Research Stub DOGE training app base.apk

2025-11-11 21:54

Research Stub Template

tags: #stub #[topic-tag] #[source-type]

created: 2025-11-10

source: virustotal.com

Core Insight

An Android application, base.apk, seems to be a modified version of an app that's existed since 2022. On Feb 20, 2025, someone (accomplice?) submitted base.apk to virustotal for malware analysis. The app contacts doge[.]gov

Key Details

Source: [URL/publication/expert name]

I need to double check that this is packetware helsinki ip in prisma

https://maps.shodan.io/#30.50548389892728/-97.69042968750001/5/satellite/hash:-657993921

Virustotal details

MD5

MD5

de38272b43197585ab1af9172dd44cf1

SHA-1

SHA-1

f0773e9847f6e781f8b2842b8721bb7e9c34fdc1

SHA-256

SHA-25

Permahash

94cb8b2ef60fbd441f14bdade46bd0fedb208d75833bed1e255edbb5f8ba32a4

File type

Android - executable, mobile. android. apk

Zip archive data, at least v0.0 to extract, compression method=deflate

Android Package (60.6%)   Java Archive (30.3%)   ZIP compressed archive (8.9%)

Magika

APK

File size

190.43 KB (195000 bytes)

History

First Submission

2025-02-20 13:30:08 UTC

Last Submission

2025-02-20 13:30:08 UTC

Last Analysis

2025-02-20 13:30:08 UTC

Latest Contents Modification

1980-12-31 16:00:00.

VirusTotal behavior, contacted IPs and domains

VirusTotal Graph

basedotapk

https://www.virustotal.com/graph/embed/g427735b373c44c868c5f38e1639e79f35bb9ff63b0fe4ca4993fad609bdd959b?theme=dark

Files containing doge.gov IP address on strings according to virustotal

a seeming training document created by DOGE 2/17/2025, submitted 30 minutes later

https://www.virustotal.com/gui/file/0ba697bf64aa204b95083de6db43e271587adb95da46f8f3ad937e34ac9c0569

a json submitted 2/27/2025

https://www.virustotal.com/gui/file/f5b1400daad54056b8799eeab116ac579ac30a8294720d114adb82b51f8789e1/details

TrID - CryEngine Project (generic) (36.6%)   Poser pose (22.9%)   Delphi Project source (with rem) (16.5%)   T'SoundSystem Source (with rem) (12.8%)   JSON Entity Model (11%)

Magika - TXT

File size - 624.73 KB (639725 bytes)

a transcript involving musk submitted 10/20/2025

https://www.virustotal.com/gui/file/e4ec24e16f455464732a549185b832c48c95c8b1449d5e24fc326c5e8b2fbd3f/details

a pdf created 5/27/2025, submitted virustotal 6/27/2025

https://www.virustotal.com/gui/file/2b084b1c3805d130d4bb67da93fcf5d8fe0e9b16059a526cf7f063869a51758a/details

what seems to be spanish language research report just referencing doge

https://www.virustotal.com/gui/file/71508ef995d020b2f993ffe2c7ab10399829bc0dcff87054e0b0b60fbca2bb6e/behavior

Year of Snake translations

祝您蛇年越蛇越多

Wishing you a prosperous Year of the Snake!

“祝您蛇年越蛇越多”是一句结合了谐音梗与祝福寓意的创意新年贺词,

其中“越蛇越多”巧妙利用了“蛇”与“捨”(舍)的同音,

寓意在新的一年里,

能够舍弃烦恼与不顺,

收获更多好运与福气

"Wishing you a prosperous Year of the Snake!" is a creative New Year's greeting that combines a pun with auspicious meaning.

The phrase "the more snakes, the more prosperous" cleverly uses the homophone of "snake" (蛇) and "to give up" (捨),

implying that in the new year,

one can let go of troubles and misfortunes

and gain more good fortune and blessings.

这种表达方式在2025年蛇年期间被广泛用于网络祝福语中,既幽默又充满吉祥意味

This expression was widely used in online New Year's greetings during the Year of the Snake in 2025, being both humorous and auspicious.

 。此外,类似的创意祝福还包括“好運蛇進來”“蛇麼都有”等,均以“蛇”字为核心,通过谐音和吉祥话的结合,传递出对新年的美好期盼

 。“越蛇越多”是一句在2025蛇年流行的创意谐音祝福语,其核心在于“蛇”与“捨”(舍)的同音双关。这句话的完整寓意是“越舍越多”,表达的是一种积极的人生哲理:懂得舍弃,才能获得更多。

在中华文化中,“舍”与“得”常被视为相辅相成的概念。

Zài zhōnghuá wénhuà zhōng,“shě” yǔ “dé” cháng bèi shì wéi xiāngfǔxiāngchéng de gàiniàn.

这句祝福语鼓励人们在新的一年里,

Zhè jù zhùfú yǔ gǔlì rénmen zài xīn de yī nián lǐ,

能够放下过去的烦恼、执念或不必要的负担(舍),

nénggòu fàngxià guòqù de fánnǎo, zhí niàn huò bù bìyào de fùdān (shě),

从而为新的机遇、

cóng'ér wéi xīn de jīyù,

财富和幸福(得)腾出空间,

cáifù hé xìngfú (dé) téng chū kōngjiān,

最终实现“越舍越多”的良性循环。

zuìzhōng shíxiàn “yuè shě yuè duō” de liángxìng xúnhuán.

In Chinese culture, "giving" and "receiving" are often seen as complementary concepts. This blessing encourages people to let go of past worries, obsessions, or unnecessary burdens (giving) in the new year, thus making room for new opportunities, wealth, and happiness (receiving), ultimately achieving a virtuous cycle of "the more you give, the more you receive."

它常与其他蛇年谐音梗一起使用,如“有蛇(捨)有得”、“蛇麼攏賀”(什麼都好),共同营造出既幽默风趣又充满智慧与正能量的节日氛围。

Tā cháng yǔ qítā shé nián xiéyīn gěng yīqǐ shǐyòng, rú “yǒu shé (shě) yǒu dé”,“shé me lǒng hè”(shénme dōu hǎo), gòngtóng yíngzào chū jì yōumò fēngqù yòu chōngmǎn zhìhuì yǔ zhèng néngliàng de jiérì fēnwéi.

It is often used in conjunction with other homophones related to the Year of the Snake, such as "with snakes you get something" and "everything is good", together creating a festive atmosphere that is both humorous and full of wisdom and positive energy.

OR following translation?

"The more snakes, the more prosperous" is a popular creative homophonic blessing in the Year of the Snake in 2025, its core being the double entendre of the homophone of "snake" (蛇) and "to give up" (捨). The complete meaning of this phrase is "the more you give up, the more you gain,"

"Wishing you a prosperous Year of the Snake!" is a creative New Year's greeting that combines a pun with auspicious meaning. The phrase "the more snakes, the more prosperous" cleverly uses the homophone of "snake" (蛇) and "to give up" (捨), implying that in the new year, one can let go of troubles and misfortunes and gain more good fortune and blessings.

This expression was widely used in online New Year's greetings during the Year of the Snake in 2025, being both humorous and auspicious.

Similar creative blessings include "Good luck snake in!" and "May you have everything you need!", all centered around the character "snake," conveying a positive outlook for the new year through a combination of homophones and auspicious phrases.

在中华文化中,“舍”与“得”常被视为相辅相成的概念。这句祝福语鼓励人们在新的一年里,能够放下过去的烦恼、执念或不必要的负担(舍),从而为新的机遇、财富和幸福(得)腾出空间,最终实现“越舍越多”的良性循环。

In Chinese culture, "giving" and "receiving" are often seen as complementary concepts. This blessing encourages people to let go of past worries, obsessions, or unnecessary burdens (giving) in the new year, thus making room for new opportunities, wealth, and happiness (receiving), ultimately achieving a virtuous cycle of "the more you give, the more you receive."

它常与其他蛇年谐音梗一起使用,如“有蛇(捨)有得”、“蛇麼攏賀”(什麼都好),共同营造出既幽默风趣又充满智慧与正能量的节日氛围。

 祝您蛇年越蛇越多

Date: [when published/discovered]

Verification level:

  • primary source

  • secondary

  • expert opinion

  • speculation

Here we Go--actual analysis of base.apk file 2/16/2025

https://www.virustotal.com/gui/file/4d38c7fa3f09f34549d52d5fa61e7e6ad76d8fec6aa616272019e63f480c7917/details

Summary

Android Type

APK

Package Name

org.chromium.webapk.a10b47e057fc5f098_v2

Main Activity

org.chromium.webapk.shell_apk.h2o.H2OMainActivity

Internal Version

1

Displayed Version

1

Minimum SDK Version

24

Target SDK Version

33

Certificate Attributes

Valid From

2025-02-13 22:09:30

Valid To

2052-07-02 22:09:30

Serial Number

9b570a92e2b10118

Thumbprint

620fd1937c5e1ae09f13cadba356306c21c83d72

Certificate Subject

Distinguished Name

O:Google, OU:WebAPK

Organization

Google

Organizational Unit

WebAPK

Certificate Issuer

Distinguished Name

O:Google, OU:WebAPK

Organization

Google

Organizational Unit

WebAPK

Permissions

android.permission.POST_NOTIFICATIONS

Activities

org.chromium.webapk.shell_apk.h2o.H2OMainActivity

org.chromium.webapk.shell_apk.ManageDataLauncherActivity

org.chromium.webapk.shell_apk.NotificationPermissionRequestActivity

org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity

org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity

org.chromium.webapk.shell_apk.h2o.SplashActivity

Services

org.chromium.webapk.shell_apk.IdentityService

org.chromium.webapk.shell_apk.WebApkServiceFactory

Providers

org.chromium.webapk.shell_apk.h2o.SplashContentProvider

Intent Filters By Action

org.webapk.IDENTITY_SERVICE_API

org.chromium.webapk.shell_apk.IdentityService

android.intent.action.MAIN

org.chromium.webapk.shell_apk.WebApkServiceFactory

org.chromium.webapk.shell_apk.h2o.H2OMainActivity

org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity

android.intent.action.VIEW

org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity

android.nfc.action.NDEF_DISCOVERED

org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity

Intent Filters By Category

android.intent.category.WEBAPK_API

org.chromium.webapk.shell_apk.WebApkServiceFactory

android.intent.category.LAUNCHER

org.chromium.webapk.shell_apk.h2o.H2OMainActivity

org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity

android.intent.category.DEFAULT

org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity

android.intent.category.BROWSABLE

org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity

Bundle Info

Contents Metadata

Contained Files

29

Uncompressed Size

219.86 KB

Earliest Content Modification

1980-01-01 00:00:00

Latest Content Modification

1980-12-31 16:00:00

Contained Files By Type

UNKNOWN

7

XML

10

PNG

12

Contained Files By Extension

DEX

1

MF

1

ARSC

1

RSA

2

SF

2

XML

10

PNG

11

another version found of base.apk

https://www.virustotal.com/graph/embed/g77ff6f07f55842e48790a79329edad6ee5d0370edf624ccb8c5847934809e7f9?theme=dark

notification_badge.png has been tracked for a while by researchers

https://www.virustotal.com/gui/file/58a07deae1426b075118f044a01bd8b556d7869ceb4f2b3941cb1b823a34bbc7/community

https://www.virustotal.com/graph/g77ff6f07f55842e48790a79329edad6ee5d0370edf624ccb8c5847934809e7f9

classes.dex first submitted 1/27/2025, again 10/11/2025

https://www.virustotal.com/gui/file/102c312a5f31159dfc00e78d79312c83875850aee86900465f87d820118fa005/details

Doge.gov itself page on VT

https://www.virustotal.com/gui/domain/doge.gov/relations

graph

https://www.virustotal.com/graph/embed/g99b07ea1c9fc4e27a2c633c81678a26a70cc00651db848e08d8634647eb0de6f?theme=dark

YumeKey tool on the web contacted DOGE.gov 1/21/2025

https://www.virustotal.com/gui/file/5099e6accc82be312d14ed61572f5027138a8a313bc1a4cd703fdf48cd2c250b

Registry keys set\

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time\Config\LastKnownGoodTime

`\xca\xb2 \x1f\xc4\xdb\x01

Registry keys deleted

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\PreferenceMACs\Default\extensions.settings

jinpwnsoft creators of YumeKey

https://www.virustotal.com/gui/domain/jinpwnsoft.re/relations

Telegram channel created 4/22/2023

https://rentry.co/jinpwnsoft

https://t.me/s/jinpwnsoft_news?after=2

dvgpwa.life created feb 2025 and has links, need to determine relationship

https://www.virustotal.com/gui/domain/dvgpwa.life/relations

https://www.virustotal.com/graph/embed/gd9c9c1e467754b14a1ebcdef0c4bb509e4c5d21e0e7a4965a577a90b791d4212?theme=dark

Historic ip resolutions for join.doge.gov

104.18.4.127 - resolved to tun.doge.gov on 3/20/2025

Unofficial twitter api...

https://rapidapi.com/twttrapi-twttrapi-default/api/twttrapi

https://rapidapi.com/twttrapi-twttrapi-default/api/twttrapi/playground/apiendpoint_cbb30ac7-6e4b-4916-81b0-5e14ec57fb4a

next section DOGE的云

https://www.shodan.io/search?query=DOGE%E7%9A%84%E4%BA%91

search query: DOGE的云 (Doge's cloud)

https://www.shodan.io/host/106.81.40.111/raw

  • synology_dsm:{

    • custom_login_title:"DOGE的云",

    • hostname:"Synology920"

    },

  • timestamp:"2025-10-25T12:47:05.398975",

  • transport:"tcp"

}

],

The Hook Factor

What makes this shocking, counterintuitive, or insider knowledge?

Evidence Type

  • Hard data/statistics

  • Expert testimony

  • Leaked/classified documents

  • Personal anecdote/case study

  • Technical analysis

  • Historical precedent

Forward Links

Connects to: #[related-topic] #[related-person] #[related-event]

Story potential: [which article angle could this support?]

Missing Pieces

What would make this more persuasive?

  • Need stronger source verification

  • Missing expert perspective

  • Need opposing viewpoint

  • Requires additional context

  • Need visual evidence

  • Needs victim/human impact story

Quote Bank

"[Most compelling quote from source]"

"[Secondary quote if valuable]"

Research confidence

  • high

  • medium

  • low

Story readiness:

  • ready

  • needs-more

  • parking-lot