Metrolist.apk

24.03 MB

Analyzed: 2026-06-25 19:24 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
90/100
Threat scan flagged Modern target SDK
Privacy Permissions & network
91/100
High-risk permissions HTTP URLs found AllowBackup enabled Low data access
90/100
Excellent
Overall trust

Facts

Threat scan 1/75 flagged, 0 suspicious
Permissions 12 requested
Network strings 18 URLs (5 HTTP, 13 HTTPS)
Target SDK 36
Certificate Valid until 2051-11-25 (25 years, suspicious)

Warnings

Threat scan flagged: 1/75 scanners marked this file as malicious.
Found 5 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.RECEIVE_BOOT_COMPLETED
AllowBackup is enabled.
Package Name com.metrolist.music
Version Code 149
Version Name 13.6.0
App Category 1
Application Name com.metrolist.music.App
Debuggable No
Allow Backup Yes
Min SDK Android 26 (Oreo)
Target SDK Android 36 (Unknown)
Supported ABIs
arm64-v8a armeabi-v7a

Certificate & Signer

Valid From 2024-07-09 02:38:44
Valid To 2051-11-25 02:38:44
Serial Number 1b6dab4ded502e68
Thumbprint ea524c9c5fe4ed77e63f713c943105385ec7a9b4
Issuer: C 20
Issuer: CN Unknown
Issuer: DN C:20, CN:Unknown, L:egypt, O:dev, ST:cairo, OU:Metrolist
Issuer: L egypt
Issuer: O dev
Issuer: OU Metrolist
Issuer: ST cairo
Subject: C 20
Subject: CN Unknown
Subject: DN C:20, CN:Unknown, L:egypt, O:dev, ST:cairo, OU:Metrolist
Subject: L egypt
Subject: O dev
Subject: OU Metrolist
Subject: ST cairo

Security Scan

1 /75
⚠️ Threats Detected
Detected by 1 vendor: huorong (TrojanSpy/Android.Stealer.ar)
Scanned by 75 security vendors
Last scan: 2026-06-25 19:22 UTC
Malicious
1
Suspicious
0
Harmless
0
Undetected
67
Timeout
0
Failure
0

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.792
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260625-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.267
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45040AVA:64.31475
Google undetected
No result reported
Engine 1782406860
Gridinsoft undetected
No result reported
Engine 1.0.249.174
Ikarus undetected
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.59.59943
K7GW undetected
No result reported
Engine 14.59.59943
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.239
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26050.11
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.5.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-06-25.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.12.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1236
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38758
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5629
ZoneAlarm undetected
No result reported
Engine 6.25-116107815
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong malicious
TrojanSpy/Android.Stealer.ar
Engine ef52b13:ef52b13:d686325:d686325
tehtris type-unsupported
No result reported

File Signatures

SHA-256 0560beb1c6d3caa6aa348212bae28398e839c87e9bde7a0330a54f5c6ddedb49
MD5 d022c3c1ef78e531ffc17888a23aa60e
SHA-1 2d23749922db55f97fdab3b36de1231f0b437282
SSDEEP 786432:g/ddEMTbrYAtaTVSpd1NtOPQCR7bibPozhrhSHLeMck:g/ddhrjtaJSpdfAYCR7urAor4k
TLSH T1E647224AFAD8DA2EC47180774847357522574C2A7E03DAC36A88772D24B7EF44F86ADC
VHASH 030191114393381337db1d0f72bfe63e
PERMHASH 2d88ac9e363270032aaef9dfceea140a649404a797a04b7712d918a636ff3f36

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (49%), Java Archive (24.5%), Sweet Home 3D Design (generic) (19%), ZIP compressed archive (7.2%) TrID file type guesses with probabilities.
dhash 0000181e1e080908 Perceptual hash used to compare visual similarity of files.
raw md5 e02181bdfb72a09db414c760cd11f46b Raw MD5 hash of the file contents.
extensions xml (470), png (164), txt (141), version (100), kotlin_module (23), proto (22), bin (11), webp (10), kotlin_builtins (8), properties (7), js (4), so (4), dex (3), json (3), AndroidDispatcherFactory (1), arsc (1), BuiltInsLoader (1), ConfigLoader (1), CoroutineExceptionHandler (1), ExternalOverridabilityCondition (1), html (1), HttpClientEngineContainer (1), KotlinxSerializationExtensionProvider (1), list (1), MetadataExtensions (1), MF (1), mp3 (1), OkHttpNetworkFetcherServiceLoaderTarget (1), prof (1), profm (1), RSA (1), SF (1), textproto (1), ttf (1) File extensions found inside the APK and how many of each.
file types XML (470), unknown (352), PNG (164), ELF (4), HTML (1), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 992 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 54 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Harmless 98% confidence CLEAN

Deep Manifest Analysis

Activity Intents (1)

com.metrolist.music.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
android.intent.action.MUSIC_PLAYER android.intent.action.MUSIC_PLAYER
com.metrolist.music.action.RECOGNITION com.metrolist.music.action.RECOGNITION
android.media.action.MEDIA_PLAY_FROM_SEARCH android.media.action.MEDIA_PLAY_FROM_SEARCH
android.nfc.action.NDEF_DISCOVERED android.nfc.action.NDEF_DISCOVERED
Send Activity Action: Deliver some data to someone else. android.intent.action.SEND
Categories
android.intent.category.LEANBACK_LAUNCHER android.intent.category.APP_MUSIC android.intent.category.DEFAULT android.intent.category.BROWSABLE

Service Intents (3)

com.metrolist.music.playback.ExoDownloadService
Actions
androidx.media3.exoplayer.downloadService.action.RESTART androidx.media3.exoplayer.downloadService.action.RESTART
com.metrolist.music.playback.MusicService
Actions
androidx.media3.session.MediaSessionService androidx.media3.session.MediaSessionService
androidx.media3.session.MediaLibraryService androidx.media3.session.MediaLibraryService
android.media.browse.MediaBrowserService android.media.browse.MediaBrowserService
com.metrolist.music.quicksettings.MusicRecognizerTileService
Actions
android.service.quicksettings.action.QS_TILE android.service.quicksettings.action.QS_TILE

Receiver Intents (7)

androidx.media3.session.MediaButtonReceiver
Actions
Media Button Broadcast Action: The "Media Button" was pressed. android.intent.action.MEDIA_BUTTON
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver
Actions
Locked Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.LOCKED_BOOT_COMPLETED
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
Time Changed Broadcast Action: The time was set. android.intent.action.TIME_SET
Timezone Changed Broadcast Action: The timezone has changed. android.intent.action.TIMEZONE_CHANGED
My Package Replaced Broadcast Action: A new version of your application has been installed android.intent.action.MY_PACKAGE_REPLACED
com.metrolist.music.widget.MusicRecognizerWidgetReceiver
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.metrolist.music.widget.recognizer.TAP_MIC com.metrolist.music.widget.recognizer.TAP_MIC
com.metrolist.music.widget.recognizer.UPDATE com.metrolist.music.widget.recognizer.UPDATE
com.metrolist.music.widget.recognizer.RESET com.metrolist.music.widget.recognizer.RESET
com.metrolist.music.widget.MusicWidgetReceiver
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.metrolist.music.widget.PLAY_PAUSE com.metrolist.music.widget.PLAY_PAUSE
com.metrolist.music.widget.LIKE com.metrolist.music.widget.LIKE
com.metrolist.music.widget.UPDATE_WIDGET com.metrolist.music.widget.UPDATE_WIDGET
com.metrolist.music.widget.PlaylistWidgetReceiver
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.metrolist.music.widget.TurntableWidgetReceiver
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.metrolist.music.widget.TURNTABLE_PLAY_PAUSE com.metrolist.music.widget.TURNTABLE_PLAY_PAUSE
com.metrolist.music.widget.TURNTABLE_LIKE com.metrolist.music.widget.TURNTABLE_LIKE
com.metrolist.music.widget.UPDATE_TURNTABLE_WIDGET com.metrolist.music.widget.UPDATE_TURNTABLE_WIDGET

Native Libraries (2)

libandroidx.graphics.path libandroidx.graphics.path.so
libdatastore_shared_counter libdatastore_shared_counter.so

Requested Permissions (12)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
android.permission.SCHEDULE_EXACT_ALARM Custom app or vendor permission (not publicly documented). android.permission.SCHEDULE_EXACT_ALARM
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK
android.permission.FOREGROUND_SERVICE_DATA_SYNC Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_DATA_SYNC
android.permission.FOREGROUND_SERVICE_MICROPHONE Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_MICROPHONE
record audio android.permission.RECORD_AUDIO
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.metrolist.music.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (3)

Microphone Feature for {@link #getSystemAvailableFeatures} and android.hardware.microphone
Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (5)

com.metrolist.music.ui.screens.CrashActivity
com.metrolist.music.MainActivity
com.yalantis.ucrop.UCropActivity
com.metrolist.music.recognition.RecognitionLaunchActivity
androidx.compose.ui.tooling.PreviewActivity

Services (6)

com.metrolist.music.playback.MusicService
com.metrolist.music.playback.ExoDownloadService
com.metrolist.music.widget.MusicRecognizerWidgetService
com.metrolist.music.recognition.RecognitionForegroundService
com.metrolist.music.quicksettings.MusicRecognizerTileService
androidx.room.MultiInstanceInvalidationService

Broadcast Receivers (9)

com.metrolist.music.listentogether.ListenTogetherActionReceiver com.metrolist.music.listentogether.ListenTogetherActionReceiver
com.metrolist.music.playback.alarm.MusicAlarmReceiver com.metrolist.music.playback.alarm.MusicAlarmReceiver
com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver com.metrolist.music.playback.alarm.MusicAlarmRescheduleReceiver
androidx.media3.session.MediaButtonReceiver androidx.media3.session.MediaButtonReceiver
com.metrolist.music.widget.MusicWidgetReceiver com.metrolist.music.widget.MusicWidgetReceiver
com.metrolist.music.widget.PlaylistWidgetReceiver com.metrolist.music.widget.PlaylistWidgetReceiver
com.metrolist.music.widget.TurntableWidgetReceiver com.metrolist.music.widget.TurntableWidgetReceiver
com.metrolist.music.widget.MusicRecognizerWidgetReceiver com.metrolist.music.widget.MusicRecognizerWidgetReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (3)

androidx.core.content.FileProvider
com.dpi.DensityScaler
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-06-25
First Submission 2026-06-25
Last Submission 2026-06-25
Stored Until 2026-07-25