Safe
Anime streaming app with zero tier-1 detections; heuristic C2 flag reflects benign CDN contact, not malware.
742fdbacce5fe71f7d…17bf2eb98fThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean engine profile: zero malicious detections across 67 reporting engines, with 17 tier-1 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, and others) all reporting no threat. The DirectIpC2 heuristic rule fired because the sample contacted external IPs without DNS queries; however, analysis of those IPs reveals they are Cloudflare (1.1.1.1), GitHub CDN (185.199.x.x), and Google services (74.125.x.x, 173.194.x.x, 64.233.x.x, 209.85.x.x) — standard infrastructure for content delivery. The contacted URL (animekai.to login page) and file prevalence (common_old, 168 submissions) confirm this is a known streaming application. No malicious sandbox verdicts, no dropped malicious children, and no contacted hosts in our malicious cache further support a benign classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=0; 17 tier-1 engines (Avast, Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Ikarus, F-Secure, Emsisoft, GData, Avira, AVG, DrWeb) all silent
engines.malicious=0/67; no named malware family consensus; onlyLowTrustFlagging=false
Contacted IPs include 1.1.1.1 (Cloudflare), 185.199.x.x (GitHub CDN), 74.125.x.x and 173.194.x.x (Google services) — legitimate CDN/cloud infrastructure, not malicious C2
prevalence.classification=common_old (158 submitters, 168 submissions over 341 days); no external-intel hits (CIRCL, YARAify, MalwareBazaar all negative)
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired but evidence shows benign streaming-app service contact, not C2 exfiltration
- Zero malicious detections across 67 antivirus engines
- 17 tier-1 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, GData, Ikarus, F-Secure, DrWeb, Avast, AVG) all report clean
- Contacted IPs are legitimate CDN and cloud services (Cloudflare, Google, GitHub)
- Common-old prevalence (168 submissions, 158 sources) indicates known, widely-distributed application
- No malicious sandbox verdicts, no dropped malicious children, no malicious host contact
This file is safe to use. The heuristic C2 alert reflects benign streaming-app behaviour (CDN contact) rather than malware activity. Standard Android app permission review is recommended as with any application.
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence1.1.1.1 · 185.199.108.133 · 185.199.111.133
0 detections across 76 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- AnimeTV.apk
- Size
- 6.01 MB
- MIME type
- (unknown)
- Detected type
- Android
- SHA-256
- 742fdbacce5fe71f7d9f828168df04d661002db0bf6148d571281517bf2eb98f
- MD5
- d362da27b5fe9471e68d1a7550eb2cef
- SHA-1
- da92e5bea93757eedd658d8a4b4476d569a13db8
- First seen (VT)
- 7/12/2025, 12:54:47 PM
- Last analysis (VT)
- 3/1/2026, 2:59:57 AM
- First scan (MalwareTips)
- 6/18/2026, 4:39:59 PM
- Last scan (MalwareTips)
- 6/18/2026, 4:39:59 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.