小树洞AI icon

simpleDemo-release.apk

小树洞AI

89.22 MB

Analyzed: 2026-07-03 10:02 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
89/100
Threat scan flagged Modern target SDK
Privacy Permissions & network
72/100
High-risk permissions AllowBackup enabled
80/100
Good
Overall trust

Facts

Threat scan 1/74 flagged, 0 suspicious
Permissions 25 requested
Network strings 1 URLs (0 HTTP, 1 HTTPS)
Target SDK 35
Certificate Valid until 2051-04-17 (25 years, suspicious)

Warnings

Threat scan flagged: 1/74 scanners marked this file as malicious.
High-risk permissions detected: android.permission.WRITE_SETTINGS
Requests 25 permissions (review carefully).
AllowBackup is enabled.
Package Name com.xiaoshudong.app
Version Code 29
Version Name 1.29
Application Name io.dcloud.application.DCloudApplication
Debuggable No
Allow Backup Yes
Min SDK Android 23 (Marshmallow)
Target SDK Android 35 (Android 15)
Supported ABIs
arm64-v8a armeabi armeabi-v7a x86 x86_64

Certificate & Signer

Valid From 2026-04-23 12:49:25
Valid To 2051-04-17 12:49:25
Serial Number 1
Thumbprint 332da307a0d3da1099c5975e8b8356b2436fef96
Issuer: C SYD
Issuer: CN LilyChoi
Issuer: DN C:SYD, CN:LilyChoi, L:Australia, O:null, ST:Sydney, OU:null
Issuer: L Australia
Issuer: O null
Issuer: OU null
Issuer: ST Sydney
Subject: C SYD
Subject: CN LilyChoi
Subject: DN C:SYD, CN:LilyChoi, L:Australia, O:null, ST:Sydney, OU:null
Subject: L Australia
Subject: O null
Subject: OU null
Subject: ST Sydney

Security Scan

1 /74
⚠️ Threats Detected
Detected by 1 vendor: K7GW (Trojan ( 0058bdfd1 ))
Scanned by 74 security vendors
Last scan: 2026-07-03 10:02 UTC
Malicious
1
Suspicious
0
Harmless
0
Undetected
64
Timeout
1
Failure
1

Scan Providers

74 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.794
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.1.10706
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260702-02
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav undetected
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.3.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.270
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.48.0
GData undetected
No result reported
Engine GD:27.45129AVA:64.31519
Google undetected
No result reported
Engine 1783065646
Gridinsoft undetected
No result reported
Engine 1.0.249.174
Ikarus failure
No result reported
Engine 6.5.4.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.60.60018
K7GW malicious
Trojan ( 0058bdfd1 )
Engine 14.60.60016
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.239
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.15146
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26050.11
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.7.0.1
Skyhigh timeout
No result reported
Sophos undetected
No result reported
Engine 3.6.2.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-07-03.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.12.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1241
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38776
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5635
ZoneAlarm undetected
No result reported
Engine 6.25-116107998
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 2694dc8:2694dc8:c6047a5:c6047a5
tehtris type-unsupported
No result reported

File Signatures

SHA-256 b1290c3a430e6dd670c3410e9e8580f9b8298fb422918208ef4f5c24997a58c3
MD5 f003cb29332f50140ee09e00b56a7df9
SHA-1 13d6aba5c9ce36ab1987556a2d8c378a71542e54
SSDEEP 1572864:MoGtM+IAjLwbDL3jEURNMG2tU6YB05Z1MtrSRNAyQO7S4VadVu36jEZn9/dKL3:jpALaL34OJ2gBO4sRNAyQdQaHuAEZ1dO
TLSH T155283399F7ACD83FD433203285AA122225975D038B669B07764CB75C6B7B7E40E58FC8
VHASH 8d90dd766a0696608132abc16d96797e
PERMHASH 86c7a8f4d746e68fbdd2c651d8a49f721a86d7887df7382ca57fbe4722de877e

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (40%), Java Archive (20%), VYM Mind Map (18.5%), Sweet Home 3D Design (generic) (15.5%), ZIP compressed archive (5.9%) TrID file type guesses with probabilities.
dhash 0000001c1c0d0008 Perceptual hash used to compare visual similarity of files.
raw md5 04c84e69556e3b013ff85e92aa6e1f68 Raw MD5 hash of the file contents.
extensions png (437), xml (332), so (57), css (47), version (43), js (20), properties (16), kotlin_builtins (7), ts (7), json (5), dex (4), ttf (4), dat (2), gif (2), gz (2), html (2), AutoDiscoverable (1), bin (1), CoroutineExceptionHandler (1), MainDispatcherFactory (1), MessageBodyReader (1), MessageBodyWriter (1), ogg (1), prof (1), profm (1), Providers (1), scss (1), textproto (1) File extensions found inside the APK and how many of each.
file types PNG (437), XML (330), unknown (161), ELF (57), DEX (4), JavaScript (3), GIF (2), HTML (2), JSON (2), Java Bytecode (1), OGG (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 1577 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 145 MB Estimated total size of all files after extraction.

Sandbox

Sandbox Verdicts

Zenbox android
Harmless 92% confidence CLEAN

Deep Manifest Analysis

Activity Intents (2)

io.dcloud.PandoraEntry
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER
io.dcloud.PandoraEntryActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE

Receiver Intents (1)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION

Native Libraries (14)

Breakpad Crash Reporter Crash reporting library that captures diagnostic minidumps. libbreakpad-core.so
C++ Standard Library Android NDK C++ runtime used by native code. libc++_shared.so
libdcblur libdcblur.so
libgifimage libgifimage.so
libimagepipeline libimagepipeline.so
liblamemp3 liblamemp3.so
libnative-filters libnative-filters.so
libnative-imagetranscoder libnative-imagetranscoder.so
libpl_droidsonroids_gif libpl_droidsonroids_gif.so
libsecsdk libsecsdk.so
libweexcore libweexcore.so
libweexjsb libweexjsb.so
libweexjss libweexjss.so
libweexjst libweexjst.so

Requested Permissions (25)

change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
Mount Unmount Filesystems android.permission.MOUNT_UNMOUNT_FILESYSTEMS
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
Read Logs android.permission.READ_LOGS
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
take pictures and videos This app can take pictures and record videos using the camera while the app is in use. android.permission.CAMERA
find accounts on the device Allows the app to get the list of accounts known by the tablet. This may include any accounts created by applications you have installed. android.permission.GET_ACCOUNTS
read phone status and identity Allows the app to access the phone features of the device. This permission allows the app to determine the phone number and device IDs, whether a call is active, and the remote number connected by a call. android.permission.READ_PHONE_STATE
connect and disconnect from Wi-Fi Allows the app to connect to and disconnect from Wi-Fi access points and to make changes to device configuration for Wi-Fi networks. android.permission.CHANGE_WIFI_STATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
Flashlight android.permission.FLASHLIGHT
modify system settings Allows the app to modify the system\'s settings data. Malicious apps may corrupt your system\'s configuration. android.permission.WRITE_SETTINGS
record audio android.permission.RECORD_AUDIO
change your audio settings Allows the app to modify global audio settings such as volume and which speaker is used for output. android.permission.MODIFY_AUDIO_SETTINGS
com.android.vending.BILLING
modify or delete the contents of your shared storage Allows the app to write the contents of your shared storage. android.permission.WRITE_EXTERNAL_STORAGE
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
App badge update Allows the app to update the launcher icon badge count on Huawei launchers. com.huawei.android.launcher.permission.CHANGE_BADGE
App badge update Allows the app to update the launcher icon badge count on launcher launchers. com.vivo.notification.permission.BADGE_ICON
com.asus.msa.SupplementaryDID.ACCESS
freemme.permission.msa Custom app or vendor permission (not publicly documented). freemme.permission.msa
pair with Bluetooth devices Allows the app to view the configuration of Bluetooth on the tablet, and to make and accept connections with paired devices. android.permission.BLUETOOTH
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.xiaoshudong.app.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (2)

Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Camera Autofocus Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.autofocus

Activities (15)

io.dcloud.PandoraEntry
io.dcloud.PandoraEntryActivity
io.dcloud.debug.PullDebugActivity
io.dcloud.feature.nativeObj.photoview.PhotoActivity
io.dcloud.WebAppActivity
io.dcloud.ProcessMediator
io.dcloud.WebviewActivity
com.dmcbig.mediapicker.PickerActivity
com.dmcbig.mediapicker.PreviewActivity
io.dcloud.feature.gallery.imageedit.IMGEditActivity
io.dcloud.sdk.activity.WebViewActivity
com.android.billingclient.api.ProxyBillingActivity
com.android.billingclient.api.ProxyBillingActivityV2
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
com.google.android.gms.common.api.GoogleApiActivity

Services (6)

io.dcloud.debug.WebSocketService
io.dcloud.debug.PullService
io.dcloud.sdk.base.service.DownloadService
com.google.android.gms.auth.api.signin.RevocationBoundService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (3)

com.taobao.weex.WXGlobalEventReceiver com.taobao.weex.WXGlobalEventReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (3)

io.dcloud.common.util.DCloud_FileProvider
io.dcloud.sdk.base.service.provider.DCloudAdFileProvider
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-07-03
First Submission 2026-07-03
Last Submission 2026-07-03
Stored Until 2026-08-02