The salt used during string obfuscation changes every compilation. The output is completely different each time.
Multiple attempts to compile slightly modified modules did not bring any improvement.
Even an apk file without obfuscation received a false positive.
A review of older versions in the Playstore revealed something interesting.
An apk file from October 2022 was downloaded from the Playstore and scanned with Virustotal - everything OK.
All other versions available in the Playstore (apk and aab files) from November 2022 onwards give a false positive.
Now I need to find out what was changed in the period October - November 2002 (within the app or on Google side).
I will now disable some libraries individually to further narrow down the problem.
Library1 = ah_checkinternet
Library2 = ajwebkit
Library3 = aspopupmenu
Library4 = b4xencryption
Library5 = b4xpreferencesdialog
Library6 = bctextengine
Library7 = bctoast
Library8 = byteconverter
Library9 = convertimage
Library10 = core
Library11 = dateutils
Library12 = encryption
Library13 = firebaseanalytics
Library14 = firebasenotifications
Library15 = googleplaybilling
Library16 = ime
Library17 = json
Library18 = network
Library19 = phone
Library20 = randomaccessfile
Library21 = reflection
Library22 = runtimepermissions
Library23 = sql
Library24 = ss_aesencryption
Library25 = tabstripviewpager
Library26 = touchimageview
Library27 = viewsex
Library28 = webviewxtended
Library29 = xcustomlistview
Library30 = xui
Library31 = xui views