URL:

https://site.golesyapro.site/?utm_source=tiktok&utm_medium=paid&utm_id=1850859175001234&utm_campaign=GOLESYA%2003%20TESTE&ttclid=E_C_P_CoACygtuirO90kgTONszyYGQ7nGTwxTWWp7c4I4ANt4yAQ2JXZh5FW-lu3Z4NSJ5tZ79hbKcOB5E3xEoLeKzXY2LABBtpVHU35XDMRLSIwvHL3_mgKTnLkClpdGx2KAuxOFKBrY1-yN6ieYAYvZsOmHmbPPIt91WRF8eAf_n0dtYT2-5QYp4HUDS6isl57uvST5ZPk2xjUsjkLlwVdH82ebS8h8m4nDxB7-BifqX2O0f3LGpB_wNxgrI8bVvU1Y93a1FKh4dbEEohCMTe8lmi-LYLeYDjq3zqVmLkhWxfs5pSDDiTSU0yEEujt4Dtvpm5Hm5mCdlOBksAsLLWkC2sLpPNxIEdjIuMA

Full analysis: https://app.any.run/tasks/85cb27be-2073-4f9c-9cd8-5a3b8a1d8550
Verdict: Malicious activity
Threats:

BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

Analysis date: December 14, 2025, 17:33:23
OS: Android 14
Tags:
btmob
rat
evasion
websocket
Indicators:
MD5:

029CACD8A82EEB931D7228997E650C25

SHA1:

FA675CE516E1106C171654EA9041B188614BC648

SHA256:

C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1

SSDEEP:

12:2klA5imaQtg+62W0FvCPWBDsNr7WilwTCaI+9oI8wTLj:2klOqW+2xFxBDs5Wilm1I+9V8wXj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Initiates background APK installation

      • app_process64 (PID: 4378)
    • BTMOB has been detected

      • app_process64 (PID: 4475)
    • Checks whether the screen is currently on

      • app_process64 (PID: 4475)
  • SUSPICIOUS

    • Accesses system-level resources

      • app_process64 (PID: 4475)
    • Abuses foreground service for persistence

      • app_process64 (PID: 4475)
    • Retrieves installed applications on device

      • app_process64 (PID: 4475)
    • Retrieves a list of running services

      • app_process64 (PID: 4475)
    • Retrieves Android OS build information

      • app_process64 (PID: 4475)
    • Overlays content on other applications

      • app_process64 (PID: 4475)
    • Checks for external IP

      • netd (PID: 347)
      • app_process64 (PID: 4475)
    • Checks if the device's lock screen is showing

      • app_process64 (PID: 4475)
    • Establishing a connection

      • app_process64 (PID: 4475)
    • Prevents its uninstallation by user

      • app_process64 (PID: 4475)
    • Uses encryption API functions

      • app_process64 (PID: 4475)
    • Updates data in the storage of application settings (SharedPreferences)

      • app_process64 (PID: 4475)
    • Creates a WakeLock to manage power state

      • app_process64 (PID: 4475)
    • Collects data about the device's environment (JVM version)

      • app_process64 (PID: 4475)
    • Acquires a wake lock to keep the device awake

      • app_process64 (PID: 4475)
    • Requests access to accessibility settings

      • app_process64 (PID: 4475)
    • Launches a new activity

      • app_process64 (PID: 4475)
    • Intercepts events for accessibility services

      • app_process64 (PID: 4475)
    • Returns the name of the current network operator

      • app_process64 (PID: 4475)
    • Accesses external device storage files

      • app_process64 (PID: 4475)
    • Starts a service

      • app_process64 (PID: 4475)
    • Connects to unusual port

      • app_process64 (PID: 4475)
    • Leverages accessibility to control apps

      • app_process64 (PID: 4475)
  • INFO

    • Dynamically registers broadcast event listeners

      • app_process64 (PID: 4378)
      • app_process64 (PID: 4475)
    • Stores data using SQLite database

      • app_process64 (PID: 4475)
    • Dynamically inspects or modifies classes, methods, and fields at runtime

      • app_process64 (PID: 4475)
    • Retrieves data from storage of application settings (SharedPreferences)

      • app_process64 (PID: 4475)
    • Listens for changes in sensors

      • app_process64 (PID: 4475)
    • Retrieves the value of a secure system setting

      • app_process64 (PID: 4475)
    • Verifies whether the device is connected to the internet

      • app_process64 (PID: 4475)
    • Gets file name without full path

      • app_process64 (PID: 4475)
    • Retrieves the value of a global system setting

      • app_process64 (PID: 4475)
    • Detects device power status

      • app_process64 (PID: 4475)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
31
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
347/system/bin/netd/system/bin/netd
init
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
3962org.chromium.chrome /system/bin/app_process64
app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
4014org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
4025org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
4053com.android.traceur /system/bin/app_process64app_process64
User:
u0_a54
Integrity Level:
UNKNOWN
Exit code:
512
4065org.chromium.chrome:privileged_process0 /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
4067com.android.adservices.api /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
4139org.chromium.chrome_zygote /system/bin/app_process64app_process64
User:
u0_a72
Integrity Level:
UNKNOWN
Exit code:
0
4164com.android.providers.partnerbookmarks /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
4216/system/bin/dmesgd/system/bin/dmesgdinit
User:
dmesgd
Integrity Level:
UNKNOWN
Exit code:
0
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
1 032
Text files
96
Unknown types
1

Dropped files

PID
Process
Filename
Type
4378app_process64/data/user/0/ggg.ggg/cache/oat_primary/arm64/base.4378.tmpbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/no_backup/androidx.work.workdb-journalbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/shared_prefs/com.mobitech.scanner.xmlxml
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/no_backup/androidx.work.workdb-walbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/app_webview/last-exit-infobinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/shared_prefs/WebViewChromiumPrefs.xmlxml
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/app_webview/Default/Web Data-journalbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/app_webview/Default/Shared Dictionary/cache/indexbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/app_webview/Default/Shared Dictionary/cache/index-dir/temp-indexbinary
MD5:
SHA256:
4475app_process64/data/data/com.mobitech.scanner/app_webview/Default/Local Storage/leveldb/MANIFEST-000001binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
282
TCP/UDP connections
401
DNS requests
232
Threats
32

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3962
app_process64
GET
302
104.26.2.143:443
https://cdn.tailwindcss.com/
US
whitelisted
1921
app_process64
GET
204
142.250.185.196:443
https://www.google.com/generate_204
US
whitelisted
3962
app_process64
GET
200
147.93.37.231:443
https://site.golesyapro.site/?utm_source=tiktok
CY
html
1.59 Kb
unknown
1921
app_process64
GET
204
142.250.186.163:80
http://connectivitycheck.gstatic.com/generate_204
US
whitelisted
3962
app_process64
GET
200
216.58.206.78:80
http://clients2.google.com/time/1/current?cup2key=9:lnfHnTvcKeU8wDdwB2NX4Ra52e8v_l1ij4Yn7h04F9I&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
104 b
whitelisted
GET
204
142.250.185.196:80
http://www.google.com/gen_204
US
whitelisted
3962
app_process64
GET
200
147.93.37.231:443
https://site.golesyapro.site/play.png
CY
image
115 Kb
unknown
2931
app_process64
POST
200
142.250.27.129:443
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetchEekChain
US
binary
778 b
whitelisted
3962
app_process64
POST
204
216.239.34.36:443
https://region1.google-analytics.com/g/collect?v=2&tid=G-C13E58ST8H&gtm=45je5ca1v9230051551za200zd9230051551&_p=1765733623292&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&cid=389190920.1765733623&ul=en-us&sr=1024x576&uaa=&uab=&uafvl=Chromium%3B137.0.7122.0%7CNot%252FA)Brand%3B24.0.0.0&uamb=1&uam=V50_ThinQ&uap=Android&uapv=14.0.0&uaw=0&are=1&frm=0&pscdl=&_s=1&tag_exp=103116026~103200004~104527907~104528500~104684208~104684211~105391252~115583767~115938465~115938468~116184927~116184929~116217636~116217638~116251938~116251940~116744866&sid=1765733623&sct=1&seg=0&dl=https%3A%2F%2Fgolesyapro.site%2F&dr=https%3A%2F%2Fsite.golesyapro.site%2F&dt=Golesya%20Pro%20-%20App%20de%20Resultados%20de%20F%C3%BAtbol%20%7C%20Descarga%20APK&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1025
US
whitelisted
3962
app_process64
GET
200
104.26.2.143:443
https://cdn.tailwindcss.com/3.4.17
US
binary
128 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
452
mdnsd
224.0.0.251:5353
whitelisted
142.250.185.196:80
www.google.com
GOOGLE
US
whitelisted
142.250.186.163:80
connectivitycheck.gstatic.com
GOOGLE
US
whitelisted
142.250.185.196:443
www.google.com
GOOGLE
US
whitelisted
3962
app_process64
216.58.206.78:80
clients2.google.com
GOOGLE
US
whitelisted
3962
app_process64
147.93.37.231:443
site.golesyapro.site
AS-HOSTINGER
CY
unknown
3962
app_process64
142.250.185.196:443
www.google.com
GOOGLE
US
whitelisted
3962
app_process64
64.233.167.84:443
accounts.google.com
GOOGLE
US
whitelisted
3962
app_process64
104.26.2.143:443
cdn.tailwindcss.com
CLOUDFLARENET
US
whitelisted
1921
app_process64
142.250.186.163:80
connectivitycheck.gstatic.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
www.google.com
  • 142.250.185.196
whitelisted
clients2.google.com
  • 216.58.206.78
whitelisted
site.golesyapro.site
  • 147.93.37.231
unknown
accounts.google.com
  • 64.233.167.84
  • 64.233.166.84
whitelisted
cdn.tailwindcss.com
  • 104.26.2.143
  • 172.67.68.11
  • 104.26.3.143
whitelisted
connectivitycheck.gstatic.com
  • 142.250.186.163
whitelisted
time.android.com
  • 216.239.35.0
  • 216.239.35.4
  • 216.239.35.8
  • 216.239.35.12
whitelisted
staging-remoteprovisioning.sandbox.googleapis.com
  • 142.250.27.129
whitelisted
golesyapro.site
  • 147.93.37.231
unknown

Threats

PID
Process
Class
Message
1921
app_process64
Misc activity
ET INFO Android Device Connectivity Check
3962
app_process64
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
3962
app_process64
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
347
netd
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)
4475
app_process64
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
4475
app_process64
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
4475
app_process64
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
4475
app_process64
Device Retrieving External IP Address Detected
SUSPICIOUS [ANY.RUN] An IP address was received from the server as a result of an HTTP request
347
netd
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
347
netd
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
No debug info