Malware vendors usually use these services to test their load. They wouldn't release anything that would get detected on day 0. And I think antivirus vendors do more in-house analysis only if there are reasons to - such as votes from users, or other AVs detecting the sample.