APK Security & Privacy Score
Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.
Security
Scan-weighted
90/100
Threat scan flagged
Modern target SDK
Privacy
Permissions & network
91/100
High-risk permissions
HTTP URLs found
AllowBackup enabled
Low data access
90/100
Excellent
Overall trust
Facts
Threat scan
1/75 flagged, 0 suspicious
Permissions
12 requested
Network strings
18 URLs (5 HTTP, 13 HTTPS)
Target SDK
36
Certificate
Valid until 2051-11-25 (25 years, suspicious)
Warnings
Threat scan flagged: 1/75 scanners marked this file as malicious.
Found 5 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.RECEIVE_BOOT_COMPLETED
AllowBackup is enabled.
Package Name
com.metrolist.music
Version Code
149
Version Name
13.6.0
App Category
1
Application Name
com.metrolist.music.App
Debuggable
No
Allow Backup
Yes
Min SDK
Android 26 (Oreo)
Target SDK
Android 36 (Unknown)
Supported ABIs
arm64-v8a
armeabi-v7a
Certificate & Signer
Valid From
Valid To
Serial Number
Thumbprint
Issuer: C
Issuer: CN
Issuer: DN
Issuer: L
Issuer: O
Issuer: OU
Issuer: ST
Subject: C
Subject: CN
Subject: DN
Subject: L
Subject: O
Subject: OU
Subject: ST
Security Scan
1
⚠️ Threats Detected
Detected by
1 vendor:
huorong
(TrojanSpy/Android.Stealer.ar)
Malicious
1
Suspicious
0
Harmless
0
Undetected
67
Timeout
0
Failure
0
Scan Providers
ALYac
APEX
AVG
Acronis
AhnLab-V3
Alibaba
Antiy-AVL
Arcabit
Avast
Avast-Mobile
Avira
BitDefender
BitDefenderFalx
Bkav
CAT-QuickHeal
CMC
CTX
ClamAV
CrowdStrike
Cylance
Cynet
DeepInstinct
DrWeb
ESET-NOD32
Elastic
Emsisoft
F-Secure
Fortinet
GData
Google
Gridinsoft
Ikarus
Jiangmin
K7AntiVirus
K7GW
Kaspersky
Kingsoft
Lionic
Malwarebytes
MaxSecure
McAfeeD
MicroWorld-eScan
Microsoft
NANO-Antivirus
Paloalto
Panda
Rising
SUPERAntiSpyware
Sangfor
SentinelOne
Skyhigh
Sophos
Symantec
SymantecMobileInsight
TACHYON
Tencent
Trapmine
TrellixENS
TrendMicro
TrendMicro-HouseCall
Trustlook
VBA32
VIPRE
Varist
ViRobot
VirIT
Webroot
Xcitium
Yandex
Zillya
ZoneAlarm
Zoner
alibabacloud
huorong
TrojanSpy/Android.Stealer.ar
tehtris
File Signatures
SHA-256
0560beb1c6d3caa6aa348212bae28398e839c87e9bde7a0330a54f5c6ddedb49
MD5
d022c3c1ef78e531ffc17888a23aa60e
SHA-1
2d23749922db55f97fdab3b36de1231f0b437282
SSDEEP
786432:g/ddEMTbrYAtaTVSpd1NtOPQCR7bibPozhrhSHLeMck:g/ddhrjtaJSpdfAYCR7urAor4k
TLSH
T1E647224AFAD8DA2EC47180774847357522574C2A7E03DAC36A88772D24B7EF44F86ADC
VHASH
030191114393381337db1d0f72bfe63e
PERMHASH
2d88ac9e363270032aaef9dfceea140a649404a797a04b7712d918a636ff3f36
File Intelligence
Type Description
Human-friendly file type name based on multiple detection methods.
Type Extension
Most likely file extension inferred from the content.
Type Tag
Primary type tag assigned by the classifier.
Type Tags
Additional type tags that describe the file content.
Magic
File signature result from magic bytes inspection.
Magika
File type predicted by Magika (ML-based file type detection).
TrID
TrID file type guesses with probabilities.
dhash
Perceptual hash used to compare visual similarity of files.
raw md5
Raw MD5 hash of the file contents.
extensions
File extensions found inside the APK and how many of each.
file types
Detected embedded file types and their counts.
highest datetime
Latest timestamp found among files inside the archive.
lowest datetime
Earliest timestamp found among files inside the archive.
num children
Number of files contained within the archive.
type
Container type detected for the analyzed file.
uncompressed size
Estimated total size of all files after extraction.
Sandbox
Sandbox Verdicts
Zenbox android
Harmless
98% confidence
CLEAN
Deep Manifest Analysis
Activity Intents (1)
com.metrolist.music.MainActivity
Service Intents (3)
com.metrolist.music.playback.ExoDownloadService
com.metrolist.music.playback.MusicService
com.metrolist.music.quicksettings.MusicRecognizerTileService
Receiver Intents (7)
androidx.media3.session.MediaButtonReceiver
Profile installer
androidx.profileinstaller.ProfileInstallReceiver
com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver
com.metrolist.music.widget.MusicRecognizerWidgetReceiver
com.metrolist.music.widget.MusicWidgetReceiver
com.metrolist.music.widget.PlaylistWidgetReceiver
com.metrolist.music.widget.TurntableWidgetReceiver
Native Libraries (2)
libandroidx.graphics.path
libandroidx.graphics.path.so
libdatastore_shared_counter
libdatastore_shared_counter.so
Requested Permissions (12)
have full network access
android.permission.INTERNET
android.permission.POST_NOTIFICATIONS
android.permission.POST_NOTIFICATIONS
view network connections
android.permission.ACCESS_NETWORK_STATE
run at startup
android.permission.RECEIVE_BOOT_COMPLETED
keep car screen turned on
android.permission.WAKE_LOCK
android.permission.SCHEDULE_EXACT_ALARM
android.permission.SCHEDULE_EXACT_ALARM
Foreground service
android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK
android.permission.FOREGROUND_SERVICE_DATA_SYNC
android.permission.FOREGROUND_SERVICE_DATA_SYNC
android.permission.FOREGROUND_SERVICE_MICROPHONE
android.permission.FOREGROUND_SERVICE_MICROPHONE
record audio
android.permission.RECORD_AUDIO
Dynamic receiver access
com.metrolist.music.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Uses Features (3)
Microphone
android.hardware.microphone
Touchscreen
android.hardware.touchscreen
Leanback
android.software.leanback
Activities (5)
com.metrolist.music.ui.screens.CrashActivity
com.metrolist.music.MainActivity
com.yalantis.ucrop.UCropActivity
com.metrolist.music.recognition.RecognitionLaunchActivity
androidx.compose.ui.tooling.PreviewActivity
Services (6)
com.metrolist.music.playback.MusicService
com.metrolist.music.playback.ExoDownloadService
com.metrolist.music.widget.MusicRecognizerWidgetService
com.metrolist.music.recognition.RecognitionForegroundService
com.metrolist.music.quicksettings.MusicRecognizerTileService
androidx.room.MultiInstanceInvalidationService
Broadcast Receivers (9)
com.metrolist.music.listentogether.ListenTogetherActionReceiver
com.metrolist.music.listentogether.ListenTogetherActionReceiver
com.metrolist.music.playback.alarm.MusicAlarmReceiver
com.metrolist.music.playback.alarm.MusicAlarmReceiver
com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver
com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver
androidx.media3.session.MediaButtonReceiver
androidx.media3.session.MediaButtonReceiver
com.metrolist.music.widget.MusicWidgetReceiver
com.metrolist.music.widget.MusicWidgetReceiver
com.metrolist.music.widget.PlaylistWidgetReceiver
com.metrolist.music.widget.PlaylistWidgetReceiver
com.metrolist.music.widget.TurntableWidgetReceiver
com.metrolist.music.widget.TurntableWidgetReceiver
com.metrolist.music.widget.MusicRecognizerWidgetReceiver
com.metrolist.music.widget.MusicRecognizerWidgetReceiver
Profile installer
androidx.profileinstaller.ProfileInstallReceiver
Content Providers (3)
androidx.core.content.FileProvider
com.dpi.DensityScaler
androidx.startup.InitializationProvider
URL Endpoints (26)
http://apache.org/xml/features/disallow-doctype-decl
http://apache.org/xml/features/nonvalidating/load-external-dtd
http://javax.xml.XMLConstants/feature/secure-processing
http://javax.xml.XMLConstants/property/accessExternalDTD
http://javax.xml.XMLConstants/property/accessExternalStylesheet
https://aistudio.google.com/apikey
https://console.anthropic.com/setti
https://console.anthropic.com/settings/keys
https://console.mistral.ai/api-keys
https://console.x.ai
https://deepl.com/pro-api
https://github.com/MetrolistGroup/Metrolist/releases
https://kotl.in/issue
https://openrouter.ai
https://perplexity.ai/settings/api
https://plataform.openai.com/api-keys
https://platform.openai.com/api-keys
https://www.slf4j.org/codes.html#ignoredBindings
https://www.slf4j.org/codes.html#multiple_bindings
https://www.slf4j.org/codes.html#noProviders
Submission Details
Submitted At
First Submission
Last Submission
Stored Until