Safe
Android APK with zero malicious engine detections; tier-1 engines silent; direct-IP contact is routine for Android apps reaching legitimate CDN infrastructure.
aa2609eb3e098ae78e…8bcd8e1639The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
This Android APK exhibits a clean engine profile: zero malicious detections, zero tier-1 consensus on any family, and 16 tier-1 engines reporting no threat. The heuristic 'MalwareTips.Synth.DirectIpC2' fired because the sample contacted 20 external IPs without DNS queries; however, this pattern is routine for Android apps communicating with CDN and service providers (Google, GitHub, Cloudflare). The contacted IPs are public infrastructure, not hidden C2 endpoints. Behaviour analysis shows 6 ambient MITRE techniques (system info discovery, encrypted channels, obfuscated files) with zero offensive techniques, no malicious sandbox verdicts, and no malicious dropped children. The file is unsigned but carries no brand mismatch or adversarial filename flags. Obfuscation and reflection are standard Android app protection techniques. Medium prevalence (45 submissions) with no malicious verdicts across the ecosystem supports a benign classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/64 malicious; tier1Malicious=0; tier1ReportedClean=16 (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Avast, AVG, DrWeb, Ikarus all silent)
triggeredHeuristics: 'MalwareTips.Synth.DirectIpC2' fired but contacted IPs are Google (142.251.157.119, 173.194.194.94, 216.239.32.223), GitHub (140.82.114.6), Cloudflare (172.67.151.52) — legitimate CDN/service endpoints, not C2
behaviour: 0 offensive MITRE techniques; 6 ambient (T1071, T1406, T1421, T1422, T1426, T1573); no malicious sandbox verdicts; 2 dropped children both unknown/clean; no malicious contacted hosts
file: unsigned Android APK, 35 days old, medium prevalence (45 submissions), no external intel hits (CIRCL, MalwareBazaar, YARAify negative), no brand mismatch, no adversarial filename flags
tags 'obfuscated' and 'reflection' are standard Android app protection patterns, not malware indicators
- Zero malicious detections across 64 reporting engines
- 16 tier-1 vendors (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Avast, AVG, DrWeb, Ikarus) all silent
- Contacted IPs are public infrastructure (Google, GitHub, Cloudflare), not hidden C2 servers
- Zero offensive MITRE techniques; 6 ambient techniques consistent with benign app behaviour
- No malicious sandbox verdicts, no malicious dropped children, no malicious contacted hosts
This file is consistent with a benign Android application. No security action is required. Standard Android security practices (install from trusted sources, review app permissions) are sufficient.
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- f6a9c4cdc6931083299a…b8bfd5Never scannednever seen before
- e601797de9d98f6c3247…82155bNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence142.251.157.119 · 192.178.212.95 · 173.194.194.94
0 detections across 73 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- StreamVault-1.0.11.apk
- Size
- 15.90 MB
- MIME type
- (unknown)
- Detected type
- Android
- SHA-256
- aa2609eb3e098ae78e07c7954f379e82884a9e5ff063d00bde443b8bcd8e1639
- MD5
- 89335f8305392d34f39a2830360e83e4
- SHA-1
- c4ce81294df631472f05774fba81bae89383aa16
- First seen (VT)
- 5/14/2026, 11:44:43 PM
- Last analysis (VT)
- 6/17/2026, 7:06:26 AM
- First scan (MalwareTips)
- 6/18/2026, 5:52:40 PM
- Last scan (MalwareTips)
- 6/18/2026, 5:52:40 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.