Is Glass Widgets v1.4 (Patched).apk safe?
73 engines report clean on a medium-prevalence Android APK with no malicious detections.
All 73 engines returned clean results with 16 tier-1 engines explicitly marking it harmless. The file shows medium prevalence across 694 sources and only ambient MITRE techniques. No sandbox runtime data is available and the single heuristic note on direct-IP traffic is flagged as inconclusive without host reputation.
9c0f3307454684c5f2…9ad2ec954624d9Recommended next actions
Before installing
Install it only from Google Play, the developer's official store, or another source you independently trust.
If you already installed it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 73 engines returned clean results with 16 tier-1 engines explicitly marking it harmless. The file shows medium prevalence across 694 sources and only ambient MITRE techniques. No sandbox runtime data is available and the single heuristic note on direct-IP traffic is flagged as inconclusive without host reputation.
Zero malicious detections across the entire engine set, including 16 tier-1 engines, provides strong consensus for safety. Medium prevalence with nearly 800 submissions indicates the file is not rare or newly introduced. The absence of sandbox execution means runtime behaviour cannot be confirmed, but the lack of offensive MITRE techniques and the heuristic rule's own caveat about legitimate direct-IP traffic keep the risk low. The missing host-reputation cross-check is noted as a coverage gap rather than a clean result.
What We Detected
73 antivirus engines scanned the APK; none flagged it malicious. 16 tier-1 engines explicitly returned clean verdicts. The file carries tags for obfuscation and embedded ELF code, common in Android apps, but no engine translated those traits into a detection.
Threat Behavior
No sandbox execution occurred, so dynamic behaviour is unknown. Static signals show 13 direct IP contacts without domain names, yet the triggering heuristic itself states this pattern appears in legitimate installers. No dropped children, persistence indicators, or offensive MITRE techniques were recorded.
What To Do Now
The file can be installed if obtained from a trusted source. Keep Android security features and app-permission reviews enabled. If the app requests unusual permissions or exhibits unexpected network activity after installation, remove it and re-scan.
Where this verdict could be wrong1 caveat
- contactedHosts is null so no host-reputation result is available despite 13 contacted IPs being recorded
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/73 engines flagged malicious
- 16 tier-1 engines returned clean
- medium prevalence across 694 sources
- contactedHosts cross-check not completed despite 13 recorded IPs
The evidence supports treating the APK as safe for use from trusted sources; continue monitoring permissions and network behaviour after installation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 73 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Partial13 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Glass Widgets v1.4 (Patched).apk
9c0f3307454684c5f2208b86b0985d49ff86866d1ad11290d29ad2ec954624d9
01Uploaded file
Network
Hosts contacted
- Contacted hostObserved
172.67.151.52
Contact observed during runtime.
02Isolated runtime analysis - Contacted hostObserved
142.251.154.119
Contact observed during runtime.
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
3 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 73engines flagged
- 694sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 73 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at - 03
The hash has been submitted 787 times from 694 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Glass Widgets v1.4 (Patched).apk — 9c0f3307454684c5f2208b86b0985d49ff86866d1ad11290d29ad2ec954624d9
ProvenanceObservedSourceUploaded fileObserved at - 05
Contacted host: 172.67.151.52 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Contacted host: 142.251.154.119 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence172.67.151.52 · 142.251.154.119 · 104.16.160.145
0 of 73 engines flagged this file
View all 73 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Glass Widgets v1.4 (Patched).apk
- Format
- Android
- Code signing
- Not applicable to this file type
- Size
- 18.3 MB
- Last analyzed
- Aug 4, 2026, 12:07 PM UTC
9c0f3307454684c5f2208b86b0985d49ff86866d1ad11290d29ad2ec954624d9Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Install it only from Google Play, the developer's official store, or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Glass Widgets v1.4 (Patched).apk safe?
What is Glass Widgets v1.4 (Patched).apk?
How many antivirus engines detected Glass Widgets v1.4 (Patched).apk?
What is the SHA-256 hash of Glass Widgets v1.4 (Patched).apk?
Is it safe to install Glass Widgets v1.4 (Patched).apk?
How up to date is this analysis of Glass Widgets v1.4 (Patched).apk?
Community
Member reviews and reports for this exact file hash.