Closed ljh740 closed 4 years ago
会解密的啊 脚本是frida-iOS-dump的集成
Quantumult.zip 样本 PlugIns/Quantumult Network Extension.appex/Quantumult Network Extension otool -l Quantumult\ Network\ Extension.appex/Quantumult\ Network\ Extension |grep "cmd LC_ENCRYPTION_INFO" -A 4 cmd LC_ENCRYPTION_INFO_64 cmdsize 24 cryptoff 16384 cryptsize 1589248
我瞅瞅
Fixed in b6d314163ae5df1461708d577263ba8a3146c395
make sure to npm install -g bagbak
在Extension 里面的文件 cryptid 1