Yape icon

base.apk

Yape

69.43 MB

Analyzed: 2026-05-17 17:49 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
96/100
Threat scan clean Modern target SDK
Privacy Permissions & network
56/100
High-risk permissions HTTP URLs found Possible tracking
71/100
Caution
Overall trust

Facts

Threat scan 0/75 flagged, 0 suspicious
Permissions 32 requested
Network strings 33 URLs (1 HTTP, 32 HTTPS)
Target SDK 35
Certificate Valid until 2043-12-28 (18 years, suspicious)

Warnings

Found 1 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.PACKAGE_USAGE_STATS, android.permission.RECEIVE_BOOT_COMPLETED
Requests 32 permissions (review carefully).
Possible analytics/tracking domains found: app-measurement.com
Package Name com.bcp.innovacxion.yapeapp
Version Code 24943
Version Name 3.64.1
Application Name o.updateConfiguration
Debuggable No
Allow Backup No
Min SDK Android 26 (Oreo)
Target SDK Android 35 (Android 15)
Supported ABIs
Universal

Certificate & Signer

Valid From 2016-08-11 21:21:28
Valid To 2043-12-28 21:21:28
Serial Number 3711d136
Thumbprint 9597ecb0ba13d9d5d40a2d363cad8828dbb93e21
Issuer: C PE
Issuer: CN Banco de Credito del Peru
Issuer: DN C:PE, CN:Banco de Credito del Peru, L:Lima, O:Banco de Credito del Peru, ST:Lima, OU:Centro de Innovacion
Issuer: L Lima
Issuer: O Banco de Credito del Peru
Issuer: OU Centro de Innovacion
Issuer: ST Lima
Subject: C PE
Subject: CN Banco de Credito del Peru
Subject: DN C:PE, CN:Banco de Credito del Peru, L:Lima, O:Banco de Credito del Peru, ST:Lima, OU:Centro de Innovacion
Subject: L Lima
Subject: O Banco de Credito del Peru
Subject: OU Centro de Innovacion
Subject: ST Lima

Security Scan

0 /75
✓ Clean
Scanned by 75 security vendors
Last scan: 2026-05-13 00:49 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
63
Timeout
2
Failure
1

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.777
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.0.10666
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260512-02
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav failure
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.261
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44524AVA:64.31231
Google undetected
No result reported
Engine 1778626857
Gridinsoft undetected
No result reported
Engine 1.0.245.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.52.59485
K7GW undetected
No result reported
Engine 14.52.59485
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.235
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14532
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.6.2.19
Skyhigh timeout
No result reported
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-05-12.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.12.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.0
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1205
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38641
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5600
ZoneAlarm undetected
No result reported
Engine 6.24-114820814
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 8e87f09:8e87f09:364e302:364e302
tehtris type-unsupported
No result reported

File Signatures

SHA-256 eb7aedc506297bb4ca1328662918159a8a2f4fc90360ef87aaf5657e0c9a3c98
MD5 67cb344231ecc9f9a94d5d8f127fbf89
SHA-1 908db4035dac500bedb0b4b8c6f7b8c5f96f39b5
SSDEEP 1572864:LaITr4SX4/4LuDUb3QP4H2xDQ8KoI5ymK:BT8Eb3QP4H2xUHoIAt
TLSH T141F73396F346158BDFB761F1883D422603359C649606364B7848B22C3E772D9AFBCBD2
VHASH f6048652102c939d653fa021bb115f26
PERMHASH 0156c946d8987501c7cc877021668dea71966e78af2341366acf26187286a296

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID SPSS Extension (35.2%), Android Package (31.7%), Java Archive (15.8%), Sweet Home 3D Design (generic) (12.3%), ZIP compressed archive (4.7%) TrID file type guesses with probabilities.
dhash 0000001c1e1d0410 Perceptual hash used to compare visual similarity of files.
raw md5 d08dc5ffd5b7cdbed1cac97d08587319 Raw MD5 hash of the file contents.
extensions xml (607), version (117), proto (76), properties (54), rtttl (28), dex (9), kotlin_builtins (8), json (7), html (3), tflite (3), txt (3), zzip (3), cer (2), zip (2), accessgetWindowcp (1), accessgetZenkakuHankarucp (1), ActivityResultLauncherKt (1), ActivityResultRegistry (1), bin (1), bks (1), CoroutineExceptionHandler (1), der (1), getBreakEK5gGoQ (1), getKeyCode (1), getSemicolonEK5gGoQ (1), gz (1), lic (1), MainDispatcherFactory (1), md (1), MF (1), p12 (1), prof (1), profm (1), textproto (1) File extensions found inside the APK and how many of each.
file types XML (607), unknown (368), PNG (17), HTML (3), JSON (2), ZIP (2), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 2540 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 127 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

com.yape.activity.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE

Requested Permissions (32)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
read your contacts Allows the app to read data about your contacts stored on your tablet. Apps will also have access to the accounts on your tablet that have created contacts. This may include accounts created by apps you have installed. This permission allows apps to save your contact data, and malicious apps may share contact data without your knowledge. android.permission.READ_CONTACTS
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
android.permission.WRITE_INTERNAL_STORAGE Custom app or vendor permission (not publicly documented). android.permission.WRITE_INTERNAL_STORAGE
android.permission.READ_INTERNAL_STORAGE Custom app or vendor permission (not publicly documented). android.permission.READ_INTERNAL_STORAGE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
android.permission.HIDE_OVERLAY_WINDOWS Custom app or vendor permission (not publicly documented). android.permission.HIDE_OVERLAY_WINDOWS
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
com.google.android.gms.permission.AD_ID Custom app or vendor permission (not publicly documented). com.google.android.gms.permission.AD_ID
android.permission.DOWNLOAD_WITHOUT_NOTIFICATION Custom app or vendor permission (not publicly documented). android.permission.DOWNLOAD_WITHOUT_NOTIFICATION
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
AdServices Attribution Required to call AdServices Attribution APIs. android.permission.ACCESS_ADSERVICES_ATTRIBUTION
AdServices Advertising ID Required to call AdServices Advertising ID APIs. android.permission.ACCESS_ADSERVICES_AD_ID
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Package Usage Stats android.permission.PACKAGE_USAGE_STATS
com.samsung.android.mapsagent.permission.READ_APP_INFO Custom app or vendor permission (not publicly documented). com.samsung.android.mapsagent.permission.READ_APP_INFO
com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA Custom app or vendor permission (not publicly documented). com.huawei.appmarket.service.commondata.permission.GET_COMMON_DATA
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.USE_BIOMETRIC Custom app or vendor permission (not publicly documented). android.permission.USE_BIOMETRIC
android.permission.USE_FINGERPRINT Custom app or vendor permission (not publicly documented). android.permission.USE_FINGERPRINT
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.bcp.innovacxion.yapeapp.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
Flashlight android.permission.FLASHLIGHT
com.bcp.innovacxion.yapeapp.permission.PROCESS_PUSH_MSG Custom app or vendor permission (not publicly documented). com.bcp.innovacxion.yapeapp.permission.PROCESS_PUSH_MSG
com.bcp.innovacxion.yapeapp.permission.PUSH_PROVIDER Custom app or vendor permission (not publicly documented). com.bcp.innovacxion.yapeapp.permission.PUSH_PROVIDER

Uses Features (3)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Camera Autofocus Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.autofocus
Camera Flash Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.flash

Activities (34)

com.yape.activity.MainActivity
com.qualtrics.digital.QualtricsSurveyActivity
com.qualtrics.digital.QualtricsPopOverActivity
o.ModalBottomSheet_androidKtModalBottomSheetDialog11
com.qualtrics.digital.QualtricsEmbeddedFeedbackActivity
zendesk.messaging.android.internal.messagingscreen.MessagingActivity
zendesk.messaging.android.internal.conversationscreen.ImageViewerActivity
io.customer.messagingpush.activity.NotificationClickReceiverActivity
io.customer.messaginginapp.gist.presentation.GistModalActivity
o.accessgetTouchcp
com.bcp.ciam.facialbiometry.presentation.view.activity.MainFacialActivity
com.facephi.selphi.Widget
com.facephi.selphid.Widget
com.facephi.fphiselphidwidgetcore.FPhiWidgetPermission
o.accesssetAnchoredZoomStartYp
o.TextureViewImplementation1ExternalSyntheticLambda0
com.google.android.libraries.places.widget.AutocompleteActivity
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
com.google.android.gms.common.api.GoogleApiActivity
androidx.compose.ui.tooling.PreviewActivity
com.facephi.fphiwidgetcore.FPhiWidgetPermission
com.microblink.blinkid.activity.DocumentScanActivity
com.microblink.blinkid.activity.BarcodeScanActivity
com.microblink.blinkid.activity.FieldByFieldScanActivity
com.microblink.blinkid.activity.LegacyDocumentVerificationActivity
com.microblink.blinkid.activity.BlinkCardActivity
com.microblink.blinkid.activity.BlinkIdActivity
com.microblink.blinkid.activity.DocumentCaptureActivity
com.microblink.blinkid.activity.edit.BlinkCardEditActivity
com.huawei.hms.support.api.push.TransActivity
lib.visanet.com.pe.visanetlib.presentation.ui.VisaNetValidateActivity
com.google.android.play.core.common.PlayCoreDialogWrapperActivity
com.huawei.hms.activity.BridgeActivity
com.huawei.hms.activity.EnableServiceActivity

Services (20)

o.getDisabledUncheckedBorderColor0d7_KjU
o.getDisabledBorderColor0d7_KjU
com.google.android.gms.metadata.ModuleDependencies
com.google.firebase.components.ComponentDiscoveryService
o.accessgetMediaFastForwardcp
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
androidx.camera.core.impl.MetadataHolderService
o.requestInputModeiuPiT84
com.google.mlkit.common.internal.MlKitComponentDiscoveryService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
androidx.work.impl.background.systemalarm.SystemAlarmService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService
com.google.android.gms.auth.api.signin.RevocationBoundService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
com.huawei.hms.support.api.push.service.HmsMsgService
com.huawei.agconnect.core.ServiceDiscovery

Broadcast Receivers (20)

o.ExpandedMenuView o.ExpandedMenuView
o.CascadingMenuPopupCascadingMenuInfo$onTransact o.CascadingMenuPopupCascadingMenuInfo$onTransact
com.qualtrics.digital.QualtricsNotificationManager com.qualtrics.digital.QualtricsNotificationManager
io.customer.messagingpush.CustomerIOCloudMessagingReceiver io.customer.messagingpush.CustomerIOCloudMessagingReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
o.getInputModeaOaMEAU o.getInputModeaOaMEAU
o.InputModeManagerImpl o.InputModeManagerImpl
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
androidx.work.impl.diagnostics.DiagnosticsReceiver androidx.work.impl.diagnostics.DiagnosticsReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.huawei.hms.support.api.push.PushMsgReceiver com.huawei.hms.support.api.push.PushMsgReceiver
com.huawei.hms.support.api.push.PushReceiver com.huawei.hms.support.api.push.PushReceiver

Content Providers (10)

androidx.core.content.FileProvider
o.measureChildView
zendesk.messaging.android.internal.ZendeskFileProvider
com.google.firebase.provider.FirebaseInitProvider
o.getKeyboardaOaMEAU
com.google.mlkit.common.internal.MlKitInitProvider
androidx.startup.InitializationProvider
com.huawei.hms.support.api.push.PushProvider
com.huawei.hms.aaid.InitProvider
o.AlertDialogLayout

URL Endpoints (36)

http://onelink.to/9sgxge https://accounts.google.com https://accounts.google.com/o/oauth2/revoke?token= https://app-measurement.com/a https://app-measurement.com/s/d https://bit.ly/2XFpdma https://cloud.google.com/kms/docs/reference/rest/v1/projects.locations.keyRings.cryptoKeys#CryptoKey https://data.microblink.com/enc https://developer.android.com/build/agp-upgrade-assistant https://developer.android.com/google/play/integrity/reference/com/google/android/play/core/integrity/model/IntegrityErrorCode.html# https://developer.android.com/kotlin/add-kotlin https://firebase.google.com/support/guides/disable-analytics https://goo.gl/NAOOOI https://google.com/search https://info.yape.com.pe/AppAnulacionCeluSeguro_Bot https://info.yape.com.pe/AppAnulacionSeguroVida_Bot https://info.yape.com.pe/AppDerivaAsesorSeguroVida https://info.yape.com.pe/AppModBeneficiarioSeguroVida_Bot https://info.yape.com.pe/AppUtilizarDMS_Bot https://info.yape.com.pe/App_CancelarSeguroSalud_Bot

Submission Details

Submitted At 2026-05-17
First Submission 2026-05-17
Last Submission 2026-05-17
Stored Until 2026-06-16