| File name: | 4d66b097cc900cde8ab5d22f3ab915f5879c6ea2eef9f85196ddff149315eefe.apk |
| Full analysis: | https://app.any.run/tasks/e2778e03-768a-4c5d-a640-127358ed8d5d |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2025, 21:37:40 |
| OS: | Android 14 |
| Tags: | |
| MIME: | application/vnd.android.package-archive |
| File info: | Android package (APK), with zipflinger virtual entry, with APK Signing Block |
| MD5: | A9E6073A72646397E7EF4A5B72F46469 |
| SHA1: | 2137572751419D58A31EF5B3C02426A99F9A3F17 |
| SHA256: | 4D66B097CC900CDE8AB5D22F3AB915F5879C6EA2EEF9F85196DDFF149315EEFE |
| SSDEEP: | 98304:dLWjKK8da0PPM+I3Gl3+k4gSGjOUsZyo5wrYIu0r8tduXlUSNuo2TQbv6X1X5BOJ:jwHsXoPU |
| .apk | | | Android Package (73.9) |
|---|---|---|
| .jar | | | Java Archive (20.4) |
| .zip | | | ZIP compressed archive (5.6) |
| ZipRequiredVersion: | - |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1981:01:01 01:01:02 |
| ZipCRC: | 0x3c63078e |
| ZipCompressedSize: | 187 |
| ZipUncompressedSize: | 316 |
| ZipFileName: | res/interpolator/btn_checkbox_checked_mtrl_animation_interpolator_0.xml |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2274 | zygote64 | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2315 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2331 | webview_zygote | /system/bin/app_process32 | — | app_process32 |
User: webview_zygote Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2365 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2547 | org.chromium.webview_shell | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2579 | webview_zygote | /system/bin/app_process32 | — | app_process32 |
User: webview_zygote Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2274 | app_process64 | /data/data/com.bhumiit.total/databases/androidx.work.workdb-journal | binary | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/databases/androidx.work.workdb-wal | binary | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/shared_prefs/com.google.android.gms.measurement.prefs.xml | xml | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/shared_prefs/WebViewChromiumPrefs.xml | xml | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/app_webview/Default/Local Storage/leveldb/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/app_webview/Default/Local Storage/leveldb/000001.dbtmp | text | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/app_webview/Default/Local Storage/leveldb/CURRENT | text | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/cache/WebView/Default/HTTP Cache/Code Cache/webui_js/index | binary | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/cache/WebView/Default/HTTP Cache/Code Cache/js/index | binary | |
MD5:— | SHA256:— | |||
| 2274 | app_process64 | /data/data/com.bhumiit.total/cache/WebView/Default/HTTP Cache/Code Cache/wasm/index | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 172.217.18.3:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
445 | mdnsd | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 216.239.35.8:123 | time.android.com | — | — | whitelisted |
— | — | 172.217.18.4:443 | www.google.com | GOOGLE | US | whitelisted |
— | — | 172.217.18.3:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 64.233.167.81:443 | staging-remoteprovisioning.sandbox.googleapis.com | GOOGLE | US | whitelisted |
2365 | app_process32 | 142.250.184.227:443 | update.googleapis.com | GOOGLE | US | whitelisted |
2365 | app_process32 | 142.250.185.206:443 | dl.google.com | GOOGLE | US | whitelisted |
2274 | app_process64 | 142.250.186.130:443 | googleads.g.doubleclick.net | GOOGLE | US | whitelisted |
2315 | app_process32 | 142.250.185.67:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
2274 | app_process64 | 142.250.185.106:443 | fonts.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
connectivitycheck.gstatic.com |
| whitelisted |
time.android.com |
| whitelisted |
staging-remoteprovisioning.sandbox.googleapis.com |
| whitelisted |
google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
dl.google.com |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Android Device Connectivity Check |