Is Aldiko+Classic_3.1.3_APKPure.apk safe?
No engine detections, no malicious children, and no complete contacted-host reputation result was available contacts after 2807 days of medium prevalence.
Zero of 72 engines flagged the APK. Sandbox analysis found no malicious behaviour, dropped children are clean, and contacted hosts show no malicious reputation. The single heuristic note on direct-IP traffic is explicitly non-diagnostic without corroboration.
b43f1107342580600d…23df13071f9df1Recommended next actions
Before installing
Install it only from Google Play, the developer's official store, or another source you independently trust.
If you already installed it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Zero of 72 engines flagged the APK. Sandbox analysis found no malicious behaviour, dropped children are clean, and contacted hosts show no malicious reputation. The single heuristic note on direct-IP traffic is explicitly non-diagnostic without corroboration.
The file has been submitted 58 times over nearly eight years with no malicious labels from any engine tier. Contacted-no complete contacted-host reputation result was available results. The only heuristic trigger notes that direct-IP traffic can be legitimate and requires additional evidence before any C2 conclusion. No external-intel hits or similar-hash matches contradict the clean record.
What We Detected
72 engines scanned the Aldiko Classic 3.1.3 APK; none returned malicious or suspicious verdicts. Behaviour telemetry recorded two direct-IP contacts and several analytics endpoints, but contacted-host reputation cross-check found zero malicious or suspicious entries. Three dropped children were inspected and none carried malicious verdicts.
Threat Behavior
No sandbox execution occurred, so runtime behaviour is inferred from static and network evidence only. The single heuristic rule that fired (DirectIpC2) explicitly cautions that direct-IP traffic occurs in legitimate installers and must be correlated with host reputation before any malicious interpretation. No MITRE offensive techniques, persistence indicators, or brand-mismatch signals were present.
What To Do Now
The sample shows the profile of a long-standing, widely distributed e-book reader. Keep Android security features enabled and obtain apps from official stores when possible; this instance carries no indicators that would justify altering those protections.
- Zero malicious detections across 72 engines
- Medium prevalence over 2807 days with clean history
- No malicious dropped children or host contacts
The evidence supports treating the file as safe for normal use; continue relying on Android's built-in security controls.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 72 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Partial4 of 6 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Aldiko+Classic_3.1.3_APKPure.apk
b43f1107342580600dc318259e4f9eaa4ca76a7141ada13ae123df13071f9df1
01Uploaded file
Files
Created or changed
- Written fileObserved
com.aldiko.classic-1.apk.classes-1573713886.zip
/data/data/com.aldiko.classic/code_cache/secondary-dexes/com.aldiko.classic-1.apk.classes-1573713886.zip
02Isolated runtime analysis - Written fileObserved
multidex.version.xml
/data/data/com.aldiko.classic/shared_prefs/multidex.version.xml
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
213.133.127.178
Contact observed during runtime.
04Isolated runtime analysis - Contacted hostObserved
77.238.180.12
Contact observed during runtime.
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- 902bcb550403557780cb…a34353Never scannednever seen before
- 17132f23ea0257fa5ff8…6c5957Never scannednever seen before
- acc476794f2cb09e0e36…a39e46Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 72engines flagged
- 54sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 72 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at - 03
The hash has been submitted 58 times from 54 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Aldiko+Classic_3.1.3_APKPure.apk — b43f1107342580600dc318259e4f9eaa4ca76a7141ada13ae123df13071f9df1
ProvenanceObservedSourceUploaded fileObserved at - 05
File written: com.aldiko.classic-1.apk.classes-1573713886.zip — /data/data/com.aldiko.classic/code_cache/secondary-dexes/com.aldiko.classic-1.apk.classes-1573713886.zip
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: multidex.version.xml — /data/data/com.aldiko.classic/shared_prefs/multidex.version.xml
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 213.133.127.178 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 77.238.180.12 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence213.133.127.178 · 77.238.180.12
0 of 72 engines flagged this file
View all 72 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Aldiko+Classic_3.1.3_APKPure.apk
- Format
- Android
- Code signing
- Not applicable to this file type
- Size
- 16.4 MB
- Last analyzed
- Aug 6, 2026, 8:34 AM UTC
b43f1107342580600dc318259e4f9eaa4ca76a7141ada13ae123df13071f9df1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Install it only from Google Play, the developer's official store, or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Aldiko+Classic_3.1.3_APKPure.apk safe?
What is Aldiko+Classic_3.1.3_APKPure.apk?
How many antivirus engines detected Aldiko+Classic_3.1.3_APKPure.apk?
What is the SHA-256 hash of Aldiko+Classic_3.1.3_APKPure.apk?
Is it safe to install Aldiko+Classic_3.1.3_APKPure.apk?
How up to date is this analysis of Aldiko+Classic_3.1.3_APKPure.apk?
Community
Member reviews and reports for this exact file hash.