APK Security & Privacy Score
Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.
Security
Scan-weighted
88/100
Threat scan flagged
Modern target SDK
Privacy
Permissions & network
68/100
High-risk permissions
AllowBackup enabled
Possible tracking
77/100
Good
Overall trust
Facts
Threat scan
1/76 flagged, 0 suspicious
Permissions
25 requested
Network strings
96 URLs (0 HTTP, 96 HTTPS)
Target SDK
34
Certificate
Valid until 2049-09-08 (23 years, suspicious)
Warnings
Threat scan flagged: 1/76 scanners marked this file as malicious.
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES
Requests 25 permissions (review carefully).
AllowBackup is enabled.
Possible analytics/tracking domains found: app.adjust.cn, app.adjust.com, app.adjust.net.in, app.adjust.world, app.eu.adjust.com
Package Name
com.sfcg.qj1685.kjww
Version Code
12
Version Name
1.1.62
Application Name
com.speed.client.CCAppClient
Debuggable
No
Allow Backup
Yes
Min SDK
Android 21 (Lollipop)
Target SDK
Android 34 (Android 14)
Supported ABIs
arm64-v8a
armeabi-v7a
Certificate & Signer
Valid From
Valid To
Serial Number
Thumbprint
Issuer: CN
Issuer: DN
Issuer: L
Issuer: O
Issuer: OU
Issuer: ST
Subject: CN
Subject: DN
Subject: L
Subject: O
Subject: OU
Subject: ST
Security Scan
1
⚠️ Threats Detected
Detected by
1 vendor:
AhnLab-V3
(PUP/Android.Malct.1266834)
Malicious
1
Suspicious
0
Harmless
0
Undetected
65
Timeout
1
Failure
1
Scan Providers
ALYac
APEX
AVG
Acronis
AhnLab-V3
PUP/Android.Malct.1266834
Alibaba
Antiy-AVL
Arcabit
Avast
Avast-Mobile
Avira
Baidu
BitDefender
BitDefenderFalx
Bkav
CAT-QuickHeal
CMC
CTX
ClamAV
CrowdStrike
Cylance
Cynet
DeepInstinct
DrWeb
ESET-NOD32
Elastic
Emsisoft
F-Secure
Fortinet
GData
Google
Gridinsoft
Ikarus
Jiangmin
K7AntiVirus
K7GW
Kaspersky
Kingsoft
Lionic
Malwarebytes
MaxSecure
McAfeeD
MicroWorld-eScan
Microsoft
NANO-Antivirus
Paloalto
Panda
Rising
SUPERAntiSpyware
Sangfor
SentinelOne
Skyhigh
Sophos
Symantec
SymantecMobileInsight
TACHYON
Tencent
Trapmine
TrellixENS
TrendMicro
TrendMicro-HouseCall
Trustlook
VBA32
VIPRE
Varist
ViRobot
VirIT
Webroot
Xcitium
Yandex
Zillya
ZoneAlarm
Zoner
alibabacloud
huorong
tehtris
File Signatures
SHA-256
e765b2f1468a9078a62f72e909b4e635cac2c791151f6ddac1e8c28ba9b07b88
MD5
c21529efece0a4946d8167bd69c72668
SHA-1
b9aace96f99454a156d7d9b19417a3fe65cc3e39
SSDEEP
196608:lJt+80q9iZbTSq4WU+fs6VYVxZAUT5AY23T:vtcq9iZPRRVSxZTT5At
TLSH
T1A5660187F749F8AFC4F3D33286750662651A8D118B83E6971954B3BC1DBBAC04A85ECC
VHASH
b6ef3e5c9b259c8663e5259dc1472a04
PERMHASH
78532a3843c9a67ddaa1c48f567a1f60b9d2ba0b87abaff4fd0080264f199aa2
File Intelligence
Type Description
Human-friendly file type name based on multiple detection methods.
Type Extension
Most likely file extension inferred from the content.
Type Tag
Primary type tag assigned by the classifier.
Type Tags
Additional type tags that describe the file content.
Magic
File signature result from magic bytes inspection.
Magika
File type predicted by Magika (ML-based file type detection).
TrID
TrID file type guesses with probabilities.
dhash
Perceptual hash used to compare visual similarity of files.
raw md5
Raw MD5 hash of the file contents.
extensions
File extensions found inside the APK and how many of each.
file types
Detected embedded file types and their counts.
highest datetime
Latest timestamp found among files inside the archive.
lowest datetime
Earliest timestamp found among files inside the archive.
num children
Number of files contained within the archive.
type
Container type detected for the analyzed file.
uncompressed size
Estimated total size of all files after extraction.
Deep Manifest Analysis
Activity Intents (5)
com.engagelab.privates.common.component.MTCommonActivity
com.facebook.CustomTabActivity
com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity
com.speed.client.CCMainActivity
com.zing.zalo.zalosdk.oauth.BrowserLoginActivity
Service Intents (4)
com.blankj.utilcode.util.MessengerUtils$ServerService
com.engagelab.privates.push.platform.google.callback.MTGoogleCallback
Firebase messaging service
com.google.firebase.messaging.FirebaseMessagingService
com.speed.client.jpush.UserService
Receiver Intents (5)
com.adjust.sdk.AdjustReferrerReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver
com.speed.client.jpush.UserReceiver
Native Libraries (4)
libbugsnag-ndk
libbugsnag-ndk.so
libbugsnag-plugin-android-anr
libbugsnag-plugin-android-anr.so
libbugsnag-root-detection
libbugsnag-root-detection.so
libgtcore
libgtcore.so
Requested Permissions (25)
have full network access
android.permission.INTERNET
view network connections
android.permission.ACCESS_NETWORK_STATE
android.permission.SCHEDULE_EXACT_ALARM
android.permission.SCHEDULE_EXACT_ALARM
keep car screen turned on
android.permission.WAKE_LOCK
Cloud messaging receive
com.google.android.c2dm.permission.RECEIVE
Foreground service
android.permission.FOREGROUND_SERVICE
view Wi-Fi connections
android.permission.ACCESS_WIFI_STATE
Mount Unmount Filesystems
android.permission.MOUNT_UNMOUNT_FILESYSTEMS
read the contents of your shared storage
android.permission.READ_EXTERNAL_STORAGE
modify or delete the contents of your shared storage
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.REQUEST_INSTALL_PACKAGES
android.permission.READ_MEDIA_IMAGES
android.permission.READ_MEDIA_IMAGES
Install Packages
android.permission.INSTALL_PACKAGES
take pictures and videos
android.permission.CAMERA
com.google.android.gms.permission.AD_ID
com.google.android.gms.permission.AD_ID
android.permission.POST_NOTIFICATIONS
android.permission.POST_NOTIFICATIONS
AdServices Attribution
android.permission.ACCESS_ADSERVICES_ATTRIBUTION
AdServices Advertising ID
android.permission.ACCESS_ADSERVICES_AD_ID
android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE
android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE
com.zing.zalo.permission.ACCESS_THIRD_PARTY_APP_AUTHORIZATION
com.zing.zalo.permission.ACCESS_THIRD_PARTY_APP_AUTHORIZATION
Dynamic receiver access
com.sfcg.qj1685.kjww.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Install Referrer service
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
change network connectivity
android.permission.CHANGE_NETWORK_STATE
connect and disconnect from Wi-Fi
android.permission.CHANGE_WIFI_STATE
read phone status and identity
android.permission.READ_PHONE_STATE
Uses Features (1)
Camera
android.hardware.camera
Activities (18)
com.speed.client.CCMainActivity
com.speed.client.CCWebActivity
com.speed.client.third_login.TgLoginActivity
com.facebook.CustomTabActivity
com.facebook.FacebookActivity
com.zing.zalo.zalosdk.oauth.BrowserLoginActivity
com.speed.client.jpush.UserActivity400
androidx.credentials.playservices.HiddenActivity
com.linecorp.linesdk.auth.internal.LineAuthenticationActivity
com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
com.google.android.gms.common.api.GoogleApiActivity
com.facebook.CustomTabMainActivity
com.zing.zalo.zalosdk.oauth.OpenAPIActivity
com.zing.zalo.zalosdk.oauth.WebLoginActivity
com.blankj.utilcode.util.UtilsTransActivity4MainProcess
com.blankj.utilcode.util.UtilsTransActivity
com.engagelab.privates.common.component.MTCommonActivity
Services (9)
com.speed.client.jpush.UserService
androidx.credentials.playservices.CredentialProviderMetadataHolder
com.google.android.gms.auth.api.signin.RevocationBoundService
Firebase messaging service
com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.blankj.utilcode.util.MessengerUtils$ServerService
com.engagelab.privates.push.platform.google.callback.MTGoogleCallback
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
Broadcast Receivers (6)
com.speed.client.jpush.UserReceiver
com.speed.client.jpush.UserReceiver
com.adjust.sdk.AdjustReferrerReceiver
com.adjust.sdk.AdjustReferrerReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
Content Providers (8)
androidx.core.content.FileProvider
com.squareup.picasso.PicassoProvider
com.google.firebase.provider.FirebaseInitProvider
com.facebook.internal.FacebookInitProvider
com.blankj.utilcode.util.UtilsFileProvider
com.engagelab.privates.common.component.MTCommonProvider
com.bugsnag.android.internal.BugsnagContentProvider
com.sensorsdata.analytics.android.sdk.data.SensorsDataContentProvider
URL Endpoints (97)
https://.facebook.com
https://access.line.me/.well-known/openid-configuration
https://access.line.me/oauth2/v2.1/login
https://accounts.google.com
https://accounts.google.com/o/oauth2/revoke?token=
https://api.line.me/
https://apiup-cf.cbfes.com/sa?project=production
https://app.adjust.cn
https://app.adjust.com
https://app.adjust.net.in
https://app.adjust.world
https://app.eu.adjust.com
https://app.tr.adjust.com
https://app.us.adjust.com
https://bugsnag.com
https://dev-oauth.zaloapp.com
https://developers.facebook.com/docs/android/getting-started
https://developers.facebook.com/docs/android/getting-started#add-app_id
https://developers.facebook.com/docs/android/getting-started#client-token
https://developers.facebook.com/docs/android/troubleshooting/#faq_267321845055988
Submission Details
Submitted At
First Submission
Last Submission
Stored Until