| URL: | https://site.golesyapro.site/?utm_source=tiktok&utm_medium=paid&utm_id=1850859175001234&utm_campaign=GOLESYA%2003%20TESTE&ttclid=E_C_P_CoACygtuirO90kgTONszyYGQ7nGTwxTWWp7c4I4ANt4yAQ2JXZh5FW-lu3Z4NSJ5tZ79hbKcOB5E3xEoLeKzXY2LABBtpVHU35XDMRLSIwvHL3_mgKTnLkClpdGx2KAuxOFKBrY1-yN6ieYAYvZsOmHmbPPIt91WRF8eAf_n0dtYT2-5QYp4HUDS6isl57uvST5ZPk2xjUsjkLlwVdH82ebS8h8m4nDxB7-BifqX2O0f3LGpB_wNxgrI8bVvU1Y93a1FKh4dbEEohCMTe8lmi-LYLeYDjq3zqVmLkhWxfs5pSDDiTSU0yEEujt4Dtvpm5Hm5mCdlOBksAsLLWkC2sLpPNxIEdjIuMA |
| Full analysis: | https://app.any.run/tasks/85cb27be-2073-4f9c-9cd8-5a3b8a1d8550 |
| Verdict: | Malicious activity |
| Threats: | BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks. |
| Analysis date: | December 14, 2025, 17:33:23 |
| OS: | Android 14 |
| Tags: | |
| Indicators: | |
| MD5: | 029CACD8A82EEB931D7228997E650C25 |
| SHA1: | FA675CE516E1106C171654EA9041B188614BC648 |
| SHA256: | C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1 |
| SSDEEP: | 12:2klA5imaQtg+62W0FvCPWBDsNr7WilwTCaI+9oI8wTLj:2klOqW+2xFxBDs5Wilm1I+9V8wXj |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 347 | /system/bin/netd | /system/bin/netd | init | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 3962 | org.chromium.chrome | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4014 | org.chromium.chrome_zygote | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4025 | org.chromium.chrome_zygote | /system/bin/app_process64 | — | app_process64 |
User: u0_a72 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4053 | com.android.traceur | /system/bin/app_process64 | — | app_process64 |
User: u0_a54 Integrity Level: UNKNOWN Exit code: 512 | ||||
| 4065 | org.chromium.chrome:privileged_process0 | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4067 | com.android.adservices.api | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4139 | org.chromium.chrome_zygote | /system/bin/app_process64 | — | app_process64 |
User: u0_a72 Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4164 | com.android.providers.partnerbookmarks | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 4216 | /system/bin/dmesgd | /system/bin/dmesgd | — | init |
User: dmesgd Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4378 | app_process64 | /data/user/0/ggg.ggg/cache/oat_primary/arm64/base.4378.tmp | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/no_backup/androidx.work.workdb-journal | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/shared_prefs/com.mobitech.scanner.xml | xml | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/no_backup/androidx.work.workdb-wal | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/app_webview/last-exit-info | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/shared_prefs/WebViewChromiumPrefs.xml | xml | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/app_webview/Default/Web Data-journal | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/app_webview/Default/Shared Dictionary/cache/index | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/app_webview/Default/Shared Dictionary/cache/index-dir/temp-index | binary | |
MD5:— | SHA256:— | |||
| 4475 | app_process64 | /data/data/com.mobitech.scanner/app_webview/Default/Local Storage/leveldb/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3962 | app_process64 | GET | 302 | 104.26.2.143:443 | https://cdn.tailwindcss.com/ | US | — | — | whitelisted |
1921 | app_process64 | GET | 204 | 142.250.185.196:443 | https://www.google.com/generate_204 | US | — | — | whitelisted |
3962 | app_process64 | GET | 200 | 147.93.37.231:443 | https://site.golesyapro.site/?utm_source=tiktok | CY | html | 1.59 Kb | unknown |
1921 | app_process64 | GET | 204 | 142.250.186.163:80 | http://connectivitycheck.gstatic.com/generate_204 | US | — | — | whitelisted |
3962 | app_process64 | GET | 200 | 216.58.206.78:80 | http://clients2.google.com/time/1/current?cup2key=9:lnfHnTvcKeU8wDdwB2NX4Ra52e8v_l1ij4Yn7h04F9I&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 104 b | whitelisted |
— | — | GET | 204 | 142.250.185.196:80 | http://www.google.com/gen_204 | US | — | — | whitelisted |
3962 | app_process64 | GET | 200 | 147.93.37.231:443 | https://site.golesyapro.site/play.png | CY | image | 115 Kb | unknown |
2931 | app_process64 | POST | 200 | 142.250.27.129:443 | https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetchEekChain | US | binary | 778 b | whitelisted |
3962 | app_process64 | POST | 204 | 216.239.34.36:443 | https://region1.google-analytics.com/g/collect?v=2&tid=G-C13E58ST8H>m=45je5ca1v9230051551za200zd9230051551&_p=1765733623292&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&cid=389190920.1765733623&ul=en-us&sr=1024x576&uaa=&uab=&uafvl=Chromium%3B137.0.7122.0%7CNot%252FA)Brand%3B24.0.0.0&uamb=1&uam=V50_ThinQ&uap=Android&uapv=14.0.0&uaw=0&are=1&frm=0&pscdl=&_s=1&tag_exp=103116026~103200004~104527907~104528500~104684208~104684211~105391252~115583767~115938465~115938468~116184927~116184929~116217636~116217638~116251938~116251940~116744866&sid=1765733623&sct=1&seg=0&dl=https%3A%2F%2Fgolesyapro.site%2F&dr=https%3A%2F%2Fsite.golesyapro.site%2F&dt=Golesya%20Pro%20-%20App%20de%20Resultados%20de%20F%C3%BAtbol%20%7C%20Descarga%20APK&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1025 | US | — | — | whitelisted |
3962 | app_process64 | GET | 200 | 104.26.2.143:443 | https://cdn.tailwindcss.com/3.4.17 | US | binary | 128 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
452 | mdnsd | 224.0.0.251:5353 | — | — | — | whitelisted |
— | — | 142.250.185.196:80 | www.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.186.163:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 142.250.185.196:443 | www.google.com | GOOGLE | US | whitelisted |
3962 | app_process64 | 216.58.206.78:80 | clients2.google.com | GOOGLE | US | whitelisted |
3962 | app_process64 | 147.93.37.231:443 | site.golesyapro.site | AS-HOSTINGER | CY | unknown |
3962 | app_process64 | 142.250.185.196:443 | www.google.com | GOOGLE | US | whitelisted |
3962 | app_process64 | 64.233.167.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
3962 | app_process64 | 104.26.2.143:443 | cdn.tailwindcss.com | CLOUDFLARENET | US | whitelisted |
1921 | app_process64 | 142.250.186.163:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.google.com |
| whitelisted |
clients2.google.com |
| whitelisted |
site.golesyapro.site |
| unknown |
accounts.google.com |
| whitelisted |
cdn.tailwindcss.com |
| whitelisted |
connectivitycheck.gstatic.com |
| whitelisted |
time.android.com |
| whitelisted |
staging-remoteprovisioning.sandbox.googleapis.com |
| whitelisted |
golesyapro.site |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1921 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
3962 | app_process64 | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
3962 | app_process64 | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
347 | netd | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com) |
4475 | app_process64 | Device Retrieving External IP Address Detected | ET INFO External IP Check (checkip .amazonaws .com) |
4475 | app_process64 | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |
4475 | app_process64 | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |
4475 | app_process64 | Device Retrieving External IP Address Detected | SUSPICIOUS [ANY.RUN] An IP address was received from the server as a result of an HTTP request |
347 | netd | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
347 | netd | Not Suspicious Traffic | INFO [ANY.RUN] An application monitoring request to sentry .io |