MaxVPN icon

maxvpn-2.4.0.apk

MaxVPN

67.55 MB

Analyzed: 2026-05-22 19:02 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
81/100
Threat scan flagged
Privacy Permissions & network
95/100
High-risk permissions HTTP URLs found Low data access
87/100
Good
Overall trust

Facts

Threat scan 1/75 flagged, 0 suspicious
Permissions 19 requested
Network strings 13 URLs (10 HTTP, 3 HTTPS)
Target SDK 31
Certificate Valid until 2048-03-08 (22 years, suspicious)

Warnings

Threat scan flagged: 1/75 scanners marked this file as malicious.
Found 10 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.SYSTEM_ALERT_WINDOW, android.permission.QUERY_ALL_PACKAGES, android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, android.permission.RECEIVE_BOOT_COMPLETED
Package Name max.vpn.org
Version Code 6
Version Name 2.4.0.0
Application Name org.vpn.chita.App
Debuggable No
Allow Backup No
Min SDK Android 23 (Marshmallow)
Target SDK Android 31 (Android 12)
Supported ABIs
arm64-v8a armeabi-v7a

Certificate & Signer

Valid From 2023-03-15 20:21:58
Valid To 2048-03-08 20:21:58
Serial Number 452927db
Thumbprint 9fe3c9a9cf42da9a46a9503419dffd3fadb051c3
Issuer: C US
Issuer: CN Max
Issuer: DN C:US, CN:Max, L:Boston, O:MaxVPN, ST:Boston, OU:MaxVPN
Issuer: L Boston
Issuer: O MaxVPN
Issuer: OU MaxVPN
Issuer: ST Boston
Subject: C US
Subject: CN Max
Subject: DN C:US, CN:Max, L:Boston, O:MaxVPN, ST:Boston, OU:MaxVPN
Subject: L Boston
Subject: O MaxVPN
Subject: OU MaxVPN
Subject: ST Boston

Security Scan

1 /75
⚠️ Threats Detected
Detected by 1 vendor: Kaspersky (not-a-virus:HEUR:Server-Proxy.Linux.PingTunnel.gen)
Scanned by 75 security vendors
Last scan: 2026-04-28 21:18 UTC
Malicious
1
Suspicious
0
Harmless
0
Undetected
65
Timeout
0
Failure
1

Scan Providers

75 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.774
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.0.10666
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260428-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav failure
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic undetected
No result reported
Engine 4.0.258
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44355AVA:64.31133
Google undetected
No result reported
Engine 1777406448
Gridinsoft undetected
No result reported
Engine 1.0.244.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.49.59341
K7GW undetected
No result reported
Engine 14.49.59341
Kaspersky malicious
not-a-virus:HEUR:Server-Proxy.Linux.PingTunnel.gen
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.231
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14532
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne undetected
No result reported
Engine 7.6.2.19
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.4.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-04-23.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.11.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.0
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1196
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38604
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5590
ZoneAlarm undetected
No result reported
Engine 6.24-114820531
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine fccbab7:fccbab7:8a0870e:8a0870e
tehtris type-unsupported
No result reported

File Signatures

SHA-256 6a8c813c9330077f5882a96c295420b289bfbece2920f5de003457f606507ca0
MD5 51384cc45452b18a685e878c6512e99c
SHA-1 2ac5f7b5fcb2eb1e9b6ed94f99fca770d7b484da
SSDEEP 1572864:diIp07oyWeWltgJOrCsSAZc902m0I5O29IqwXcYEaLq3jo:Ij7jW9JrFcFm30gfml
TLSH T103F7338BB74CEA2EC4779133C9660137711B8E156603D6737618B21C29B3ED44B6ABCE
VHASH 93cec71e2ae4e7311057eba79191a3e1
PERMHASH e3ee3e928006d69fce45817d08a699ab06482b25597effd5b24ad2ef65ed6d58

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID SPSS Extension (26.9%), Android Package (24.2%), Opera Widget (12.5%), Java Archive (12.1%), VYM Mind Map (11.2%) TrID file type guesses with probabilities.
dhash 0000001e1e0d0410 Perceptual hash used to compare visual similarity of files.
raw md5 c6b8efcf6e3c09239ee52f1d5c944cd0 Raw MD5 hash of the file contents.
extensions xml (514), png (200), version (64), so (61), properties (35), kotlin_module (29), java (26), html (13), proto (12), kotlin_builtins (7), acl (5), txt (4), json (3), xz (3), arm64-v8a (2), armeabi-v7a (2), dat (2), x86 (2), x86_64 (2), bin (1), CoroutineExceptionHandler (1), dex (1), gz (1), js (1), LIST (1), MainDispatcherFactory (1), MF (1), Provider (1), RSA (1), SF (1) File extensions found inside the APK and how many of each.
file types XML (514), unknown (216), PNG (200), ELF (67), DEX (1), HTML (1), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1980-00-00 00:00:00 Latest timestamp found among files inside the archive.
lowest datetime 1980-00-00 00:00:00 Earliest timestamp found among files inside the archive.
num children 2023 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 161 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (1)

activities.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER

Service Intents (10)

cisco.ciscotype.core.CiscoVpnService
Actions
android.net.VpnService android.net.VpnService
com.github.newShadowsocks.bg.VpnService
Actions
android.net.VpnService android.net.VpnService
com.github.normal.shadow.bg.VpnService
Actions
android.net.VpnService android.net.VpnService
com.github.shadowsocks.bg.VpnService
Actions
android.net.VpnService android.net.VpnService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
com.soheil.plus.SoheilPlusService
Actions
android.net.VpnService android.net.VpnService
de.blinkt.openvpn.core.OpenVPNService
Actions
android.net.VpnService android.net.VpnService
org.strongswan.android.logic.CharonVpnService
Actions
android.net.VpnService android.net.VpnService
servicies.ChitaVPNTileService
Actions
android.service.quicksettings.action.QS_TILE android.service.quicksettings.action.QS_TILE
soheil.gold.GoldService
Actions
android.net.VpnService android.net.VpnService

Receiver Intents (10)

androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
Actions
Power Connected Broadcast Action: External power has been connected to the device. android.intent.action.ACTION_POWER_CONNECTED
android.intent.action.ACTION_POWER_DISCONNECTED android.intent.action.ACTION_POWER_DISCONNECTED
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
Actions
Battery Okay Broadcast Action: Indicates the battery is now okay after being low. android.intent.action.BATTERY_OKAY
Battery Low Broadcast Action: Indicates low battery condition on the device. android.intent.action.BATTERY_LOW
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
Actions
Device Storage Low Broadcast Action: A sticky broadcast that indicates low memory android.intent.action.DEVICE_STORAGE_LOW
Device Storage Ok Broadcast Action: Indicates low memory condition on the device no longer exists android.intent.action.DEVICE_STORAGE_OK
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
Actions
androidx.work.impl.background.systemalarm.UpdateProxies androidx.work.impl.background.systemalarm.UpdateProxies
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
Time Changed Broadcast Action: The time was set. android.intent.action.TIME_SET
Timezone Changed Broadcast Action: The timezone has changed. android.intent.action.TIMEZONE_CHANGED
androidx.work.impl.diagnostics.DiagnosticsReceiver
Actions
androidx.work.diagnostics.REQUEST_DIAGNOSTICS androidx.work.diagnostics.REQUEST_DIAGNOSTICS
broadcasts.NotificationReceiver
Actions
privatify.vpn.open.2x.DISCONNECT_VPN privatify.vpn.open.2x.DISCONNECT_VPN
privatify.vpn.org.CharonVpnService.DISCONNECT privatify.vpn.org.CharonVpnService.DISCONNECT
com.batch.android.BatchPushMessageReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Native Libraries (31)

libChitaSoheil libChitaSoheil.so
libRSSupport libRSSupport.so
libandroidbridge libandroidbridge.so
libbarhopper_v3 libbarhopper_v3.so
libcharon libcharon.so
libchita-ss libchita-ss.so
libcommon-jni libcommon-jni.so
libconscrypt_jni libconscrypt_jni.so
libgojni libgojni.so
libgojnis libgojnis.so
libimcv libimcv.so
libipsec libipsec.so
libjbcrypto libjbcrypto.so
libopenconnect libopenconnect.so
libproxychains4 libproxychains4.so
libredsocks libredsocks.so
librsjni librsjni.so
librsjni_androidx librsjni_androidx.so
libsoheilTala libsoheilTala.so
libsoheilplus libsoheilplus.so
libss-local libss-local.so
libsslocal libsslocal.so
libssr-local libssr-local.so
libstrongswan libstrongswan.so
libterminal libterminal.so
libtnccs libtnccs.so
libtncif libtncif.so
libtpmtss libtpmtss.so
libtun2proxy libtun2proxy.so
libtun2socks libtun2socks.so
libzoe libzoe.so

Requested Permissions (19)

max.vpn.org.SERVICE
have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
change network connectivity Allows the app to change the state of network connectivity. android.permission.CHANGE_NETWORK_STATE
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
android.permission.QUERY_ALL_PACKAGES Custom app or vendor permission (not publicly documented). android.permission.QUERY_ALL_PACKAGES
android.permission.WHITELIST_AUTO_REVOKE_PERMISSIONS Custom app or vendor permission (not publicly documented). android.permission.WHITELIST_AUTO_REVOKE_PERMISSIONS
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
close other apps Allows the app to end background processes of other apps. This may cause other apps to stop running. android.permission.KILL_BACKGROUND_PROCESSES
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Custom app or vendor permission (not publicly documented). android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
retrieve running apps Allows the app to retrieve information about currently and recently running tasks. This may allow the app to discover information about which applications are used on the device. android.permission.GET_TASKS
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
max.vpn.org.batch.permission.INTERNAL_BROADCAST Custom app or vendor permission (not publicly documented). max.vpn.org.batch.permission.INTERNAL_BROADCAST

Activities (6)

activities.MainActivity
com.google.android.gms.common.api.GoogleApiActivity
com.jakewharton.processphoenix.ProcessPhoenix
com.batch.android.MessagingActivity
com.batch.android.BatchActionActivity
com.batch.android.debug.BatchDebugActivity

Services (28)

de.blinkt.openvpn.core.OpenVPNService
de.blinkt.openvpn.core.OpenVPNStatusService
org.strongswan.android.logic.VpnStateService
org.strongswan.android.logic.CharonVpnService
cisco.ciscotype.core.CiscoVpnService
soheil.gold.GoldService
com.github.normal.shadow.bg.VpnService
com.github.newShadowsocks.bg.VpnService
com.github.shadowsocks.bg.VpnService
com.soheil.plus.SoheilPlusService
servicies.ChitaVPNTileService
androidx.work.multiprocess.RemoteWorkManagerService
com.google.firebase.components.ComponentDiscoveryService
androidx.work.impl.background.systemalarm.SystemAlarmService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.batch.android.BatchActionService
com.batch.android.BatchPushService
com.batch.android.BatchPushJobService
com.batch.android.BatchDisplayReceiptJobService
com.batch.android.eventdispatcher.DispatcherDiscoveryService
com.batch.android.push.PushRegistrationDiscoveryService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (14)

broadcasts.NotificationReceiver broadcasts.NotificationReceiver
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
androidx.work.impl.diagnostics.DiagnosticsReceiver androidx.work.impl.diagnostics.DiagnosticsReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
com.batch.android.BatchPushMessageReceiver com.batch.android.BatchPushMessageReceiver
com.batch.android.BatchPushMessageDismissReceiver com.batch.android.BatchPushMessageDismissReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Content Providers (3)

com.google.firebase.perf.provider.FirebasePerfProvider
androidx.startup.InitializationProvider
com.google.firebase.provider.FirebaseInitProvider

Submission Details

Submitted At 2026-05-22
First Submission 2026-05-22
Last Submission 2026-05-22
Stored Until 2026-06-21