Safe
Android APK with zero malicious detections across 65 engines; contacted hosts are legitimate Google/Cloudflare infrastructure; benign Firebase analytics behaviour.
392e5f1315c3d52b36…1b805ebbc0The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean engine consensus: 16 tier-1 engines (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData) all report it undetected, with zero malicious detections across 65 total engines. Behaviour analysis shows only ambient Android runtime techniques (network communication, GPS queries, telephony checks) — no offensive MITRE techniques. The triggered heuristic citing direct-IP C2 contact is a false positive: the contacted IPs belong to Google (142.251.111.94, 108.177.121.*) and Cloudflare (104.21.93.139, 172.67.*), and the contacted URL is Firebase Crashlytics, a standard Google analytics service. The file is 602 days old with common_old prevalence (243 submitters, 272 submissions), consistent with a legitimate Android application. No external intelligence (CIRCL, MalwareBazaar, YARA) corroborates any threat.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/65 malicious; tier1Malicious=0; tier1ReportedClean=16 (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData all undetected)
behaviour: 10 ambient MITRE techniques (T1071, T1095, T1406, T1426, T1430 — network, GPS, telephony queries); zero offensive techniques; zero malicious sandbox verdicts
contacted IPs: 15 direct IPs to Google (142.251.111.94, 108.177.121.*), Cloudflare (104.21.93.139, 172.67.*), Fastly (54.230.18.109) — all legitimate CDN; contacted URL is Firebase Crashlytics analytics endpoint
prevalence: common_old (243 submitters, 272 submissions over 602 days) — consistent with legitimate Android app
external intel: no CIRCL hit, no MalwareBazaar hit, no YARA rules; community comment tags generic Android capabilities, not malware families
- 16 tier-1 antivirus engines report clean (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData)
- Zero malicious detections across 65 total engines
- Contacted hosts are legitimate Google and Cloudflare CDN infrastructure
- Contacted URL is Firebase Crashlytics, a standard Google analytics service
- Common_old prevalence (243 submitters, 272 submissions) consistent with legitimate app
This file is safe to use. It is a legitimate Android application using Firebase analytics. No malware or suspicious behaviour was detected by our antivirus network or sandbox analysis.
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence142.251.111.94 · 104.21.93.139 · 104.17.111.223
0 detections across 75 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Anilab2-1.0.5.apk
- Size
- 3.63 MB
- MIME type
- (unknown)
- Detected type
- Android
- SHA-256
- 392e5f1315c3d52b367434912e46118665f245ad9d7e28c07bebff1b805ebbc0
- MD5
- 7e965af9bddff3f74c72b6f08c4f51b4
- SHA-1
- f1999a00900b2fdc00bc1c7bbeab4e7cebc020d8
- First seen (VT)
- 10/18/2024, 5:41:11 PM
- Last analysis (VT)
- 6/4/2026, 2:07:55 PM
- First scan (MalwareTips)
- 6/12/2026, 7:28:44 AM
- Last scan (MalwareTips)
- 6/12/2026, 7:28:44 AM
- Community reputation
- -12flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.