nicevpn-2.9.3.apk

78.10 MB

Analyzed: 2026-02-12 12:48 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
91/100
Threat scan clean Modern target SDK
Privacy Permissions & network
92/100
High-risk permissions HTTP URLs found AllowBackup enabled Low data access
91/100
Excellent
Overall trust

Facts

Threat scan 0/75 flagged, 0 suspicious
Permissions 14 requested
Network strings 9 URLs (4 HTTP, 5 HTTPS)
Target SDK 35
Certificate Valid until 2049-03-17 (23 years, suspicious)

Warnings

Found 4 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.REQUEST_INSTALL_PACKAGES, android.permission.QUERY_ALL_PACKAGES, android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, android.permission.RECEIVE_BOOT_COMPLETED
AllowBackup is enabled.
Package Name com.marshal.vpn
Version Code 11
Version Name 2.9.3
Application Name com.marshal.vpn.MyVPNApplication
Debuggable No
Allow Backup Yes
Min SDK Android 24 (Nougat)
Target SDK Android 35 (Android 15)
Supported ABIs
arm64-v8a armeabi-v7a x86 x86_64

Certificate & Signer

Valid From 2024-03-23 15:27:47
Valid To 2049-03-17 15:27:47
Serial Number 1
Thumbprint f31bd6694f1360288686537d22a0029253a1c8dd
Issuer: C IR
Issuer: CN marshal cz
Issuer: DN C:IR, CN:marshal cz, L:tehran, ST:kamranie
Issuer: L tehran
Issuer: ST kamranie
Subject: C IR
Subject: CN marshal cz
Subject: DN C:IR, CN:marshal cz, L:tehran, ST:kamranie
Subject: L tehran
Subject: ST kamranie

Security Scan

0 /75
✓ Clean
Scanned by 75 security vendors
Last scan: 2025-12-17 17:30 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
65
Timeout
0
Failure
1

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.726
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.29.1.10604
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 251217-00
Avira undetected
No result reported
Engine 8.3.3.24
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav failure
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.1.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.72.9030
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.241
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.42904AVA:64.30342
Google undetected
No result reported
Engine 1765983651
Gridinsoft undetected
No result reported
Engine 1.0.231.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.23.58015
K7GW undetected
No result reported
Engine 14.24.57988
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.185
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.10275
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.25110.1
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.4.1.3
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.3.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2025-12-17.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.7.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.0
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1107
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38272
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5507
ZoneAlarm undetected
No result reported
Engine 6.21-110947197
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine c3db73c:c3db73c:5924d3c:5924d3c
tehtris type-unsupported
No result reported

File Signatures

SHA-256 97f1b37a1be4af8ff6b26be1b771288a1776581b6427055a4e5813cc937c778b
MD5 b17ea842ecaa4de7287d05e58e0d9457
SHA-1 a68156afb83d52a0f8abc454f233b7c5bae87258
SSDEEP 1572864:uSLX4DRfZeWE4uC1rEs9dVf7aWvJXODfvpM5qDPvXGkjhPdw4g24ChJQ:u8cZeWE09jTxxezvpM5qrGkK
TLSH T12408339AF3549C2FCA3725764DA64172671A8C52CA03A763B05C372C2AB71DC4F8EBD4
VHASH 309b83a50dafa0281b9314e7166226c4
PERMHASH fae059da678a031c55555588a25da4d772b244015008860c4f236c037003e0a7

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (50%), VYM Mind Map (23.1%), Sweet Home 3D Design (generic) (19.4%), ZIP compressed archive (7.4%) TrID file type guesses with probabilities.
dhash 0000101e1e0d1410 Perceptual hash used to compare visual similarity of files.
raw md5 37b9aca859b5783c70a146ec53f69964 Raw MD5 hash of the file contents.
extensions xml (547), png (327), version (57), so (42), kotlin_builtins (7), webp (7), dat (2), properties (2), bin (1), dex (1), gz (1), jpg (1), json (1), prof (1), profm (1), ttf (1) File extensions found inside the APK and how many of each.
file types XML (547), PNG (327), unknown (81), ELF (42), Java Bytecode (1), JPG (1), JSON (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 1317 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 203 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

com.marshal.vpn.SplashScreenActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER

Service Intents (5)

app.openconnect.core.OpenVpnService
Actions
android.net.VpnService android.net.VpnService
com.marshal.vpn.VpnKillerService
Actions
android.net.VpnService android.net.VpnService
com.marshal.vpn.mapproto.MapVpnService
Actions
android.net.VpnService android.net.VpnService
de.blinkt.openvpn.core.OpenVPNService
Actions
android.net.VpnService android.net.VpnService
dev.dev7.lib.v2ray.services.V2rayVPNService
Actions
android.net.VpnService android.net.VpnService

Receiver Intents (1)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION

Native Libraries (16)

libconscrypt_jni libconscrypt_jni.so
libgojni libgojni.so
libjbcrypto libjbcrypto.so
libmarshchecker libmarshchecker.so
libmyssl2 libmyssl2.so
libnopie_openvpn libnopie_openvpn.so
libopenconnect libopenconnect.so
libopenvpn libopenvpn.so
libopvpnutil libopvpnutil.so
libosslspeedtest libosslspeedtest.so
libosslutil libosslutil.so
libovpnexec libovpnexec.so
libovpnutil libovpnutil.so
libpie_openvpn libpie_openvpn.so
libstoken libstoken.so
libtun2socks libtun2socks.so

Requested Permissions (14)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
read the contents of your shared storage Allows the app to read the contents of your shared storage. android.permission.READ_EXTERNAL_STORAGE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_SPECIAL_USE Custom app or vendor permission (not publicly documented). android.permission.FOREGROUND_SERVICE_SPECIAL_USE
android.permission.QUERY_ALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.QUERY_ALL_PACKAGES
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
android.permission.REQUEST_INSTALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.REQUEST_INSTALL_PACKAGES
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Custom app or vendor permission (not publicly documented). android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
close other apps Allows the app to end background processes of other apps. This may cause other apps to stop running. android.permission.KILL_BACKGROUND_PROCESSES
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. com.marshal.vpn.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (11)

com.marshal.vpn.updater.UpdateActivity
com.marshal.vpn.ChooseServer
com.marshal.vpn.ChooseService
com.marshal.vpn.perApp.PerAppActivity
com.marshal.vpn.LoginActivity
com.marshal.vpn.SplashScreenActivity
com.marshal.vpn.MainActivity
app.openconnect.api.GrantPermissionsActivity
de.blinkt.openvpn.LaunchVPN
de.blinkt.openvpn.api.GrantPermissionsActivity
de.blinkt.openvpn.activities.DisconnectVPN

Services (7)

com.marshal.vpn.mapproto.MapVpnService
app.openconnect.core.OpenVpnService
de.blinkt.openvpn.core.OpenVPNService
de.blinkt.openvpn.core.keepVPNAlive
dev.dev7.lib.v2ray.services.V2rayVPNService
com.marshal.vpn.AccountChecker
com.marshal.vpn.VpnKillerService

Broadcast Receivers (1)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver

Content Providers (2)

androidx.core.content.FileProvider
androidx.startup.InitializationProvider

Submission Details

Submitted At 2026-02-12
First Submission 2026-02-12
Last Submission 2026-02-12
Stored Until 2026-03-14