Real adware threat or FP?

See: http://urlquery.net/report.php?id=1498661548984
Re: https://www.virustotal.com/pl/url/69000c819e7980bdac8e31494acad51b33879fd51b0d2dc27a23afaa02d471ae/analysis/1498663825/
and subsequently: https://www.virustotal.com/pl/file/ed02e736a3fa5eededc97087a9dfcb094e2a25b8cad806cc32d8479fa1f819fc/analysis/1491771978/
LINODE abuse? Benign? → https://urlscan.io/result/8a5c85af-42de-4f98-94d9-4c9eb37dc7a7#summary
Document NaNx compressed. Nothing between head and body in the DOM. Android.Manifest.xml file.

Downloaded avast flags: https://www.virustotal.com/pl/file/ed02e736a3fa5eededc97087a9dfcb094e2a25b8cad806cc32d8479fa1f819fc/analysis/1498665689/

polonus