事情的起因是这样的,群里有位小朋友的手机被锁了,问及原因,原来是下载了一个名叫“cf外挂助手激活版”的这么一个软件,我收到了这份软件之后看到他是这样的…
emmmmm………..这样一来便更加深了我对他小白的印象
接下来我将这个文件上传到哈勃分析系统(https://habo.qq.com/)
将.apk文件放入Android killer中,发现入口M,查看代码信息:
.class public Lcom/h/M;
.super Landroid/app/Activity;
.source “M.java”# direct methods
.method public constructor()V
.locals 3.prologue
.line 25
move-object v0, p0move-object v2, v0
invoke-direct {v2}, Landroid/app/Activity;->
()V return-void
.end method.method private activiteDevice()V
.locals 13
.annotation system Ldalvik/annotation/Signature;
value = {
“()V”
}
.end annotation.prologue
.line 19
move-object v0, p0new-instance v5, Landroid/content/Intent;
move-object v12, v5
move-object v5, v12
move-object v6, v12
const-string v7, “android.app.action.ADD_DEVICE_ADMIN”
invoke-direct {v6, v7}, Landroid/content/Intent;->
(Ljava/lang/String;)V move-object v1, v5
.line 20
new-instance v5, Landroid/content/ComponentName;move-object v12, v5
move-object v5, v12
move-object v6, v12
move-object v7, v0
:try_start_0
const-string v8, “com.h.MyAdmin”invoke-static {v8}, Ljava/lang/Class;->forName(Ljava/lang/String;)Ljava/lang/Class;
:try_end_0
.catch Ljava/lang/ClassNotFoundException; {:try_start_0 .. :try_end_0} :catch_0move-result-object v8
invoke-direct {v6, v7, v8}, Landroid/content/ComponentName;->
(Landroid/content/Context;Ljava/lang/Class;)V move-object v2, v5
.line 21
move-object v5, v1const-string v6, “android.app.extra.DEVICE_ADMIN”
move-object v7, v2
invoke-virtual {v5, v6, v7}, Landroid/content/Intent;->putExtra(Ljava/lang/String;Landroid/os/Parcelable;)Landroid/content/Intent;
move-result-object v5
.line 24
move-object v5, v0move-object v6, v1
const/4 v7, 0x0
invoke-virtual {v5, v6, v7}, Lcom/h/M;->startActivityForResult(Landroid/content/Intent;I)V
return-void
.line 20
:catch_0
move-exception v5move-object v3, v5
new-instance v5, Ljava/lang/NoClassDefFoundError;
move-object v12, v5
move-object v5, v12
move-object v6, v12
move-object v7, v3
invoke-virtual {v7}, Ljava/lang/Throwable;->getMessage()Ljava/lang/String;
move-result-object v7
invoke-direct {v6, v7}, Ljava/lang/NoClassDefFoundError;->
(Ljava/lang/String;)V throw v5
.end method# virtual methods
.method public onCreate(Landroid/os/Bundle;)V
.locals 5
.annotation system Ldalvik/annotation/Signature;
value = {
“(“,
“Landroid/os/Bundle;”,
“)V”
}
.end annotation.annotation runtime Ljava/lang/Override;
.end annotation.prologue
move-object v0, p0move-object v1, p1
move-object v3, v0
invoke-static {v3}, LLogCatBroadcaster;->start(Landroid/content/Context;)V
.line 13
move-object v3, v0move-object v4, v1
invoke-super {v3, v4}, Landroid/app/Activity;->onCreate(Landroid/os/Bundle;)V
.line 14
move-object v3, v0invoke-direct {v3}, Lcom/h/M;->activiteDevice()V
return-void
.end method
未发现有意义的线索,接下来尝试搜索“序列 ”
nice,成功找到密码:beautifulflower,前提是得使得序列 为0,这里就需要手机进行双清操作了,没办法,谁让贪小便宜呢
顺便挂下传播勒索软件人的qq:543892683,相信这也不是他本人做的,应该是 上找的一键生成程序
顺便告诫下大家,莫贪小便宜,不要随便下群里所谓的“黑客工具”“盗 软件”“辅助外挂”之类的东西,十有八九都是有病毒的
相关资源:地摊叫卖广告软件 商场促销 文字转换声音 卖场叫卖语音广告制作
声明:本站部分文章及图片源自用户投稿,如本站任何资料有侵权请您尽早请联系jinwei@zod.com.cn进行处理,非常感谢!