rednaga / APKiD

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
1.95k stars 286 forks source link

[DETECTION] Add rule for Zimperium #319

Open apkunpacker opened 1 year ago

apkunpacker commented 1 year ago

File -

APKiD Scan :

$ apkid 'BonusFlaş_3.8.0.apks'
[+] APKiD 2.1.4 :: from RedNaga ::
[*] BonusFlaş_3.8.0.apks!base.apk!classes.dex
 |-> anti_debug : Debug.isDebuggerConnected() check
 |-> anti_vm : Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, network operator name check, possible VM check, ro.kernel.qemu check
 |-> compiler : r8
[*] BonusFlaş_3.8.0.apks!base.apk!classes2.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, emulator file check, possible Build.SERIAL check, possible VM check, ro.kernel.qemu check, ro.product.device check
 |-> compiler : r8
[*] BonusFlaş_3.8.0.apks!base.apk!classes3.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.TAGS check, SIM operator check
 |-> compiler : r8
[*] BonusFlaş_3.8.0.apks!base.apk!classes4.dex
 |-> compiler : r8
[*] BonusFlaş_3.8.0.apks!split_config.arm64_v8a.apk!lib/arm64-v8a/
 |-> obfuscator : DexGuard 9.x

Additional Info :


strings | grep  -i zimperium 

reveal over 13000+ strings containing zimperium

classes.dex contains 2500+ classes under com.zimperium.* package name

Official Website -

enovella commented 1 year ago


can you explain which product is this one? This company has so many SDKs.

apkunpacker commented 1 year ago


can you explain which product is this one? This company has so many SDKs.

quick looks reveal it specific to RASP for example libzcloud have many anti frida codes.

Application hooked by Frida                                                      
enovella commented 1 year ago

Is this DexGuard 9.x (as seen in your log above) or custom code calling to this SDK? Do you have more samples?

apkunpacker commented 1 year ago

Is this DexGuard 9.x (as seen in your log above) or custom code calling to this SDK? Do you have more samples?

yeah its dexguard 9.x with additional zimperium sdk . at the moment no more sample available.

apkunpacker commented 1 year ago

another sample for zimperium

enovella commented 6 months ago

Hi, can you explain which product is this one? This company has so many SDKs.

quick looks reveal it specific to RASP for example libzcloud have many anti frida codes.

Application hooked by Frida                                                      

Do you have a sample with these strings?