| File name: | e6a97fa7-0ec8-48dd-9b56-758d1a27ce8d |
| Full analysis: | https://app.any.run/tasks/c379cee3-07bb-4469-9a28-c54166aafd59 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2025, 00:15:17 |
| OS: | Android 14 |
| MIME: | text/html |
| File info: | HTML document, Unicode text, UTF-8 text, with very long lines (65199), with no line terminators |
| MD5: | C36249399102B5C8DE912BA52695A01F |
| SHA1: | 2B7A93E143769CC3F7BC2EF9A2B0C2A08A6433D8 |
| SHA256: | F2FB4A708D05C02ADABFD7C10AE4724678BECFBFF360AE5C583C3C4B36437FDB |
| SSDEEP: | 3072:SKioxxfTYfkhT54XPAZakQ7OYYyj6XYZAaf:S2HYf+T8PIakQ7xj6XYZAaf |
| .htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
|---|---|---|
| .html | | | HyperText Markup Language (19.3) |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 2281 | org.chromium.webview_shell | /system/bin/app_process64 | app_process64 | |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2305 | zygote | /system/bin/app_process32 | — | app_process32 |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 2327 | webview_zygote | /system/bin/app_process32 | — | app_process32 |
User: webview_zygote Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 404 | 142.250.185.99:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
— | — | GET | 404 | 142.250.186.132:80 | http://www.google.com/gen_204 | unknown | — | — | whitelisted |
— | — | GET | 404 | 142.250.185.99:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
— | — | GET | 404 | 142.250.186.132:80 | http://www.google.com/gen_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 216.239.32.223:80 | http://play.googleapis.com/generate_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 216.239.38.223:80 | http://play.googleapis.com/generate_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 142.250.186.99:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 142.250.186.132:80 | http://www.google.com/gen_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 142.250.185.99:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
804 | app_process64 | GET | 404 | 142.250.186.99:80 | http://connectivitycheck.gstatic.com/generate_204 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
449 | mdnsd | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 142.250.186.132:443 | www.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.185.99:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
— | — | 142.250.186.132:80 | www.google.com | GOOGLE | US | whitelisted |
804 | app_process64 | 142.250.185.99:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
804 | app_process64 | 142.250.186.132:443 | www.google.com | GOOGLE | US | whitelisted |
804 | app_process64 | 216.239.38.223:80 | play.googleapis.com | GOOGLE | US | whitelisted |
804 | app_process64 | 142.250.186.99:80 | connectivitycheck.gstatic.com | GOOGLE | US | whitelisted |
804 | app_process64 | 142.250.186.132:80 | www.google.com | GOOGLE | US | whitelisted |
804 | app_process64 | 216.239.32.223:80 | play.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
connectivitycheck.gstatic.com |
| whitelisted |
www.google.com |
| whitelisted |
google.com |
| whitelisted |
play.googleapis.com |
| whitelisted |
time.android.com |
| whitelisted |
pornhub.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Misc activity | ET INFO Android Device Connectivity Check |
— | — | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |
804 | app_process64 | Misc activity | ET INFO Android Device Connectivity Check |