Research Stub DOGE Training App Basedotapk

Research Stub Template

https://monogr.ph/690e414a108d69266a4d5a21

tags: stub #[topic-tag] #[source-type]

created: 2025-11-10

source: virustotal.com

Core Insight

An Android application, base.apk, seems to be a modified version of an app that’s existed since 2022. On Feb 20, 2025, someone (accomplice?) submitted base.apk to virustotal for malware analysis. The app contacts doge[.]gov

Key Details

Source: [URL/publication/expert name]

I Need to Double Check that This is Packetware Helsinki Ip in Prisma

https://maps.shodan.io/#30.50548389892728/-97.69042968750001/5/satellite/hash:-657993921

image.png

Virustotal Details

image.png

MD5

MD5

SHA-1

SHA-1

SHA-256

SHA-25

Permahash

File type

- executable, mobile. android. apk

Android Package (60.6%) Java Archive (30.3%) ZIP compressed archive (8.9%)

Magika

File size

History

First Submission

Last Submission

Last Analysis

Latest Contents Modification

VirusTotal Behavior, Contacted IPs and Domains

image.png

image.png

image.png

VirusTotal Graph

basedotapk

https://www.virustotal.com/graph/embed/g427735b373c44c868c5f38e1639e79f35bb9ff63b0fe4ca4993fad609bdd959b?theme=dark

image.png

image.png

image.png

Files Containing doge.gov IP Address on Strings according to Virustotal

A Seeming Training Document Created by DOGE 2/17/2025, Submitted 30 Minutes Later

https://www.virustotal.com/gui/file/0ba697bf64aa204b95083de6db43e271587adb95da46f8f3ad937e34ac9c0569

image.png

image.png

A Json Submitted 2/27/2025

https://www.virustotal.com/gui/file/f5b1400daad54056b8799eeab116ac579ac30a8294720d114adb82b51f8789e1/details

image.png

image.png

TrID - CryEngine Project (generic) (36.6%) Poser pose (22.9%) Delphi Project source (with rem) (16.5%) T’SoundSystem Source (with rem) (12.8%) JSON Entity Model (11%)
Magika - TXT
File size - 624.73 KB (639725 bytes)

A Transcript Involving Musk Submitted 10/20/2025

https://www.virustotal.com/gui/file/e4ec24e16f455464732a549185b832c48c95c8b1449d5e24fc326c5e8b2fbd3f/details

image.png

image.png

A Pdf Created 5/27/2025, Submitted Virustotal 6/27/2025

https://www.virustotal.com/gui/file/2b084b1c3805d130d4bb67da93fcf5d8fe0e9b16059a526cf7f063869a51758a/details

image.png

What Seems to Be Spanish Language Research Report just Referencing Doge

https://www.virustotal.com/gui/file/71508ef995d020b2f993ffe2c7ab10399829bc0dcff87054e0b0b60fbca2bb6e/behavior

Year of Snake Translations

祝您蛇年越蛇越多

Wishing you a prosperous Year of the Snake!

“祝您蛇年越蛇越多”是一句结合了谐音梗与祝福寓意的创意新年贺词,
其中”越蛇越多”巧妙利用了”蛇”与”捨”(舍)的同音,
寓意在新的一年里,
能够舍弃烦恼与不顺,
收获更多好运与福气

“Wishing you a prosperous Year of the Snake!” is a creative New Year’s greeting that combines a pun with auspicious meaning.

The phrase “the more snakes, the more prosperous” cleverly uses the homophone of “snake” (蛇) and “to give up” (捨),

implying that in the new year,

one can let go of troubles and misfortunes

and gain more good fortune and blessings.

这种表达方式在2025年蛇年期间被广泛用于网络祝福语中,既幽默又充满吉祥意味
This expression was widely used in online New Year’s greetings during the Year of the Snake in 2025, being both humorous and auspicious.

。此外,类似的创意祝福还包括”好運蛇進來""蛇麼都有”等,均以”蛇”字为核心,通过谐音和吉祥话的结合,传递出对新年的美好期盼

。“越蛇越多”是一句在2025蛇年流行的创意谐音祝福语,其核心在于”蛇”与”捨”(舍)的同音双关。这句话的完整寓意是”越舍越多”,表达的是一种积极的人生哲理:懂得舍弃,才能获得更多。

在中华文化中,“舍”与”得”常被视为相辅相成的概念。
Zài zhōnghuá wénhuà zhōng,“shě” yǔ “dé” cháng bèi shì wéi xiāngfǔxiāngchéng de gàiniàn.

这句祝福语鼓励人们在新的一年里,

Zhè jù zhùfú yǔ gǔlì rénmen zài xīn de yī nián lǐ,

能够放下过去的烦恼、执念或不必要的负担(舍),

nénggòu fàngxià guòqù de fánnǎo, zhí niàn huò bù bìyào de fùdān (shě),

从而为新的机遇、

cóng’ér wéi xīn de jīyù,

财富和幸福(得)腾出空间,

cáifù hé xìngfú (dé) téng chū kōngjiān,

最终实现”越舍越多”的良性循环。

zuìzhōng shíxiàn “yuè shě yuè duō” de liángxìng xúnhuán.

In Chinese culture, “giving” and “receiving” are often seen as complementary concepts. This blessing encourages people to let go of past worries, obsessions, or unnecessary burdens (giving) in the new year, thus making room for new opportunities, wealth, and happiness (receiving), ultimately achieving a virtuous cycle of “the more you give, the more you receive.”

它常与其他蛇年谐音梗一起使用,如”有蛇(捨)有得”、“蛇麼攏賀”(什麼都好),共同营造出既幽默风趣又充满智慧与正能量的节日氛围。

Tā cháng yǔ qítā shé nián xiéyīn gěng yīqǐ shǐyòng, rú “yǒu shé (shě) yǒu dé”,“shé me lǒng hè”(shénme dōu hǎo), gòngtóng yíngzào chū jì yōumò fēngqù yòu chōngmǎn zhìhuì yǔ zhèng néngliàng de jiérì fēnwéi.

It is often used in conjunction with other homophones related to the Year of the Snake, such as “with snakes you get something” and “everything is good”, together creating a festive atmosphere that is both humorous and full of wisdom and positive energy.

OR following translation?

“The more snakes, the more prosperous” is a popular creative homophonic blessing in the Year of the Snake in 2025, its core being the double entendre of the homophone of “snake” (蛇) and “to give up” (捨). The complete meaning of this phrase is “the more you give up, the more you gain,”

“Wishing you a prosperous Year of the Snake!” is a creative New Year’s greeting that combines a pun with auspicious meaning. The phrase “the more snakes, the more prosperous” cleverly uses the homophone of “snake” (蛇) and “to give up” (捨), implying that in the new year, one can let go of troubles and misfortunes and gain more good fortune and blessings.

This expression was widely used in online New Year’s greetings during the Year of the Snake in 2025, being both humorous and auspicious.

Similar creative blessings include “Good luck snake in!” and “May you have everything you need!”, all centered around the character “snake,” conveying a positive outlook for the new year through a combination of homophones and auspicious phrases.

在中华文化中,“舍”与”得”常被视为相辅相成的概念。这句祝福语鼓励人们在新的一年里,能够放下过去的烦恼、执念或不必要的负担(舍),从而为新的机遇、财富和幸福(得)腾出空间,最终实现”越舍越多”的良性循环。

In Chinese culture, “giving” and “receiving” are often seen as complementary concepts. This blessing encourages people to let go of past worries, obsessions, or unnecessary burdens (giving) in the new year, thus making room for new opportunities, wealth, and happiness (receiving), ultimately achieving a virtuous cycle of “the more you give, the more you receive.”

它常与其他蛇年谐音梗一起使用,如”有蛇(捨)有得”、“蛇麼攏賀”(什麼都好),共同营造出既幽默风趣又充满智慧与正能量的节日氛围。

祝您蛇年越蛇越多

Date: [when published/discovered]

Verification level:

  • primary source

  • secondary

  • expert opinion

  • speculation

Here We Go—actual Analysis of base.apk File 2/16/2025

https://www.virustotal.com/gui/file/4d38c7fa3f09f34549d52d5fa61e7e6ad76d8fec6aa616272019e63f480c7917/details

image.png

Summary
Android Type
APK
Package Name
org.chromium.webapk.a10b47e057fc5f098_v2
Main Activity
org.chromium.webapk.shell_apk.h2o.H2OMainActivity
Internal Version
1
Displayed Version
1
Minimum SDK Version
24
Target SDK Version
33
Certificate Attributes
Valid From
2025-02-13 22:09:30
Valid To
2052-07-02 22:09:30
Serial Number
9b570a92e2b10118
Thumbprint
620fd1937c5e1ae09f13cadba356306c21c83d72
Certificate Subject
Distinguished Name
O:Google, OU:WebAPK
Organization
Google
Organizational Unit
WebAPK
Certificate Issuer
Distinguished Name
O:Google, OU:WebAPK
Organization
Google
Organizational Unit
WebAPK
Permissions
android.permission.POST_NOTIFICATIONS
Activities
org.chromium.webapk.shell_apk.h2o.H2OMainActivity
org.chromium.webapk.shell_apk.ManageDataLauncherActivity
org.chromium.webapk.shell_apk.NotificationPermissionRequestActivity
org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity
org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity
org.chromium.webapk.shell_apk.h2o.SplashActivity
Services
org.chromium.webapk.shell_apk.IdentityService
org.chromium.webapk.shell_apk.WebApkServiceFactory
Providers
org.chromium.webapk.shell_apk.h2o.SplashContentProvider
Intent Filters By Action
org.webapk.IDENTITY_SERVICE_API
org.chromium.webapk.shell_apk.IdentityService
android.intent.action.MAIN
org.chromium.webapk.shell_apk.WebApkServiceFactory
org.chromium.webapk.shell_apk.h2o.H2OMainActivity
org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity
android.intent.action.VIEW
org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity
android.nfc.action.NDEF_DISCOVERED
org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity
Intent Filters By Category
android.intent.category.WEBAPK_API
org.chromium.webapk.shell_apk.WebApkServiceFactory
android.intent.category.LAUNCHER
org.chromium.webapk.shell_apk.h2o.H2OMainActivity
org.chromium.webapk.shell_apk.h2o.H2OOpaqueMainActivity
android.intent.category.DEFAULT
org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity
android.intent.category.BROWSABLE
org.chromium.webapk.shell_apk.h2o.H2OTransparentLauncherActivity
Bundle Info
Contents Metadata
Contained Files
29
Uncompressed Size
219.86 KB
Earliest Content Modification
1980-01-01 00:00:00
Latest Content Modification
1980-12-31 16:00:00
Contained Files By Type
UNKNOWN
7
XML
10
PNG
12
Contained Files By Extension
DEX
1
MF
1
ARSC
1
RSA
2
SF
2
XML
10
PNG
11

Another Version Found of base.apk

https://www.virustotal.com/graph/embed/g77ff6f07f55842e48790a79329edad6ee5d0370edf624ccb8c5847934809e7f9?theme=dark

notification_badge.png Has Been Tracked for a while by Researchers

https://www.virustotal.com/gui/file/58a07deae1426b075118f044a01bd8b556d7869ceb4f2b3941cb1b823a34bbc7/community

https://www.virustotal.com/graph/g77ff6f07f55842e48790a79329edad6ee5d0370edf624ccb8c5847934809e7f9

classes.dex First Submitted 1/27/2025, Again 10/11/2025

https://www.virustotal.com/gui/file/102c312a5f31159dfc00e78d79312c83875850aee86900465f87d820118fa005/details

image.png

Doge.gov Itself Page on VT

image.png

https://www.virustotal.com/gui/domain/doge.gov/relations

image.png

graph

https://www.virustotal.com/graph/embed/g99b07ea1c9fc4e27a2c633c81678a26a70cc00651db848e08d8634647eb0de6f?theme=dark

YumeKey Tool on the Web Contacted DOGE.gov 1/21/2025

https://www.virustotal.com/gui/file/5099e6accc82be312d14ed61572f5027138a8a313bc1a4cd703fdf48cd2c250b

image.png

image.png

Registry keys set\

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Time\Config\LastKnownGoodTime
`\xca\xb2 \x1f\xc4\xdb\x01

Registry keys deleted
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\PreferenceMACs\Default\extensions.settings

Jinpwnsoft Creators of YumeKey

https://www.virustotal.com/gui/domain/jinpwnsoft.re/relations

Telegram channel created 4/22/2023

image.png

image.png

image.png

https://rentry.co/jinpwnsoft

https://t.me/s/jinpwnsoft_news?after=2

https://www.virustotal.com/gui/domain/dvgpwa.life/relations

https://www.virustotal.com/graph/embed/gd9c9c1e467754b14a1ebcdef0c4bb509e4c5d21e0e7a4965a577a90b791d4212?theme=dark

image.png

Historic Ip Resolutions for join.doge.gov

image.png

image.png

104.18.4.127 - resolved to tun.doge.gov on 3/20/2025

Unofficial Twitter Api.

https://rapidapi.com/twttrapi-twttrapi-default/api/twttrapi

https://rapidapi.com/twttrapi-twttrapi-default/api/twttrapi/playground/apiendpoint_cbb30ac7-6e4b-4916-81b0-5e14ec57fb4a

image.png

Next Section DOGE的云

https://www.shodan.io/search?query=DOGE%E7%9A%84%E4%BA%91

search query: DOGE的云 (Doge’s cloud)

https://www.shodan.io/host/106.81.40.111/raw

  • synology_dsm:{

    • custom_login_title:“DOGE的云”,

    • hostname:“Synology920”

    },

  • timestamp:“2025-10-25T12:47:05.398975”,

  • transport:“tcp”

}

],

The Hook Factor

What makes this shocking, counterintuitive, or insider knowledge?

Evidence Type

  • Hard data/statistics

  • Expert testimony

  • Leaked/classified documents

  • Personal anecdote/case study

  • Technical analysis

  • Historical precedent

Connects to: #[related-topic] #[related-person] #[related-event]

Story potential: [which article angle could this support?]

Missing Pieces

What would make this more persuasive?

  • Need stronger source verification

  • Missing expert perspective

  • Need opposing viewpoint

  • Requires additional context

  • Need visual evidence

  • Needs victim/human impact story

Quote Bank

“[Most compelling quote from source]”

“[Secondary quote if valuable]”

Research confidence

  • high

  • medium

  • low

Story readiness:

  • ready

  • needs-more

  • parking-lot