4

开盒(?)拼多多

(偷)
**如果您有任何财务限制、技术限制、社会限制,使你被困在中国应用。留意您可用的、帮助减轻您的独特威胁的选择。

拼多多恶意⾏为分析报告:https://github.com/davincifans101/pinduoduo_backdoor_detailed_report/blob/main/report_cn.pdf
  1. 保活⾏为,指将⾃⼰加⼊系统的⾃启动⽩名单、关联启动⽩名单、后台⽩名单、锁屏⽩名单、悬浮窗、1像素透明图标、省电策略等⽅式,绕过系统强制休眠限制,持续后台存活。修改隐藏⾃⾝耗电量,逃避⽤户注意。
  2. 通过相关权限,绕过系统限制构造相关全屏⼴告、虚假通知(例如锁屏、解锁、全屏红包消息),诱导⽤户点击;劫持⽤户壁纸,劫持⽤户⽇历、闹钟等;⼀直展⽰消息未读状态,吸引⽤户点击;修改⽤户电池状态。
  3. 通过假图标、Widget等⽅式,让⽤户在桌⾯⽆法删除app;或通过注⼊系统进程⽅式,拦截回滚⽤户卸载操作
  4. 通过漏洞,突破隐私合规监管和系统限制,为⾃⾝添加权限,收集⽤户的位置、Wifi、识别码、相册、安装包信息、⽤户帐户信息、历史通知等,甚⾄包括聊天记录,对⽤户进⾏精准画像
  5. 提权后或通过漏洞,获取其他运⾏情况,获取其他App DAU、MAU和当前⻚⾯,通知历史。监控list中
  6. 明确包含淘宝、头条等多个头部⼚商
  7. 提权后攻击其他App、系统App,覆盖⽂件驻留后门,进⾏持久化;为⾃⾝添加权限;杀掉其他App。
  8. 利⽤应⽤市场接⼝、⼚商⼴告接⼝、浏览器、微信WebView漏洞,实现⽤户点击链接打开⽹⻚即被静默安装拼多多。结合社交裂变,效果巨⼤。通过URL跳转漏洞、XSS漏洞等为⾃⾝链接借助⽩域名加⽩,逃避微信、浏览器封禁




https://play.google.com/store/apps/details?id=com.xunmeng.pinduoduo
Report created on Dec. 2, 2022, 9:53 a.m.

追踪(2):
  1. JiGuang Aurora Mobile JPush
  2. https://ir.jiguang.cn/corporate-profileFounded in 2011, Aurora Mobile is a leading mobile big data solutions platform in China, pioneered in providing mobile developer services such as push notification, instant messaging, analytics, sharing and short message service (SMS). Aurora Mobile has accumulated data from approximately 1.39 million mobile applications that have utilized the Company’s developer services and nearly 30.8 billion installations of the Company’s software development kits (SDKs), with monthly active unique device base of nearly 1.34 billion, as of September 2019. Based on Aurora Mobile’s vast data coverage and insights garnered, the Company has expanded its offerings into big data solutions, including targeted marketing, financial risk management, market intelligence and location-based intelligence. By utilizing artificial intelligence and machine learning, Aurora Mobile strives to help improve productivity for businesses and society through harnessing the power of mobile big data to derive actionable insights and knowledge.Code detection rule: cn.jpush.androidNetwork detection rule: .*\.jiguang\.cn
  3. Tencent Stats
  4. http://stat.qq.com/AnalyticsCode detection rule: com.tencent.stat | com.tencent.wxop.statNetwork detection rule: NC

权限要求(75):
  1. ACCESS_COARSE_LOCATION
  2. access approximate location only in the foreground访问最突出的大概位置
  3. ACCESS_FINE_LOCATION
  4. access precise location only in the foreground访问最突出的精确位置
  5. ACCESS_MEDIA_LOCATION
  6. read locations from your media collection从您的媒体收藏中读取位置
  7. ACCESS_NETWORK_STATE
  8. view network connections查看网络连线
  9. ACCESS_WIFI_STATE
  10. view Wi-Fi connections查看Wi-Fi连线
  11. AUTHENTICATE_ACCOUNTS
  12. BLUETOOTH
  13. pair with Bluetooth devices与蓝牙设备配对
  14. BLUETOOTH_ADMIN
  15. access Bluetooth settings造访造访蓝牙设定
  16. CAMERA
  17. take pictures and videos拍取照片和影像
  18. CHANGE_NETWORK_STATE
  19. change network connectivity更改网络相互接线可能性
  20. CHANGE_WIFI_STATE
  21. connect and disconnect from Wi-Fi从Wi-Fi连线与断线
  22. FLASHLIGHT
  23. FOREGROUND_SERVICErun foreground service运行前景服务
  24. GET_ACCOUNTS
  25. find accounts on the device找到设备上的帐户
  26. GET_PACKAGE_SIZEmeasure app storage space计量应用存储空间
  27. INTERNET
  28. have full network access拥有完整的网络造访权
  29. MANAGE_ACCOUNTS
  30. MODIFY_AUDIO_SETTINGSchange your audio settings
  31. 更改你的音频设定
  32. READ_CONTACTSread your contacts
  33. 读取您的联络人
  34. READ_EXTERNAL_STORAGEread the contents of your shared storage
  35. 读取您的共享存储内容
  36. READ_LOGS
  37. READ_PHONE_NUMBERSread phone numbers
  38. 读取电话号码
  39. READ_PHONE_STATEread phone status and identity
  40. 读取电话狀況和身份
  41. READ_SYNC_SETTINGSread sync settings读取同步设定
  42. READ_SYNC_STATSread sync statistics读取同步统计资料
  43. RECEIVE_BOOT_COMPLETEDrun at startup
  44. 在启动时运行
  45. RECORD_AUDIOrecord audio
  46. 记录音讯
  47. SET_WALLPAPERset wallpaper
  48. 设置壁紙
  49. SYSTEM_ALERT_WINDOWThis app can appear on top of other apps
  50. 此应用程序可以出现在其他应用程序之上
  51. USE_BIOMETRIC
  52. use biometric hardware使用生物识别硬件
  53. USE_FINGERPRINTuse fingerprint hardware
  54. 使用指纹硬件
  55. VIBRATEcontrol vibration
  56. 控制震动
  57. WAKE_LOCKprevent phone from sleeping阻止电话睡眠
  58. WRITE_CALENDARadd or modify calendar events and send email to guests without owners' knowledge
  59. 添加或修改日历事件,和在没有所有者了解的狀況下向客人发送电子邮件
  60. WRITE_EXTERNAL_STORAGEmodify or delete the contents of your shared storage
  61. 修改或删除你的共享存储内容
  62. WRITE_SYNC_SETTINGS
  63. toggle sync on and off触发同步开/关
  64. SET_ALARM
  65. set an alarm

    设置警钟
  1. ID
  2. INSTALL_SHORTCUT
  3. install shortcuts安装捷径
  4. READ_SETTINGS
  5. UNINSTALL_SHORTCUTuninstall shortcuts
  6. 解除安装捷径
  7. WIRTE_SETTINGS
  8. READ_SETTINGS
  9. SHORTCUT_REMOVE
  10. WRITE_SETTINGS
  11. XCARD_INSTANT_SERVICE
  12. CHANGE_BADGE
  13. READ_SETTINGS
  14. WRITE_SETTINGS
  15. GET_COMMON_DATA
  16. RECEIVE
  17. READ_SETTINGS
  18. WRITE_SETTINGS
  19. PUSH
  20. RECEIVE
  21. READ_SETTINGS
  22. WRITE_SETTINGS
  23. READ_SETTINGS
  24. WRITE_USE_APP_FEATURE_SURVEY
  25. READ
  26. WRITE
  27. provider
  28. broadcast
  29. StepProvider
  30. BADGE_ICON
  31. screentime
  32. C2D_MESSAGE
  33. JPUSH_MESSAGE
  34. lifecycle
  35. NOTIFICATION_RECORD
  36. MESSAGE
  37. remote_config
  38. READ_STEPS
  39. READ_SETTINGS
  40. WRITE_SETTINGS
MvcTemples 23-03-29
最后编辑于: 23-03-29

要评论请先登录注册

1
艳阳Sunny 天马,雌驹。
支那输出腐败和堕落的一个小小侧面
更多...
评论
23-03-31
2
要不是狂到上 google play 让洋大人也用上,估计根本不会东窗事发。
更多...
评论
23-03-30