Analysis Report on Malicious Apps Using Advanced Detection and Evasion Techniques
ID: 1e2eb27f-2b25-5422-8af3-d99ea79639c1
STIX ID: report--1e2eb27f-2b25-5422-8af3-d99ea79639c1
Feed Name: ASEC
This report analyzes an Android malware sample that employs advanced evasion techniques—strong packing, encrypted assets, native (.so) decryption, a custom package installer, and a user-input trigger—to deliver multi-stage payloads; once activated it displays a fake Play Store update and drops final-stage components that perform data theft and coin-mining. The analysis includes behavior flow, the encrypted drop location, screenshots of the UI, and indicators (multiple MD5 hashes and download URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
