
我收到了一个示例应用,想看看它是如何做诈骗的, 但看权限申请也没啥奇怪的 应用是一个很简单的记事本, 把 aab 下载链接放这了: https://www.123865.com/s/3ulGvd-wMxMd ,有兴趣的话可以看看它是怎么做热更新诈骗, 小弟非常好奇了
这下面要求了哪些权限(问了 GPT 都是一些很普通的权限, 没有涉及高危权限) package: com.rbombanza.suga uses-permission: name='android.permission.INTERNET' permission: com.rbombanza.suga.permission.C2D_MESSAGE uses-permission: name='com.rbombanza.suga.permission.C2D_MESSAGE' uses-permission: name='android.permission.POST_NOTIFICATIONS' uses-permission: name='android.permission.WAKE_LOCK' uses-permission: name='com.google.android.c2dm.permission.RECEIVE' uses-permission: name='android.permission.VIBRATE' uses-permission: name='android.permission.RECEIVE_BOOT_COMPLETED' uses-permission: name='com.sec.android.provider.badge.permission.READ' uses-permission: name='com.sec.android.provider.badge.permission.WRITE' uses-permission: name='com.htc.launcher.permission.READ_SETTINGS' uses-permission: name='com.htc.launcher.permission.UPDATE_SHORTCUT' uses-permission: name='com.huawei.android.launcher.permission.CHANGE_BADGE' uses-permission: name='com.huawei.android.launcher.permission.READ_SETTINGS' uses-permission: name='com.huawei.android.launcher.permission.WRITE_SETTINGS' uses-permission: name='me.everything.badger.permission.BADGE_COUNT_READ' uses-permission: name='android.permission.ACCESS_NETWORK_STATE' uses-permission: name='android.permission.FOREGROUND_SERVICE' permission: com.rbombanza.suga.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION uses-permission: name='com.rbombanza.suga.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION' uses-permission: name='android.permission.ACCESS_ADSERVICES_ATTRIBUTION' uses-permission: name='com.google.android.gms.permission.AD_ID' uses-permission: name='com.samsung.android.mapsagent.permission.READ_APP_INFO' uses-permission: name='com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA' uses-permission: name='com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE'