科技不在高高在上 Security should never feel elite
节程安全在安卓端侧运行:不靠吓人弹窗,不堆杀软皮肤,只盯“伪装系统、无图标、强权限、异常外联”这类真问题。 JieCheng Seal runs on-device: no scareware, no skin factory—just real signals like fake-system names, hidden icons, abusive permissions and strange connections.
待填真值三件事,做透就够了Three things, done deeply
大厂不是功能多,是把不该有的删光。节程只守三条线: Enterprise feel means deleting what does not matter. Seal guards only three lines:
① 伪装系统组件① Fake-system components
“System Service / 系统更新 / vivo 插件”这类无桌面图标、借系统名信任的,直接进观察队列。 Names like System Service / System Update / OEM plugin with no launcher icon get queued, not trusted.
② 强权限滥用② Permission abuse
无障碍、设备管理员、相机、录音、短信——不是不能要,是看“谁、为什么、装完干啥”。 Accessibility, device admin, camera, mic, SMS: allowed only when behavior matches intent.
③ 哈希 + 行为双路③ Hash + behavior
公开引擎按名拦,节程按 SHA-256 命中 + 行为分判定。改名没用,动一行字节就变。 Public engines match names; Seal matches SHA-256 plus behavior. Renaming does nothing.
System Service 伪装木马说明About the “System Service” fake-app malware
该样本伪装成 vivo / iQOO / 通用安卓的“系统服务”,无图标、诱导开无障碍和设备管理员,借系统信任窃密。游龙(VirusTotal 公开引擎)已测为 0 检出;昆明引擎按“哈希 + 行为”本地判定,结果待离线虚拟机验证。 The sample impersonates a vivo/iQOO/Android “System Service”: no icon, pushes accessibility/device-admin, abuses OEM trust. Youlong public engines show 0/clean; Kunming engine judges by hash + behavior, verified in offline VM.
原版未见投毒证据;借破解包、不良网站、QQ 群文件传播的是被篡改包。节程不查哈希玄学,只拉 abuse.ch / Hybrid Analysis,进光速虚拟机断网跑。 No poisoning found in the original build. Repacked samples spread via crack sites and chat groups. Seal pulls from abuse.ch / Hybrid Analysis, runs in an offline VM—no magic hash search.
节程 · 昆明引擎 vs 游龙JieCheng Kunming vs Youlong
游龙Youlong: 公开/云查引擎,按样本名、特征、VT 聚合结果拦。System Service 这类免杀包会“全绿”。 Public/cloud engine. Matches names and signatures. Packers like System Service go all-green.
昆明引擎(节程)Kunming Engine (Seal): 端侧行为引擎。先装节程 → 再装样本 → 断网 → 看是否申设备管理员/无障碍/外联。行为分由本地算,不靠商店审核。 On-device behavior engine. Seal first, sample second, network off: watch device-admin/accessibility/beacon requests. Score is local, not store-approved.
对外口径:游龙已测 0 检出,昆明待本地验证。不写“已拦截”,不写“行为分拉满”。 External line: Youlong tested 0/clean, Kunming pending local verification. Never claim “already blocked”.
支持我们Support Us
节程不做弹窗勒索式“杀毒会员”。你愿意就扫微信,不愿意关掉继续用,功能不砍。 No scareware membership. Scan if you want, close if you don’t—features stay the same.

跑在哪Where it runs
Android 9+ 真机 / 光速虚拟机 / 离线安卓沙箱。样本永远不进真机存储,只进虚拟机;真机只当“快递柜 + 行为裁判台”。 Android 9+, real device, LightSpeed VM, offline emulator. Samples never touch real storage—VM only. Phone = locker + judge bench.