File name:

SnakeVPN.apk

Full analysis: https://app.any.run/tasks/48b56368-b7c2-47b6-a0d3-39bba65ee618
Verdict: Malicious activity
Threats:

BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.

Analysis date: May 15, 2026, 09:49:32
OS: Android 14
Tags:
rat
evasion
btmob
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

14F2CFE2F96FA4186348FB8BDD1AF79A

SHA1:

FBE84BD6C98450D598A0316A02CE1B7D2B1C6914

SHA256:

CA783469B23C4749AD028B30E8FF096DA9E8B549DB6C9BF5E5B0C89401FA384B

SSDEEP:

98304:zpOQ3Wkex35ylTUKBHSfiAIhEOM2pG6q4gg6wP/E6b6nCOfvaPTPK4q90s6pJIKk:F/BPzMw8m5lIm2aoZYLfU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Checks whether the screen is currently on

      • app_process64 (PID: 3173)
    • BTMOB has been detected

      • app_process64 (PID: 3173)
    • Hides app icon from display

      • app_process64 (PID: 3173)
  • SUSPICIOUS

    • Updates data in the storage of application settings (SharedPreferences)

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Abuses foreground service for persistence

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Cpu information query suggesting anti-analysis behavior

      • app_process64 (PID: 2841)
    • Returns the name of the current network operator

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Detects presence of QEMU emulator

      • app_process64 (PID: 2841)
    • Accesses system-level resources

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Collects data about the device's environment (JVM version)

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Establishing a connection

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Launches a new activity

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Retrieves a list of running services

      • app_process64 (PID: 3173)
    • Creates a WakeLock to manage power state

      • app_process64 (PID: 3173)
    • Acquires a wake lock to keep the device awake

      • app_process64 (PID: 3173)
    • Accesses external device storage files

      • app_process64 (PID: 3173)
    • Starts a service

      • app_process64 (PID: 3173)
    • Detects Xposed framework for modifications

      • app_process64 (PID: 3173)
    • Requests access to accessibility settings

      • app_process64 (PID: 2841)
    • Monitors changes in clipboard content

      • app_process64 (PID: 3173)
    • Checks exemption from battery optimization

      • app_process64 (PID: 3173)
    • Intercepts events for accessibility services

      • app_process64 (PID: 3173)
    • Checks if the device's lock screen is showing

      • app_process64 (PID: 3173)
    • Overlays content on other applications

      • app_process64 (PID: 3173)
    • Prevents its uninstallation by user

      • app_process64 (PID: 3173)
    • Checks for external IP

      • netd (PID: 339)
      • app_process64 (PID: 3173)
    • Leverages accessibility to control apps

      • app_process64 (PID: 3173)
    • Retrieves installed applications on device

      • app_process64 (PID: 3173)
    • Uses encryption API functions

      • app_process64 (PID: 3173)
    • Performs UI accessibility actions without user input

      • app_process64 (PID: 3173)
  • INFO

    • Loads a native library into the application

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Dynamically inspects or modifies classes, methods, and fields at runtime

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Retrieves data from storage of application settings (SharedPreferences)

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Detects device power status

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Dynamically registers broadcast event listeners

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Dynamically loads a class in Java

      • app_process64 (PID: 2841)
    • Verifies presence of SIM card

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Returns elapsed time since boot

      • app_process64 (PID: 2841)
    • Retrieves the value of a secure system setting

      • app_process64 (PID: 2841)
      • app_process64 (PID: 3173)
    • Stores data using SQLite database

      • app_process64 (PID: 3173)
    • Listens for changes in sensors

      • app_process64 (PID: 3173)
    • Verifies whether the device is connected to the internet

      • app_process64 (PID: 3173)
    • Retrieves the value of a global system setting

      • app_process64 (PID: 3173)
    • Gets file name without full path

      • app_process64 (PID: 3173)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.apk | Android Package (73.9)
.jar | Java Archive (20.4)
.zip | ZIP compressed archive (5.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0800
ZipCompression: Deflated
ZipModifyDate: 2026:05:14 10:45:48
ZipCRC: 0x5ebf4699
ZipCompressedSize: 130
ZipUncompressedSize: 120
ZipFileName: ehc/j/q/fm/hdiz/f/e/iyv/fkjqmhpl
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
339/system/bin/netd/system/bin/netd
init
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2841global.desk.micro /system/bin/app_process64
app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
9
2879com.android.webview:webview_service /system/bin/app_process32
app_process32
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
2899webview_zygote /system/bin/app_process32app_process32
User:
webview_zygote
Integrity Level:
UNKNOWN
Exit code:
0
3016com.android.webview:webview_apk /system/bin/app_process32
app_process32
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
3160/apex/com.android.art/bin/artd/apex/com.android.art/bin/artdinit
User:
artd
Integrity Level:
UNKNOWN
Exit code:
0
3165/apex/com.android.art/bin/dex2oat32 --zip-fd=6 --zip-location=/data/app/~~sqrf34VLAOeR5O0qIc41sQ==/torch.wire.rally-wbClR14cSz1xn1pULF3q1w==/base.apk --oat-fd=7 --oat-location=/data/app/~~sqrf34VLAOeR5O0qIc41sQ==/torch.wire.rally-wbClR14cSz1xn1pULF3q1w==/oat/arm64/base.odex --output-vdex-fd=8 --swap-fd=9 --class-loader-context=PCL[] --classpath-dir=/data/app/~~sqrf34VLAOeR5O0qIc41sQ==/torch.wire.rally-wbClR14cSz1xn1pULF3q1w== --instruction-set=arm64 --instruction-set-features=default --instruction-set-variant=cortex-a53 --compiler-filter=verify --compilation-reason=install --compact-dex-level=none --max-image-block-size=524288 --resolve-startup-const-strings=true --generate-mini-debug-info --runtime-arg -Xtarget-sdk-version:35 --runtime-arg -Xhidden-api-policy:enabled --runtime-arg -Xms64m --runtime-arg -Xmx512m --comments=app-version-name:69.140.105,app-version-code:331165,art-version:340090000/apex/com.android.art/bin/dex2oat32artd
User:
artd
Integrity Level:
UNKNOWN
Exit code:
0
3173torch.wire.rally /system/bin/app_process64
app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
3249com.android.providers.media.module /system/bin/app_process64app_process64
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
3354webview_zygote /system/bin/app_process32app_process32
User:
webview_zygote
Integrity Level:
UNKNOWN
Exit code:
0
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
40
Text files
107
Unknown types
0

Dropped files

PID
Process
Filename
Type
2841app_process64/data/data/global.desk.micro/shared_prefs/app_cfg.xmlxml
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/shared_prefs/app_config.xmlxml
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/shared_prefs/analytics_state.xmlxml
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/app_webview/last-exit-infotext
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/shared_prefs/WebViewChromiumPrefs.xmlxml
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/cache/WebView/Default/HTTP Cache/Code Cache/js/indexbinary
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/app_webview/Default/Shared Dictionary/cache/indexbinary
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/cache/WebView/font_unique_name_table.pbbinary
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/app_webview/Default/Local Storage/leveldb/MANIFEST-000001binary
MD5:
SHA256:
2841app_process64/data/data/global.desk.micro/cache/WebView/Default/HTTP Cache/Code Cache/wasm/indexbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
88
TCP/UDP connections
92
DNS requests
13
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
822
app_process64
GET
204
142.251.153.119:443
https://www.google.com/generate_204
US
whitelisted
3016
app_process32
POST
200
142.251.13.101:443
https://update.googleapis.com/service/update2/json?cup2key=15:xD18Bz88dby78fsCzHQgTxkx1z5t2qM1KVT2FBhskis&cup2hreq=6ae4988e2d686ec7161f9aa1f2984530df6f6390013faa5df6485652a428cbc8
US
text
482 b
whitelisted
1756
app_process64
POST
200
142.251.127.81:443
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signCertificates?challenge=AAABnisK2OUBILStYxBSM-RilyGLA8G5S94KQoM=&request_id=0b590412-05af-4f48-ae99-aa4c8c339298
US
binary
11.8 Kb
whitelisted
1756
app_process64
POST
200
142.251.127.81:443
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetchEekChain
US
binary
778 b
whitelisted
3173
app_process64
PUT
200
188.72.103.3:443
https://cdn.drama-connect.com/api/r/log
RU
text
11 b
unknown
3173
app_process64
GET
200
188.72.103.3:443
https://cdn.drama-connect.com/api/r/probe?n=439dd5468b83fa38&_=1778838608935
RU
text
27 b
unknown
3173
app_process64
GET
200
188.72.103.3:443
https://cdn.drama-connect.com/api/r/boot?e=Ls%40drama-connect.com&_=1778838608444
RU
text
74 b
unknown
3173
app_process64
PUT
200
188.72.103.3:443
https://cdn.drama-connect.com/api/r/log
RU
text
11 b
unknown
3173
app_process64
PUT
200
188.72.103.3:443
https://cdn.drama-connect.com/api/r/log
RU
text
11 b
unknown
3173
app_process64
GET
200
81.222.127.190:443
https://9072d033-3c6e-4fd1-9eb1-3d5e87edf813.selcdn.net/api/r/probe?n=67a84cfd735f4dc8&_=1778838608936
RU
text
27 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
443
mdnsd
224.0.0.251:5353
whitelisted
142.251.155.119:80
www.google.com
GOOGLE
US
whitelisted
192.178.183.94:80
connectivitycheck.gstatic.com
GOOGLE
US
whitelisted
142.251.157.119:443
www.google.com
GOOGLE
US
whitelisted
2841
app_process64
188.72.103.3:443
cdn.drama-connect.com
YACLOUDCDN
RU
whitelisted
2841
app_process64
185.31.114.62:443
9072d033-3c6e-4fd1-9eb1-3d5e87edf813.selcdn.net
CDNVIDEO-AS
RU
unknown
571
app_process64
216.239.35.12:123
time.android.com
GOOGLE
US
whitelisted
822
app_process64
142.251.153.119:443
www.google.com
GOOGLE
US
whitelisted
822
app_process64
192.178.183.94:80
connectivitycheck.gstatic.com
GOOGLE
US
whitelisted
2879
app_process32
142.251.20.138:443
clientservices.googleapis.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.251.14.139
  • 142.251.14.102
  • 142.251.14.100
  • 142.251.14.113
  • 142.251.14.101
  • 142.251.14.138
whitelisted
9072d033-3c6e-4fd1-9eb1-3d5e87edf813.selcdn.net
  • 185.31.114.62
  • 81.222.127.190
unknown
cdn.drama-connect.com
  • 188.72.103.3
unknown
mhjcogt0sn.a.trbcdn.net
unknown
www.google.com
  • 142.251.150.119
  • 142.251.154.119
  • 142.251.157.119
  • 142.251.152.119
  • 142.251.155.119
  • 142.251.151.119
  • 142.251.153.119
  • 142.251.156.119
whitelisted
connectivitycheck.gstatic.com
  • 192.178.183.94
whitelisted
time.android.com
  • 216.239.35.12
  • 216.239.35.4
  • 216.239.35.0
  • 216.239.35.8
whitelisted
clientservices.googleapis.com
  • 142.251.20.138
  • 142.251.20.102
  • 142.251.20.113
  • 142.251.20.100
  • 142.251.20.101
  • 142.251.20.139
whitelisted
update.googleapis.com
  • 142.251.13.101
  • 142.251.13.100
  • 142.251.13.113
  • 142.251.13.139
  • 142.251.13.138
  • 142.251.13.102
whitelisted
staging-remoteprovisioning.sandbox.googleapis.com
  • 142.251.127.81
whitelisted

Threats

PID
Process
Class
Message
822
app_process64
Misc activity
ET INFO Android Device Connectivity Check
3173
app_process64
A Network Trojan was detected
RAT [ANY.RUN] Android/BTMOB related HTTP GET request (/injections/)
3173
app_process64
A Network Trojan was detected
RAT [ANY.RUN] Android/BTMOB related HTTP GET request (/injections/)
339
netd
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
3173
app_process64
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
No debug info