豆豆3 icon

_____-3-V_1.1.0.apk_____-3-V_1.1.0_1_.apk

豆豆3

22.48 MB

Analyzed: 2026-07-07 18:53 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
10/100
Threat scan flagged Outdated target SDK
Privacy Permissions & network
33/100
High-risk permissions HTTP URLs found AllowBackup enabled Possible tracking
15/100
High Risk
Overall trust

Facts

Threat scan 19/73 flagged, 0 suspicious
Permissions 46 requested
Network strings 60 URLs (35 HTTP, 25 HTTPS)
Target SDK 26
Certificate Unknown

Warnings

Threat scan flagged: 19/73 scanners marked this file as malicious.
Signing certificate metadata is unavailable.
Found 35 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES, android.permission.SYSTEM_ALERT_WINDOW, android.permission.WRITE_SETTINGS, android.permission.PACKAGE_USAGE_STATS, android.permission.RECEIVE_BOOT_COMPLETED
Requests 46 permissions (review carefully).
AllowBackup is enabled.
Package Name com.script.keypack
Version Code 1
Version Name V_1.1.0
Application Name com.cyjh.elfin.AppContext
Debuggable No
Allow Backup Yes
Min SDK Android 16 (Jelly Bean)
Target SDK Android 26 (Oreo)
Supported ABIs
armeabi-v7a x86

Security Scan

19 /73
⚠️ Threats Detected
Detected by 19 vendors: AhnLab-V3 (PUP/Android.Agent.893945), Avast-Mobile (Android:Evo-gen [Trj]), Avira (PUA/Android.CyFin.H)
Scanned by 73 security vendors
Last scan: 2026-07-07 18:53 UTC
Malicious
19
Suspicious
0
Harmless
0
Undetected
37
Timeout
7
Failure
5

Scan Providers

73 vendors
ALYac failure
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.796
AVG timeout
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 malicious
PUP/Android.Agent.893945
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast timeout
No result reported
Engine 23.9.8494.0
Avast-Mobile malicious
Android:Evo-gen [Trj]
Engine 260707-00
Avira malicious
PUA/Android.CyFin.H
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx malicious
Android.Riskware.Agent.CUH
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal malicious
Android.Agent.GEN10334 (PUP)
Engine 22.00
CMC timeout
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV timeout
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DrWeb malicious
Android.Siggen.Susp.34790
Engine 7.0.75.2070
ESET-NOD32 malicious
Android/AdDisplay.CyFin.B potentially unwanted application
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.270
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure malicious
PotentialRisk.PUA/Android.CyFin.H
Engine 18.10.1547.307
Fortinet timeout
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45181AVA:64.31546
Google malicious
Detected
Engine 1783443652
Gridinsoft undetected
No result reported
Engine 1.0.249.174
Ikarus failure
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.61.60066
K7GW malicious
Trojan ( 0056334a1 )
Engine 14.61.60064
Kaspersky malicious
not-a-virus:HEUR:AdWare.AndroidOS.Ewind.hz
Engine 22.0.1.28
Kingsoft malicious
Android.Troj.Spy.Q
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.239
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26060.3008
NANO-Antivirus malicious
Riskware.Android.Ewind.jzzoas
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising malicious
Spyware.Loki/Android!8.1B53 (CLOUD)
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh timeout
No result reported
Sophos malicious
Andr/Xgen-BDY
Engine 3.6.2.0
Symantec failure
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-07-07.02
Tencent malicious
Android.Risktool.Agent.Jtgl
Engine 1.0.0.1
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro failure
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist malicious
AndroidOS/ABRisk.GXIW-8
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT malicious
Android.Adw.G2P.JYK
Engine 9.5.1244
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38785
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya failure
No result reported
Engine 2.0.0.5637
ZoneAlarm malicious
Andr/Xgen4-AC
Engine 6.25-116108048
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine b749c68:b749c68:57f190d:57f190d
tehtris type-unsupported
No result reported
Engine v0.1.4

File Signatures

SHA-256 275f23fb944309909d9098c264411232086e78866370fab671255218dd332c80
MD5 ca3d1eb545d87afd1f6f39bcd4cf3902
SHA-1 1a257fe164cfb1452d1002383113e49477eaeab7
SSDEEP 393216:3vmp09ACelFSOLrHqaLGlZ1DOUnrqDhAQbvq1+b0oWB4xI1WrXNZWU3ldNGoHdMC:3vmpIACCLrHxLs9FqDdbCWLWfoNZWUg8
TLSH T1E23733D6BF0CE415E2A3F87683740D07A5380C6561B9EA260B58FD6C5EBBEC14285FC9
VHASH 84a6f17c0bf0dd167dd27bacb09e2b8d
PERMHASH ced177117034691263dc462287fe25cda56231b238534715b0456619d18d6f74

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Java archive data (JAR) File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (32.7%), OpenOffice Extension (26%), Java Archive (16.3%), Sweet Home 3D Design (generic) (12.7%), Universal Scene Description Zipped AR format (generic) (7.2%) TrID file type guesses with probabilities.
dhash 0000000c0e0d0400 Perceptual hash used to compare visual similarity of files.
raw md5 a6d3a62ff582bdaebe7ef34dc16041e4 Raw MD5 hash of the file contents.
extensions xml (451), png (435), so (30), java (26), dex (4), aidl (3), map (3), provider (3), default (2), gif (2), json (2), lc (2), txt (2), apk (1), arsc (1), atc (1), gz (1), html (1), info (1), jar (1), jarx (1), jpg (1), MF (1), mf (1), pro (1), prop (1), properties (1), providers (1), RSA (1), rtd (1), SF (1), ui (1), uip (1), uis (1), zip (1) File extensions found inside the APK and how many of each.
file types XML (451), PNG (435), unknown (59), ELF (35), ZIP (5), DEX (4), GIF (2), HTML (2), JPG (1), JSON (1) Detected embedded file types and their counts.
highest datetime 2025-05-16 21:58:44 UTC Latest timestamp found among files inside the archive.
lowest datetime 2025-05-16 21:58:34 UTC Earliest timestamp found among files inside the archive.
num children 995 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 48 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Malicious 64% confidence MALWARE TROJAN ADWARE EVADER

Native Libraries (18)

libgoldcoast libgoldcoast.so
libiflyads libiflyads.so
libjpgt libjpgt.so
liblept liblept.so
libmqm libmqm.so
libpngt libpngt.so
libsc libsc.so
libsc15 libsc15.so
libsc17 libsc17.so
libsc19 libsc19.so
libsc21 libsc21.so
libsc71 libsc71.so
libscVirtDisplay19 libscVirtDisplay19.so
libscVirtDisplay21 libscVirtDisplay21.so
libspeed libspeed.so
libsubstrate libsubstrate.so
libtess libtess.so
libtinyCnn libtinyCnn.so

Requested Permissions (48)

run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Mount Unmount Filesystems android.permission.MOUNT_UNMOUNT_FILESYSTEMS
android.permission.DOWNLOAD_WITHOUT_NOTIFICATION Custom app or vendor permission (not publicly documented). android.permission.DOWNLOAD_WITHOUT_NOTIFICATION
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
reroute outgoing calls Allows the app to see the number being dialed during an outgoing call with the option to redirect the call to a different number or abort the call altogether. android.permission.PROCESS_OUTGOING_CALLS
This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
Interact Across Users Full android.permission.INTERACT_ACROSS_USERS_FULL
allow Wi-Fi Multicast reception Allows the app to receive packets sent to all devices on a Wi-Fi network using multicast addresses, not just your tablet. It uses more power than the non-multicast mode. android.permission.CHANGE_WIFI_MULTICAST_STATE
read your text messages (SMS or MMS) This app can read all SMS (text) messages stored on your tablet. android.permission.READ_SMS
send and view SMS messages Allows the app to send SMS messages. This may result in unexpected charges. Malicious apps may cost you money by sending messages without your confirmation. android.permission.SEND_SMS
directly call phone numbers Allows the app to call phone numbers without your intervention. This may result in unexpected charges or calls. Note that this doesn\'t allow the app to call emergency numbers. Malicious apps may cost you money by making calls without your confirmation, or dial carrier codes which cause incoming calls to be automatically forwarded to another number. android.permission.CALL_PHONE
close other apps Allows the app to end background processes of other apps. This may cause other apps to stop running. android.permission.KILL_BACKGROUND_PROCESSES
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
retrieve running apps Allows the app to retrieve information about currently and recently running tasks. This may allow the app to discover information about which applications are used on the device. android.permission.GET_TASKS
Write Secure Settings android.permission.WRITE_SECURE_SETTINGS
modify system settings Allows the app to modify the system\'s settings data. Malicious apps may corrupt your system\'s configuration. android.permission.WRITE_SETTINGS
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
android.permission.ACCESS_COARSE_UPDATES Custom app or vendor permission (not publicly documented). android.permission.ACCESS_COARSE_UPDATES
access extra location provider commands Allows the app to access extra location provider commands. This may allow the app to interfere with the operation of the GPS or other location sources. android.permission.ACCESS_LOCATION_EXTRA_COMMANDS
Access Mock Location android.permission.ACCESS_MOCK_LOCATION
pair with Bluetooth devices Allows the app to view the configuration of Bluetooth on the tablet, and to make and accept connections with paired devices. android.permission.BLUETOOTH
access Bluetooth settings Allows the app to configure the local Bluetooth tablet, and to discover and pair with remote devices. android.permission.BLUETOOTH_ADMIN
record audio android.permission.RECORD_AUDIO
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION
disable your screen lock Allows the app to disable the keylock and any associated password security. For example, the phone disables the keylock when receiving an incoming phone call, then re-enables the keylock when the call is finished. android.permission.DISABLE_KEYGUARD
send sticky broadcast Allows the app to send sticky broadcasts, which remain after the broadcast ends. Excessive use may make the tablet slow or unstable by causing it to use too much memory. android.permission.BROADCAST_STICKY
find accounts on the device Allows the app to get the list of accounts known by the tablet. This may include any accounts created by applications you have installed. android.permission.GET_ACCOUNTS
android.permission.WRITE_INTERNAL_STORAGE Custom app or vendor permission (not publicly documented). android.permission.WRITE_INTERNAL_STORAGE
android.permission.READ_INTERNAL_STORAGE Custom app or vendor permission (not publicly documented). android.permission.READ_INTERNAL_STORAGE
Read User Dictionary android.permission.READ_USER_DICTIONARY
android.permission.ACCESS_MTK_MMHW Custom app or vendor permission (not publicly documented). android.permission.ACCESS_MTK_MMHW
Diagnostic android.permission.DIAGNOSTIC
Access Cache Filesystem android.permission.ACCESS_CACHE_FILESYSTEM
android.permission.SAMSUNG_TUNTAP Custom app or vendor permission (not publicly documented). android.permission.SAMSUNG_TUNTAP
read your contacts Allows the app to read data about your contacts stored on your tablet. Apps will also have access to the accounts on your tablet that have created contacts. This may include accounts created by apps you have installed. This permission allows apps to save your contact data, and malicious apps may share contact data without your knowledge. android.permission.READ_CONTACTS
modify your contacts Allows the app to modify the data about your contacts stored on your tablet. This permission allows apps to delete contact data. android.permission.WRITE_CONTACTS
Package Usage Stats android.permission.PACKAGE_USAGE_STATS
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE

Activities (49)

com.cyjh.elfin.activity.news.SplashActivity
com.cyjh.elfin.activity.ElfinFreeActivity
com.cyjh.elfin.activity.news.FengLingAdWebViewActivity
com.cyjh.elfin.activity.AdActivity
com.cyjh.elfin.activity.news.FullScreenTwoAdActivity
com.cyjh.elfin.activity.SettingActivity
com.cyjh.elfin.activity.ScriptLogActivity
com.cyjh.elfin.activity.ScriptLogDetailActivity
com.cyjh.elfin.activity.FeedbackActivity
com.cyjh.feedback.lib.activity.ImageSelectActivity
com.cyjh.elfin.activity.news.H5LinkJumpPageActivity
com.cyjh.elfin.activity.MessagePushActivity
com.cyjh.elfin.activity.MessageDetailActivity
com.cyjh.elfin.activity.RecommendGamesActivity
com.cyjh.elfin.activity.AbnormalGamesActivity
com.cyjh.elfin.activity.AbGamesDetailsActivity
com.cyjh.elfin.activity.ImagePicZoomActivity
com.cyjh.elfin.activity.TestActivity
com.cyjh.elfin.activity.guide.RecognitionGuideActivity
com.cyjh.elfin.activity.guide.NoTitleBarWebViewActivity
com.iflytek.voiceads.request.IFLYBrowser
com.didi.virtualapk.delegate.StubActivity
com.didi.virtualapk.core.A$1
com.didi.virtualapk.core.A$2
com.didi.virtualapk.core.B$1
com.didi.virtualapk.core.B$2
com.didi.virtualapk.core.B$3
com.didi.virtualapk.core.B$4
com.didi.virtualapk.core.B$5
com.didi.virtualapk.core.B$6
com.didi.virtualapk.core.B$7
com.didi.virtualapk.core.B$8
com.didi.virtualapk.core.C$1
com.didi.virtualapk.core.C$2
com.didi.virtualapk.core.C$3
com.didi.virtualapk.core.C$4
com.didi.virtualapk.core.C$5
com.didi.virtualapk.core.C$6
com.didi.virtualapk.core.C$7
com.didi.virtualapk.core.C$8
com.didi.virtualapk.core.D$1
com.didi.virtualapk.core.D$2
com.didi.virtualapk.core.D$3
com.didi.virtualapk.core.D$4
com.didi.virtualapk.core.D$5
com.didi.virtualapk.core.D$6
com.didi.virtualapk.core.D$7
com.didi.virtualapk.core.D$8
com.cyjh.mobileanjian.screencap.ForScreenShotActivity

Services (8)

com.iflytek.voiceads.download.DownloadService
com.cyjh.elfin.services.PhoneStateService
com.cyjh.elfin.services.SavePicService
com.cyjh.elfin.services.DownloadApkService
com.didi.virtualapk.delegate.LocalService
com.didi.virtualapk.delegate.RemoteService
com.cyjh.mq.service.IpcService
com.ime.input.InputKb

Broadcast Receivers (2)

com.cyjh.elfin.receiver.InstallAndRemoveAppSuccessReceive com.cyjh.elfin.receiver.InstallAndRemoveAppSuccessReceive
com.cyjh.elfin.receiver.StartBootReceiver com.cyjh.elfin.receiver.StartBootReceiver

Content Providers (4)

android.support.v4.content.FileProvider
mobi.oneway.common.provider.OwCommonFileProvider
mobi.oneway.common.provider.OwBFileProvider
com.didi.virtualapk.delegate.RemoteContentProvider

URL Endpoints (72)

http://11.239.113.99 http://11.239.113.99/umpx_oplus_lbs http://118.178.152.152 http://121.41.22.28:6644/api/GetAuthorFeedback http://ads.oway.mobi http://api-cn.felink.com/v1/rta http://api.mobileanjian.com/api http://api.mobileanjian.com/api/SetFeedBack http://app.51moba.com/AppConfig http://app.mobileanjian.com/AppConfig http://auth2.mobileanjian.com/ http://auth2.mobileanjian.com/AliCloud/GetStorageToken http://bbs.anjian.com/api.php?mod=u&egg= http://bbs.anjian.com/api.php?mod=u&gt http://down.nishuoa.com/fengwocps.apk http://image.cnamedomain.com http://logapi.mobileanjian.com/api/SetLog http://m.anjian.com/help/jiaoben/yxfwaj.apk http://oss-cn-****.aliyuncs.com http://oss-cn-hangzhou.aliyuncs.com

Submission Details

Submitted At 2026-07-07
First Submission 2026-07-07
Last Submission 2026-07-07
Stored Until 2026-08-06