Guess Who Am I? PE Or APK
ID: 31ae1d18-a3f9-5ac2-b54b-157e6aac0161
STIX ID: report--31ae1d18-a3f9-5ac2-b54b-157e6aac0161
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes a malicious Android APK hidden inside a Windows PE file (MZ) to bypass zipfile.py parsing and some AV tools. The sample contains a valid classes.dex, hides payload in a PE text section, attempts to execute 'su' to obtain root, and contacts admob-related endpoints — a proof-of-concept demonstrating APK-in-PE evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
