2043733214451503106-a6.apk

81.67 MB

Analyzed: 2026-07-12 09:57 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
33/100
Threat scan flagged
Privacy Permissions & network
51/100
High-risk permissions HTTP URLs found
40/100
High Risk
Overall trust

Facts

Threat scan 11/74 flagged, 0 suspicious
Permissions 48 requested
Network strings 55 URLs (8 HTTP, 47 HTTPS)
Target SDK Unknown
Certificate Valid until 2108-08-12 (82 years, suspicious)

Warnings

Threat scan flagged: 11/74 scanners marked this file as malicious.
Found 8 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.SYSTEM_ALERT_WINDOW, android.permission.RECEIVE_BOOT_COMPLETED
Requests 48 permissions (review carefully).

Analysis Coverage

This report is partial. Some core metadata could not be extracted.
version
Package Name com.baidu.location.f
Version Code
Version Name
Debuggable No
Allow Backup No
Min SDK Unknown
Target SDK Unknown
Supported ABIs
arm64-v8a armeabi-v7a x86 x86_64

Certificate & Signer

Valid From 2026-06-23 04:14:50
Valid To 2108-08-12 04:14:50
Serial Number 795e7a85
Thumbprint ca4c12c0243da40cc53541b7ae419f7b196efa2f
Issuer: CN client-344-839
Issuer: DN CN:client-344-839
Subject: CN client-344-839
Subject: DN CN:client-344-839

Security Scan

11 /74
⚠️ Threats Detected
Detected by 11 vendors: AVG (Android:Evo-gen [Trj]), AhnLab-V3 (PUP/Android.PornAgent.1237587), Avast (Android:Evo-gen [Trj])
Scanned by 74 security vendors
Last scan: 2026-07-13 20:48 UTC
Malicious
11
Suspicious
0
Harmless
0
Undetected
55
Timeout
0
Failure
1

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.798
AVG malicious
Android:Evo-gen [Trj]
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
PUP/Android.PornAgent.1237587
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast malicious
Android:Evo-gen [Trj]
Engine 23.9.8494.0
Avast-Mobile malicious
Android:Evo-gen [Trj]
Engine 260713-04
Avira malicious
TR/Android.Evo
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.Agent.gHMJM
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.271
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure malicious
Trojan.TR/Android.Evo
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45253AVA:64.31577
Google malicious
Detected
Engine 1783972883
Gridinsoft undetected
No result reported
Engine 1.0.250.174
Ikarus failure
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.62.60121
K7GW undetected
No result reported
Engine 14.62.60121
Kaspersky malicious
not-a-virus:HEUR:RiskTool.AndroidOS.Fakapp.ak
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.246
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26060.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising malicious
Hacktool.Fakapp/Android!8.13AB6 (CLOUD)
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.6.2.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight malicious
AdLibrary:Generisk
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-07-13.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.14.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1248
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38803
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5640
ZoneAlarm undetected
No result reported
Engine 6.26-117392151
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 4418106:4418106:24c61d3:24c61d3
tehtris type-unsupported
No result reported
Engine v0.1.4

File Signatures

SHA-256 6283854bafc5e0578c814a743689bfd97bdce3e3f6d6bdd760568a3e1658f634
MD5 197b1b8f9c215a232fea3820622602e9
SHA-1 0c70ec0253604d6b8613753a6ab0779e708d1046
SSDEEP 1572864:8BjtJOPnuoYK/CX+XC6XLI9tmlLFNHmfdwBe0QRInbXo15Rm+K8Q8nf:2wPneK/2UZXLIm5BeLqXC5RN5/
TLSH T1CA18239FFB80BE99C0FF277251B10876E5059E308743EAA76848B7392473EE4C6056D9
VHASH 8e9a022a16fe5e8365f606ac9cd12e76
PERMHASH 6bea3c69904fa1693f3d30a714d2e404cac528f7ab04a65bfb9c11a983ef8cea

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v2.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (60.6%), Java Archive (30.3%), ZIP compressed archive (8.9%) TrID file type guesses with probabilities.
dhash 0000001a1e1e1300 Perceptual hash used to compare visual similarity of files.
raw md5 1cbcb17218a63d1de0473748de564a8e Raw MD5 hash of the file contents.
extensions xml (43), dex (3), arsc (1), gif (1) File extensions found inside the APK and how many of each.
file types PNG (920), XML (43), unknown (20), JSON (9), MP3 (7), GIF (1) Detected embedded file types and their counts.
highest datetime 2026-06-23 04:17:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 2026-06-23 04:17:00 UTC Earliest timestamp found among files inside the archive.
num children 2543 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 37 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (6)

com.glow.bytehyperleaf.ExternalActionActivity
Actions
im.ehyqvkwcaw.passport.AUTHORIZE im.ehyqvkwcaw.passport.AUTHORIZE
Categories
android.intent.category.DEFAULT
com.glow.bytehyperleaf.LaunchActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Send Activity Action: Deliver some data to someone else. android.intent.action.SEND
Send Multiple Activity Action: Deliver multiple data to someone else. android.intent.action.SEND_MULTIPLE
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.LAUNCHER android.intent.category.MULTIWINDOW_LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.glow.bytehyperleaf.ShareActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.BROWSABLE android.intent.category.DEFAULT
com.glow.bytehyperleaf.hui.visualcall.VisualCallActivity
Actions
m12345.cc.av.caller m12345.cc.av.caller
Categories
android.intent.category.BROWSABLE android.intent.category.DEFAULT
com.glow.bytehyperleaf.hui.visualcall.VisualCallReceiveActivity
Actions
m12345.cc.av.receive m12345.cc.av.receive
im.ehyqvkwcaw.tel.CallApiAbove29Dialer
Actions
Dial Activity Action: Dial a number as specified by the data. android.intent.action.DIAL
Categories
android.intent.category.DEFAULT

Service Intents (9)

com.blankj.utilcode.util.MessengerUtils$ServerService
Actions
com.glow.bytehyperleaf.messenger com.glow.bytehyperleaf.messenger
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
im.ehyqvkwcaw.messenger.AppChooserTargetService
Actions
android.service.chooser.ChooserTargetService android.service.chooser.ChooserTargetService
im.ehyqvkwcaw.messenger.AuthenticatorService
Actions
android.accounts.AccountAuthenticator android.accounts.AccountAuthenticator
im.ehyqvkwcaw.messenger.ContactsSyncAdapterService
Actions
android.content.SyncAdapter android.content.SyncAdapter
im.ehyqvkwcaw.messenger.MusicBrowserService
Actions
android.media.browse.MediaBrowserService android.media.browse.MediaBrowserService
im.ehyqvkwcaw.messenger.WearDataLayerListenerService
Actions
com.google.android.gms.wearable.DATA_CHANGED com.google.android.gms.wearable.DATA_CHANGED
com.google.android.gms.wearable.MESSAGE_RECEIVED com.google.android.gms.wearable.MESSAGE_RECEIVED
com.google.android.gms.wearable.CAPABILITY_CHANGED com.google.android.gms.wearable.CAPABILITY_CHANGED
com.google.android.gms.wearable.CHANNEL_EVENT com.google.android.gms.wearable.CHANNEL_EVENT
im.ehyqvkwcaw.messenger.voip.AppConnectionService
Actions
android.telecom.ConnectionService android.telecom.ConnectionService
im.ehyqvkwcaw.tel.CallApiAbove29ScreeningService
Actions
android.telecom.CallScreeningService android.telecom.CallScreeningService

Receiver Intents (10)

com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
im.ehyqvkwcaw.keepalive.MonitorReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
com.silence.gray.wake com.silence.gray.wake
User Present Broadcast Action: Sent when the user is present after device wakes up (e.g when the android.intent.action.USER_PRESENT
android.intent.action.ACTION_POWER_DISCONNECTED android.intent.action.ACTION_POWER_DISCONNECTED
Power Connected Broadcast Action: External power has been connected to the device. android.intent.action.ACTION_POWER_CONNECTED
Package Added Broadcast Action: A new application package has been installed on the android.intent.action.PACKAGE_ADDED
Package Removed Broadcast Action: An existing application package has been removed from android.intent.action.PACKAGE_REMOVED
im.ehyqvkwcaw.keepalive.ScreenReceiver
Actions
User Present Broadcast Action: Sent when the user is present after device wakes up (e.g when the android.intent.action.USER_PRESENT
Screen On Broadcast Action: Sent when the device wakes up and becomes interactive. android.intent.action.SCREEN_ON
Screen Off Broadcast Action: Sent when the device goes to sleep and becomes non-interactive. android.intent.action.SCREEN_OFF
im.ehyqvkwcaw.messenger.AppStartReceiver
Actions
im.ehyqvkwcaw.start im.ehyqvkwcaw.start
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
im.ehyqvkwcaw.messenger.AutoMessageHeardReceiver
Actions
im.ehyqvkwcaw.messenger.ACTION_MESSAGE_HEARD im.ehyqvkwcaw.messenger.ACTION_MESSAGE_HEARD
im.ehyqvkwcaw.messenger.AutoMessageReplyReceiver
Actions
im.ehyqvkwcaw.messenger.ACTION_MESSAGE_REPLY im.ehyqvkwcaw.messenger.ACTION_MESSAGE_REPLY
im.ehyqvkwcaw.messenger.MusicPlayerReceiver
Actions
im.ehyqvkwcaw.android.musicplayer.close im.ehyqvkwcaw.android.musicplayer.close
im.ehyqvkwcaw.android.musicplayer.pause im.ehyqvkwcaw.android.musicplayer.pause
im.ehyqvkwcaw.android.musicplayer.next im.ehyqvkwcaw.android.musicplayer.next
im.ehyqvkwcaw.android.musicplayer.play im.ehyqvkwcaw.android.musicplayer.play
im.ehyqvkwcaw.android.musicplayer.previous im.ehyqvkwcaw.android.musicplayer.previous
Media Button Broadcast Action: The "Media Button" was pressed. android.intent.action.MEDIA_BUTTON
android.media.AUDIO_BECOMING_NOISY android.media.AUDIO_BECOMING_NOISY
im.ehyqvkwcaw.messenger.RefererReceiver
Actions
com.android.vending.INSTALL_REFERRER com.android.vending.INSTALL_REFERRER
im.ehyqvkwcaw.messenger.voip.VoIPMediaButtonReceiver
Actions
Media Button Broadcast Action: The "Media Button" was pressed. android.intent.action.MEDIA_BUTTON
im.ehyqvkwcaw.tel.IncomingCallReceiver
Actions
android.intent.action.PHONE_STATE android.intent.action.PHONE_STATE

Native Libraries (5)

libDingRtc libDingRtc.so
libclientcore libclientcore.so
libemulator_check libemulator_check.so
libproperty_get libproperty_get.so
libtmessages.31 libtmessages.31.so

Requested Permissions (48)

access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
android.permission.ACCESS_NOTIFICATION_POLICY Custom app or vendor permission (not publicly documented). android.permission.ACCESS_NOTIFICATION_POLICY
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
Authenticate Accounts android.permission.AUTHENTICATE_ACCOUNTS
android.permission.BIND_CHOOSER_TARGET_SERVICE Custom app or vendor permission (not publicly documented). android.permission.BIND_CHOOSER_TARGET_SERVICE
android.permission.BIND_JOB_SERVICE Custom app or vendor permission (not publicly documented). android.permission.BIND_JOB_SERVICE
android.permission.BIND_SCREENING_SERVICE Custom app or vendor permission (not publicly documented). android.permission.BIND_SCREENING_SERVICE
android.permission.BIND_TELECOM_CONNECTION_SERVICE Custom app or vendor permission (not publicly documented). android.permission.BIND_TELECOM_CONNECTION_SERVICE
pair with Bluetooth devices Allows the app to view the configuration of Bluetooth on the tablet, and to make and accept connections with paired devices. android.permission.BLUETOOTH
android.permission.BROADCAST_PACKAGE_ADDED Custom app or vendor permission (not publicly documented). android.permission.BROADCAST_PACKAGE_ADDED
android.permission.BROADCAST_PACKAGE_CHANGED Custom app or vendor permission (not publicly documented). android.permission.BROADCAST_PACKAGE_CHANGED
android.permission.BROADCAST_PACKAGE_INSTALL Custom app or vendor permission (not publicly documented). android.permission.BROADCAST_PACKAGE_INSTALL
android.permission.BROADCAST_PACKAGE_REPLACED Custom app or vendor permission (not publicly documented). android.permission.BROADCAST_PACKAGE_REPLACED
send sticky broadcast Allows the app to send sticky broadcasts, which remain after the broadcast ends. Excessive use may make the tablet slow or unstable by causing it to use too much memory. android.permission.BROADCAST_STICKY
directly call phone numbers Allows the app to call phone numbers without your intervention. This may result in unexpected charges or calls. Note that this doesn\'t allow the app to call emergency numbers. Malicious apps may cost you money by making calls without your confirmation, or dial carrier codes which cause incoming calls to be automatically forwarded to another number. android.permission.CALL_PHONE
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
Flashlight android.permission.FLASHLIGHT
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK
android.permission.FOREGROUND_SERVICE_MEDIA_PROJECTION Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_MEDIA_PROJECTION
retrieve running apps Allows the app to retrieve information about currently and recently running tasks. This may allow the app to discover information about which applications are used on the device. android.permission.GET_TASKS
Install Packages android.permission.INSTALL_PACKAGES
android.permission.INSTALL_SHORTCUT Custom app or vendor permission (not publicly documented). android.permission.INSTALL_SHORTCUT
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
android.permission.MANAGE_OWN_CALLS Custom app or vendor permission (not publicly documented). android.permission.MANAGE_OWN_CALLS
change your audio settings Allows the app to modify global audio settings such as volume and which speaker is used for output. android.permission.MODIFY_AUDIO_SETTINGS
Modify Phone State android.permission.MODIFY_PHONE_STATE
App badge update Allows the app to update the launcher icon badge count on Android launchers. android.permission.READ_APP_BADGE
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
Read Logs android.permission.READ_LOGS
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
Read Privileged Phone State android.permission.READ_PRIVILEGED_PHONE_STATE
Read Profile android.permission.READ_PROFILE
read sync settings Allows the app to read the sync settings for an account. For example, this can determine whether the People app is synced with an account. android.permission.READ_SYNC_SETTINGS
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
record audio android.permission.RECORD_AUDIO
reorder running apps Allows the app to move tasks to the foreground and background. The app may do this without your input. android.permission.REORDER_TASKS
This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
android.permission.USE_FINGERPRINT Custom app or vendor permission (not publicly documented). android.permission.USE_FINGERPRINT
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
Write Secure Settings android.permission.WRITE_SECURE_SETTINGS
toggle sync on and off Allows an app to modify the sync settings for an account. For example, this can be used to enable sync of the People app with an account. android.permission.WRITE_SYNC_SETTINGS

URL Endpoints (70)

http://192.168.1.4:20000/ http://192.200.1.242:1999/ http://game.bjz.com/ http://ip-api.com/json/ http://m.bjz.com/ http://schemas.microsoft.com/DRM/2007/03/protocols/AcquireLicense http://www.google.com http://www.shareinstall.com.cn/js-test.html?appkey=aa717156fa6e34325d3d4a7004a6647a http://www.slf4j.org/codes.html http://www.slf4j.org/codes.html#StaticLoggerBinder http://www.slf4j.org/codes.html#loggerNameMismatch http://www.slf4j.org/codes.html#multiple_bindings http://www.slf4j.org/codes.html#no_static_mdc_binder http://www.slf4j.org/codes.html#null_LF http://www.slf4j.org/codes.html#null_MDCA http://www.slf4j.org/codes.html#replay http://www.slf4j.org/codes.html#substituteLogger http://www.slf4j.org/codes.html#unsuccessfulInit http://www.slf4j.org/codes.html#version_mismatch http://xml.apache.org/xslt}indent-amount

Submission Details

Submitted At 2026-07-12
First Submission 2026-07-12
Last Submission 2026-07-12
Stored Until 2026-08-11

Other Versions

_hMM_j.apk com.baidu.location.f Unknown _hMM_j.apk Analyzed 2026-07-14 07:55 UTC
View report