ibisPaint X icon

ibisPaint_X_v14.0.0__Premium_.apk

ibisPaint X

48.81 MB

Analyzed: 2026-04-29 23:18 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
64/100
Threat scan flagged Modern target SDK
Privacy Permissions & network
91/100
HTTP URLs found Low data access
75/100
Good
Overall trust

Facts

Threat scan 5/75 flagged, 0 suspicious
Permissions 15 requested
Network strings 72 URLs (5 HTTP, 67 HTTPS)
Target SDK 35
Certificate Valid until 2045-10-26 (19 years, suspicious)

Warnings

Threat scan flagged: 5/75 scanners marked this file as malicious.
Found 5 HTTP URL strings (unencrypted).
Package Name jp.ne.ibis.ibispaintx.app
Version Code 1400000004
Version Name 14.0.0
Application Name np.manager.FuckSign
Debuggable No
Allow Backup No
Min SDK Android 24 (Nougat)
Target SDK Android 35 (Android 15)
Supported ABIs
arm64-v8a

Certificate & Signer

Valid From 2020-11-01 10:49:08
Valid To 2045-10-26 10:49:08
Serial Number 47723c30
Thumbprint 2412f88ac73778c3d659d47a3112e27898f953b9
Issuer: C IN
Issuer: DN C:IN
Subject: C IN
Subject: DN C:IN

Security Scan

5 /75
⚠️ Threats Detected
Detected by 5 vendors: AhnLab-V3 (PUP/Android.Agent.1128333), Avira (SPR/ANDR.Obfus.BAB.Gen), BitDefenderFalx (Android.Riskware.Packer.X)
Scanned by 75 security vendors
Last scan: 2026-04-13 06:05 UTC
Malicious
5
Suspicious
0
Harmless
0
Undetected
61
Timeout
0
Failure
0

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.768
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
PUP/Android.Agent.1128333
Engine 3.29.3.10609
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260412-00
Avira malicious
SPR/ANDR.Obfus.BAB.Gen
Engine 8.3.3.24
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.Packer.X
Engine 2.0.936
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb malicious
Tool.NPMod.1
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.255
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure malicious
PrivacyRisk.SPR/ANDR.Obfus.BAB.Gen
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44175AVA:64.31025
Google undetected
No result reported
Engine 1776056456
Gridinsoft undetected
No result reported
Engine 1.0.242.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.46.59175
K7GW undetected
No result reported
Engine 14.46.59176
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.214
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14392
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.6.2.19
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-04-13.01
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.11.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1184
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38562
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5579
ZoneAlarm undetected
No result reported
Engine 6.23-113519592
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 90dbe51:90dbe51:e6fb51a:e6fb51a
tehtris type-unsupported
No result reported

File Signatures

SHA-256 a1f4f32d0b39368b3dfedea4184448c9e4df195a1e73ed2c007c196b95ba9973
MD5 af104143b612d6e5a6bfd972c2a8011b
SHA-1 7c16b17d5b0fc1b3591d50e23b4080561793aa56
SSDEEP 786432:gfHea+TyRqzwH39cHWNXb+jI0KQJwcmC/LiCz8N+ZvxdM6dV+28aPXsa26aUBXV7:gPx/R+kL+Hla0Luw9xd/mj0B
TLSH T1C2B73385F7C8EA1EC47B81374AA6127B26560C1A9F42CA17A258721C3DF3ED84F46FC5
VHASH bf05101a9f11d7d29bfa00c2d99ee6dc
PERMHASH 938aa4f0840dabe222cb846b254cb48efa017fda0001eb29cdbe72af063e4934

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v2.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (48.6%), Opera Widget (25.2%), Sweet Home 3D Design (generic) (18.9%), ZIP compressed archive (7.2%) TrID file type guesses with probabilities.
dhash 0000001c1e0e0500 Perceptual hash used to compare visual similarity of files.
raw md5 df44ddaaa415288f730dc8c20f9ba1d6 Raw MD5 hash of the file contents.
extensions png (472), xml (374), html (34), txt (24), css (23), js (16), jpg (13), so (12), dex (6), json (6), svg (5), properties (4), c (1), gz (1), ico (1), l0 (1), pem (1), prof (1), profm (1), q (1), textproto (1) File extensions found inside the APK and how many of each.
file types PNG (472), XML (376), unknown (93), HTML (34), JPG (13), ELF (12) Detected embedded file types and their counts.
highest datetime 2026-03-31 15:09:46 UTC Latest timestamp found among files inside the archive.
lowest datetime 2026-03-31 12:22:00 UTC Earliest timestamp found among files inside the archive.
num children 1887 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 106 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Harmless 98% confidence CLEAN

Deep Manifest Analysis

Activity Intents (4)

com.facebook.CustomTabActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
jp.ne.ibis.ibispaintx.app.InitializeCheckActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
Edit Activity Action: Provide explicit editable access to the given data. android.intent.action.EDIT
Send Activity Action: Deliver some data to someone else. android.intent.action.SEND
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE
jp.ne.ibis.ibispaintx.app.util.activity.ForegroundTargetActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
net.openid.appauth.RedirectUriReceiverActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE

Service Intents (2)

Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
jp.ne.ibis.ibispaintx.app.firebase.MessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (10)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
Actions
Power Connected Broadcast Action: External power has been connected to the device. android.intent.action.ACTION_POWER_CONNECTED
android.intent.action.ACTION_POWER_DISCONNECTED android.intent.action.ACTION_POWER_DISCONNECTED
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
Actions
Battery Okay Broadcast Action: Indicates the battery is now okay after being low. android.intent.action.BATTERY_OKAY
Battery Low Broadcast Action: Indicates low battery condition on the device. android.intent.action.BATTERY_LOW
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
Actions
Device Storage Low Broadcast Action: A sticky broadcast that indicates low memory android.intent.action.DEVICE_STORAGE_LOW
Device Storage Ok Broadcast Action: Indicates low memory condition on the device no longer exists android.intent.action.DEVICE_STORAGE_OK
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
Actions
androidx.work.impl.background.systemalarm.UpdateProxies androidx.work.impl.background.systemalarm.UpdateProxies
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
Time Changed Broadcast Action: The time was set. android.intent.action.TIME_SET
Timezone Changed Broadcast Action: The timezone has changed. android.intent.action.TIMEZONE_CHANGED
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Native Libraries (12)

libapminsighta libapminsighta.so
libapminsightb libapminsightb.so
libapplovin-native-crash-reporter libapplovin-native-crash-reporter.so
libbuffer_pgl libbuffer_pgl.so
libdatastore_shared_counter libdatastore_shared_counter.so
libfile_lock_pgl libfile_lock_pgl.so
libibispaint libibispaint.so
libnms libnms.so
libpglarmor libpglarmor.so
libtensorflowlite_gpu_jni libtensorflowlite_gpu_jni.so
libtensorflowlite_jni libtensorflowlite_jni.so
libtt_ugen_layout libtt_ugen_layout.so

Requested Permissions (15)

ibisPaint X
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
record audio android.permission.RECORD_AUDIO
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
android.permission.READ_BASIC_PHONE_STATE Custom app or vendor permission (not publicly documented). android.permission.READ_BASIC_PHONE_STATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE Custom app or vendor permission (not publicly documented). android.permission.ACCESS_ADSERVICES_CUSTOM_AUDIENCE
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. jp.ne.ibis.ibispaintx.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (2)

Microphone Feature for {@link #getSystemAvailableFeatures} and android.hardware.microphone
Screen Portrait Feature for {@link #getSystemAvailableFeatures} and android.hardware.screen.portrait

Activities (24)

jp.ne.ibis.ibispaintx.app.glwtk.SaveToDeviceActivity
jp.ne.ibis.ibispaintx.app.market.MarketAuthenticationActivity
jp.ne.ibis.ibispaintx.app.glwtk.IbisPaintActivity
jp.ne.ibis.ibispaintx.app.account.GoogleAccountAuthentication$ResultActivity
jp.ne.ibis.ibispaintx.app.account.TwitterLoginActivity
jp.ne.ibis.ibispaintx.app.account.SignInWithAppleActivity
jp.ne.ibis.ibispaintx.app.account.IbisAccountLoginActivity
jp.ne.ibis.ibispaintx.app.network.BrowserActivity
jp.ne.ibis.ibispaintx.app.tutorial.TutorialActivity
jp.ne.ibis.ibispaintx.app.artlist.ArtListShareTargetActivity
jp.ne.ibis.ibispaintx.app.util.activity.ForegroundTargetActivity
jp.ne.ibis.ibispaintx.app.purchase.PurchaseActivity
com.facebook.CustomTabActivity
jp.ne.ibis.ibispaintx.app.InitializeCheckActivity
ibisPaint X
com.facebook.FacebookActivity
com.facebook.CustomTabMainActivity
net.openid.appauth.AuthorizationManagementActivity
net.openid.appauth.RedirectUriReceiverActivity
jp.maio.sdk.android.AdFullscreenActivity
jp.maio.sdk.android.HtmlBasedAdActivity
jp.fluct.fluctsdk.fullscreenads.internal.FluctFullscreenVideoActivity
jp.fluct.fluctsdk.FluctAdVideoActivity
com.google.android.gms.common.api.GoogleApiActivity

Services (9)

jp.ne.ibis.ibispaintx.app.firebase.MessagingService
jp.ne.ibis.ibispaintx.app.ApplicationLifecycleService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.google.firebase.sessions.SessionLifecycleService
androidx.work.impl.background.systemalarm.SystemAlarmService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService

Broadcast Receivers (11)

com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (8)

jp.ne.ibis.ibispaintx.app.provider.InitializationContentProvider
jp.ne.ibis.ibispaintx.app.provider.IbisPaintContentProvider
jp.ne.ibis.ibispaintx.app.provider.ClipboardContentProvider
jp.ne.ibis.ibispaintx.app.provider.ArtListContentProvider
androidx.startup.InitializationProvider
com.google.firebase.provider.FirebaseInitProvider
com.facebook.internal.FacebookInitProvider
com.squareup.picasso.PicassoProvider

URL Endpoints (86)

http://developer.android.com/google/play-services/setup.html http://g.co/dev/packagevisibility http://play.google.com http://schemas.microsoft.com/DRM/2007/03/protocols/AcquireLicense http://www.google.com http://www.slf4j.org/codes.html#StaticLoggerBinder http://www.slf4j.org/codes.html#loggerNameMismatch http://www.slf4j.org/codes.html#multiple_bindings http://www.slf4j.org/codes.html#replay http://www.slf4j.org/codes.html#substituteLogger http://www.slf4j.org/codes.html#unsuccessfulInit http://www.slf4j.org/codes.html#version_mismatch http://www.smpte-ra.org/schemas/2052-1/2010/smpte-tt http://xml.apache.org/xslt}indent-amount http://xmlpull.org/v1/doc/features.html#process-namespaces https://([a-zA-Z https://account.ibis.ne.jp https://accounts.google.com/o/oauth2/v2/auth https://aomedia.org/emsg/ID3 https://appassets.androidplatform.net

Submission Details

Submitted At 2026-04-29
First Submission 2026-04-29
Last Submission 2026-04-29
Stored Until 2026-05-29

Other Versions

ibisPaint X jp.ne.ibis.ibispaintx.app 14.0.1 (1400010010) ibisPaint_X_14.0.1-mod.apk Analyzed 2026-04-29 23:13 UTC
View report