Safe
Unsigned Android app with legitimate cloud integration; no tier-1 detections; heuristic C2 flag resolves to benign CDN infrastructure.
29aa89fd3cc4e1c54c…c9078dff50The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero malicious detections across 67 engines, including all major tier-1 vendors (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira). The triggered heuristic 'MalwareTips.Synth.DirectIpC2' flagged direct-IP communication as a C2 indicator, but analysis reveals the contacted IPs belong to Google, Cloudflare, and Facebook — legitimate cloud providers, not attacker infrastructure. The app's behaviour (Firebase config, Google Mobile Services, device reconnaissance) aligns with a typical sports or streaming application. Medium prevalence (1890 submissions) and absence of malicious sandbox verdicts further support benignity. Unsigned APK with obfuscation is standard for third-party Android apps.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/67 malicious; tier1Malicious=0; tier1ReportedClean=16 (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira silent)
triggeredHeuristics 'MalwareTips.Synth.DirectIpC2' fired on direct-IP contact, but IPs resolve to Google (142.251.x.x, 173.194.x.x), Cloudflare (172.67.x.x), Facebook (64.233.x.x) — legitimate CDN, not malicious C2
behaviour: 7 ambient MITRE techniques (T1406, T1409, T1421, T1422, T1424, T1426, T1430 — Android device reconnaissance); zero offensive techniques; Firebase + Google Mobile Services integration
prevalence: medium (1460 submitters, 1890 submissions); no malicious sandbox verdicts, no malicious dropped children, no malicious contacted hosts
unsigned APK with obfuscation and native libraries (ELF) — standard for third-party Android apps; no brand mismatch, no adversarial input flags
- Zero malicious detections from 67 engines; 16 tier-1 vendors silent
- Contacted IPs resolve to Google, Cloudflare, Facebook — legitimate infrastructure
- Firebase + Google Mobile Services integration — standard for legitimate apps
- Medium prevalence (1890 submissions) — widely distributed, not rare/suspicious
- No malicious sandbox verdicts, no dropped malicious children, no malicious host contact
This file is safe. The heuristic C2 alert is a false positive on benign cloud communication. Proceed with normal use.
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 11 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence172.67.151.52 · 142.251.156.119 · 192.178.129.101
0 detections across 74 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- SportzX_v2.5.apk
- Size
- 14.38 MB
- MIME type
- (unknown)
- Detected type
- Android
- SHA-256
- 29aa89fd3cc4e1c54c62796bf232d3803dd8ebc01225162409e732c9078dff50
- MD5
- 8ed2ccb3b306780d0637ed6ee155a749
- SHA-1
- 3c8d92f83c484c84118c32c84283cab7de317443
- First seen (VT)
- 5/13/2026, 10:30:44 AM
- Last analysis (VT)
- 6/17/2026, 6:01:07 PM
- First scan (MalwareTips)
- 6/18/2026, 4:54:47 PM
- Last scan (MalwareTips)
- 6/18/2026, 4:54:47 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.