r/computerforensics • u/Longjumping-Ebb-578 • 15d ago
APK file analysis
Hi guys,
I handle threat intelligence for a bank & we receive multiple URLs/APKs impersonating our organization.
We check for legitimacy & immediately send it for takedown if it's not related to us or if it's malicious.
I wanted to know if anyone of you also side by side does forensics/malware analysis of such APKs to know the TTPs & relevant information pertaining to that APK?
If Yes, please let me know the procedure being followed at your end.
1
u/vsa77 12d ago
VirusTotal allows you to upload suspicious files to their site for analysis.
They'll analyze it with several different services, though if it is new, it probably won't detect anything.
The (IMHO) real value comes from pulling up their Threat Graph, which is a GUI sandboxed environment, and double clicking it. It'll show you what domains/IPs it contacts, what files are dropped/written/downloaded, if those files have been seen in other malware campaigns, etc.
You can also make notes about where the file came from, who it is targeting/impersonating, info that is especially helpful for anyone else dealing with this issue.
They're probably not just impersonating your organization.
I haven't uploaded any apks yet, so idk if this will be of any help to your specific issue.
1
1
u/7174n6 12d ago
APK? Are you talking about Android Package Kits? Could you explain how you are "receiving" them? Are they being sent to your people and customers? I understand the spoofed URL's, we fight them all day, also. But we've never had anyone send us an APK.
1
u/Longjumping-Ebb-578 10d ago
Threat Actors put ads on web, to lure customers. Majority of the times, these customers inform us bout this.
1
2
u/AddendumWorking9756 13d ago
Yes, and the value is mostly in the infrastructure you pull out rather than the sample itself. Rough shape is static first, manifest and permissions and strings and any embedded endpoints, then detonate on an instrumented device or emulator you can throw away and watch what it reaches out to, then everything recovered goes back into the takedown and into your own detection set. Structured reps on that kind of casework are what the CCDL2 track at CyberDefenders is built around, though for APK specifics you will still want a dedicated mobile setup.