Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DETECTION] Improve Ijiami packer ELF rule #365

Open
enovella opened this issue Sep 17, 2023 · 0 comments
Open

[DETECTION] Improve Ijiami packer ELF rule #365

enovella opened this issue Sep 17, 2023 · 0 comments
Labels
detection-issue Bad detection or no detection

Comments

@enovella
Copy link
Collaborator

$ apkid ../com.green*
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk
 |-> packer : Ijiami
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libagora-core.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libijiami_sdk1.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libsgmain.so!classes.dex
 |-> compiler : unknown (please file detection issue!)
 |-> obfuscator : unreadable field names, unreadable method names
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libsgmiddletier.so!classes.dex
 |-> compiler : unknown (please file detection issue!)
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libsgmisc.so!classes.dex
 |-> compiler : unknown (please file detection issue!)
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libsgnocaptcha.so!classes.dex
 |-> compiler : unknown (please file detection issue!)
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libsgsecuritybody.so!classes.dex
 |-> compiler : unknown (please file detection issue!)
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libijm-emulator.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libhtsfx.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libexecmain.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!lib/arm64-v8a/libexec.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/1763780556!lib/arm64-v8a/libPglmetasec_ml.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/1763780556!classes.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.MANUFACTURER check, SIM operator check, network interface name check, network operator name check, possible Build.SERIAL check, subscriber ID check
 |-> compiler : dexlib 2.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/1763780556!assets/mapnaveinfoox111.dex
 |-> compiler : dexlib 2.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/gdt_plugin/gdtadv2.jar!assets/yaq3_0.sec
 |-> anti_vm : Build.MODEL check
 |-> compiler : dexlib 2.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/gdt_plugin/gdtadv2.jar!classes.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check
 |-> compiler : dexlib 2.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/gdt_plugin/gdtadv2.jar!lib/arm64-v8a/libturingau.so
 |-> obfuscator : Obfuscator-LLVM version 9.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/gdt_plugin/gdtadv2.jar!lib/armeabi/libturingau.so
 |-> obfuscator : Obfuscator-LLVM version 9.x
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_Browse.apk!classes.dex
 |-> compiler : dx
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_DnsPlug.jar!classes.dex
 |-> compiler : dx
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_Http.apk!classes.dex
 |-> compiler : dx
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_Ping.jar!classes.dex
 |-> compiler : dx
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_TraceRoute.jar!classes.dex
 |-> compiler : dx
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/OTS_VideoTest.apk!classes.dex
 |-> compiler : dx (possible dexmerge)
 |-> manipulator : dexmerge
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/libijmDataEncryption.so
 |-> packer : UPX (unknown, modified)
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/libijmDataEncryption_arm64.so
 |-> anti_hook : syscalls
[*] ../com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!classes.dex
 |-> compiler : dexlib 2.x

Sample

Check

  • com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/libijmDataEncryption_arm64.so
  • com.greenpoint.android.mc10086.activity_9.1.0_Apkpure.apk!assets/libijmDataEncryption.so
@enovella enovella added the detection-issue Bad detection or no detection label Sep 17, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
detection-issue Bad detection or no detection
Projects
None yet
Development

No branches or pull requests

1 participant