D01
MalwareBazaar Hash Lookup
LIVE v7.4.1 Every scanned APK's SHA256 hash is checked against abuse.ch's open malware database. If the hash matches a known malicious sample, the risk score jumps to CRITICAL immediately.
D02
AppXpose CertNet
LIVE v7.4.1 Crowd-sourced database of signing certificates. Compares each app's cert against 4,700+ verified certs (F-Droid) and real user scans (trust-on-first-use). Confidence threshold: 7+ devices must report the same cert before it becomes the verified baseline. A cert mismatch means the APK was likely repackaged or faked.
D03
Community APK Hash Verification
LIVE v7.4.1 Crowd-sourced APK hash database. Every scan contributes the app's SHA256 hash. Once 7+ distinct devices report the same hash for a package version, it becomes the verified baseline. If your APK hash differs from the community consensus, the app was likely tampered with or repackaged.
D04
Koodous Threat Intelligence
LIVE v7.4.1 Every APK hash is checked against Koodous, a community-driven Android threat intelligence platform with millions of analyzed samples. Runs in parallel with MalwareBazaar so two independent malware databases are queried simultaneously. A Koodous detection adds +13 to the risk score.
D05
On-Device APK Integrity Checker
LIVE v7.4.1 Runs entirely on the device, parallel to the tracker scan. Inspects DEX headers (magic bytes, endian tags, link fields), signing blocks, native libraries, and file structures. Detects hooking frameworks (Cydia Substrate, Whale/LSPosed, ADBI), root tools (su, busybox, resetprop), debug artifacts (gdbserver, lldb-server, ida.key), repackaging indicators (patched DEX files), and known packer signatures (Jiagu, DexProtector, Bangcle). Severity-classified from LOW to CRITICAL.