Ecash App icon

ecash-app-0.9.0_90090-7edacbae.apk

Ecash App

97.45 MB

Analyzed: 2026-07-15 14:40 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
99/100
Threat scan clean Modern target SDK
Privacy Permissions & network
86/100
High-risk permissions
92/100
Excellent
Overall trust

Facts

Threat scan 0/74 flagged, 0 suspicious
Permissions 10 requested
Network strings 3 URLs (0 HTTP, 3 HTTPS)
Target SDK 36
Certificate Valid until 2052-12-07 (26 years, suspicious)

Warnings

High-risk permissions detected: android.permission.RECEIVE_BOOT_COMPLETED
Package Name org.fedimint.app
Version Code 90090
Version Name 0.9.0
Application Name android.app.Application
Debuggable No
Allow Backup No
Min SDK Android 24 (Nougat)
Target SDK Android 36 (Unknown)
Supported ABIs
arm64-v8a armeabi-v7a x86_64

Certificate & Signer

Valid From 2025-07-22 13:54:59
Valid To 2052-12-07 13:54:59
Serial Number 94ab453d942d3b00
Thumbprint d3ff81ddb7df3d21fc397ec69a8f21d92b9cb982
Issuer: DN O:Fedimint, OU:Fedimint
Issuer: O Fedimint
Issuer: OU Fedimint
Subject: DN O:Fedimint, OU:Fedimint
Subject: O Fedimint
Subject: OU Fedimint

Security Scan

0 /74
✓ Clean
Scanned by 74 security vendors
Last scan: 2026-07-15 14:40 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
67
Timeout
0
Failure
0

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.798
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260715-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.271
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45275AVA:64.31584
Google undetected
No result reported
Engine 1784124968
Gridinsoft undetected
No result reported
Engine 1.0.250.174
Ikarus undetected
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.63.60140
K7GW undetected
No result reported
Engine 14.63.60142
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.246
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26060.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.6.2.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-07-15.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.14.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1250
Webroot undetected
No result reported
Engine 1.10.0.2
Xcitium undetected
No result reported
Engine 38808
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5642
ZoneAlarm undetected
No result reported
Engine 6.26-117392185
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine a114442:a114442:3f757df:3f757df
tehtris type-unsupported
No result reported

File Signatures

SHA-256 991a610d6f4843dfaf77a48e741aa142ff9534b103edb51255ed6e962ab0eedc
MD5 3e99f73568baca5243500a0a112d8105
SHA-1 eb427320ce03b4abe8b2f79980efef7d701be7a3
SSDEEP 786432:3qh2/AdSAK0fwbK1z2xmuxcNNXaE3Roq8vrAHZymUbLPjUklmug57fNH1:3uzgAigz2x5oUmev2/JfN1
TLSH T1E528D007F05CC936D9CAF17CBE5E15A2B324385805E5C25A7818961CFF9B5F00BB6BA2
VHASH a844ac476b1fa23d07d6550c2d03ee84
PERMHASH 9c1c4f873a53c7fcb902379dba9bbb30d27e56f8c07e0c2241d263b6e7544957

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID SPSS Extension (30.7%), Android Package (27.6%), Java Archive (13.8%), VYM Mind Map (12.8%), Sweet Home 3D Design (generic) (10.7%) TrID file type guesses with probabilities.
dhash 00001c1e1c0e0900 Perceptual hash used to compare visual similarity of files.
raw md5 2561112eb2e28d60703766d024f71dcd Raw MD5 hash of the file contents.
extensions xml (220), png (212), version (58), so (15), kotlin_builtins (8), properties (5), json (4), bin (2), dex (2), frag (2), arsc (1), CoroutineExceptionHandler (1), MainDispatcherFactory (1), MF (1), ogg (1), otf (1), prof (1), profm (1), textproto (1), txt (1), Z (1) File extensions found inside the APK and how many of each.
file types XML (220), PNG (212), unknown (88), ELF (15), JSON (2), Java Bytecode (1), OGG (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 539 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 105 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

org.fedimint.app.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
android.nfc.action.NDEF_DISCOVERED android.nfc.action.NDEF_DISCOVERED
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE

Service Intents (1)

org.fedimint.app.EcashHceService
Actions
android.nfc.cardemulation.action.HOST_APDU_SERVICE android.nfc.cardemulation.action.HOST_APDU_SERVICE

Receiver Intents (2)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
com.pravera.flutter_foreground_task.service.RebootReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
My Package Replaced Broadcast Action: A new version of your application has been installed android.intent.action.MY_PACKAGE_REPLACED
android.intent.action.QUICKBOOT_POWERON android.intent.action.QUICKBOOT_POWERON

Native Libraries (9)

libapp libapp.so
C++ Standard Library Android NDK C++ runtime used by native code. libc++_shared.so
libdatastore_shared_counter libdatastore_shared_counter.so
libecashapp libecashapp.so
libflutter libflutter.so
libiroh-402ea07a39f6780d libiroh-402ea07a39f6780d.so
libiroh-ac4df46d2499bd97 libiroh-ac4df46d2499bd97.so
libiroh_relay-0cb1a38adba3a51c libiroh_relay-0cb1a38adba3a51c.so
libiroh_relay-911494077f3c207d libiroh_relay-911494077f3c207d.so

Requested Permissions (10)

Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_DATA_SYNC Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_DATA_SYNC
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
control Near Field Communication Allows the app to communicate with Near Field Communication (NFC) tags, cards, and readers. android.permission.NFC
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. org.fedimint.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA

Uses Features (8)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Camera Autofocus Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.autofocus
Camera Flash Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.flash
Camera Front Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.front
Nfc Feature for {@link #getSystemAvailableFeatures} and android.hardware.nfc
Nfc Host Card Emulation Feature for {@link #getSystemAvailableFeatures} and android.hardware.nfc.hce
Screen Landscape Feature for {@link #getSystemAvailableFeatures} and android.hardware.screen.landscape
Wifi Feature for {@link #getSystemAvailableFeatures} and android.hardware.wifi

Activities (4)

org.fedimint.app.MainActivity
io.flutter.plugins.urllauncher.WebViewActivity
com.google.android.gms.common.api.GoogleApiActivity
com.journeyapps.barcodescanner.CaptureActivity

Services (3)

com.pravera.flutter_foreground_task.service.ForegroundService
org.fedimint.app.EcashHceService
com.baseflow.geolocator.GeolocatorLocationService

Broadcast Receivers (3)

com.pravera.flutter_foreground_task.service.RebootReceiver com.pravera.flutter_foreground_task.service.RebootReceiver
com.pravera.flutter_foreground_task.service.RestartReceiver com.pravera.flutter_foreground_task.service.RestartReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (1)

androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-07-15
First Submission 2026-07-15
Last Submission 2026-07-15
Stored Until 2026-08-14

Other Versions

Ecash App org.fedimint.app 0.8.0 (80090) ecash_app.apk Analyzed 2026-07-15 14:47 UTC
View report