Xuper icon

Xuper_4.99.2_src.apk

Xuper

31.92 MB

Analyzed: 2026-03-02 20:46 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
78/100
Threat scan flagged
Privacy Permissions & network
86/100
High-risk permissions HTTP URLs found AllowBackup enabled Possible tracking
82/100
Good
Overall trust

Facts

Threat scan 2/76 flagged, 0 suspicious
Permissions 17 requested
Network strings 69 URLs (15 HTTP, 54 HTTPS)
Target SDK 33
Certificate Valid until 2035-07-17 (9 years, suspicious)

Warnings

Threat scan flagged: 2/76 scanners marked this file as malicious.
Found 15 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES
AllowBackup is enabled.
Possible analytics/tracking domains found: alogsus.umeng.com, alogus.umeng.com, app-measurement.com, aspect-upush.umeng.com, audid.umeng.com
Package Name com.android.mgstv
Version Code 49902
Version Name 4.99.2
Application Name com.interactive.brasiliptv.app.AppWrapper
Debuggable No
Allow Backup Yes
Min SDK Android 19 (KitKat)
Target SDK Android 33 (Android 13)
Supported ABIs
arm64-v8a armeabi-v7a

Certificate & Signer

Valid From 2008-02-29 01:33:46
Valid To 2035-07-17 01:33:46
Serial Number 936eacbe07f201df
Thumbprint 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Issuer: C US
Issuer: CN Android
Issuer: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Issuer: L Mountain View
Issuer: O Android
Issuer: OU Android
Issuer: ST California
Issuer: email android@android.com
Subject: C US
Subject: CN Android
Subject: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject: L Mountain View
Subject: O Android
Subject: OU Android
Subject: ST California
Subject: email android@android.com

Security Scan

2 /76
⚠️ Threats Detected
Detected by 2 vendors: BitDefenderFalx (Android.Riskware.TestKey.rA), Tencent (a.remote.Pandora)
Scanned by 76 security vendors
Last scan: 2026-02-28 00:24 UTC
Malicious
2
Suspicious
0
Harmless
0
Undetected
56
Timeout
8
Failure
0

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.752
AVG timeout
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.29.1.10604
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast timeout
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260227-04
Avira undetected
No result reported
Engine 8.3.3.24
Baidu timeout
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.TestKey.rA
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV timeout
No result reported
Engine 1.5.1.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.251
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.43680AVA:64.30742
Google undetected
No result reported
Engine 1772233255
Gridinsoft undetected
No result reported
Engine 1.0.239.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.38.58731
K7GW undetected
No result reported
Engine 14.38.58732
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.211
MaxSecure timeout
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14023
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26010.1
NANO-Antivirus timeout
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.5.3.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.3.1.0
Symantec timeout
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-02-27.02
Tencent malicious
a.remote.Pandora
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.10.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT confirmed-timeout
No result reported
Engine 9.5.1155
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38449
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5554
ZoneAlarm undetected
No result reported
Engine 6.23-113518533
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 10e1e75:10e1e75:71ab9b9:71ab9b9
tehtris type-unsupported
No result reported
Engine v0.1.4

File Signatures

SHA-256 1218ee4d06735bc6a9faa7775bd94b6ad88163aed9c194dff36a8ec6b395caeb
MD5 cce92b819161305f08c7fef3618feced
SHA-1 886e912765528f173baac2a6e45eba578348e39e
SSDEEP 786432:w/4O8Ffj8rTzmOs3sqvUuPQPQHsj9JjRglqaBeNRJr:RFArmOs5cGQHJlg/BGr
TLSH T1F0772357F718F94AD0F756324BBA025641170D508F83D24F2A19F1B82AF3AC49F5BACA
VHASH 887031e02dd12d08bf12fdd01d23db46
PERMHASH f720508ae0ddf3df3efa76ba8ee24e6b0e2f41b09b2ffa3b7828654ee367c62f

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v2.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (49%), Java Archive (24.5%), Sweet Home 3D Design (generic) (19%), ZIP compressed archive (7.2%) TrID file type guesses with probabilities.
dhash 0000101c1e160500 Perceptual hash used to compare visual similarity of files.
raw md5 9998e56a0805aeb9b4620d7f8ab9adfa Raw MD5 hash of the file contents.
extensions xml (640), png (354), dex (3), webp (2), arsc (1) File extensions found inside the APK and how many of each.
file types XML (640), PNG (354), DEX (3), unknown (3) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1980-01-01 00:00:00 UTC Earliest timestamp found among files inside the archive.
num children 2371 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 19 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Harmless 83% confidence CLEAN

Deep Manifest Analysis

Activity Intents (1)

com.interactive.brasiliptv.ui.activity.WelcomeActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER android.intent.category.LEANBACK_LAUNCHER

Service Intents (8)

Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
com.interactive.brasiliptv.service.MyFirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
com.taobao.accs.ChannelService
Actions
com.taobao.accs.intent.action.START_SERVICE com.taobao.accs.intent.action.START_SERVICE
com.taobao.accs.intent.action.ELECTION com.taobao.accs.intent.action.ELECTION
com.taobao.accs.data.MsgDistributeService
Actions
com.taobao.accs.intent.action.RECEIVE com.taobao.accs.intent.action.RECEIVE
com.umeng.message.component.UmengIntentService
Actions
org.agoo.android.intent.action.RECEIVE org.agoo.android.intent.action.RECEIVE
com.umeng.message.component.UmengMessageHandlerService
Actions
com.umeng.message.action com.umeng.message.action
com.umeng.message.component.UmengMessageReceiverService
Actions
org.android.agoo.client.MessageReceiverService org.android.agoo.client.MessageReceiverService
org.android.agoo.accs.AgooService
Actions
com.taobao.accs.intent.action.RECEIVE com.taobao.accs.intent.action.RECEIVE

Receiver Intents (3)

com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
com.qiniu.android.dns.NetworkReceiver
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
User Present Broadcast Action: Sent when the user is present after device wakes up (e.g when the android.intent.action.USER_PRESENT
com.taobao.accs.ServiceReceiver
Actions
com.taobao.accs.intent.action.COMMAND com.taobao.accs.intent.action.COMMAND
com.taobao.accs.intent.action.START_FROM_AGOO com.taobao.accs.intent.action.START_FROM_AGOO

Native Libraries (13)

libboost_multidex libboost_multidex.so
C++ Standard Library Android NDK C++ runtime used by native code. libc++_shared.so
libcrashlytics-common libcrashlytics-common.so
libcrashlytics-handler libcrashlytics-handler.so
libcrashlytics-trampoline libcrashlytics-trampoline.so
libcrashlytics libcrashlytics.so
libcrashsdk libcrashsdk.so
libijkffmpeg libijkffmpeg.so
libijkplayer libijkplayer.so
libijksdl libijksdl.so
libranger-jni libranger-jni.so
libtnet-3.1.14 libtnet-3.1.14.so
libumeng-spy libumeng-spy.so

Requested Permissions (17)

com.google.android.gms.permission.AD_ID Custom app or vendor permission (not publicly documented). com.google.android.gms.permission.AD_ID
Write Media Storage android.permission.WRITE_MEDIA_STORAGE
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
android.permission.READ_MEDIA_AUDIO Custom app or vendor permission (not publicly documented). android.permission.READ_MEDIA_AUDIO
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
retrieve running apps Allows the app to retrieve information about currently and recently running tasks. This may allow the app to discover information about which applications are used on the device. android.permission.GET_TASKS
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
Mount Unmount Filesystems android.permission.MOUNT_UNMOUNT_FILESYSTEMS
App badge update Allows the app to update the launcher icon badge count on Huawei launchers. com.huawei.android.launcher.permission.CHANGE_BADGE
App badge update Allows the app to update the launcher icon badge count on launcher launchers. com.vivo.notification.permission.BADGE_ICON

Uses Features (2)

Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (33)

com.interactive.brasiliptv.ui.activity.WelcomeActivity
com.interactive.brasiliptv.ui.activity.GuidePageActivity
com.main.ui.activity.HomeActivity
com.vod.ui.activity.VodDetailsActivity
com.vod.ui.activity.VodCategoryActivity
com.vod.ui.activity.VodSearchActivity
com.vod.ui.activity.RestrictLevelSearchActivity
com.vod.ui.activity.TopicActivity
com.vod.ui.activity.TopicMoreActivity
com.vod.ui.activity.ActorDetailsActivity
com.vod.ui.activity.KidsCategoryActivity
com.vod.ui.activity.FilterActivity
com.download.activity.DownloadActivity
com.download.activity.LocalPlayActivity
com.download.permission.OverlayActivity
com.live.ui.activity.LiveFreeActivity
com.live.ui.activity.LiveVoiceSearchActivity
com.live.ui.activity.MatchScheduleActivity
com.live.ui.activity.MatchDetailActivity
com.live.ui.activity.MatchCategoryActivity
com.live.ui.activity.MatchRankCategoryActivity
com.live.ui.activity.LiveNewVoiceSearchActivity
com.mine.ui.activity.UserCenterActivity
com.mine.ui.activity.OrderHistoryActivity
com.mine.ui.activity.DisplayQRCodeActivity
com.mine.ui.activity.EventCenterActivity
com.mine.ui.activity.InviteFriendsActivity
com.login.ui.activity.ForcePasswordChangeActivity
com.module.ui.activity.CommonWebActivity
com.module.ui.activity.WebActivity
com.google.android.gms.common.api.GoogleApiActivity
com.umeng.message.component.UmengNotificationClickActivity
com.umeng.message.notify.UPushMessageNotifyActivity

Services (21)

com.interactive.brasiliptv.service.MyFirebaseMessagingService
com.main.service.GoMediaService
com.module.receiver.ReportService
com.taobao.accs.ChannelService
com.taobao.accs.data.MsgDistributeService
org.android.agoo.accs.AgooService
com.umeng.message.UmengIntentService
com.umeng.message.XiaomiIntentService
com.umeng.message.UmengMessageIntentReceiverService
com.google.firebase.components.ComponentDiscoveryService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
com.bytedance.boost_multidex.OptimizeService
com.umeng.message.component.UmengIntentService
com.umeng.message.component.UmengMessageReceiverService
com.umeng.message.component.UmengMessageHandlerService
com.taobao.accs.ChannelService$KernelService
com.taobao.accs.internal.AccsJobService

Broadcast Receivers (8)

com.taobao.accs.EventReceiver com.taobao.accs.EventReceiver
com.taobao.accs.ServiceReceiver com.taobao.accs.ServiceReceiver
com.taobao.agoo.AgooCommondReceiver com.taobao.agoo.AgooCommondReceiver
com.qiniu.android.dns.NetworkReceiver com.qiniu.android.dns.NetworkReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.umeng.message.component.UmengNotificationReceiver com.umeng.message.component.UmengNotificationReceiver

Content Providers (3)

com.therouter.InnerTheRouterContentProvider
com.mobile.provider.DownloadFileProvider
com.umeng.message.component.UmengMessageProvider

URL Endpoints (74)

http://%1$s/#/brasiltv-activity?lang=%2$s&uid=%3$s&appId=%4$s&tk=%5$s&loginType=%6$s&timeStamp=%7$s&portalCode=%8$s&theme=dark http://%1$s/#/tv-privacy-policy?lang=%2$s&appId=%3$s&timeStamp=%4$s http://192.168.1.10 http://developer.umeng.com/docs/66650/cate/66650 http://download/DownloadActivity http://module_login/ForcePasswordChangeActivity http://module_main/HomeActivity http://module_mine/InviteFriendsActivity http://module_mine/UserCenterActivity http://module_vod/TopicActivity http://module_vod/VodCategoryActivity http://module_vod/VodDetailsActivity http://www.ANTLR.org http://www.ANTLR.org/ http://www.baidu.com http://www.google.com http://www.magelang.com https://alogsus.umeng.com https://alogus.umeng.com https://app-measurement.com/a

Submission Details

Submitted At 2026-03-02
First Submission 2026-03-02
Last Submission 2026-03-02
Stored Until 2026-04-01