| File name: | Smart Launcher Premium v6.6 build 020 Mod.apk |
| Full analysis: | https://app.any.run/tasks/fa7492d1-be0b-4780-92d6-f5c52797b87d |
| Verdict: | Malicious activity |
| Analysis date: | April 05, 2025, 04:01:13 |
| OS: | Android 14 |
| Tags: | |
| MIME: | application/vnd.android.package-archive |
| File info: | Android package (APK), with classes.dex |
| MD5: | 8AA25F7F82602FDB4538505B032C0E35 |
| SHA1: | EE3CE698B2DE80DEEBE8D02D91C774D33F2F3FD6 |
| SHA256: | 76A698A8A0B4EFA5622BE97C81C28222B0957BFF4EA6A3E2AB98565E58BB01C1 |
| SSDEEP: | 196608:SQEf/Gov5eKi5dffavXeQ4ysp0t//Hxtl:5Ef1525ZWpo2//rl |
| .apk | | | Android Package (73.9) |
|---|---|---|
| .jar | | | Java Archive (20.4) |
| .zip | | | ZIP compressed archive (5.6) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2025:04:02 15:50:40 |
| ZipCRC: | 0x050c07ff |
| ZipCompressedSize: | 10810 |
| ZipUncompressedSize: | 58656 |
| ZipFileName: | AndroidManifest.xml |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2233 | ginlemon.flowerfree | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 11 | ||||
| 2371 | crash_dump64 2296 2370 4 | /apex/com.android.runtime/bin/crash_dump64 | — | app_process64 |
User: u0_a108 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2372 | crash_dump64 2296 2370 4 | /apex/com.android.runtime/bin/crash_dump64 | — | crash_dump64 |
User: u0_a108 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2373 | ginlemon.flowerfree | /system/bin/app_process64 | — | app_process64 |
User: u0_a108 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2374 | ginlemon.flowerfree | /system/bin/app_process64 | — | app_process64 |
User: u0_a108 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2379 | ginlemon.flowerfree | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2574 | com.android.dialer | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2706 | /system/bin/dumpsys telecom EmergencyDiagnostics | /system/bin/dumpsys | — | app_process64 |
User: radio Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2978 | com.android.deskclock | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/shared_prefs/com.google.firebase.crashlytics.xml | xml | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/files/.com.google.firebase.crashlytics.files.v2:ginlemon.flowerfree/open-sessions/67F0AB2403BB000108B915129DF2D3AF/report | binary | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/shared_prefs/FirebaseHeartBeatW0RFRkFVTFRd+MTo3NDIwMTYxMDcyOTc6YW5kcm9pZDo0NmI3ZDY5NjgwOTk3YzJh.xml | xml | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/shared_prefs/com.google.firebase.messaging.xml | xml | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/files/frc_1:742016107297:android:46b7d69680997c2a_firebase_defaults.json | binary | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/shared_prefs/frc_1:742016107297:android:46b7d69680997c2a_firebase_settings.xml | xml | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/files/PersistedInstallation3618211230460403358tmp | binary | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/databases/ginlemon.flower.db-journal | binary | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/files/PersistedInstallation.W0RFRkFVTFRd+MTo3NDIwMTYxMDcyOTc6YW5kcm9pZDo0NmI3ZDY5NjgwOTk3YzJh.json | binary | |
MD5:— | SHA256:— | |||
| 2233 | app_process64 | /data/data/ginlemon.flowerfree/shared_prefs/ginlemon.flowerfree.xml | xml | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 142.250.184.227:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
449 | mdnsd | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 216.239.35.0:123 | time.android.com | — | — | whitelisted |
— | — | 142.250.186.68:443 | www.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.184.227:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 142.251.18.81:443 | staging-remoteprovisioning.sandbox.googleapis.com | GOOGLE | US | whitelisted |
1773 | app_process64 | 188.166.201.8:443 | applink.smartlauncher.net | DIGITALOCEAN-ASN | NL | unknown |
2233 | app_process64 | 216.58.206.42:443 | firebaseinstallations.googleapis.com | GOOGLE | US | whitelisted |
2233 | app_process64 | 172.67.25.94:443 | pastebin.com | CLOUDFLARENET | US | whitelisted |
2233 | app_process64 | 142.250.186.106:443 | firebaseinstallations.googleapis.com | GOOGLE | US | whitelisted |
2379 | app_process64 | 172.67.25.94:443 | pastebin.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
connectivitycheck.gstatic.com |
| whitelisted |
time.android.com |
| whitelisted |
google.com |
| whitelisted |
staging-remoteprovisioning.sandbox.googleapis.com |
| whitelisted |
applink.smartlauncher.net |
| unknown |
firebaseinstallations.googleapis.com |
| whitelisted |
pastebin.com |
| whitelisted |
firebaseremoteconfig.googleapis.com |
| whitelisted |
spi |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Android Device Connectivity Check |
342 | netd | Not Suspicious Traffic | INFO [ANY.RUN] Online Pastebin Text Storage |