酷我音乐 icon

cn.kuwo.kwmusiccas5.0.0.0pj.apk

酷我音乐

31.13 MB

Analyzed: 2026-06-21 03:00 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
78/100
Threat scan flagged Outdated target SDK
Privacy Permissions & network
46/100
High-risk permissions HTTP URLs found AllowBackup enabled Possible tracking
58/100
Caution
Overall trust

Facts

Threat scan 1/76 flagged, 0 suspicious
Permissions 29 requested
Network strings 111 URLs (99 HTTP, 12 HTTPS)
Target SDK 27
Certificate Valid until 2035-07-17 (9 years, suspicious)

Warnings

Threat scan flagged: 1/76 scanners marked this file as malicious.
Found 99 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.SYSTEM_ALERT_WINDOW, android.permission.WRITE_SETTINGS, android.permission.RECEIVE_BOOT_COMPLETED
Requests 29 permissions (review carefully).
AllowBackup is enabled.
Possible analytics/tracking domains found: alog.umeng.com, alog.umengcloud.com, uop.umeng.com
Package Name cn.kuwo.kwmusiccas
Version Code 5000
Version Name 5.0.0.0
Application Name cn.kuwo.kwmusiccar.App
Debuggable No
Allow Backup Yes
Min SDK Android 16 (Jelly Bean)
Target SDK Android 27 (Oreo)
Supported ABIs
armeabi

Certificate & Signer

Valid From 2008-02-29 01:33:46
Valid To 2035-07-17 01:33:46
Serial Number 936eacbe07f201df
Thumbprint 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Issuer: C US
Issuer: CN Android
Issuer: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Issuer: L Mountain View
Issuer: O Android
Issuer: OU Android
Issuer: ST California
Issuer: email android@android.com
Subject: C US
Subject: CN Android
Subject: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject: L Mountain View
Subject: O Android
Subject: OU Android
Subject: ST California
Subject: email android@android.com

Security Scan

1 /76
⚠️ Threats Detected
Detected by 1 vendor: Avast-Mobile (Android:Evo-gen [Trj])
Scanned by 76 security vendors
Last scan: 2022-11-23 16:27 UTC
Malicious
1
Suspicious
0
Harmless
0
Undetected
65
Timeout
0
Failure
0

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 1.1.3.1
APEX type-unsupported
No result reported
Engine 6.358
AVG undetected
No result reported
Engine 22.11.7701.0
Acronis undetected
No result reported
Engine 1.2.0.113
Ad-Aware undetected
No result reported
Engine 3.0.21.193
AhnLab-V3 undetected
No result reported
Engine 3.22.2.10299
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2022.0.0.18
Avast undetected
No result reported
Engine 22.11.7701.0
Avast-Mobile malicious
Android:Evo-gen [Trj]
Engine 221123-00
Avira undetected
No result reported
Engine 8.3.3.16
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
BitDefenderTheta undetected
No result reported
Engine 7.2.37796.0
Bkav undetected
No result reported
Engine 1.3.0.9899
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
ClamAV undetected
No result reported
Engine 0.105.1.0
Comodo undetected
No result reported
Engine 35181
CrowdStrike type-unsupported
No result reported
Engine 1.0
Cybereason type-unsupported
No result reported
Engine 1.2.449
Cylance type-unsupported
No result reported
Engine 2.3.1.101
Cynet type-unsupported
No result reported
Engine 4.0.0.27
Cyren undetected
No result reported
Engine 6.5.1.2
DrWeb undetected
No result reported
Engine 7.0.58.8230
ESET-NOD32 undetected
No result reported
Engine 26302
Elastic undetected
No result reported
Engine 4.0.59
Emsisoft undetected
No result reported
Engine 2022.6.0.32461
F-Secure undetected
No result reported
Engine 18.10.1137.128
FireEye undetected
No result reported
Engine 35.24.1.0
Fortinet undetected
No result reported
Engine 6.4.258.0
GData undetected
No result reported
Engine A:25.34569B:27.29645
Google undetected
No result reported
Engine 1669215680
Gridinsoft undetected
No result reported
Engine 1.0.101.174
Ikarus undetected
No result reported
Engine 6.0.33.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 12.52.45476
K7GW undetected
No result reported
Engine 12.52.45476
Kaspersky undetected
No result reported
Engine 21.0.1.45
Kingsoft undetected
No result reported
Engine 2017.9.26.565
Lionic undetected
No result reported
Engine 7.5
MAX undetected
No result reported
Engine 2019.9.16.1
Malwarebytes undetected
No result reported
Engine 4.3.3.37
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfee undetected
No result reported
Engine 6.0.6.653
McAfee-GW-Edition undetected
No result reported
Engine v2019.1.2+3728
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.19800.4
NANO-Antivirus undetected
No result reported
Engine 1.0.146.25648
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.27
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.23.0.0
SentinelOne type-unsupported
No result reported
Engine 22.3.2.9
Sophos undetected
No result reported
Engine 1.4.1.0
Symantec undetected
No result reported
Engine 1.19.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2022-11-23.03
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.1.119
TrendMicro undetected
No result reported
Engine 11.0.0.1006
TrendMicro-HouseCall undetected
No result reported
Engine 10.0.0.1040
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.0.0
VIPRE undetected
No result reported
Engine 6.0.0.35
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.331
Webroot type-unsupported
No result reported
Engine 1.0.0.403
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.4756
ZoneAlarm undetected
No result reported
Engine 1.0
Zoner undetected
No result reported
Engine 2.2.2.0
tehtris type-unsupported
No result reported
Engine v0.1.4

File Signatures

SHA-256 6fb8f785639c033427087b5315c92bd49e1c4c14d7f536831e6b8bdebfeb2a6b
MD5 4f01e0aa6f1a37d5028df25f93d27dac
SHA-1 34476971a48ebc8e40a355983ae79cf560b9ccf4
SSDEEP 786432:dfCGrMNQsWz0FYY6rxPvUTxBNQ+vB7XbYcTvOBluridHaev9rMqzc:dfBdsWtVrxns/v1HiBIridaevNA
TLSH T16B67238EA699F31BC4764433CAA21432B6768E1C251A81371A95B0F45CBBF341B87FDD
VHASH 568ea7ca7f1f84a82d90c00c3b24a6d4

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v1.0 to extract File signature result from magic bytes inspection.
TrID Android Package (51.6%), Java Archive (18.1%), Sweet Home 3D design (generic) (14%), Mozilla Archive Format (gen) (9.3%), ZIP compressed archive (5.3%) TrID file type guesses with probabilities.
extensions txt (842), png (146), xml (1) File extensions found inside the APK and how many of each.
file types unknown (853), PNG (146), XML (1) Detected embedded file types and their counts.
highest datetime 2008-02-29 10:33:46 UTC Latest timestamp found among files inside the archive.
lowest datetime 2008-02-29 10:33:46 UTC Earliest timestamp found among files inside the archive.
num children 2350 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 2.3 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

cn.kuwo.kwmusiccar.WelcomeActivity
Actions
cn.kuwo.kwmusicauto.action.STARTAPP cn.kuwo.kwmusicauto.action.STARTAPP
cn.kuwo.kwmusicauto.action.PLAY_MUSIC cn.kuwo.kwmusicauto.action.PLAY_MUSIC
cn.kuwo.kwmusicauto.action.SEARCH_MUSIC cn.kuwo.kwmusicauto.action.SEARCH_MUSIC
cn.kuwo.kwmusicauto.action.OPEN_FAVORITE_MUSIC cn.kuwo.kwmusicauto.action.OPEN_FAVORITE_MUSIC
cn.kuwo.kwmusicauto.action.vip.PLAY_ALL_MUSIC cn.kuwo.kwmusicauto.action.vip.PLAY_ALL_MUSIC
cn.kuwo.kwmusicauto.action.PLAY_INDEX_MUSIC cn.kuwo.kwmusicauto.action.PLAY_INDEX_MUSIC
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
cn.kuwo.kwmusicauto.action.RANDOM_PLAY_MUSIC cn.kuwo.kwmusicauto.action.RANDOM_PLAY_MUSIC
View Activity Action: Display the data to the user. android.intent.action.VIEW
cn.kuwo.kwmusicauto.action.PLAY_ALBUM cn.kuwo.kwmusicauto.action.PLAY_ALBUM
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT

Service Intents (3)

cn.kuwo.autosdk.AutoSdkService
Actions
cn.kuwo.service.AutoSdkService cn.kuwo.service.AutoSdkService
cn.kuwo.mod.push.PushService
Actions
cn.kuwo.mode.push.PushService cn.kuwo.mode.push.PushService
cn.kuwo.service.MainService
Actions
cn.kuwo.service.MainService cn.kuwo.service.MainService

Receiver Intents (4)

cn.kuwo.base.util.NetworkStateUtil
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
cn.kuwo.kwmusiccar.MediaButtonReceiver
Actions
Media Button Broadcast Action: The "Media Button" was pressed. android.intent.action.MEDIA_BUTTON
cn.kuwo.kwmusiccar.PlayMusicReceiver
Actions
cn.kuwo.kwmusicauto.action.vip.PLAY_ALL_MUSIC cn.kuwo.kwmusicauto.action.vip.PLAY_ALL_MUSIC
cn.kuwo.kwmusicauto.action.PLAY_MUSIC cn.kuwo.kwmusicauto.action.PLAY_MUSIC
cn.kuwo.mod.notification.NotificationReceiver
Actions
kuwo.musichd_car.pre kuwo.musichd_car.pre
kuwo.musichd_car.next kuwo.musichd_car.next
kuwo.musichd_car.playing kuwo.musichd_car.playing
kuwo.musichd_car.go.main kuwo.musichd_car.go.main
kuwo.musichd_car.exitapp kuwo.musichd_car.exitapp

Native Libraries (18)

libcalsig libcalsig.so
libgifimage libgifimage.so
libijkffmpeg libijkffmpeg.so
libijkplayer libijkplayer.so
libijkplayerV7 libijkplayerV7.so
libijksdl libijksdl.so
libijksdlV7 libijksdlV7.so
libimagepipeline libimagepipeline.so
libkwbase libkwbase.so
libkwframe libkwframe.so
libkwframeV7 libkwframeV7.so
liblocSDK7a liblocSDK7a.so
libmsc libmsc.so
libmusic3d libmusic3d.so
libopenal libopenal.so
libopenalwrapper libopenalwrapper.so
libp2p libp2p.so
libzegoliveroom libzegoliveroom.so

Requested Permissions (41)

modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
modify system settings Allows the app to modify the system\'s settings data. Malicious apps may corrupt your system\'s configuration. android.permission.WRITE_SETTINGS
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
Mount Format Filesystems android.permission.MOUNT_FORMAT_FILESYSTEMS
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
Read Logs android.permission.READ_LOGS
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
App badge update Allows the app to update the launcher icon badge count on launcher launchers. com.android.launcher.permission.INSTALL_SHORTCUT
App badge update Allows the app to update the launcher icon badge count on launcher launchers. com.android.launcher.permission.UNINSTALL_SHORTCUT
reorder running apps Allows the app to move tasks to the foreground and background. The app may do this without your input. android.permission.REORDER_TASKS
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
disable your screen lock Allows the app to disable the keylock and any associated password security. For example, the phone disables the keylock when receiving an incoming phone call, then re-enables the keylock when the call is finished. android.permission.DISABLE_KEYGUARD
retrieve running apps Allows the app to retrieve information about currently and recently running tasks. This may allow the app to discover information about which applications are used on the device. android.permission.GET_TASKS
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
android.permission.DOWNLOAD_WITHOUT_NOTIFICATION Custom app or vendor permission (not publicly documented). android.permission.DOWNLOAD_WITHOUT_NOTIFICATION
change your audio settings Allows the app to modify global audio settings such as volume and which speaker is used for output. android.permission.MODIFY_AUDIO_SETTINGS
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
Mount Unmount Filesystems android.permission.MOUNT_UNMOUNT_FILESYSTEMS
Read Logs android.permission.READ_LOGS
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
record audio android.permission.RECORD_AUDIO
pair with Bluetooth devices Allows the app to view the configuration of Bluetooth on the tablet, and to make and accept connections with paired devices. android.permission.BLUETOOTH
reroute outgoing calls Allows the app to see the number being dialed during an outgoing call with the option to redirect the call to a different number or abort the call altogether. android.permission.PROCESS_OUTGOING_CALLS

Activities (5)

cn.kuwo.kwmusiccar.MainActivity
cn.kuwo.kwmusiccar.NoSDCardActivity
cn.kuwo.kwmusiccar.ad.AdOpenActivity
cn.kuwo.kwmusiccar.WelcomeActivity
cn.kuwo.show.live.activities.MainActivity

Services (4)

com.baidu.location.f
cn.kuwo.service.MainService
cn.kuwo.autosdk.AutoSdkService
cn.kuwo.mod.push.PushService

Broadcast Receivers (4)

cn.kuwo.base.util.NetworkStateUtil cn.kuwo.base.util.NetworkStateUtil
cn.kuwo.kwmusiccar.MediaButtonReceiver cn.kuwo.kwmusiccar.MediaButtonReceiver
cn.kuwo.mod.notification.NotificationReceiver cn.kuwo.mod.notification.NotificationReceiver
cn.kuwo.kwmusiccar.PlayMusicReceiver cn.kuwo.kwmusiccar.PlayMusicReceiver

URL Endpoints (111)

http://60.28.198.33/music.pay http://60.28.200.82:808/uparcrash.lct http://60.28.210.108:8080/ http://ad.tencentmusic.com http://ad.tencentmusic.com/track/getAdFail http://ad.tencentmusic.com/track/heap http://alog.umeng.com/app_logs http://alog.umengcloud.com/app_logs http://ar.i.kuwo.cn/US_NEW http://ar.i.kuwo.cn/US_NEW/kuwo/vuser http://ar.i.kuwo.cn/US_NEW/kuwo/vuser?f=ar&q= http://artistpic.kuwo.cn/pic.web http://artistpicserver.kuwo.cn/pic.web http://car-vip.kuwo.cn/ http://car-vip.kuwo.cn/vehicle/merge http://car-vip.kuwo.cn/vehicle/vipinfo http://cfg.imtt.qq.com/tbs?v=2&mk= http://checkdcserver.kuwo.cn/u.dc?type=updatedc http://console.ecom.kuwo.cn/vip_adv/v2/vipzone/carSongList http://data.openspeech.cn/index.php/clientrequest/clientcollect/isCollect

Submission Details

Submitted At 2026-06-21
First Submission 2026-06-21
Last Submission 2026-06-21
Stored Until 2026-07-21