimetype= ?', u'[vnd.android.cursor.item/name]', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 2', u'null', u'null']
[u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1, raw_contact_id]', u'mimetype= ?', u'[vnd.android.cursor.item/name]', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 1', u'null', u'null']
[u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1, raw_contact_id]', u'mimetype= ?', u'[vnd.android.cursor.item/name]', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 3 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 1 AND data2 = 1', u'null', u'null']
[u'content://sms', u'[address, date, body, type]', u'null', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 2 AND data2 = 1', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 2', u'null', u'null']
[u'content://com.android.contacts/data', u'[data1]', u'raw_contact_id = 4 AND data2 = 1', u'null', u'null']
行为描述: 获取网络状态信息[*]
详情信息: NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
[NetworkInfo: type: mobile[UMTS], state: DISCONNECTED/DISCONNECTED, reason: dataDisabled, extra: epc.tmobile.com, roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false, NetworkInfo: type: mobile_mms[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_supl[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_hipri[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_fota[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_ims[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_cbs[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi_p2p[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false]
[NetworkInfo: type: mobile[UMTS], state: DISCONNECTED/DISCONNECTED, reason: dataDisabled, extra: epc.tmobile.com, roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false, NetworkInfo: type: mobile_mms[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_supl[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_hipri[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_fota[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_ims[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_cbs[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi_p2p[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false]
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
[NetworkInfo: type: mobile[UMTS], state: DISCONNECTED/DISCONNECTED, reason: dataDisabled, extra: epc.tmobile.com, roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false, NetworkInfo: type: mobile_mms[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_supl[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_hipri[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_fota[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_ims[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: mobile_cbs[UMTS], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: true, NetworkInfo: type: wifi_p2p[], state: UNKNOWN/IDLE, reason: (unspecified), extra: (none), roaming: false, failover: false, isAvailable: false]
NetworkInfo: type: WIFI[], state: CONNECTED/CONNECTED, reason: (unspecified), extra: freewifi, roaming: false, failover: false, isAvailable: true
行为描述: 写入sdcard
详情信息: path:/mnt/sdcard/baidu/.cuid
path:/mnt/sdcard/contact.txt
path:/mnt/sdcard/sms.txt
path:/mnt/sdcard/contact.txt
path:/mnt/sdcard/sms.txt
path:/mnt/sdcard/contact.txt
path:/mnt/sdcard/sms.txt
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
path:/mnt/sdcard/baidu/tempdata/ller.dat
Activities
VirSCANVirSCAN
活动名 类型
com.gdut.systemmail.MainActivity android.intent.action.MAIN
com.gdut.systemmail.MainActivity android.intent.category.DEFAULT
com.gdut.systemmail.MainActivity android.intent.category.LAUNCHER
启动方式
VirSCANVirSCAN
名称 信息
com.gdut.systemmail.receiver.BootCompleteReceiver 开机启动服务
广告信息
VirSCANVirSCAN
名称 信息
com.baidu 百度
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.READ_SMS 读取短信
android.permission.WRITE_SMS 写短信
android.permission.READ_CONTACTS 读取联系人信息
android.permission.WRITE_CONTACTS 写入联系人信息
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.ACCESS_COARSE_LOCATION 获取粗略的位置(通过wifi、基站)
android.permission.ACCESS_FINE_LOCATION 获取精确的位置(通过GPS)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.INTERNET 连接网络(2G或3G)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS 挂载、反挂载外部文件系统
android.permission.READ_LOGS 读取系统日志
android.permission.VIBRATE 允许设备震动
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
服务列表
VirSCANVirSCAN
名称
com.gdut.systemmail.service.EmailService
com.baidu.location.f
文件列表
VirSCANVirSCAN
文件名 校验码
META-INF/MANIFEST.MF 0x9a188ad3
META-INF/ANDROID_.SF 0xf07d45ad
META-INF/ANDROID_.RSA 0x34386fd9
AndroidManifest.xml 0xb09fdbd1
assets/ 0x0
assets/libjiagu.so 0x2cc8a022
assets/libjiagu_x86.so 0x70e57ad
classes.dex 0x23b9f778
com/sun/mail/dsn/mailcap 0x7605dc17
dsn.mf 0x1e4e9355
javamail.charset.map 0xad0dfcee
javamail.default.address.map 0xf20496b
javamail.default.providers 0x45ea1b21
javamail.imap.provider 0x8934555a
javamail.pop3.provider 0xa23c9bc
javamail.smtp.address.map 0xf20496b
javamail.smtp.provider 0x990c469d
lib/armeabi-v7a/liblocSDK6a.so 0xbd43d388
lib/armeabi/liblocSDK6a.so 0xaee383c3
mailcap 0xd7759e43
mailcap.default 0x6f616b6
mimetypes.default 0x97dd5cdb
org/apache/harmony/awt/internal/nls/messages.properties 0x5f88eb12
res/drawable-hdpi/ic_launcher.png 0x86c9a968
res/layout/main.xml 0x76a7fc71
resources.arsc 0xfe6d9158
运行截图
VirSCANVirSCAN
VirSCAN