URL:

gog6.com

Full analysis: https://app.any.run/tasks/3f1997e2-030d-4a67-9082-57d5911c7a44
Verdict: Malicious activity
Analysis date: September 28, 2025, 03:53:52
OS: Android 14
Tags:
phishing
Indicators:
MD5:

CD95A9C72FCF7EEF7462102ADB6DE8B1

SHA1:

FAE0E2C12D97D22DE2902DC43689EB2DEC53EDFF

SHA256:

12C06C7099697FAA9726A15592CCCA3F542A5A41BCC39F5073F6371101E2BDC2

SSDEEP:

3:+I:+I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • app_process64 (PID: 2758)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
44
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #PHISHING app_process64 app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs dmesgd no specs toybox no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs app_process64 no specs

Process information

PID
CMD
Path
Indicators
Parent process
2758org.chromium.chrome /system/bin/app_process64
app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2811org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2832org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
2850<pre-initialized> /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2869<pre-initialized> /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2935com.android.providers.partnerbookmarks /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2961org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
3035org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
3054org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
3073org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
22
Suspicious files
315
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3035app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.0Rxthi/list.pbbinary
MD5:
SHA256:
3035app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.0Rxthi/manifest.jsonbinary
MD5:
SHA256:
3035app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.0Rxthi/LICENSEtext
MD5:
SHA256:
3035app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.0Rxthi/_metadata/verified_contents.jsontext
MD5:
SHA256:
3035app_process64/data/data/org.chromium.chrome/app_chrome/component_crx_cache/cab4d1f0a6a2a1afecae808a520f6690dd2b9d58bf54762877f2dc9715d55461binary
MD5:
SHA256:
3054app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.KEdphs/privacy-sandbox-attestations.datbinary
MD5:
SHA256:
3054app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.KEdphs/manifest.jsonbinary
MD5:
SHA256:
3054app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.KEdphs/_metadata/verified_contents.jsontext
MD5:
SHA256:
3054app_process64/data/data/org.chromium.chrome/app_chrome/component_crx_cache/38c89b12bb20a8f2751c9c7cd2e31c173a47af08c115e1ecccc2f5151a2cf2c6binary
MD5:
SHA256:
3092app_process64/data/data/org.chromium.chrome/cache/.org.chromium.Chromium.Vfe3ds/manifest.jsonbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
136
DNS requests
191
Threats
253

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
204
142.250.186.164:80
http://www.google.com/gen_204
unknown
whitelisted
2758
app_process64
GET
200
142.250.184.206:80
http://clients2.google.com/time/1/current?cup2key=9:K5B0a-GWMjW2rcpPMmHazEr9R4nxj_HsYQcdSEw_0DM&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
2758
app_process64
GET
302
142.250.186.115:80
http://www.gog6.com/
unknown
unknown
2758
app_process64
GET
301
216.239.32.21:80
http://gog6.com/
unknown
whitelisted
2758
app_process64
GET
301
142.250.186.115:80
http://www.gog6.com/?m=1
unknown
unknown
831
app_process64
GET
204
216.58.206.35:80
http://connectivitycheck.gstatic.com/generate_204
unknown
whitelisted
2758
app_process64
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/obedbbhbpmojnkanicioggnmelmoomoc/427c3b0e1922e377fd0a67afb3421a260db016bdf67354de23c8892914805b58
unknown
whitelisted
2758
app_process64
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
unknown
whitelisted
2758
app_process64
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acpeapixpwuzscfa5h5j5m7c4xaa_2025.6.16.0/niikhdgajlphfehepabhhblakbdgeefj_2025.06.16.00_all_acgsomx5qtwgffxcrxwhoksfom7q.crx3
unknown
whitelisted
2758
app_process64
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjhkYWYwZDctOTExOS00MGQ5LTgyNjAtN2FlY2ZjMDg0NmNj/1.0.0.17_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
446
mdnsd
224.0.0.251:5353
whitelisted
142.250.186.164:80
www.google.com
GOOGLE
US
whitelisted
142.250.186.164:443
www.google.com
GOOGLE
US
whitelisted
216.58.206.35:80
connectivitycheck.gstatic.com
GOOGLE
US
whitelisted
2758
app_process64
142.250.184.206:80
clients2.google.com
GOOGLE
US
whitelisted
2758
app_process64
142.250.186.164:443
www.google.com
whitelisted
574
app_process64
216.239.35.4:123
time.android.com
whitelisted
2758
app_process64
216.239.32.21:80
gog6.com
GOOGLE
US
whitelisted
2758
app_process64
142.250.102.84:443
accounts.google.com
GOOGLE
US
whitelisted
2758
app_process64
142.250.186.115:80
www.gog6.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.google.com
  • 142.250.186.164
  • 142.250.186.36
  • 142.250.186.132
  • 172.217.17.132
whitelisted
google.com
  • 142.250.186.174
whitelisted
clients2.google.com
  • 142.250.184.206
whitelisted
gog6.com
  • 216.239.32.21
  • 216.239.34.21
  • 216.239.38.21
  • 216.239.36.21
unknown
accounts.google.com
  • 142.250.102.84
  • 142.251.31.84
whitelisted
www.gog6.com
  • 142.250.186.115
  • 142.250.185.243
unknown
time.android.com
  • 216.239.35.4
  • 216.239.35.8
  • 216.239.35.12
  • 216.239.35.0
unknown
fonts.googleapis.com
  • 142.250.184.234
whitelisted
de.tynt.com
  • 67.202.105.34
whitelisted
fontlibrary.org
  • 45.56.91.11
unknown

Threats

PID
Process
Class
Message
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
2758
app_process64
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info