Our call: Is copy.apk safe?Safe
Zero tier-1 engine detections across 75 engines; 3,407 submitters; contacted hosts are legitimate Google/Firebase infrastructure.
- 0 of 75 antivirus engines flagged the file.Observed · Antivirus analysis
- The hash has a long, established submission history across 3,407 sources.Derived · Submission history
- No completed runtime observation is available for this file.Derived · Runtime coverage
d0f133e073fc34ddda…2d9f9b97a7Recommended next actions
Before installing
Install it only from Google Play, the developer's official store, or another source you independently trust.
If you already installed it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Partial4 of 24 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
copy.apk
d0f133e073fc34dddad298e7dd6a695d935e0dbd2a627d74a402792d9f9b97a7
01Uploaded file
Files
Created or changed
- Written fileObserved
initialization_marker
/data/user/0/com.maertsno.m/files/.crashlytics.v3/com.maertsno.m/initialization_marker
02Isolated runtime analysis - Written fileObserved
FirebaseHeartBeatW0RFRkFVTFRd+MTo1MjE3MDI5NTk3MjY6YW5kcm9pZDo2NzQwMzQ5YjE0NDIwZDNlZWQ1NDdm.xml
/data/user/0/com.maertsno.m/shared_prefs/FirebaseHeartBeatW0RFRkFVTFRd+MTo1MjE3MDI5NTk3MjY6YW5kcm9pZDo2NzQwMzQ5YjE0NDIwZDNlZWQ1NDdm.xml
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
104.21.88.154
Contact observed during runtime.
04Isolated runtime analysis - Contacted hostObserved
172.67.216.55
Contact observed during runtime.
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 3,407 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at - 04
Scanned file: copy.apk — d0f133e073fc34dddad298e7dd6a695d935e0dbd2a627d74a402792d9f9b97a7
ProvenanceObservedSourceUploaded fileObserved at - 05
File written: initialization_marker — /data/user/0/com.maertsno.m/files/.crashlytics.v3/com.maertsno.m/initialization_marker
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: FirebaseHeartBeatW0RFRkFVTFRd+MTo1MjE3MDI5NTk3MjY6YW5kcm9pZDo2NzQwMzQ5YjE0NDIwZDNlZWQ1NDdm.xml — /data/user/0/com.maertsno.m/shared_prefs/FirebaseHeartBeatW0RFRkFVTFRd+MTo1MjE3MDI5NTk3MjY6YW5kcm9pZDo2NzQwMzQ5YjE0NDIwZDNlZWQ1NDdm.xml
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 104.21.88.154 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 172.67.216.55 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
This Android APK shows no malicious detections from any tier-1 antivirus engine (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Ikarus, DrWeb, Avast, AVG). The file is widely distributed (5,692 submissions, 3,407 unique sources) and established in the ecosystem. Contacted IP addresses resolve to legitimate Google and Firebase services, not attacker infrastructure.
The evidence strongly supports a safe classification. All 17 tier-1 engines report the file as undetected, and no tier-1 consensus on any malware family exists. The heuristic rule 'MalwareTips.Synth.DirectIpC2' fired because the app contacted external IPs without using DNS, but inspection reveals those IPs belong to Google, Cloudflare, and Firebase — standard cloud services used by Android apps for telemetry and remote configuration. The file's prevalence (common_old, 353 days, 5,692 submissions) is inconsistent with novel malware. Behaviour analysis shows only ambient MITRE techniques typical of Android apps (network communication, device info queries, GPS checks, clipboard access) with zero offensive techniques. No malicious sandbox verdicts or malicious dropped children were detected. Community comments are conflicting, with one researcher scoring it 'Clean' and another flagging obfuscation — but the absence of tier-1 consensus and the benign contacted hosts override the obfuscation concern.
What We Detected
This Android APK (copy.apk, 18.5 MB) was submitted 353 days ago and has been analysed by 75 antivirus engines. Zero engines reported malicious or suspicious detections. All 17 tier-1 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Ikarus, DrWeb, Avast, AVG) reported the file as undetected.
Threat Behavior
The file exhibits ambient Android app behaviours: network communication (T1071), device information queries (T1406, T1409, T1421, T1422, T1424, T1426, T1430), GPS checks (T1430), and clipboard access (T1573). A heuristic rule flagged direct-IP contact (20 external IPs, zero domains), but inspection shows these IPs belong to Google (142.251.*, 172.253.*), Cloudflare (172.67.*), and Firebase — standard cloud infrastructure used by Android apps for telemetry and remote configuration. No malicious sandbox verdicts, no malicious dropped children, and no contact with known-malicious hosts were detected.
Prevalence & Context
The file is classified as 'common_old' with 3,407 unique submitters and 5,692 total submissions since June 2025. This wide distribution and established presence in the ecosystem is inconsistent with novel malware. Community researchers provided conflicting assessments: one flagged obfuscation and sensitive permissions; another scored it 'Clean' (20/100). The absence of tier-1 consensus and benign contacted hosts suggest the file is either a legitimate app or a false positive.
What To Do Now
No action is required. The file shows no signs of malware based on tier-1 engine consensus and contacted infrastructure analysis. If you are concerned about the app's permissions or behaviour, review the Android manifest and consider whether the requested permissions (location, clipboard, device identifiers) are appropriate for the app's intended function.
Where this verdict could be wrong4 caveats
- triggeredHeuristics flagged direct-IP C2 pattern (medium severity) — if the IPs were truly attacker-controlled, this would be a strong malicious signal. However, manual inspection of the IP list shows they belong to Google, Cloudflare, and Firebase, which are legitimate services used by Android apps for telemetry and remote config.
- community comment #1 alleges obfuscation, root-access requests, file deletion, and account queries — these are concerning behaviours. However, no tier-1 engine detected malware, and the file's 353-day prevalence suggests it has been widely analysed without consensus malicious verdict.
- file tags 'obfuscated' and 'reflection' could indicate evasion techniques, but they are also common in legitimate Android apps using ProGuard obfuscation and reflection for API compatibility. Without malicious sandbox verdicts or tier-1 consensus, obfuscation alone is insufficient to override the clean engine consensus.
- community comment #3 scores the file 20/100 'Clean', which contradicts comment #1's malicious assessment. The lack of researcher consensus, combined with zero tier-1 detections, suggests the file is either benign or a false positive rather than confirmed malware.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero tier-1 engine detections across 17 high-trust antivirus engines
- Contacted hosts are all legitimate Google, Cloudflare, and Firebase infrastructure
- File is widely distributed (3,407 submitters, 5,692 submissions) with no consensus malicious verdict
- No malicious sandbox verdicts, no malicious dropped children, no offensive MITRE techniques
- Community researcher scored the file 'Clean' (20/100)
- File is obfuscated (ProGuard or similar), which is common in both legitimate and malicious Android apps
- Heuristic rule flagged direct-IP contact pattern, though the IPs resolve to legitimate cloud services
- One community researcher flagged sensitive permissions and obfuscation techniques
This file is safe to use based on tier-1 engine consensus and benign contacted infrastructure. If you have concerns about the app's permissions or behaviour, review the Android manifest and consider whether the requested permissions align with the app's intended function.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 6c8288c4332da47f57c5…1e5938Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence104.21.88.154 · 172.67.216.55 · 172.253.115.94
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- copy.apk
- Format
- Android
- Code signing
- Not applicable to this file type
- Size
- 17.6 MB
- Last analyzed
- Jun 18, 2026, 8:58 PM UTC
d0f133e073fc34dddad298e7dd6a695d935e0dbd2a627d74a402792d9f9b97a7Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
Install it only from Google Play, the developer's official store, or another source you independently trust.
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
Keep your antivirus and Windows updates switched on so you stay protected.