BCT Mobile icon

app-debug.apk

BCT Mobile

18.91 MB

Analyzed: 2026-04-14 13:05 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
91/100
Threat scan clean Debuggable build Modern target SDK
Privacy Permissions & network
45/100
High-risk permissions HTTP URLs found
60/100
Caution
Overall trust

Facts

Threat scan 0/76 flagged, 0 suspicious
Permissions 21 requested
Network strings 3 URLs (3 HTTP, 0 HTTPS)
Target SDK 34
Certificate Valid until 2053-03-09 (27 years, suspicious)

Warnings

Found 3 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES, android.permission.RECEIVE_BOOT_COMPLETED
Package Name com.itsi.bct.mobile
Version Code 50009
Version Name 5.0.1
Application Name com.itsi.bct.mobile.BctMobileApp
Debuggable Yes
Allow Backup No
Min SDK Android 29 (Android 10)
Target SDK Android 34 (Android 14)
Supported ABIs
Universal

Certificate & Signer

Valid From 2023-03-17 09:35:55
Valid To 2053-03-09 09:35:55
Serial Number 1
Thumbprint c6bf4b81cf07b108eb940521edc08a27525f2672
Issuer: C US
Issuer: CN Android Debug
Issuer: DN C:US, CN:Android Debug, O:Android
Issuer: O Android
Subject: C US
Subject: CN Android Debug
Subject: DN C:US, CN:Android Debug, O:Android
Subject: O Android

Security Scan

0 /76
✓ Clean
Scanned by 76 security vendors
Last scan: 2026-04-14 13:04 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
66
Timeout
0
Failure
1

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.769
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.29.3.10609
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260413-00
Avira undetected
No result reported
Engine 8.3.3.24
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.255
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44187AVA:64.31033
Google failure
No result reported
Engine 1776164461
Gridinsoft undetected
No result reported
Engine 1.0.243.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.47.59193
K7GW undetected
No result reported
Engine 14.47.59194
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.214
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14392
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.6.2.19
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-04-14.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.11.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1186
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38565
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5580
ZoneAlarm undetected
No result reported
Engine 6.23-113519599
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 68c9d6c:68c9d6c:xxxxxxx:xxxxxxx
tehtris type-unsupported
No result reported

File Signatures

SHA-256 df3994816dd6037d0c5a151a55695b42c64d27a19b847733f2db35db94bc691d
MD5 1b61c7b1f93a1f2dee4b156475db0bb2
SHA-1 3b7284a9c6ceadd017b74522e91faf8d1fc3c871
SSDEEP 98304:r982OkPI7OvB7T20z8AdmKm1xtDXXNccxeK628ytjcIIS3zZW02riYcGn7wcoTwq:rBOMPB7TrJmKKdckKo2gv
TLSH T10A17BE12F7101D37CC7F963A19B6035127356E96A70383A32548F26DBCF32D49AA9BC9
VHASH 2bc48dc5bb5d02e71c2d655a7f9ed028
PERMHASH c19962dcc5ffcc9ad6a9871ca461a494bdffcfa69a0e53a0b2569ec66797e04c

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=store File signature result from magic bytes inspection.
TrID Android Package (50%), VYM Mind Map (23.1%), Sweet Home 3D Design (generic) (19.4%), ZIP compressed archive (7.4%) TrID file type guesses with probabilities.
dhash 20783c1e0e2e1b40 Perceptual hash used to compare visual similarity of files.
raw md5 30b14eb12eccadf391e7e564bcd5e76c Raw MD5 hash of the file contents.
extensions xml (693), png (207), version (67), dex (18), kotlin_builtins (7), properties (5), bin (1), CoroutineExceptionHandler (1), MainDispatcherFactory (1) File extensions found inside the APK and how many of each.
file types XML (693), PNG (207), unknown (99), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 1214 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 17 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Malicious 68% confidence MALWARE SPREADER TROJAN EVADER

Deep Manifest Analysis

Activity Intents (1)

com.itsi.bct.mobile.ui.splash.SplashActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER

Service Intents (2)

com.itsi.bct.mobile.service.CallAccessibilityService
Actions
android.accessibilityservice.AccessibilityService android.accessibilityservice.AccessibilityService
com.itsi.bct.mobile.service.WhatsappAccessibilityService
Actions
android.accessibilityservice.AccessibilityService android.accessibilityservice.AccessibilityService

Receiver Intents (11)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
Actions
Power Connected Broadcast Action: External power has been connected to the device. android.intent.action.ACTION_POWER_CONNECTED
android.intent.action.ACTION_POWER_DISCONNECTED android.intent.action.ACTION_POWER_DISCONNECTED
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
Actions
Battery Okay Broadcast Action: Indicates the battery is now okay after being low. android.intent.action.BATTERY_OKAY
Battery Low Broadcast Action: Indicates low battery condition on the device. android.intent.action.BATTERY_LOW
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
Actions
Device Storage Low Broadcast Action: A sticky broadcast that indicates low memory android.intent.action.DEVICE_STORAGE_LOW
Device Storage Ok Broadcast Action: Indicates low memory condition on the device no longer exists android.intent.action.DEVICE_STORAGE_OK
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
Actions
androidx.work.impl.background.systemalarm.UpdateProxies androidx.work.impl.background.systemalarm.UpdateProxies
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
Time Changed Broadcast Action: The time was set. android.intent.action.TIME_SET
Timezone Changed Broadcast Action: The timezone has changed. android.intent.action.TIMEZONE_CHANGED
androidx.work.impl.diagnostics.DiagnosticsReceiver
Actions
androidx.work.diagnostics.REQUEST_DIAGNOSTICS androidx.work.diagnostics.REQUEST_DIAGNOSTICS
com.itsi.bct.mobile.receiver.ApkUpdateReceiver
Actions
Package Added Broadcast Action: A new application package has been installed on the android.intent.action.PACKAGE_ADDED
Package Removed Broadcast Action: An existing application package has been removed from android.intent.action.PACKAGE_REMOVED
com.itsi.bct.mobile.receiver.BctPhoneCallBroadcastReceiver
Actions
android.intent.action.PHONE_STATE android.intent.action.PHONE_STATE
com.itsi.bct.mobile.receiver.SMSSentBroadcastReceiver
Actions
SENT_SMS_ACTION SENT_SMS_ACTION

Requested Permissions (22)

view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
android.permission.ANSWER_PHONE_CALLS Custom app or vendor permission (not publicly documented). android.permission.ANSWER_PHONE_CALLS
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_DATA_SYNC Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_DATA_SYNC
record audio android.permission.RECORD_AUDIO
com.simplemobiletools.dialer.permission.BIND_CALL_CONTROL_SERVICE Custom app or vendor permission (not publicly documented). com.simplemobiletools.dialer.permission.BIND_CALL_CONTROL_SERVICE
send and view SMS messages Allows the app to send SMS messages. This may result in unexpected charges. Malicious apps may cost you money by sending messages without your confirmation. android.permission.SEND_SMS
directly call phone numbers Allows the app to call phone numbers without your intervention. This may result in unexpected charges or calls. Note that this doesn\'t allow the app to call emergency numbers. Malicious apps may cost you money by making calls without your confirmation, or dial carrier codes which cause incoming calls to be automatically forwarded to another number. android.permission.CALL_PHONE
read call log This app can read your call history. android.permission.READ_CALL_LOG
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.itsi.bct.mobile.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (2)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Telephony Feature for {@link #getSystemAvailableFeatures} and android.hardware.telephony

Activities (13)

com.itsi.bct.mobile.ui.password.ChangePasswordActivity
com.itsi.bct.mobile.ui.splash.SplashActivity
com.itsi.bct.mobile.ui.main.MainActivity
com.itsi.bct.mobile.ui.login.LoginActivity
com.itsi.bct.mobile.ui.login.ExpiredPasswordResetActivity
com.itsi.bct.mobile.ui.customer.CustomerActivity
com.itsi.bct.mobile.ui.debt.DebtActivity
com.itsi.bct.mobile.ui.history.DunningHistoryActivity
com.itsi.bct.mobile.ui.profile.ProfileActivity
com.itsi.bct.mobile.ui.login.OtpActivity
com.itsi.bct.mobile.ui.splash.DeviceRootedActivity
com.itsi.bct.mobile.ui.notification.NotificationListActivity
com.google.android.gms.common.api.GoogleApiActivity

Services (8)

com.itsi.bct.mobile.service.WhatsappAccessibilityService
com.itsi.bct.mobile.service.SSEService
com.itsi.bct.mobile.service.CallAccessibilityService
com.itsi.bct.mobile.service.CallControlPersistenceService
androidx.work.impl.background.systemalarm.SystemAlarmService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService

Broadcast Receivers (12)

com.itsi.bct.mobile.receiver.ApkUpdateReceiver com.itsi.bct.mobile.receiver.ApkUpdateReceiver
com.itsi.bct.mobile.receiver.BctPhoneCallBroadcastReceiver com.itsi.bct.mobile.receiver.BctPhoneCallBroadcastReceiver
com.itsi.bct.mobile.receiver.SMSSentBroadcastReceiver com.itsi.bct.mobile.receiver.SMSSentBroadcastReceiver
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
androidx.work.impl.diagnostics.DiagnosticsReceiver androidx.work.impl.diagnostics.DiagnosticsReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (2)

com.itsi.bct.mobile.utils.ApkInstallerUtil
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-04-14
First Submission 2026-04-14
Last Submission 2026-04-14
Stored Until 2026-05-14