comerciaapostef_1_.apk

20.46 MB

Analyzed: 2026-04-27 08:00 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
90/100
Threat scan clean
Privacy Permissions & network
96/100
High-risk permissions HTTP URLs found AllowBackup enabled Low data access
93/100
Excellent
Overall trust

Facts

Threat scan 0/75 flagged, 0 suspicious
Permissions 6 requested
Network strings 6 URLs (6 HTTP, 0 HTTPS)
Target SDK 32
Certificate Valid until 2046-06-26 (20 years, suspicious)

Warnings

Found 6 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES, android.permission.SYSTEM_ALERT_WINDOW
AllowBackup is enabled.
Package Name icg.es.comerciaapos
Version Code 1033
Version Name 1033
Debuggable No
Allow Backup Yes
Min SDK Android 22 (Lollipop)
Target SDK Android 32 (Android 12L)
Supported ABIs
Universal

Certificate & Signer

Valid From 2021-07-02 10:30:01
Valid To 2046-06-26 10:30:01
Serial Number 31bc0e79
Thumbprint 545242a749ed99d1cc319c3adb2a8a0544a4bb05
Issuer: C ES
Issuer: DN C:ES, L:Torrefarrera, O:HioPos Cloud, ST:Spain
Issuer: L Torrefarrera
Issuer: O HioPos Cloud
Issuer: ST Spain
Subject: C ES
Subject: DN C:ES, L:Torrefarrera, O:HioPos Cloud, ST:Spain
Subject: L Torrefarrera
Subject: O HioPos Cloud
Subject: ST Spain

Security Scan

0 /75
✓ Clean
Scanned by 75 security vendors
Last scan: 2026-04-27 08:00 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
62
Timeout
5
Failure
0

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.773
AVG timeout
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.0.10666
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast timeout
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260426-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV timeout
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.257
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44337AVA:64.31123
Google undetected
No result reported
Engine 1777273262
Gridinsoft undetected
No result reported
Engine 1.0.244.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.48.59321
K7GW undetected
No result reported
Engine 14.48.59321
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.231
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14532
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor timeout
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.6.2.19
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-04-23.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.11.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.0
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1194
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38600
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5588
ZoneAlarm undetected
No result reported
Engine 6.24-114820517
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 07ae075:07ae075:a9d2355:a9d2355
tehtris type-unsupported
No result reported

File Signatures

SHA-256 cc9eb3add9dde9ab7a4d6dbd4a072a309e841f0eb7ef14c8f2080fc2c79aba2d
MD5 7b7f71bb2ff855be17aae37843b083ce
SHA-1 f7c5bca378e2076c39bda7fa9b844a96c6de9ea2
SSDEEP 393216:RFUnCC57YR0n/nb8ymap+i6vuJ/PjLESkyORRDT0ixYoycNl7eWx:/DoYin/nL8kPj4L94qyc3Z
TLSH T1D1272396F7546A2FD877103309EA5276265B4D478E839B832948371C39BB6F80F49BCC
VHASH 01487cb8b38ba11072de4f2004f50b2d
PERMHASH 4d710a82563cfa3140db37bc4491cce90a8fe00f3df760b4682a23457a9cbb60

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (49%), Java Archive (24.5%), Sweet Home 3D Design (generic) (19%), ZIP compressed archive (7.2%) TrID file type guesses with probabilities.
dhash 0000001e1c0d1410 Perceptual hash used to compare visual similarity of files.
raw md5 ffdc99ba2bb8fe8c3565695b2c90bc29 Raw MD5 hash of the file contents.
extensions xml (525), png (180), txt (128), version (38), webp (10), dtd (8), kotlin_builtins (7), dex (3), apk (2), aar (1), arsc (1), JsonFactory (1), MF (1), ObjectCodec (1), properties (1), RSA (1), SF (1), textproto (1), ttf (1), TTF (1) File extensions found inside the APK and how many of each.
file types XML (526), unknown (200), PNG (180), DEX (3), ZIP (3) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 912 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 29 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (6)

icg.es.comerciaapos.BehaviorActivity
Actions
icg.actions.electronicpayment.comerciaapostef.GET_BEHAVIOR icg.actions.electronicpayment.comerciaapostef.GET_BEHAVIOR
Categories
android.intent.category.DEFAULT
icg.es.comerciaapos.GetCustomParamsActivity
Actions
icg.actions.electronicpayment.comerciaapostef.GET_CUSTOM_PARAMS icg.actions.electronicpayment.comerciaapostef.GET_CUSTOM_PARAMS
Categories
android.intent.category.DEFAULT
icg.es.comerciaapos.GetVersionActivity
Actions
icg.actions.electronicpayment.comerciaapostef.GET_VERSION icg.actions.electronicpayment.comerciaapostef.GET_VERSION
Categories
android.intent.category.DEFAULT
icg.es.comerciaapos.InitializeActivity
Actions
icg.actions.electronicpayment.comerciaapostef.INITIALIZE icg.actions.electronicpayment.comerciaapostef.INITIALIZE
Categories
android.intent.category.DEFAULT
icg.es.comerciaapos.ShowSetupScreen
Actions
icg.actions.electronicpayment.comerciaapostef.SHOW_SETUP_SCREEN icg.actions.electronicpayment.comerciaapostef.SHOW_SETUP_SCREEN
Categories
android.intent.category.DEFAULT
icg.es.comerciaapos.TransactionActivity
Actions
icg.actions.electronicpayment.comerciaapostef.TRANSACTION icg.actions.electronicpayment.comerciaapostef.TRANSACTION
Categories
android.intent.category.DEFAULT

Requested Permissions (6)

This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
reorder running apps Allows the app to move tasks to the foreground and background. The app may do this without your input. android.permission.REORDER_TASKS
com.comercia.permission.ACCESS_IN_STORE_PAYMENT_API Custom app or vendor permission (not publicly documented). com.comercia.permission.ACCESS_IN_STORE_PAYMENT_API
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE

Activities (6)

icg.es.comerciaapos.InitializeActivity
icg.es.comerciaapos.BehaviorActivity
icg.es.comerciaapos.GetVersionActivity
icg.es.comerciaapos.TransactionActivity
icg.es.comerciaapos.GetCustomParamsActivity
icg.es.comerciaapos.ShowSetupScreen

Content Providers (2)

androidx.core.content.FileProvider
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-04-27
First Submission 2026-04-27
Last Submission 2026-04-27
Stored Until 2026-05-27