fbapp-lite.apk

90.80 MB

Analyzed: 2026-05-12 16:15 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
94/100
Threat scan clean Modern target SDK
Privacy Permissions & network
95/100
High-risk permissions HTTP URLs found Low data access
94/100
Excellent
Overall trust

Facts

Threat scan 0/74 flagged, 0 suspicious
Permissions 13 requested
Network strings 56 URLs (17 HTTP, 39 HTTPS)
Target SDK 36
Certificate Valid until 2053-03-06 (27 years, suspicious)

Warnings

Found 17 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.QUERY_ALL_PACKAGES, android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, android.permission.RECEIVE_BOOT_COMPLETED
Package Name com.fbclient.app
Version Code 2026042911
Version Name 3.0.3
Application Name com.follow.clash.Application
Debuggable No
Allow Backup No
Min SDK Android 24 (Nougat)
Target SDK Android 36 (Unknown)
Supported ABIs
arm64-v8a armeabi-v7a x86_64

Certificate & Signer

Valid From 2025-10-19 15:32:13
Valid To 2053-03-06 15:32:13
Serial Number e8368584e681ef4e
Thumbprint 3e14cac0f42247f226d868ffb59e2072def44e0e
Issuer: C USA
Issuer: CN NetAPPGod
Issuer: DN C:USA, CN:NetAPPGod, L:NetAPPGod, O:NetAPPGod, ST:NetAPPGod, OU:NetAPPGod
Issuer: L NetAPPGod
Issuer: O NetAPPGod
Issuer: OU NetAPPGod
Issuer: ST NetAPPGod
Subject: C USA
Subject: CN NetAPPGod
Subject: DN C:USA, CN:NetAPPGod, L:NetAPPGod, O:NetAPPGod, ST:NetAPPGod, OU:NetAPPGod
Subject: L NetAPPGod
Subject: O NetAPPGod
Subject: OU NetAPPGod
Subject: ST NetAPPGod

Security Scan

0 /74
✓ Clean
Scanned by 74 security vendors
Last scan: 2026-05-04 13:54 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
64
Timeout
2
Failure
0

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.775
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.0.10666
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260504-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.259
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44424AVA:64.31172
Google undetected
No result reported
Engine 1777899680
Gridinsoft undetected
No result reported
Engine 1.0.245.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.49.59392
K7GW undetected
No result reported
Engine 14.49.59393
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.234
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14532
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.6.2.19
Skyhigh timeout
No result reported
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-04-23.02
Trapmine type-unsupported
No result reported
Engine 4.0.11.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.0
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1199
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38619
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5593
ZoneAlarm undetected
No result reported
Engine 6.24-114820666
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 23282a5:23282a5:abbc3b7:abbc3b7
tehtris type-unsupported
No result reported

File Signatures

SHA-256 c3ca7bfcbc5fe2b194fa4099efcd7e08089eb8acadebb5965862feca5c4b8912
MD5 4d6a3f9b241bb664b9a392fafb6b0186
SHA-1 77d92de4d9151e296c3689cb653b80ec2113cc23
SSDEEP 1572864:tA4z06w16Nz6Txbze0Bqiytl1Mr/LcOyQtshg3SL66fbosN4GaidBlX1yH4O0dOn:tDVNONUU/Aob3i8sndQ4OVTtL
TLSH T1622823D2DBA81C2AE9B27532D12F11E35EA44F119043E71F412CB51878B3A85CE65FFA
VHASH 55b37b32a59c9556fa8fcbfc5b92c629
PERMHASH 40f64c39161ca96285b0d79a4494f50f101379a2a1c757524008f47736af561e

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (50%), VYM Mind Map (23.1%), Sweet Home 3D Design (generic) (19.4%), ZIP compressed archive (7.4%) TrID file type guesses with probabilities.
dhash 0000101e1d1e0a00 Perceptual hash used to compare visual similarity of files.
raw md5 b0b36d762dce88db5ed0630f6ff46d7a Raw MD5 hash of the file contents.
extensions png (956), so (23), ico (3), json (3), ttf (3), dat (2), bin (1), dex (1), jpg (1), metadb (1), mmdb (1), prof (1), profm (1), properties (1), textproto (1), Z (1) File extensions found inside the APK and how many of each.
file types PNG (956), ELF (23), unknown (18), JSON (2), JPG (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 7246 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 199 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (2)

com.follow.clash.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
android.service.quicksettings.action.QS_TILE_PREFERENCES android.service.quicksettings.action.QS_TILE_PREFERENCES
Categories
android.intent.category.LAUNCHER android.intent.category.LEANBACK_LAUNCHER
com.follow.clash.TempActivity
Actions
com.fbclient.app.action.START com.fbclient.app.action.START
com.fbclient.app.action.STOP com.fbclient.app.action.STOP
com.fbclient.app.action.TOGGLE com.fbclient.app.action.TOGGLE
Categories
android.intent.category.DEFAULT

Service Intents (4)

com.follow.clash.TileService
Actions
android.service.quicksettings.action.QS_TILE android.service.quicksettings.action.QS_TILE
com.follow.clash.service.VpnService
Actions
android.net.VpnService android.net.VpnService
com.google.android.gms.metadata.ModuleDependencies
Actions
com.google.android.gms.metadata.MODULE_DEPENDENCIES com.google.android.gms.metadata.MODULE_DEPENDENCIES
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (3)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
com.follow.clash.BroadcastReceiver
Actions
com.fbclient.app.intent.action.SERVICE_CREATED com.fbclient.app.intent.action.SERVICE_CREATED
com.fbclient.app.intent.action.SERVICE_DESTROYED com.fbclient.app.intent.action.SERVICE_DESTROYED
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Native Libraries (8)

libapp libapp.so
libclash libclash.so
libcore libcore.so
libdartjni libdartjni.so
libdatastore_shared_counter libdatastore_shared_counter.so
libfastdev_quickjs_runtime libfastdev_quickjs_runtime.so
libflutter libflutter.so
libsqlite3 libsqlite3.so

Requested Permissions (13)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
android.permission.QUERY_ALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.QUERY_ALL_PACKAGES
android.permission.FOREGROUND_SERVICE_SPECIAL_USE Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_SPECIAL_USE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Custom app or vendor permission (not publicly documented). android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
com.fbclient.app.permission.RECEIVE_BROADCASTS Custom app or vendor permission (not publicly documented). com.fbclient.app.permission.RECEIVE_BROADCASTS
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.fbclient.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (3)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (10)

com.follow.clash.MainActivity
com.follow.clash.TempActivity
im.crisp.client.external.ChatActivity
io.flutter.plugins.urllauncher.WebViewActivity
com.pichillilorenzo.flutter_inappwebview_android.in_app_browser.InAppBrowserActivity
com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ChromeCustomTabsActivity
com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.TrustedWebActivity
com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ChromeCustomTabsActivitySingleInstance
com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.TrustedWebActivitySingleInstance
com.google.android.gms.common.api.GoogleApiActivity

Services (9)

com.follow.clash.TileService
com.follow.clash.service.VpnService
com.follow.clash.service.CommonService
com.follow.clash.service.RemoteService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.google.android.gms.metadata.ModuleDependencies
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (5)

com.follow.clash.BroadcastReceiver com.follow.clash.BroadcastReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ActionBroadcastReceiver com.pichillilorenzo.flutter_inappwebview_android.chrome_custom_tabs.ActionBroadcastReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Content Providers (5)

com.follow.clash.service.FilesProvider
androidx.core.content.FileProvider
com.google.firebase.provider.FirebaseInitProvider
io.flutter.plugins.imagepicker.ImagePickerFileProvider
androidx.startup.InitializationProvider

URL Endpoints (74)

http://apache.org/xml/features/nonvalidating/load-dtd-grammar http://apache.org/xml/features/nonvalidating/load-external-dtd http://apache.org/xml/properties/security-manager http://g.co/dev/packagevisibility http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/ http://iptc.org/std/Iptc4xmpExt/2008-02-29/ http://javax.xml.XMLConstants/feature/secure-processing http://javax.xml.XMLConstants/property/accessExternalDTD http://javax.xml.XMLConstants/property/accessExternalStylesheet http://ns.useplus.org/ldf/xmp/1.0/ http://purl.org/dc/elements/1.1/ http://purl.org/dc/terms/ http://schemas.openxmlformats.org/officeDocument/2006/extended-properties/ http://schemas.openxmlformats.org/package/2006/metadata/core-properties/ http://schemas.openxmlformats.org/wordprocessingml/2006/main http://www.oracle.com/xml/jaxp/properties/entityExpansionLimit http://xml.apache.org/xslt}indent-amount http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities https://aomedia.org/emsg/ID3

Submission Details

Submitted At 2026-05-12
First Submission 2026-05-12
Last Submission 2026-05-12
Stored Until 2026-06-11