20251112-v8.09.9-medianetTv-release.apk

6.87 MB

Analyzed: 2026-03-02 21:01 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
94/100
Threat scan clean Modern target SDK
Privacy Permissions & network
91/100
High-risk permissions HTTP URLs found Possible tracking Low data access
92/100
Excellent
Overall trust

Facts

Threat scan 0/76 flagged, 0 suspicious
Permissions 14 requested
Network strings 34 URLs (7 HTTP, 27 HTTPS)
Target SDK 35
Certificate Valid until 2034-12-17 (9 years, suspicious)

Warnings

Found 7 HTTP URL strings (unencrypted).
High-risk permissions detected: android.permission.SYSTEM_ALERT_WINDOW, android.permission.RECEIVE_BOOT_COMPLETED
Possible analytics/tracking domains found: app-measurement.com, firebase-settings.crashlytics.com, pagead2.googlesyndication.com
Package Name mv.medianet.app.androidtv
Version Code 8000909
Version Name 8.09.9
Application Name com.smartivus.tvbox.TVBoxApplication
Debuggable No
Allow Backup No
Min SDK Android 24 (Nougat)
Target SDK Android 35 (Android 15)
Supported ABIs
Universal

Certificate & Signer

Valid From 2024-12-19 09:20:38
Valid To 2034-12-17 09:20:38
Serial Number bbd89bb67b835de1
Thumbprint 0f9f0cb90b1380c5ce326810fb923541647671fd
Issuer: C MV
Issuer: CN MedianetAndroidApp
Issuer: DN C:MV, CN:MedianetAndroidApp, L:Male, O:Medianet, ST:Unknown, OU:Smartivus
Issuer: L Male
Issuer: O Medianet
Issuer: OU Smartivus
Issuer: ST Unknown
Subject: C MV
Subject: CN MedianetAndroidApp
Subject: DN C:MV, CN:MedianetAndroidApp, L:Male, O:Medianet, ST:Unknown, OU:Smartivus
Subject: L Male
Subject: O Medianet
Subject: OU Smartivus
Subject: ST Unknown

Security Scan

0 /76
✓ Clean
Scanned by 76 security vendors
Last scan: 2026-03-02 21:01 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
66
Timeout
0
Failure
1

Scan Providers

76 vendors
ALYac undetected
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.754
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.29.1.10604
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260302-02
Avira undetected
No result reported
Engine 8.3.3.24
Baidu undetected
No result reported
Engine 1.0.0.2
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav failure
No result reported
Engine 2.0.0.1
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV undetected
No result reported
Engine 1.5.1.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet undetected
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.251
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.43713AVA:64.30759
Google undetected
No result reported
Engine 1772481702
Gridinsoft undetected
No result reported
Engine 1.0.239.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.39.58754
K7GW undetected
No result reported
Engine 14.39.58754
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.211
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14023
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26010.1
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.5.3.1
Skyhigh undetected
No result reported
Engine v2021.2.0+4045
Sophos undetected
No result reported
Engine 3.3.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-03-02.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.10.0
TrellixENS undetected
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.5.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT undetected
No result reported
Engine 9.5.1156
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38455
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5555
ZoneAlarm undetected
No result reported
Engine 6.23-113518561
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 31e254f:31e254f:7fbf6b0:7fbf6b0
tehtris type-unsupported
No result reported

File Signatures

SHA-256 f9efe3707f20907befe0f6f34a4ada5f4330b85afb793b0007f35916b36115a7
MD5 3d38f1cd254b5b160c542885fd626598
SHA-1 f5530de572209d33ce8f5a1ab6238392b116c7d0
SSDEEP 98304:D0OtjdZsIpFsuzeDT3Hlqh0JHyUKE8dpdX4bl8zmUeZoG2hlb22aNcGxrlDw5Y:1tjDsERwTB8EgX4J8zaZoG2hc2a5wu
TLSH T1E07601D3FB2C982FD9BB09738DAB523137764D158692AB0725443A2C6D732884F9DBC4
VHASH fe14b1f2c1732ba17f21ec70a5d36ea7
PERMHASH 1af6c9551bff1e4a15a6849acdb020d341bcc4df7bb370daad612a11df3a5ee7

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (50%), VYM Mind Map (23.1%), Sweet Home 3D Design (generic) (19.4%), ZIP compressed archive (7.4%) TrID file type guesses with probabilities.
dhash 0000001e1c1d1408 Perceptual hash used to compare visual similarity of files.
raw md5 dff082aa066ca15861c5cb892328b7d7 Raw MD5 hash of the file contents.
extensions xml (474), png (378), version (85), properties (20), kotlin_builtins (8), ttf (8), webp (6), txt (5), proto (3), dex (2), ogg (2), bin (1), CoroutineExceptionHandler (1), gz (1), MainDispatcherFactory (1), prof (1), profm (1), textproto (1) File extensions found inside the APK and how many of each.
file types XML (474), PNG (378), unknown (145), OGG (2), Java Bytecode (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 2248 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 9.7 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (4)

com.smartivus.tvbox.MainActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.DEFAULT android.intent.category.MONKEY
com.smartivus.tvbox.MainActivityTv
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.DEFAULT android.intent.category.MONKEY
com.smartivus.tvbox.StartupActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
Categories
android.intent.category.LAUNCHER android.intent.category.LEANBACK_LAUNCHER android.intent.category.DEFAULT android.intent.category.MONKEY
com.smartivus.tvbox.launcher.settings.SettingsActivity
Categories
android.intent.category.DEFAULT

Service Intents (2)

Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
com.smartivus.tvbox.core.FcmService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (9)

Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
Actions
Install performance profile Installs a profile that helps optimize app performance. androidx.profileinstaller.action.INSTALL_PROFILE
Skip profile install Skips profile installation for this build. androidx.profileinstaller.action.SKIP_FILE
Save performance profile Saves a profile generated during app usage. androidx.profileinstaller.action.SAVE_PROFILE
Benchmark operation Runs a profile installer benchmark operation. androidx.profileinstaller.action.BENCHMARK_OPERATION
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
Actions
Power Connected Broadcast Action: External power has been connected to the device. android.intent.action.ACTION_POWER_CONNECTED
android.intent.action.ACTION_POWER_DISCONNECTED android.intent.action.ACTION_POWER_DISCONNECTED
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
Actions
Battery Okay Broadcast Action: Indicates the battery is now okay after being low. android.intent.action.BATTERY_OKAY
Battery Low Broadcast Action: Indicates low battery condition on the device. android.intent.action.BATTERY_LOW
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Actions
android.net.conn.CONNECTIVITY_CHANGE android.net.conn.CONNECTIVITY_CHANGE
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
Actions
Device Storage Low Broadcast Action: A sticky broadcast that indicates low memory android.intent.action.DEVICE_STORAGE_LOW
Device Storage Ok Broadcast Action: Indicates low memory condition on the device no longer exists android.intent.action.DEVICE_STORAGE_OK
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
Actions
androidx.work.impl.background.systemalarm.UpdateProxies androidx.work.impl.background.systemalarm.UpdateProxies
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
Actions
Boot Completed Broadcast Action: This is broadcast once, after the system has finished android.intent.action.BOOT_COMPLETED
Time Changed Broadcast Action: The time was set. android.intent.action.TIME_SET
Timezone Changed Broadcast Action: The timezone has changed. android.intent.action.TIMEZONE_CHANGED
androidx.work.impl.diagnostics.DiagnosticsReceiver
Actions
androidx.work.diagnostics.REQUEST_DIAGNOSTICS androidx.work.diagnostics.REQUEST_DIAGNOSTICS
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE

Requested Permissions (14)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
This app can appear on top of other apps This app can appear on top of other apps or other parts of the screen. This may interfere with normal app usage and change the way that other apps appear. android.permission.SYSTEM_ALERT_WINDOW
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
android.permission.SCHEDULE_EXACT_ALARM Custom app or vendor permission (not publicly documented). android.permission.SCHEDULE_EXACT_ALARM
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
AdServices Attribution Required to call AdServices Attribution APIs. android.permission.ACCESS_ADSERVICES_ATTRIBUTION
AdServices Advertising ID Required to call AdServices Advertising ID APIs. android.permission.ACCESS_ADSERVICES_AD_ID
run at startup Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the tablet and allow the app to slow down the overall tablet by always running. android.permission.RECEIVE_BOOT_COMPLETED
Foreground service Allows the app to run a foreground service. android.permission.FOREGROUND_SERVICE
Dynamic receiver access Internal app permission used to protect dynamic broadcast receivers. mv.medianet.app.androidtv.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Uses Features (4)

Faketouch Feature for {@link #getSystemAvailableFeatures} and android.hardware.faketouch
Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Wifi Feature for {@link #getSystemAvailableFeatures} and android.hardware.wifi
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (5)

com.smartivus.tvbox.StartupActivity
com.smartivus.tvbox.MainActivity
com.smartivus.tvbox.MainActivityTv
com.smartivus.tvbox.launcher.settings.SettingsActivity
com.google.android.gms.common.api.GoogleApiActivity

Services (13)

com.smartivus.tvbox.core.FcmService
androidx.appcompat.app.AppLocalesMetadataHolderService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
com.google.firebase.sessions.SessionLifecycleService
androidx.work.impl.background.systemalarm.SystemAlarmService
androidx.work.impl.background.systemjob.SystemJobService
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService

Broadcast Receivers (13)

com.smartivus.tvbox.core.CoreApplication$NotificationAlarmReceiver com.smartivus.tvbox.core.CoreApplication$NotificationAlarmReceiver
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
Work rescheduler Reschedules background work after reboot or app update. androidx.work.impl.background.systemalarm.RescheduleReceiver
androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
androidx.work.impl.diagnostics.DiagnosticsReceiver androidx.work.impl.diagnostics.DiagnosticsReceiver
Profile installer Installs performance profiles to speed up app startup and hot paths. androidx.profileinstaller.ProfileInstallReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver

Content Providers (3)

com.google.firebase.provider.FirebaseInitProvider
androidx.startup.InitializationProvider
com.squareup.picasso.PicassoProvider

URL Endpoints (41)

http://api-ott.medianet.mv/generate_204 http://dashif.org/guidelines/last-segment-number http://dashif.org/guidelines/thumbnail_tile http://dashif.org/guidelines/trickmode http://dashif.org/thumbnail_tile http://g.co/dev/packagevisibility http://hb.medianet.mv/ http://schemas.microsoft.com/DRM/2007/03/protocols/AcquireLicense https://aomedia.org/emsg/ID3 https://api-ott.medianet.mv https://api-ott.medianet.mv/ https://app-measurement.com/a https://default.url https://developer.android.com/guide/topics/media/issues/cleartext-not-permitted https://developer.android.com/guide/topics/media/issues/player-accessed-on-wrong-thread https://developer.android.com/training/articles/direct-boot https://developer.apple.com/streaming/emsg-id3 https://firebase-settings.crashlytics.com/spi/v2/platforms/android/gmp/ https://firebase.google.com/docs/crashlytics/get-started?platform=android#add-plugin https://firebase.google.com/support/guides/disable-analytics

Submission Details

Submitted At 2026-03-02
First Submission 2026-03-02
Last Submission 2026-03-02
Stored Until 2026-04-01