File name:

AdminPanel.apk

Full analysis: https://app.any.run/tasks/f3805e6d-1007-4298-9459-86835ead9500
Verdict: Malicious activity
Analysis date: June 04, 2024, 12:39:38
OS: Ubuntu 22.04.2
MIME: application/zip
File info: Zip archive data, at least v0.0 to extract, compression method=store
MD5:

0F95929770FFFBD893371CF6AE608623

SHA1:

3086389ED5A47978C8CF41992ADC25D772C4D853

SHA256:

925D9992DED887BFC3FA02DC06746C249CC27C008EE03DDBCD82292F4D0CACA4

SSDEEP:

98304:t3tt57aswZL6xHXM79znRWfIgihfiPaB9mj9QOB6FcaGNHRhG+SV4WeaWxEeVReq:/hP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks DMI information (probably VM detection)

      • systemd-hostnamed (PID: 11968)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.apk | Android Package (73.9)
.jar | Java Archive (20.4)
.zip | ZIP compressed archive (5.6)

EXIF

ZIP

ZipRequiredVersion: -
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 1981:01:01 01:01:02
ZipCRC: 0x54866976
ZipCompressedSize: 214
ZipUncompressedSize: 400
ZipFileName: res/animator/linear_indeterminate_line1_head_interpolator.xml
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
217
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sh no specs systemctl no specs systemctl no specs dbus-daemon no specs nautilus no specs systemd-hostnamed no specs

Process information

PID
CMD
Path
Indicators
Parent process
11946/bin/sh -c "runas /user:administrator /tmp/AdminPanel\.apk "/bin/shany-guest-agent
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
11947systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
11948systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
11951/usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only/usr/bin/dbus-daemondbus-daemon
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
11952/usr/bin/nautilus --gapplication-service/usr/bin/nautilusdbus-daemon
User:
user
Integrity Level:
UNKNOWN
11968/lib/systemd/systemd-hostnamed/lib/systemd/systemd-hostnamedsystemd
User:
root
Integrity Level:
UNKNOWN
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
11952nautilus/home/user/.local/share/nautilus/tags/meta.db-wal
MD5:
SHA256:
11952nautilus/home/user/.local/share/nautilus/tags/meta.db-shm
MD5:
SHA256:
11952nautilus/home/user/.local/share/nautilus/tags/.meta.isrunning
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
10
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
195.181.175.16:443
odrs.gnome.org
Datacamp Limited
DE
unknown
470
avahi-daemon
224.0.0.251:5353
unknown
185.125.188.59:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
185.125.188.58:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
185.125.188.54:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
unknown

DNS requests

Domain
IP
Reputation
odrs.gnome.org
  • 195.181.175.16
  • 195.181.170.18
  • 156.146.33.140
  • 156.146.33.137
  • 156.146.33.14
  • 195.181.175.41
  • 212.102.56.178
  • 212.102.56.182
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::10
  • 2a02:6ea0:c700::17
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::22
unknown
api.snapcraft.io
  • 185.125.188.59
  • 185.125.188.55
  • 185.125.188.54
  • 185.125.188.58
unknown
connectivity-check.ubuntu.com
  • 2620:2d:4000:1::96
  • 2620:2d:4002:1::197
  • 2001:67c:1562::24
  • 2001:67c:1562::23
  • 2620:2d:4000:1::22
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::97
  • 2620:2d:4000:1::2b
  • 2620:2d:4000:1::98
  • 2620:2d:4002:1::198
unknown
49.100.168.192.in-addr.arpa
unknown

Threats

No threats detected
No debug info