Hello Bitdefender Team,
I'm an independent Android developer, and one of my applications is being detected as Android.Riskware.Repack.rPNRO by BitDefenderFalx on VirusTotal.
The APK is signed with my own release keystore and is built directly from my source code. It is also published on Google Play and is currently under review for the Samsung Galaxy Store.
VirusTotal reports that only BitDefenderFalx detects the APK as Android.Riskware.Repack.rPNRO, while the other antivirus engines do not report it as malicious.
Could you please help me understand:
- What exactly triggers the Android.Riskware.Repack.rPNRO detection?
- Is this a heuristic/ML detection or does it indicate that the APK appears to be repackaged?
- Are there common coding patterns, libraries, or APK characteristics that can cause this detection?
- Is there anything I can change in my build process to avoid this detection?
- If this is a false positive, what is the recommended process for having the detection reviewed and removed?
I'm happy to provide the VirusTotal report, APK, SHA-256 hash, or any additional information needed for your analysis.
Thank you for your assistance.