Is Precise Volume v2.0.0-beta-17 (Paid).apk safe?
Seven of 74 engines flagged this modified Android package, including two tier-1 detections, but inconsistent PUA and thief labels prevent firm family attribution.
Two tier-1 engines detected this APK, and seven of 74 engines raised concerns overall. Most labels describe a modified, signature-altered, or potentially unwanted app, while one names an Android thief; without completed sandbox observation or host-reputation coverage, the stronger claim remains unconfirmed.
9f2e371f5368c3c8b2…943c1f038617cbRecommended next actions
Before installing
Do not install it until the source and publisher can be verified independently.
If you already installed it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from Google Play or the developer's official store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Two tier-1 engines detected this APK, and seven of 74 engines raised concerns overall. Most labels describe a modified, signature-altered, or potentially unwanted app, while one names an Android thief; without completed sandbox observation or host-reputation coverage, the stronger claim remains unconfirmed.
Seven of 74 engines flagged the APK, including two independent tier-1 detections. DrWeb identifies an Android thief, but Ikarus and several other engines describe PUA, riskware, signature modification, or generic application risk, so there is no strong family consensus. No completed sandbox run is available, meaning the listed techniques and network indicators cannot establish malicious runtime behavior. Nine external IP addresses appear in the evidence, but their reputation was not checked or saved, so they cannot be characterized as clean or hostile. Broad historical prevalence and the absence of researcher-rule or known-malware hits reduce confidence in the harshest interpretation, but they do not outweigh the two tier-1 detections enough to justify installation.
What We Detected
Seven of 74 antivirus engines flagged the APK. DrWeb reported Android.Thief.1.origin, while Ikarus reported PUA.AndroidOS.ApkSignatureKiller; Avast-Mobile, BitDefenderFalx, AhnLab-V3, K7GW, and SymantecMobileInsight supplied PUP, riskware, generic trojan, or application-risk labels. This disagreement supports concern about a modified or unwanted package but does not establish one specific malware family.
Threat Behavior
No completed sandbox observation is available because behaviour.sandboxCount=0. Static and extracted evidence lists obfuscation, reflection, seven ambient Android techniques, and nine external IP addresses. The contacted-host reputation check is missing, so no complete conclusion can be drawn about those network destinations. One dropped file was inspected without a confirmed harmful result, although its status remains unknown.
What To Do Now
Avoid installing this paid or modified APK from an unofficial source. Obtain the app through its official store or developer channel, keep mobile protection enabled, and remove the package if it was already installed; review sensitive permissions and account activity if it had access to personal data.
Where this verdict could be wrong4 caveats
- Thirteen tier-1 engines reported no detection, including Microsoft, Kaspersky, ESET-NOD32, BitDefender, and Fortinet.
- Most positive labels describe PUA, riskware, or generic application risk rather than a consistent malware family.
- The file is established rather than newly observed, with 357 sources and 468 submissions.
- MalwareBazaar returned no hit and YARAify returned zero matching rules, although absence of external hits does not prove benignity.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Thirteen tier-1 engines reported no detection
- No strong tier-1 family consensus
- No confirmed malicious dropped child
- 357 sources and 468 historical submissions
- No MalwareBazaar, CIRCL, or YARAify hit
- 7/74 antivirus detections
- Two independent tier-1 detections
- DrWeb thief-family label
- Ikarus signature-killer PUA label
- Obfuscated and reflection-related APK tags
- Nine external IP contacts without completed reputation coverage
Do not sideload this copy; use the official app store or developer release instead. Keep endpoint and mobile protection enabled, and scan or remove the APK if it is already present.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete7 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Partial9 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Precise Volume v2.0.0-beta-17 (Paid).apk
9f2e371f5368c3c8b2494c24a8b76e1730d4201579ff67323f943c1f038617cb
01Uploaded file
Files
Created or changed
- Dropped fileDerived
109f56eb6eba3250c034fce31dc5771c4a273a9fa059326a1405072c62f4e984
No child-file verdict was available.
02Dropped-file analysis
Network
Hosts contacted
- Contacted hostObserved
192.178.129.138
Contact observed during runtime.
03Isolated runtime analysis - Contacted hostObserved
172.217.214.94
Contact observed during runtime.
04Isolated runtime analysis - +1 more recorded observation in Analyst mode
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 109f56eb6eba3250c034…f4e984Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 7 / 74engines flagged
- 357sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
7 of 74 antivirus engines flagged the file, including AhnLab-V3 and Avast-Mobile.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 357 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 468 times from 357 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Precise Volume v2.0.0-beta-17 (Paid).apk — 9f2e371f5368c3c8b2494c24a8b76e1730d4201579ff67323f943c1f038617cb
ProvenanceObservedSourceUploaded fileObserved at - 05
Dropped file: 109f56eb6eba3250c034fce31dc5771c4a273a9fa059326a1405072c62f4e984 — No child-file verdict was available.
ProvenanceDerivedSourceDropped-file analysisObserved at - 06
Contacted host: 192.178.129.138 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 172.217.214.94 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence192.178.129.138 · 172.217.214.94 · 172.67.151.52
7 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Precise Volume v2.0.0-beta-17 (Paid).apk
- Format
- Android
- Code signing
- Not applicable to this file type
- Size
- 16.4 MB
- Last analyzed
- Sep 21, 2026, 3:05 PM UTC
9f2e371f5368c3c8b2494c24a8b76e1730d4201579ff67323f943c1f038617cbSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't install it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this app and use a fresh copy from a trusted source. Get a fresh copy from Google Play or the developer's official store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Precise Volume v2.0.0-beta-17 (Paid).apk safe, or is it malware?
What is Precise Volume v2.0.0-beta-17 (Paid).apk?
How many antivirus engines detected Precise Volume v2.0.0-beta-17 (Paid).apk?
I already downloaded and installed Precise Volume v2.0.0-beta-17 (Paid).apk — what should I do?
How do I remove Precise Volume v2.0.0-beta-17 (Paid).apk?
What kind of malware is Precise Volume v2.0.0-beta-17 (Paid).apk?
What is the SHA-256 hash of Precise Volume v2.0.0-beta-17 (Paid).apk?
How up to date is this analysis of Precise Volume v2.0.0-beta-17 (Paid).apk?
Community
Member reviews and reports for this exact file hash.