Suspicious
Unsigned Android APK showing PUA detections plus direct-IP behaviour with no domain usage.
232892dd36a2d3873d…7a99be0768The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The combination of a single tier-1 PUA detection, multiple adware-oriented labels, and the DirectIpC2 heuristic outweighs the clean external-intel and common_old history. Absence of signing and sandbox verdicts prevents a clean verdict, while the PUA-focused labels and lack of named malware families prevent a full malicious classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Sophos (tier1) result 'Android Xgen PUA (PUA)' with adwarePua label
MalwareTips.Synth.DirectIpC2 fired on 9 direct IPs / 0 domains
engines.tier1Malicious=1, tier1FamilyConsensus.strong=false
prevalence.classification=common_old (134 submitters)
- common_old prevalence (134 submitters)
- No malicious sandbox verdicts
- No dropped malicious children
- Unsigned APK
- Direct IP contacts without domains
- PUA / adware detections from tier-1 and tier-2 engines
Treat as unwanted software; avoid installation and remove if present.
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 9 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence198.54.120.71 · 142.251.143.170 · 142.251.143.132
4 detections across 75 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- X-IBO-PRO.apk
- Size
- 20.64 MB
- MIME type
- (unknown)
- Detected type
- Android
- SHA-256
- 232892dd36a2d3873d0e6dc47f42fc87faf42a569ec30523dae6ef7a99be0768
- MD5
- 9d43c43d14b6ae676f0985125a3ca916
- SHA-1
- f0b3c1078344f3ba32baebc634e8cd6e026293af
- First seen (VT)
- 4/15/2024, 5:11:04 AM
- Last analysis (VT)
- 4/30/2026, 10:00:26 PM
- First scan (MalwareTips)
- 5/25/2026, 6:36:43 PM
- Last scan (MalwareTips)
- 5/25/2026, 6:36:43 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.