Wildberriespersonal__1_.apk

1.79 MB

Analyzed: 2026-07-16 09:19 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
33/100
Threat scan flagged Modern target SDK
Privacy Permissions & network
94/100
High-risk permissions Low data access
49/100
High Risk
Overall trust

Facts

Threat scan 11/74 flagged, 0 suspicious
Permissions 13 requested
Network strings 1 URLs (0 HTTP, 1 HTTPS)
Target SDK 34
Certificate Valid until 2035-07-17 (9 years, suspicious)

Warnings

Threat scan flagged: 11/74 scanners marked this file as malicious.
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES, android.permission.REQUEST_DELETE_PACKAGES, android.permission.RECEIVE_BOOT_COMPLETED
Package Name dev.brightharbor.wildberriespersonal.cdbh
Version Code 1
Version Name 1337.0-2026_07_15_21-54-17
Application Name com.obfuscate.MainApplication
Debuggable No
Allow Backup No
Min SDK Android 26 (Oreo)
Target SDK Android 34 (Android 14)
Supported ABIs
Universal

Certificate & Signer

Valid From 2008-02-29 01:33:46
Valid To 2035-07-17 01:33:46
Serial Number 936eacbe07f201df
Thumbprint 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Issuer: C US
Issuer: CN Android
Issuer: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Issuer: L Mountain View
Issuer: O Android
Issuer: OU Android
Issuer: ST California
Issuer: email android@android.com
Subject: C US
Subject: CN Android
Subject: DN C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject: L Mountain View
Subject: O Android
Subject: OU Android
Subject: ST California
Subject: email android@android.com

Security Scan

11 /74
⚠️ Threats Detected
Detected by 11 vendors: AVG (Android:Evo-gen [Trj]), AhnLab-V3 (Dropper/Android.Agent.1323023), Avast (Android:Evo-gen [Trj])
Scanned by 74 security vendors
Last scan: 2026-07-16 09:19 UTC
Malicious
11
Suspicious
0
Harmless
0
Undetected
55
Timeout
0
Failure
1

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.798
AVG malicious
Android:Evo-gen [Trj]
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
Dropper/Android.Agent.1323023
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast malicious
Android:Evo-gen [Trj]
Engine 23.9.8494.0
Avast-Mobile malicious
Android:Evo-gen [Trj]
Engine 260716-00
Avira malicious
ANDROID/Evo.AG1589579.Gen
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.Packer.aJO
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet malicious
Malicious (score: 99)
Engine 4.0.3.4
DrWeb malicious
Android.DownLoader.Mamont.4.origin
Engine 7.0.75.2070
ESET-NOD32 malicious
Android/TrojanDownloader.Agent.BKU trojan
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.271
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure malicious
Malware.ANDROID/Evo.AG1589579.Gen
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45283AVA:64.31587
Google undetected
No result reported
Engine 1784188850
Gridinsoft undetected
No result reported
Engine 1.0.250.174
Ikarus failure
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.63.60148
K7GW undetected
No result reported
Engine 14.63.60149
Kaspersky malicious
HEUR:Trojan-Downloader.AndroidOS.Banker.bh
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.246
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26060.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.6.2.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-07-15.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.14.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1250
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38811
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5642
ZoneAlarm undetected
No result reported
Engine 6.26-117392247
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine a114442:a114442:3f757df:3f757df
tehtris type-unsupported
No result reported

File Signatures

SHA-256 f2c017a31e314d868cbd9e5f49ed9715da4795100baa047a0ab98f0171021271
MD5 154c0bc3ce6e2a491e5af7e43b9f4467
SHA-1 910399e0403d7fef2cce443551d6f7c438ea258e
SSDEEP 49152:Bq+720ikCugle3SxH1AhQn7qju3PQgXuEpipln:0+7rse3SxVAhQnAu3PQgXVE
TLSH T17C85BD46F349947AC4F782324A3607A50267DC268E83D7C3696C763C5DBB9C88F5AF84
VHASH ae44da44fb8ae154d50428c8a08c2d86
PERMHASH 51389cd34bf4317f6eb3d8891928571672122f78b72129565e3e76c207557d05

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v2.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (49%), Java Archive (24.5%), Sweet Home 3D Design (generic) (19%), ZIP compressed archive (7.2%) TrID file type guesses with probabilities.
dhash 0000001e1e0d1410 Perceptual hash used to compare visual similarity of files.
raw md5 b9911e51eef03614e76818b8c9c454cd Raw MD5 hash of the file contents.
extensions xml (263), png (151), webp (10), kotlin_builtins (7), e (2), arsc (1), bin (1), dex (1), MF (1), pad (1), prof (1), profm (1), RSA (1), SF (1) File extensions found inside the APK and how many of each.
file types XML (263), PNG (151), unknown (27), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 2026-07-15 21:55:32 UTC Latest timestamp found among files inside the archive.
lowest datetime 2026-07-15 21:55:32 UTC Earliest timestamp found among files inside the archive.
num children 442 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 2.5 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Harmless 95% confidence CLEAN

Deep Manifest Analysis

Activity Intents (1)

com.nexus.portal.FrameActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER

Service Intents (1)

com.nexus.portal.BlockerVpnService
Actions
android.net.VpnService android.net.VpnService

Receiver Intents (1)

com.nexus.portal.InstallResultReceiver
Actions
DONE_INSTALL_IMPLANT DONE_INSTALL_IMPLANT
DONE_UNINSTALL_IMPLANT DONE_UNINSTALL_IMPLANT

Requested Permissions (13)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
android.permission.READ_MEDIA_VIDEO Custom app or vendor permission (not publicly documented). android.permission.READ_MEDIA_VIDEO
android.permission.READ_MEDIA_IMAGES Custom app or vendor permission (not publicly documented). android.permission.READ_MEDIA_IMAGES
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_SPECIAL_USE Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_SPECIAL_USE
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
android.permission.REQUEST_DELETE_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_DELETE_PACKAGES
toggle sync on and off Allows an app to modify the sync settings for an account. For example, this can be used to enable sync of the People app with an account. android.permission.WRITE_SYNC_SETTINGS
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. dev.brightharbor.wildberriespersonal.cdbh.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (1)

com.nexus.portal.FrameActivity

Services (1)

com.nexus.portal.BlockerVpnService

Broadcast Receivers (1)

com.nexus.portal.InstallResultReceiver com.nexus.portal.InstallResultReceiver

Content Providers (2)

androidx.core.content.FileProvider
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-07-16
First Submission 2026-07-16
Last Submission 2026-07-16
Stored Until 2026-08-15