Package
com.sec.android.app.DataCreate
Automation Test
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it.
- Its largest observed manifest declares 51 permissions: 14 runtime (user-granted), 9 signature or system-level, 7 install-time and 21 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (51)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_CHECKIN_PROPERTIES |
Signature or privileged system permission. |
ACCESS_WIFI_STATE |
Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. |
BLUETOOTH |
Allows the app to view the configuration of the Bluetooth on the phone, and to make and accept connections with paired devices. |
CAMERA |
This app can take pictures and record videos using the camera while the app is in use. |
GET_ACCOUNTS |
Allows the app to get the list of accounts known by the phone. This may include any accounts created by applications you have installed. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
MANAGE_APP_OPS_MODES |
Signature-level system permission, for platform-signed apps. |
MANAGE_EXTERNAL_STORAGE |
Signature-level system permission, for platform-signed apps. docs ↗ |
POST_NOTIFICATIONS |
Allows the app to show notifications |
QUERY_ALL_PACKAGES |
Allows an app to see all installed packages. |
READ_CALENDAR |
This app can read all calendar events stored on your phone and share or save your calendar data. |
READ_CALL_LOG |
This app can read your call history. |
READ_CONTACTS |
Allows the app to read data about your contacts stored on your phone. Apps will also have access to the accounts on your phone that have created contacts. This may include accounts created by apps you have installed. This permission allows apps to save your contact data, and malicious apps may share contact data without your knowledge. |
READ_EXTERNAL_STORAGE |
Allows the app to read the contents of your shared storage. |
READ_MEDIA_STORAGE |
- |
READ_PRIVILEGED_PHONE_STATE |
Signature or privileged system permission. docs ↗ |
READ_SMS |
This app can read all SMS (text) messages stored on your phone. |
RECEIVE_MMS |
Allows the app to receive and process MMS messages. This means the app could monitor or delete messages sent to your device without showing them to you. |
RESTART_PACKAGES |
Allows the app to end background processes of other apps. This may cause other apps to stop running. |
SEND_SMS |
Allows the app to send SMS messages. This may result in unexpected charges. Malicious apps may cost you money by sending messages without your confirmation. |
START_ACTIVITIES_FROM_BACKGROUND |
Signature or privileged system permission. docs ↗ |
UPDATE_APP_OPS_STATS |
Signature or privileged system permission. |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_CALENDAR |
This app can add, remove, or change calendar events on your phone. This app can send messages that may appear to come from calendar owners, or change events without notifying their owners. |
WRITE_CALL_LOG |
Allows the app to modify your phone's call log, including data about incoming and outgoing calls. Malicious apps may use this to erase or modify your call log. |
WRITE_CONTACTS |
Allows the app to modify the data about your contacts stored on your phone. This permission allows apps to delete contact data. |
WRITE_EXTERNAL_STORAGE |
Allows the app to write the contents of your shared storage. |
WRITE_MEDIA_STORAGE |
Signature or privileged system permission. |
WRITE_SECURE_SETTINGS |
Signature or privileged system permission. |
WRITE_SETTINGS |
Allows the app to modify the system's settings data. Malicious apps may corrupt your system's configuration. |
WRITE_SMS |
Install-time permission, granted automatically. |
sec.RECEIVE_BLOCKED_SMS_MMS |
- |
com.android.browser.permission.READ_HISTORY_BOOKMARKS |
- |
com.android.browser.permission.WRITE_HISTORY_BOOKMARKS |
- |
com.android.launcher.permission.READ_SETTINGS |
- |
com.infraware.provider.SNoteProvider.permission.READ |
- |
com.infraware.provider.SNoteProvider.permission.WRITE |
- |
com.samsung.android.launcher.permission.READ_SETTINGS |
- |
com.samsung.android.launcher.permission.WRITE_SETTINGS |
- |
com.samsung.android.memo.READ |
- |
com.samsung.android.memo.WRITE |
- |
com.sec.android.app.DataCreate.permission.KEYSTRING |
- |
com.sec.android.app.clockpackage.permission.READ_WCCONTENT |
- |
com.sec.android.app.clockpackage.permission.WRITE_WCCONTENT |
- |
com.sec.android.app.phoneutil.permission.KEYSTRING |
- |
com.sec.android.permission.READ_MEMO |
- |
com.sec.android.permission.WRITE_MEMO |
- |
com.sec.android.provider.logsprovider.permission.READ_LOGS |
- |
com.sec.android.provider.logsprovider.permission.WRITE_LOGS |
- |
com.sec.android.widgetapp.q1_penmemo.permission.READ |
- |
com.sec.android.widgetapp.q1_penmemo.permission.WRITE |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A346B | Android 14 | OEM Samsung | 1 | 4 Mar 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 28 May 2026 |
| Samsung | SM-M315F | Android 12 | - | 1 | 2 Feb 2026 |
| Samsung | SM-N950U1 | Android 9.0 | - | 1 | 20 Aug 2025 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X200 | Android 14 | - | 1 | 27 Aug 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| Automation Test | en-gb | 12 |
| Automation Test | es-us | 3 |
| Automation Test | 2 | |
| Automation Test | en-us | 2 |
| Automation Test | es-ES | 2 |
| Automation Test | es-es | 2 |
| Automation Test | fr-fr | 2 |
| Automation Test | fr-FR | 1 |
| Automation Test | fr-dz | 1 |
| Automation Test | es-US | 1 |
| Automation Test | nl-nl | 1 |
| Automation Test | de-de | 1 |
| Automation Test | en-GB | 1 |
| Automation Test | en-US | 1 |
| Automation Test | en | 1 |
| Automation Test | en-nl | 1 |