APK Security & Privacy Score
Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.
Security
Scan-weighted
53/100
Threat scan flagged
Outdated target SDK
Privacy
Permissions & network
82/100
High-risk permissions
HTTP URLs found
AllowBackup enabled
Possible tracking
64/100
Caution
Overall trust
Facts
Threat scan
5/76 flagged, 0 suspicious
Permissions
20 requested
Network strings
41 URLs (1 HTTP, 40 HTTPS)
Target SDK
27
Certificate
Valid until 2049-05-18 (23 years, suspicious)
Warnings
Threat scan flagged: 5/76 scanners marked this file as malicious.
Found 1 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.SYSTEM_ALERT_WINDOW, android.permission.WRITE_SETTINGS, android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
AllowBackup is enabled.
Possible analytics/tracking domains found: app-measurement.com, pagead2.googlesyndication.com, update.crashlytics.com
Package Name
com.shabakaty.cbox.tw
Version Code
10605
Version Name
1.6.5
Application Name
com.shabakaty.cbox.tv.TVLeanbackApplication
Debuggable
No
Allow Backup
Yes
Min SDK
Android 21 (Lollipop)
Target SDK
Android 27 (Oreo)
Supported ABIs
arm64-v8a
armeabi-v7a
x86
x86_64
Certificate & Signer
Valid From
Valid To
Serial Number
Thumbprint
Issuer: C
Issuer: CN
Issuer: DN
Issuer: L
Issuer: O
Issuer: OU
Issuer: ST
Subject: C
Subject: CN
Subject: DN
Subject: L
Subject: O
Subject: OU
Subject: ST
Security Scan
5
⚠️ Threats Detected
Detected by
5 vendors:
AhnLab-V3 (PUP/Android.Malct.1265389), Avast-Mobile (APK:CRepMalware [Trj]), DrWeb (Tool.Obfuscator.TrashCode.1)
Malicious
5
Suspicious
0
Harmless
0
Undetected
63
Timeout
0
Failure
0
Scan Providers
ALYac
APEX
AVG
Acronis
AhnLab-V3
PUP/Android.Malct.1265389
Alibaba
Antiy-AVL
Arcabit
Avast
Avast-Mobile
APK:CRepMalware [Trj]
Avira
Baidu
BitDefender
BitDefenderFalx
Bkav
CAT-QuickHeal
CMC
CTX
ClamAV
CrowdStrike
Cylance
Cynet
DeepInstinct
DrWeb
Tool.Obfuscator.TrashCode.1
ESET-NOD32
Elastic
Emsisoft
F-Secure
Fortinet
GData
Google
Gridinsoft
Ikarus
PUA.Agent
Jiangmin
K7AntiVirus
K7GW
Trojan ( 0056a2a01 )
Kaspersky
Kingsoft
Lionic
Malwarebytes
MaxSecure
McAfeeD
MicroWorld-eScan
Microsoft
NANO-Antivirus
Paloalto
Panda
Rising
SUPERAntiSpyware
Sangfor
SentinelOne
Skyhigh
Sophos
Symantec
SymantecMobileInsight
TACHYON
Tencent
Trapmine
TrellixENS
TrendMicro
TrendMicro-HouseCall
Trustlook
VBA32
VIPRE
Varist
ViRobot
VirIT
Webroot
Xcitium
Yandex
Zillya
ZoneAlarm
Zoner
alibabacloud
huorong
tehtris
File Signatures
SHA-256
7474d5d0f67cfc9547be46acd36fd20f9353a0a2eb86a521a171be5503dd3396
MD5
2b2d6dd7a80c6c6fce5e4d82343fe18c
SHA-1
8c7867f4ae26b99926c11b643ea46acb31745ed0
SSDEEP
196608:qXqipFICARDp+KR6oz1z23l4OH5QQgD6dPqz87XcokifHGlGgnRCNT+j+jVu:qXPxAxp2oI3+OCQg2yEMokifHG4gnRqw
TLSH
T1C4C6010AFA4DAE2FC8F359350A5B43627126ED8A532181236119F7397DB7BC48E17BC4
VHASH
5de987f8ec7c0bd5be521fae9514d636
PERMHASH
d66061a9213777e13ad6555d198c88057e2191bbab15ed7c0fcdd52a31511087
File Intelligence
Type Description
Human-friendly file type name based on multiple detection methods.
Type Extension
Most likely file extension inferred from the content.
Type Tag
Primary type tag assigned by the classifier.
Type Tags
Additional type tags that describe the file content.
Magic
File signature result from magic bytes inspection.
Magika
File type predicted by Magika (ML-based file type detection).
TrID
TrID file type guesses with probabilities.
dhash
Perceptual hash used to compare visual similarity of files.
raw md5
Raw MD5 hash of the file contents.
extensions
File extensions found inside the APK and how many of each.
file types
Detected embedded file types and their counts.
highest datetime
Latest timestamp found among files inside the archive.
lowest datetime
Earliest timestamp found among files inside the archive.
num children
Number of files contained within the archive.
type
Container type detected for the analyzed file.
uncompressed size
Estimated total size of all files after extraction.
Sandbox
Sandbox Verdicts
Zenbox android
Malicious
68% confidence
MALWARE
TROJAN
EVADER
Deep Manifest Analysis
Activity Intents (1)
com.shabakaty.cbox.tv.activities.HomeActivity
Receiver Intents (1)
com.applisto.appcloner.classes.FakeCamera$FakeCameraReceiver
Native Libraries (7)
libRSSupport
libRSSupport.so
libappcloner
libappcloner.so
libnpdcc
libnpdcc.so
librsjni
librsjni.so
librsjni_androidx
librsjni_androidx.so
libsandhook-native
libsandhook-native.so
libsandhook
libsandhook.so
Requested Permissions (25)
have full network access
android.permission.INTERNET
modify or delete the contents of your shared storage
android.permission.WRITE_EXTERNAL_STORAGE
read the contents of your shared storage
android.permission.READ_EXTERNAL_STORAGE
view Wi-Fi connections
android.permission.ACCESS_WIFI_STATE
view network connections
android.permission.ACCESS_NETWORK_STATE
keep car screen turned on
android.permission.WAKE_LOCK
Install Referrer service
com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
Read Logs
android.permission.READ_LOGS
Flashlight
android.permission.FLASHLIGHT
net.dinglisch.android.tasker.PERMISSION_RUN_TASKS
access Bluetooth settings
android.permission.BLUETOOTH_ADMIN
control vibration
android.permission.VIBRATE
This app can appear on top of other apps
android.permission.SYSTEM_ALERT_WINDOW
modify or delete the contents of your shared storage
android.permission.WRITE_EXTERNAL_STORAGE
connect and disconnect from Wi-Fi
android.permission.CHANGE_WIFI_STATE
have full network access
android.permission.INTERNET
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
view network connections
android.permission.ACCESS_NETWORK_STATE
android.permission.USE_FINGERPRINT
android.permission.USE_FINGERPRINT
view Wi-Fi connections
android.permission.ACCESS_WIFI_STATE
take pictures and videos
android.permission.CAMERA
read the contents of your shared storage
android.permission.READ_EXTERNAL_STORAGE
pair with Bluetooth devices
android.permission.BLUETOOTH
modify system settings
android.permission.WRITE_SETTINGS
android.permission.READ_SETTINGS
android.permission.READ_SETTINGS
Uses Features (2)
Touchscreen
android.hardware.touchscreen
Leanback
android.software.leanback
Activities (6)
com.shabakaty.cbox.tv.activities.HomeActivity
com.shabakaty.cbox.tv.activities.ErrorActivity
com.shabakaty.cbox.tv.activities.SettingsActivity
com.shabakaty.cbox.tv.player.ExoPlayerActivity
com.applisto.appcloner.classes.DefaultProvider$MyActivity
com.applisto.appcloner.classes.FakeCamera$FakeCameraActivity
Services (6)
com.google.firebase.components.ComponentDiscoveryService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
com.applisto.appcloner.service.RemoteService
Broadcast Receivers (5)
com.google.android.gms.measurement.AppMeasurementReceiver
com.google.android.gms.measurement.AppMeasurementReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.applisto.appcloner.classes.DefaultProvider$DefaultReceiver
com.applisto.appcloner.classes.DefaultProvider$DefaultReceiver
com.applisto.appcloner.classes.FakeCamera$FakeCameraReceiver
com.applisto.appcloner.classes.FakeCamera$FakeCameraReceiver
com.applisto.appcloner.classes.DisableClipboardAccess$ClearClipboardReceiver
com.applisto.appcloner.classes.DisableClipboardAccess$ClearClipboardReceiver
Content Providers (3)
com.squareup.picasso.PicassoProvider
com.google.firebase.provider.FirebaseInitProvider
com.applisto.appcloner.classes.DefaultProvider
URL Endpoints (44)
http://whois.domaintools.com/
https://app-measurement.com/a
https://firebase.google.com/support/guides/disable-analytics
https://firebase.google.com/support/privacy/init-options
https://github.com/castorflex
https://github.com/castorflex/SmoothProgressBar
https://github.com/castorflex/SmoothProgressBar.git
https://goo.gl/J1sWQy
https://goo.gl/NAOOOI
https://google.com/search
https://music-1539414046135.firebaseio.com
https://pagead2.googlesyndication.com/pagead/gen_204?id=gmob-apps
https://plus.google.com/
https://update.crashlytics.com/spi/v1/platforms/android/apps
https://www.google.com
https://www.googleapis.com/auth/appstate
https://www.googleapis.com/auth/datastoremobile
https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/drive.appdata
https://www.googleapis.com/auth/drive.apps
Submission Details
Submitted At
First Submission
Last Submission
Stored Until