| File name: | 3272f9ad58c0f5334fe39c1ccaeeef01d4602f8ef7f8f5fe2ab80e966e6c634e.apk |
| Full analysis: | https://app.any.run/tasks/62d5e857-3139-4a72-bfc6-1e2fcc381b15 |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2025, 12:34:33 |
| OS: | Android 14 |
| Tags: | |
| MIME: | application/vnd.android.package-archive |
| File info: | Android package (APK), with APK Signing Block |
| MD5: | 3B66C0037E534D2201E9A562810CB659 |
| SHA1: | 969B166E52BEAF24B008594AACF92E8A73099442 |
| SHA256: | 3272F9AD58C0F5334FE39C1CCAEEEF01D4602F8EF7F8F5FE2AB80E966E6C634E |
| SSDEEP: | 98304:X1x3Hl2djokzEzzAZ92TyCqPJzaD7qzQjlx7TompsZ630ZONaYXg+XnERLJ/qRA9:sg2mjzMZt |
| .apk | | | Android Package (73.9) |
|---|---|---|
| .jar | | | Java Archive (20.4) |
| .zip | | | ZIP compressed archive (5.6) |
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | None |
| ZipModifyDate: | 2024:10:04 17:31:08 |
| ZipCRC: | 0x257e3129 |
| ZipCompressedSize: | 690 |
| ZipUncompressedSize: | 690 |
| ZipFileName: | res/drawable-ldrtl-xhdpi/abc_ic_menu_cut_mtrl_alpha.png |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2272 | glimmer.makeshift.multiple | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2384 | /apex/com.android.art/bin/artd | /apex/com.android.art/bin/artd | — | init |
User: artd Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2388 | /apex/com.android.art/bin/dex2oat32 --zip-fd=6 --zip-location=/data/app/~~UZ0cIhgwuej911wWtd8vmg==/founding.wrecking.sandstorm-s9MgPnM50njpNm5DlYQb1Q==/base.apk --oat-fd=7 --oat-location=/data/app/~~UZ0cIhgwuej911wWtd8vmg==/founding.wrecking.sandstorm-s9MgPnM50njpNm5DlYQb1Q==/oat/arm64/base.odex --output-vdex-fd=8 --swap-fd=9 --class-loader-context=PCL[] --classpath-dir=/data/app/~~UZ0cIhgwuej911wWtd8vmg==/founding.wrecking.sandstorm-s9MgPnM50njpNm5DlYQb1Q== --instruction-set=arm64 --instruction-set-features=default --instruction-set-variant=cortex-a53 --compiler-filter=verify --compilation-reason=install --compact-dex-level=none --max-image-block-size=524288 --resolve-startup-const-strings=true --generate-mini-debug-info --runtime-arg -Xtarget-sdk-version:34 --runtime-arg -Xhidden-api-policy:enabled --runtime-arg -Xms64m --runtime-arg -Xmx512m --comments=app-version-name:1.0,app-version-code:1,art-version:340090000 | /apex/com.android.art/bin/dex2oat32 | — | artd |
User: artd Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2409 | founding.wrecking.sandstorm | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2425 | /system/bin/trigger_perfetto com.android.telemetry.interaction-jank-monitor-7 | /system/bin/trigger_perfetto | — | app_process64 |
User: u0_a81 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2444 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2457 | webview_zygote | /system/bin/app_process32 | — | app_process32 |
User: webview_zygote Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2495 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2578 | com.android.systemui.accessibility.accessibilitymenu | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2611 | /system/bin/trigger_perfetto com.android.telemetry.interaction-jank-monitor-9 | /system/bin/trigger_perfetto | — | app_process64 |
User: u0_a81 Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2272 | app_process64 | /data/data/glimmer.makeshift.multiple/cache/final-signed.apk | compressed | |
MD5:— | SHA256:— | |||
| 2272 | app_process64 | /data/data/glimmer.makeshift.multiple/cache/oat_primary/arm64/base.2272.tmp | binary | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/code_cache/decrypted.dex | binary | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/shared_prefs/SharedFiles.xml | xml | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/shared_prefs/WebViewChromiumPrefs.xml | xml | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/app_webview/Default/Local Storage/leveldb/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/app_webview/Default/Local Storage/leveldb/000001.dbtmp | text | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/app_webview/Default/Local Storage/leveldb/CURRENT | text | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/cache/WebView/Default/HTTP Cache/Code Cache/webui_js/index | binary | |
MD5:— | SHA256:— | |||
| 2409 | app_process64 | /data/data/founding.wrecking.sandstorm/cache/WebView/Default/HTTP Cache/Code Cache/js/index | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 142.250.186.35:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | — | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
2409 | app_process64 | POST | 522 | 104.21.64.1:80 | http://cmsspain.shop/RestApi | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
445 | mdnsd | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 216.239.35.4:123 | time.android.com | — | — | whitelisted |
— | — | 142.250.184.228:443 | www.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.186.35:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 142.251.168.81:443 | staging-remoteprovisioning.sandbox.googleapis.com | GOOGLE | US | whitelisted |
2272 | app_process64 | 149.154.167.220:443 | api.telegram.org | Telegram Messenger Inc | GB | whitelisted |
2409 | app_process64 | 149.154.167.220:443 | api.telegram.org | Telegram Messenger Inc | GB | whitelisted |
2495 | app_process32 | 142.250.185.67:443 | update.googleapis.com | GOOGLE | US | whitelisted |
2444 | app_process32 | 142.250.185.131:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
2495 | app_process32 | 142.250.181.238:443 | dl.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
connectivitycheck.gstatic.com |
| whitelisted |
google.com |
| whitelisted |
time.android.com |
| whitelisted |
staging-remoteprovisioning.sandbox.googleapis.com |
| whitelisted |
api.telegram.org |
| whitelisted |
update.googleapis.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
cmsspain.shop |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Android Device Connectivity Check |
341 | netd | Misc activity | ET HUNTING Telegram API Domain in DNS Lookup |
2272 | app_process64 | Misc activity | ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI) |
2272 | app_process64 | Misc activity | ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI) |
2272 | app_process64 | Misc activity | ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI) |
341 | netd | Misc activity | ET HUNTING Telegram API Domain in DNS Lookup |
2409 | app_process64 | Misc activity | ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI) |