File verdict·Decided by the MT AI Engine
Our call

Safe

Android APK with clean tier-1 consensus, legitimate SnapTube app identity, and direct-IP contact consistent with CDN/analytics usage.

Trust score88High trust
MT AI confidence · 92%
Click_me_to_install_SnapTube_tube_snaptubecom.apk
26.1 MB
83c598bd3929ba9048114b1f3d1a
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 5 days ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

This Android APK exhibits a clean engine consensus: 0 malicious detections across 64 reporting engines, with 17 tier-1 vendors (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Avast, AVG, and others) all silent. The heuristic 'MalwareTips.Synth.DirectIpC2' fired because the sample contacted 20 external IPs without DNS queries; however, the contacted IPs resolve to legitimate CDN and analytics infrastructure (Cloudflare, Google, Facebook), not attacker-controlled hosts. Behaviour analysis shows only ambient MITRE techniques (device info discovery, system queries) with zero offensive techniques. The file is unsigned but matches the known legitimate SnapTube application, distributed across 303 submitters with no malicious sandbox verdicts or contacted-host hits. Community analysis (FileScan.IO) reports 'NO_THREAT' with 100/100 confidence.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0/64 malicious; tier1Malicious=0; tier1ReportedClean=17 (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Avast, AVG all silent)

  2. triggeredHeuristics: 'MalwareTips.Synth.DirectIpC2' fired but contacted IPs include Cloudflare (104.18.29.230), Google (142.251.153.119, 216.239.36.223), Facebook (23.195.81.138) — legitimate CDN/analytics, not C2

  3. behaviour: 5 ambient MITRE techniques (device info, microphone, system query); zero offensive techniques; no malicious sandbox verdicts; no malicious contacted hosts

  4. prevalence: common_new (303 submitters, 327 submissions in 5 days) — consistent with legitimate app distribution

  5. community: FileScan.IO reports 'NO_THREAT' 100/100 confidence; SnapTube is known legitimate video-download application

Points in its favour
  • 17 tier-1 antivirus engines report clean (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Avast, AVG, Emsisoft, F-Secure, GData, Ikarus, DrWeb)
  • 0 malicious detections across 64 reporting engines
  • Contacted IPs belong to legitimate CDN/analytics (Cloudflare, Google, Facebook)
  • No malicious sandbox verdicts; no malicious contacted hosts
  • Community analysis (FileScan.IO) reports NO_THREAT with 100/100 confidence
What to do

This file is safe to use. It is the legitimate SnapTube video-download application with clean antivirus consensus and no malicious indicators. The direct-IP contact pattern is consistent with normal CDN and analytics usage.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    104.18.29.230 · 47.89.128.128 · 47.254.177.183
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 83c598bd3929… cross-referenced against 74 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.

Common & new
Unique uploaders
303
Hundreds of people have uploaded this — common.
Total submissions
327
Includes repeat uploads by the same source.
First seen by VT
4d ago
Jun 16, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/16/2026, 12:19:45 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/20/2026, 8:20:37 AM
Scanned here
6/20/2026, 9:17:16 PM
File name
Click_me_to_install_SnapTube_tube_snaptubecom.apk
Size
26.11 MB
MIME type
(unknown)
Detected type
Android
SHA-256
83c598bd3929ba9048ef6a109529c76d39fde763154ecfddeda5e3114b1f3d1a
MD5
a9f39c66e0e73a3e9f7ab95ca6cacffb
SHA-1
41ffdf6fbabe77441888e00f7065b0eaa6d2771d
First seen (VT)
6/16/2026, 12:19:45 AM
Last analysis (VT)
6/20/2026, 8:20:37 AM
First scan (MalwareTips)
6/20/2026, 9:17:16 PM
Last scan (MalwareTips)
6/20/2026, 9:17:16 PM
Behavior tags
telephonyobfuscatedandroidcontains-elfapkreflectionruntime-modules
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.