| URL: | xmanager.com |
| Full analysis: | https://app.any.run/tasks/f609df27-9186-4fb9-91b9-0717619b212e |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 13:38:26 |
| OS: | Android 14 |
| Tags: | |
| Indicators: | |
| MD5: | 6DA2114BFEF3315798E8D6CD9230275E |
| SHA1: | E6D59CD538C184C5AEA3D720D91230A40FBB4EA9 |
| SHA256: | E9F27D474F853AC45E07A4DA564AB9C79948AB7F9818C587D31C4D4F6A0CF70E |
| SSDEEP: | 3:fiZI:aZI |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2209 | org.chromium.webview_shell | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2210 | com.android.settings | /system/bin/app_process64 | — | app_process64 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2257 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2259 | webview_zygote | /system/bin/app_process32 | — | app_process32 |
User: webview_zygote Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2311 | zygote | /system/bin/app_process32 | app_process32 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 142.250.185.131:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
2209 | app_process64 | GET | 530 | 104.21.65.82:80 | http://xmanager.com/ | unknown | — | — | unknown |
2209 | app_process64 | GET | 301 | 185.230.63.107:80 | http://xmanagerapp.com/ | unknown | — | — | unknown |
2209 | app_process64 | GET | 530 | 104.21.65.82:80 | http://xmanager.com/favicon.ico | unknown | — | — | unknown |
2209 | app_process64 | GET | 200 | 104.21.65.82:80 | http://xmanager.com/cdn-cgi/styles/main.css | unknown | — | — | unknown |
2209 | app_process64 | GET | 301 | 149.154.167.99:80 | http://t.me/xManagerSupport/403172 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
445 | mdnsd | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 142.250.185.228:443 | www.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.185.131:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 216.239.35.4:123 | time.android.com | — | — | whitelisted |
— | — | 64.233.184.81:443 | staging-remoteprovisioning.sandbox.googleapis.com | GOOGLE | US | whitelisted |
2257 | app_process32 | 142.250.185.99:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
2311 | app_process32 | 142.250.185.131:443 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
2209 | app_process64 | 104.21.65.82:80 | xmanager.com | CLOUDFLARENET | — | unknown |
2311 | app_process32 | 142.250.185.78:443 | dl.google.com | GOOGLE | US | whitelisted |
579 | app_process64 | 216.239.35.12:123 | time.android.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
connectivitycheck.gstatic.com |
| whitelisted |
time.android.com |
| whitelisted |
staging-remoteprovisioning.sandbox.googleapis.com |
| whitelisted |
google.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
xmanager.com |
| unknown |
dl.google.com |
| whitelisted |
performance.radar.cloudflare.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Android Device Connectivity Check |
2209 | app_process64 | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |