Kuai APK Downloader
The AI review rates the findings as likely false positive, but the risk score (42/100) still counts them.
Analysis record
- Analysed
- 3 months ago
- Version
- v1.0
- Artifact
- SHA256 E8A…B97
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Network Indicators
Concrete URLs, domains, IPs, emails, and hashes extracted from the analyzed artifact.
Network indicators are queued for lazy loading
Scroll this section into view to load the detailed rows.
Publisher Evidence
Limited evidenceKuaishou
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
Requested Permissions
1 permissionAI Security Report
AI Security Review
Risky Plugins reviewed this extension with an AI-assisted security workflow on 2026-05-31. The review verdict is likely false positive with 92% confidence.
Recommended action: suppress false positive. Evidence context: threat category none; evidence quality strong.
The Firefox add‑on titled Kuai APK Downloader is published with an empty developer name and version 1.0, and it has no recorded user count. All 15 findings are classified as medium severity and belong exclusively to the ioc category, appearing in the extracted_from_files path. The specific IOC titles include:
- "XIOC-URL-http://addons.mozilla.org/ca/crl.pem0N"
- "XIOC-URL-http://ns.attribution.com/ads/1.0/'"
- "XIOC-DOMAIN-ns.adobe.com"
- "XIOC-URL-https://kuaiapkdownload.com/?s="
- "XIOC-DOMAIN-kuaiapkdownload.com"
- "XIOC-MD5-f62c0dc02f294f84bf7ddf73c8c53748"
- "XIOC-DOMAIN-ns.attribution.com"
- "[email protected]"
- "XIOC-DOMAIN-mozilla.com"
- "XIOC-DOMAIN-purl.org"
- "XIOC-DOMAIN-content-signature.mozilla.org"
- "XIOC-DOMAIN-signingca1.addons.mozilla.org"
None of the findings contain malware signatures, network‑level hijacking directives, or obfuscation that would indicate hidden malicious payloads. The only suspicious entities are generic domains such as ns.adobe.com, mozilla.com, and purl.org, which the XIOC extractor commonly misclassifies as indicators even when they are part of legitimate code‑access patterns. Because the extension shows no evidence of URL templating for search‑engine hijacking, no credential‑theft code, and no proxy or VPN behavior, it does not meet any high‑confidence malicious indicator.
A possible counterargument is that the volume of IOC hits could conceal malicious activity despite the absence of explicit malware signatures. However, the same XIOC extractor flags innocuous property accesses and CDN hostnames as IOcs, and the extension’s code shows no signs of payload hiding, recent updates, or deceptive naming that would suggest impersonation. Consequently, the lack of any confirmed malicious pattern outweighs the noise produced by the extractor.
In summary, the available evidence points to a benign utility that has been over‑reported by the IOC scanner, making this case a clear example of a likely false positive.
Key Reasons
- All findings are IOC type with no malware signatures
- No evidence of malicious behavior or code obfuscation
- Findings align with known XIOC extractor false positives
- Extension name does not impersonate a known service
False Positive Considerations
- ioc_extractor_garbage
- generic_domains_flagged_as_ioc
- no_malware_signatures
- absence_of_obfuscation
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace