P999 icon

P999com.sfcg.qj1685.kjwwv1.1.62.apk

P999

6.70 MB

Analyzed: 2026-03-22 14:33 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
88/100
Threat scan flagged Modern target SDK
Privacy Permissions & network
68/100
High-risk permissions AllowBackup enabled Possible tracking
77/100
Good
Overall trust

Facts

Threat scan 1/76 flagged, 0 suspicious
Permissions 25 requested
Network strings 96 URLs (0 HTTP, 96 HTTPS)
Target SDK 34
Certificate Valid until 2049-09-08 (23 years, suspicious)

Warnings

Threat scan flagged: 1/76 scanners marked this file as malicious.
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES
Requests 25 permissions (review carefully).
AllowBackup is enabled.
Possible analytics/tracking domains found: app.adjust.cn, app.adjust.com, app.adjust.net.in, app.adjust.world, app.eu.adjust.com
Package Name com.sfcg.qj1685.kjww
Version Code 12
Version Name 1.1.62
Application Name com.speed.client.CCAppClient
Debuggable No
Allow Backup Yes
Min SDK Android 21 (Lollipop)
Target SDK Android 34 (Android 14)
Supported ABIs
arm64-v8a armeabi-v7a

Certificate & Signer

Valid From 2019-09-16 03:15:45
Valid To 2049-09-08 03:15:45
Serial Number 51830649
Thumbprint 42d9314809342e6d240d39b6d959c1da6514335b
Issuer: CN Franky Hu
Issuer: DN CN:Franky Hu, L:Mala, O:Franky Hu, ST:Mala, OU:personal
Issuer: L Mala
Issuer: O Franky Hu
Issuer: OU personal
Issuer: ST Mala
Subject: CN Franky Hu
Subject: DN CN:Franky Hu, L:Mala, O:Franky Hu, ST:Mala, OU:personal
Subject: L Mala
Subject: O Franky Hu
Subject: OU personal
Subject: ST Mala

Security Scan

1 /76
⚠️ Threats Detected
Detected by 1 vendor: AhnLab-V3 (PUP/Android.Malct.1266834)
Scanned by 76 security vendors
Last scan: 2026-03-22 14:33 UTC
Malicious
1
Suspicious
0
Harmless
0
Undetected
65
Timeout
1
Failure
1

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.761
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
PUP/Android.Malct.1266834
Engine 3.29.3.10609
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260321-02
Avira undetected
No result reported
Engine 8.3.3.24
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.252
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.43949AVA:64.30884
Google undetected
No result reported
Engine 1774186275
Gridinsoft undetected
No result reported
Engine 1.0.241.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.42.58955
K7GW undetected
No result reported
Engine 14.42.58957
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.214
MaxSecure timeout
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14148
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26010.1
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.5.3.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.3.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-03-22.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.10.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1170
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38499
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya failure
No result reported
Engine 2.0.0.5567
ZoneAlarm undetected
No result reported
Engine 6.23-113519110
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 300dc6d:300dc6d:38b5ae0:38b5ae0
tehtris type-unsupported
No result reported
Engine v0.1.4

File Signatures

SHA-256 e765b2f1468a9078a62f72e909b4e635cac2c791151f6ddac1e8c28ba9b07b88
MD5 c21529efece0a4946d8167bd69c72668
SHA-1 b9aace96f99454a156d7d9b19417a3fe65cc3e39
SSDEEP 196608:lJt+80q9iZbTSq4WU+fs6VYVxZAUT5AY23T:vtcq9iZPRRVSxZTT5At
TLSH T1A5660187F749F8AFC4F3D33286750662651A8D118B83E6971954B3BC1DBBAC04A85ECC
VHASH b6ef3e5c9b259c8663e5259dc1472a04
PERMHASH 78532a3843c9a67ddaa1c48f567a1f60b9d2ba0b87abaff4fd0080264f199aa2

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v1.0 to extract, compression method=store File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (30.8%), OpenOffice Extension (24.5%), Java Archive (15.4%), Pocket Code/Catroid Catrobat Project (12.5%), Sweet Home 3D Design (generic) (12%) TrID file type guesses with probabilities.
dhash 0000001e1f161302 Perceptual hash used to compare visual similarity of files.
raw md5 568d90d464a0c513b9d7e65c3a181b2a Raw MD5 hash of the file contents.
extensions png (515), xml (420), properties (27), so (8), kotlin_builtins (7), js (4), txt (3), json (2), arsc (1), bin (1), dex (1), gz (1), k (1), u (1), webp (1) File extensions found inside the APK and how many of each.
file types PNG (515), XML (419), unknown (55), ELF (8), DEX (1), Java Bytecode (1), JavaScript (1) Detected embedded file types and their counts.
highest datetime 2026-01-07 02:25:30 UTC Latest timestamp found among files inside the archive.
lowest datetime 2026-01-07 02:25:28 UTC Earliest timestamp found among files inside the archive.
num children 1130 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 13 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (5)

com.engagelab.privates.common.component.MTCommonActivity
Actions
com.engagelab.privates.common.component.MTCommonActivity com.engagelab.privates.common.component.MTCommonActivity
Categories
android.intent.category.DEFAULT com.sfcg.qj1685.kjww
com.facebook.CustomTabActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.speed.client.CCMainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.zing.zalo.zalosdk.oauth.BrowserLoginActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE

Service Intents (4)

com.blankj.utilcode.util.MessengerUtils$ServerService
Actions
com.sfcg.qj1685.kjww.messenger com.sfcg.qj1685.kjww.messenger
com.engagelab.privates.push.platform.google.callback.MTGoogleCallback
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
com.speed.client.jpush.UserService
Actions
com.engagelab.privates.intent.USER_SERVICE com.engagelab.privates.intent.USER_SERVICE

Receiver Intents (5)

com.adjust.sdk.AdjustReferrerReceiver
Actions
com.android.vending.INSTALL_REFERRER com.android.vending.INSTALL_REFERRER
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
com.speed.client.jpush.UserReceiver
Actions
com.engagelab.privates.intent.USER_RECEIVER com.engagelab.privates.intent.USER_RECEIVER

Native Libraries (4)

libbugsnag-ndk libbugsnag-ndk.so
libbugsnag-plugin-android-anr libbugsnag-plugin-android-anr.so
libbugsnag-root-detection libbugsnag-root-detection.so
libgtcore libgtcore.so

Requested Permissions (25)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
android.permission.SCHEDULE_EXACT_ALARM Custom app or vendor permission (not publicly documented). android.permission.SCHEDULE_EXACT_ALARM
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
Mount Unmount Filesystems android.permission.MOUNT_UNMOUNT_FILESYSTEMS
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
android.permission.READ_MEDIA_IMAGES Custom app or vendor permission (not publicly documented). android.permission.READ_MEDIA_IMAGES
Install Packages android.permission.INSTALL_PACKAGES
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
com.google.android.gms.permission.AD_ID Custom app or vendor permission (not publicly documented). com.google.android.gms.permission.AD_ID
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
AdServices Attribution Required to call AdServices Attribution APIs. android.permission.ACCESS_ADSERVICES_ATTRIBUTION
AdServices Advertising ID Required to call AdServices Advertising ID APIs. android.permission.ACCESS_ADSERVICES_AD_ID
android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE Custom app or vendor permission (not publicly documented). android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE
com.zing.zalo.permission.ACCESS_THIRD_PARTY_APP_AUTHORIZATION Custom app or vendor permission (not publicly documented). com.zing.zalo.permission.ACCESS_THIRD_PARTY_APP_AUTHORIZATION
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.sfcg.qj1685.kjww.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE

Uses Features (1)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera

Activities (18)

com.speed.client.CCMainActivity
com.speed.client.CCWebActivity
com.speed.client.third_login.TgLoginActivity
com.facebook.CustomTabActivity
com.facebook.FacebookActivity
com.zing.zalo.zalosdk.oauth.BrowserLoginActivity
com.speed.client.jpush.UserActivity400
androidx.credentials.playservices.HiddenActivity
com.linecorp.linesdk.auth.internal.LineAuthenticationActivity
com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
com.google.android.gms.common.api.GoogleApiActivity
com.facebook.CustomTabMainActivity
com.zing.zalo.zalosdk.oauth.OpenAPIActivity
com.zing.zalo.zalosdk.oauth.WebLoginActivity
com.blankj.utilcode.util.UtilsTransActivity4MainProcess
com.blankj.utilcode.util.UtilsTransActivity
com.engagelab.privates.common.component.MTCommonActivity

Services (9)

com.speed.client.jpush.UserService
androidx.credentials.playservices.CredentialProviderMetadataHolder
com.google.android.gms.auth.api.signin.RevocationBoundService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.blankj.utilcode.util.MessengerUtils$ServerService
com.engagelab.privates.push.platform.google.callback.MTGoogleCallback
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (6)

com.speed.client.jpush.UserReceiver com.speed.client.jpush.UserReceiver
com.adjust.sdk.AdjustReferrerReceiver com.adjust.sdk.AdjustReferrerReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Content Providers (8)

androidx.core.content.FileProvider
com.squareup.picasso.PicassoProvider
com.google.firebase.provider.FirebaseInitProvider
com.facebook.internal.FacebookInitProvider
com.blankj.utilcode.util.UtilsFileProvider
com.engagelab.privates.common.component.MTCommonProvider
com.bugsnag.android.internal.BugsnagContentProvider
com.sensorsdata.analytics.android.sdk.data.SensorsDataContentProvider

URL Endpoints (97)

https://.facebook.com https://access.line.me/.well-known/openid-configuration https://access.line.me/oauth2/v2.1/login https://accounts.google.com https://accounts.google.com/o/oauth2/revoke?token= https://api.line.me/ https://apiup-cf.cbfes.com/sa?project=production https://app.adjust.cn https://app.adjust.com https://app.adjust.net.in https://app.adjust.world https://app.eu.adjust.com https://app.tr.adjust.com https://app.us.adjust.com https://bugsnag.com https://dev-oauth.zaloapp.com https://developers.facebook.com/docs/android/getting-started https://developers.facebook.com/docs/android/getting-started#add-app_id https://developers.facebook.com/docs/android/getting-started#client-token https://developers.facebook.com/docs/android/troubleshooting/#faq_267321845055988

Submission Details

Submitted At 2026-03-22
First Submission 2026-03-22
Last Submission 2026-03-22
Stored Until 2026-04-21