App Cloner++ icon

_Root-Device.com__app_cloner_pro_1700-alpha_rus.apk

App Cloner++

13.36 MB

Analyzed: 2026-07-12 00:08 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
52/100
Threat scan flagged
Privacy Permissions & network
95/100
High-risk permissions HTTP URLs found Possible tracking Low data access
67/100
Caution
Overall trust

Facts

Threat scan 6/74 flagged, 0 suspicious
Permissions 13 requested
Network strings 41 URLs (8 HTTP, 33 HTTPS)
Target SDK 29
Certificate Valid until 3024-03-23 (292 years, suspicious)

Warnings

Threat scan flagged: 6/74 scanners marked this file as malicious.
Found 8 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES
Possible analytics/tracking domains found: pagead2.googlesyndication.com
Package Name com.begal.appclone
Version Code 2024050301
Version Name 17.0.0-alpha
Application Name com.begal.appclone.MainApplication
Debuggable No
Allow Backup No
Min SDK Android 15 (Ice Cream Sandwich)
Target SDK Android 29 (Android 10)
Supported ABIs
arm64-v8a armeabi-v7a x86 x86_64

Certificate & Signer

Valid From 2024-11-20 07:41:11
Valid To 3024-03-23 07:41:11
Serial Number 7cc02aab
Thumbprint b4cfccd6ea03289675552a0e70ba6c41e4549124
Issuer: C Russia
Issuer: CN FuRReX
Issuer: DN C:Russia, CN:FuRReX, L:Petrodvorets, O:Root-Device.com, ST:Saint-Petersburg, OU:@r_device
Issuer: L Petrodvorets
Issuer: O Root-Device.com
Issuer: OU @r_device
Issuer: ST Saint-Petersburg
Subject: C Russia
Subject: CN FuRReX
Subject: DN C:Russia, CN:FuRReX, L:Petrodvorets, O:Root-Device.com, ST:Saint-Petersburg, OU:@r_device
Subject: L Petrodvorets
Subject: O Root-Device.com
Subject: OU @r_device
Subject: ST Saint-Petersburg

Security Scan

6 /74
⚠️ Threats Detected
Detected by 6 vendors: AhnLab-V3 (PUP/Android.Malct.1301630), BitDefenderFalx (Android.Riskware.Agent.gLLSN), Google (Detected)
Scanned by 74 security vendors
Last scan: 2026-06-21 07:42 UTC
Malicious
6
Suspicious
0
Harmless
0
Undetected
61
Timeout
0
Failure
0

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.790
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
PUP/Android.Malct.1301630
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260620-02
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.Agent.gLLSN
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.265
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.44986AVA:64.31451
Google malicious
Detected
Engine 1782018067
Ikarus undetected
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.58.59888
K7GW undetected
No result reported
Engine 14.58.59888
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.239
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26050.11
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.6.3.2
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos malicious
Andr/Xgen-BUV
Engine 3.5.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight malicious
AppRisk:Generisk
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-06-21.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.12.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1232
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38745
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5626
ZoneAlarm malicious
Andr/Xgen-BUV
Engine 6.25-116107715
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 24c69a4:24c69a4:1e47ea2:1e47ea2
tehtris type-unsupported
No result reported

File Signatures

SHA-256 77cfbf42450c2f780e9eb963f3763c5694440dcaa41b24ce4afcba1732a0f689
MD5 0e569babe663451d9be00d0aa9ac4713
SHA-1 a83c5f45f9ee75729842af9a767967afcbab7201
SSDEEP 393216:Z9pKEH0Jmmiri5YN6SYN2Wmn8IjaefNlEU:Z9miW5YNsNLa8IuIP
TLSH T161E62251EB8E9C19C5B3A63F97AE0E2FB5630C5C17939303D0447138A8B3DE587A5DA8
VHASH 36f7985e71ed01df1ad5b2b3e1b492e9
PERMHASH de4dfa5ee315b6eddd60760104c05f4d851041e11e37a0b69c33ce47223c22bf

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v1.0 to extract, compression method=store File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID SPSS Extension (35.2%), Android Package (31.7%), Java Archive (15.8%), Sweet Home 3D Design (generic) (12.3%), ZIP compressed archive (4.7%) TrID file type guesses with probabilities.
dhash 0000001e1e171600 Perceptual hash used to compare visual similarity of files.
raw md5 f0752ecf95fc84db6c28a467ae493ae5 Raw MD5 hash of the file contents.
extensions png (385), xml (232), kotlin_metadata (171), version (102), java (31), kotlin_module (12), dex (6), kotlin_builtins (6), properties (6), pem (4), pk8 (4), sbt (4), so (4), dat (3), pro (3), jpeg (2), MF (2), RSA (2), SF (2), css (1), gz (1), html (1), js (1), json (1), ks (1), mp3 (1), ttf (1), zip (1) File extensions found inside the APK and how many of each.
file types PNG (385), unknown (360), XML (232), ELF (14), DEX (6), JPG (2), HTML (1) Detected embedded file types and their counts.
highest datetime 2024-05-03 13:47:48 UTC Latest timestamp found among files inside the archive.
lowest datetime 1980-01-01 01:00:00 UTC Earliest timestamp found among files inside the archive.
num children 1317 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 23 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Malicious 84% confidence MALWARE TROJAN EVADER

Deep Manifest Analysis

Activity Intents (2)

com.begal.appclone.MainActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.begal.appclone.h.a.StartActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER android.intent.category.LEANBACK_LAUNCHER

Service Intents (2)

com.begal.appclone.InstallService
Actions
android.accessibilityservice.AccessibilityService android.accessibilityservice.AccessibilityService
com.google.firebase.iid.FirebaseInstanceIdService
Actions
com.google.firebase.INSTANCE_ID_EVENT com.google.firebase.INSTANCE_ID_EVENT

Receiver Intents (4)

com.amazon.device.iap.ResponseReceiver
Actions
com.amazon.inapp.purchasing.NOTIFY com.amazon.inapp.purchasing.NOTIFY
com.begal.appclone.update.UpdateReceiver
Actions
Package Added Broadcast Action: A new application package has been installed on the android.intent.action.PACKAGE_ADDED
Package Replaced Broadcast Action: A new version of an application package has been android.intent.action.PACKAGE_REPLACED
com.google.android.gms.measurement.AppMeasurementInstallReferrerReceiver
Actions
com.android.vending.INSTALL_REFERRER com.android.vending.INSTALL_REFERRER
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Native Libraries (1)

libzstd-jni libzstd-jni.so

Requested Permissions (13)

view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
android.permission.USE_FINGERPRINT Custom app or vendor permission (not publicly documented). android.permission.USE_FINGERPRINT
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
com.android.vending.BILLING
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
com.begal.appclone.permission.DEFAULT Custom app or vendor permission (not publicly documented). com.begal.appclone.permission.DEFAULT
App badge update Allows the app to update the launcher icon badge count on launcher launchers. com.android.launcher.permission.INSTALL_SHORTCUT
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
com.android.vending.CHECK_LICENSE

Uses Features (2)

Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (16)

com.begal.appclone.h.a.StartActivity
util.appcompat.OnboardingActivity
com.begal.appclone.MainActivity
com.begal.appclone.SettingsActivity
com.begal.appclone.update.UpdateActivity
com.begal.appclone.util.RootInstallerActivity
com.begal.appclone.purchase.PurchaseActivity
com.begal.appclone.MasterPasswordActivity
com.begal.appclone.HtmlEditorActivity
com.begal.appclone.ApkWebBrowserActivity
com.begal.appclone.PreferencesEditorActivity
util.ClearActivityStackActivity
util.RequestPermissionsActivity
com.nbsp.materialfilepicker.ui.FilePickerActivity
com.google.android.gms.common.api.GoogleApiActivity
com.android.apksig.ApkSigner

Services (5)

com.begal.appclone.InstallService
com.google.firebase.components.ComponentDiscoveryService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.firebase.iid.FirebaseInstanceIdService

Broadcast Receivers (5)

com.begal.appclone.update.UpdateReceiver com.begal.appclone.update.UpdateReceiver
com.amazon.device.iap.ResponseReceiver com.amazon.device.iap.ResponseReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
com.google.android.gms.measurement.AppMeasurementInstallReferrerReceiver com.google.android.gms.measurement.AppMeasurementInstallReferrerReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver

Content Providers (5)

com.begal.appclone.provider.AppProvider
com.begal.appclone.provider.ApkProvider
com.begal.appclone.provider.PurchaseInfoProvider
com.crashlytics.android.CrashlyticsInitProvider
com.google.firebase.provider.FirebaseInitProvider

URL Endpoints (41)

http://play.google.com/store/apps/details?id= http://tasker.dinglisch.net/download.html http://whois.domaintools.com/ http://www.amazon.com/gp/mas/get-appstore/android/ref=mas_mx_mba_iap_dl http://www.bouncycastle.org http://www.google.com http://www.google.com/search?q= http://www.test.com https://adaway.org/hosts.txt https://apkpure.com/ https://apkpure.com/search?q= https://appcloner-firebase-ch.firebaseio.com https://appcloner.app https://appcloner.app/api/purchase/v1/purchases?params= https://appcloner.app/api/verification/v1/verify-email?params= https://appcloner.app/privacy/ https://appcloner.app/purchase/cc/checkout?params= https://appcloner.app/terms/ https://b.whatsapp.com https://console.cloud.google.com/google/maps-apis/apis/maps-android-backend.googleapis.com/credentials

Submission Details

Submitted At 2026-07-12
First Submission 2026-07-12
Last Submission 2026-07-12
Stored Until 2026-08-11