File verdict·Decided by the MT AI Engine
Our call

Safe

Android APK with zero malicious engine detections; tier-1 engines silent; direct-IP contact is routine for Android apps reaching legitimate CDN infrastructure.

Trust score88High trust
MT AI confidence · 92%
StreamVault-1.0.11.apk
15.9 MB
aa2609eb3e098ae78e8bcd8e1639
Antivirus engines
0 of 73 flagged
Code signing
Unsigned
Age
First seen 1mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

This Android APK exhibits a clean engine profile: zero malicious detections, zero tier-1 consensus on any family, and 16 tier-1 engines reporting no threat. The heuristic 'MalwareTips.Synth.DirectIpC2' fired because the sample contacted 20 external IPs without DNS queries; however, this pattern is routine for Android apps communicating with CDN and service providers (Google, GitHub, Cloudflare). The contacted IPs are public infrastructure, not hidden C2 endpoints. Behaviour analysis shows 6 ambient MITRE techniques (system info discovery, encrypted channels, obfuscated files) with zero offensive techniques, no malicious sandbox verdicts, and no malicious dropped children. The file is unsigned but carries no brand mismatch or adversarial filename flags. Obfuscation and reflection are standard Android app protection techniques. Medium prevalence (45 submissions) with no malicious verdicts across the ecosystem supports a benign classification.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 0/64 malicious; tier1Malicious=0; tier1ReportedClean=16 (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Avast, AVG, DrWeb, Ikarus all silent)

  2. triggeredHeuristics: 'MalwareTips.Synth.DirectIpC2' fired but contacted IPs are Google (142.251.157.119, 173.194.194.94, 216.239.32.223), GitHub (140.82.114.6), Cloudflare (172.67.151.52) — legitimate CDN/service endpoints, not C2

  3. behaviour: 0 offensive MITRE techniques; 6 ambient (T1071, T1406, T1421, T1422, T1426, T1573); no malicious sandbox verdicts; 2 dropped children both unknown/clean; no malicious contacted hosts

  4. file: unsigned Android APK, 35 days old, medium prevalence (45 submissions), no external intel hits (CIRCL, MalwareBazaar, YARAify negative), no brand mismatch, no adversarial filename flags

  5. tags 'obfuscated' and 'reflection' are standard Android app protection patterns, not malware indicators

Points in its favour
  • Zero malicious detections across 64 reporting engines
  • 16 tier-1 vendors (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Avast, AVG, DrWeb, Ikarus) all silent
  • Contacted IPs are public infrastructure (Google, GitHub, Cloudflare), not hidden C2 servers
  • Zero offensive MITRE techniques; 6 ambient techniques consistent with benign app behaviour
  • No malicious sandbox verdicts, no malicious dropped children, no malicious contacted hosts
What to do

This file is consistent with a benign Android application. No security action is required. Standard Android security practices (install from trusted sources, review app permissions) are sufficient.

Dropped payload

Files this sample writes at runtime

This file drops 2 children at runtime. None are currently flagged malicious in our cache.

2 unseen
  • f6a9c4cdc6931083299ab8bfd5Never scanned
    never seen before
  • e601797de9d98f6c324782155bNever scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    142.251.157.119 · 192.178.212.95 · 173.194.194.94
Antivirus engine breakdown

0 detections across 73 engines

0 malicious0 suspicious73 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust19 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 73 engines report this file as clean.
Hash aa2609eb3e09… cross-referenced against 73 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
41
Moderate upload volume.
Total submissions
45
Includes repeat uploads by the same source.
First seen by VT
1mo ago
May 14, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
5/14/2026, 11:44:43 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/17/2026, 7:06:26 AM
Scanned here
6/18/2026, 5:52:40 PM
File name
StreamVault-1.0.11.apk
Size
15.90 MB
MIME type
(unknown)
Detected type
Android
SHA-256
aa2609eb3e098ae78e07c7954f379e82884a9e5ff063d00bde443b8bcd8e1639
MD5
89335f8305392d34f39a2830360e83e4
SHA-1
c4ce81294df631472f05774fba81bae89383aa16
First seen (VT)
5/14/2026, 11:44:43 PM
Last analysis (VT)
6/17/2026, 7:06:26 AM
First scan (MalwareTips)
6/18/2026, 5:52:40 PM
Last scan (MalwareTips)
6/18/2026, 5:52:40 PM
Behavior tags
apkobfuscatedcontains-elfandroidreflection
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.