rednaga / APKiD

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
Other
1.96k stars 286 forks source link

[DETECTION] Appguard packer wasn't detected #355

Closed enovella closed 10 months ago

enovella commented 10 months ago

Info

https://bbs.kanxue.com/thread-278113.htm

Sample

> apkid Project_WorldChampion_2.6.0_apkcombo.com.apk
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] Project_WorldChampion_2.6.0_apkcombo.com.apk!classes.dex
 |-> compiler : dexlib 2.x
[*] Project_WorldChampion_2.6.0_apkcombo.com.apk!classes2.dex
 |-> anti_debug : Debug.isDebuggerConnected() check
 |-> anti_vm : Build.BRAND check, Build.DEVICE check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, possible VM check
 |-> compiler : unknown (please file detection issue!)
 |-> yara_issue : yara issue - dex file recognized by apkid but not yara module

https://apkcombo.com/%E3%83%96%E3%83%AB%E3%83%BC%E3%83%AD%E3%83%83%E3%82%AF-project-world-champion/jp.pjfb/

dustty0 commented 10 months ago

Some NHN AppGuard applied apps lack classesN.jet / zip files. https://apkcombo.com/밀리의서재/kr.co.millie.millieshelf/download/phone-5.8.0.0-apk

Modifying rule appguard_b like below might solve the issue...?

  condition:
    is_apk and (1 of ($b*) and 1 of ($c*)) 
enovella commented 10 months ago

Some NHN AppGuard applied apps lack classesN.jet / zip files. https://apkcombo.com/밀리의서재/kr.co.millie.millieshelf/download/phone-5.8.0.0-apk

Modifying rule appguard_b like below might solve the issue...?

  condition:
    is_apk and (1 of ($b*) and 1 of ($c*)) 

It doesn't. Let me check why its not matching my sample and your new sample.

enovella commented 10 months ago

Some NHN AppGuard applied apps lack classesN.jet / zip files. https://apkcombo.com/밀리의서재/kr.co.millie.millieshelf/download/phone-5.8.0.0-apk

Modifying rule appguard_b like below might solve the issue...?

  condition:
    is_apk and (1 of ($b*) and 1 of ($c*)) 

> apkid 밀리의\ 서재_5.8.0.0_apkcombo.com.apk
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes.dex
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes2.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, network operator name check, possible VM check, ro.kernel.qemu check
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes3.dex
 |-> anti_debug : Debug.isDebuggerConnected() check
 |-> anti_vm : Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, device ID check, network operator name check, possible VM check
 |-> compiler : dexlib 2.x
 |-> protector : WhiteCryption
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes4.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.TAGS check
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes5.dex
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes6.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, possible VM check
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes7.dex
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!classes8.dex
 |-> anti_vm : Build.BOARD check, Build.MANUFACTURER check, device ID check, possible VM check
 |-> compiler : dexlib 2.x
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!lib/arm64-v8a/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!lib/armeabi-v7a/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!lib/x86/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] 밀리의 서재_5.8.0.0_apkcombo.com.apk!lib/x86_64/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
enovella commented 10 months ago

Some NHN AppGuard applied apps lack classesN.jet / zip files. https://apkcombo.com/밀리의서재/kr.co.millie.millieshelf/download/phone-5.8.0.0-apk

Modifying rule appguard_b like below might solve the issue...?

  condition:
    is_apk and (1 of ($b*) and 1 of ($c*)) 

Any other file you recognize in the assets folder? Check the commented lines please.


> unzip -l sample2.apk|egrep -i "appguard|assets"
  3044600  01-01-1981 01:01   assets/664                     // AppGuard?
  3002680  01-01-1981 01:01   assets/686                    // AppGuard?
    45488  01-01-1981 01:01   assets/Pe-icon-7-stroke.ttf
      952  01-01-1981 01:01   assets/agconfig               // AppGuard config file
       13  01-01-1981 01:01   assets/agmetainfo             // AppGuard meta info file
     1001  01-01-1981 01:01   assets/blitz-reset.css
    18523  01-01-1981 01:01   assets/blitz.css
      118  01-01-1981 01:01   assets/cdnSDK.ini
      120  01-01-1981 01:01   assets/cdnSDK.samsung.ini
     1911  01-01-1981 01:01   assets/dexopt/baseline.prof
      195  01-01-1981 01:01   assets/dexopt/baseline.profm
   287370  01-01-1981 01:01   assets/docentViewer/dist/app.js
   305732  01-01-1981 01:01   assets/docentViewer/dist/index-legacy-eaf77cfa.js
   306479  01-01-1981 01:01   assets/docentViewer/dist/index-legacy.e66483b0.js
   308737  01-01-1981 01:01   assets/docentViewer/dist/index.13953b68.js
      498  01-01-1981 01:01   assets/docentViewer/dist/index.html
      299  01-01-1981 01:01   assets/docentViewer/dist/index_original.html
    31677  01-01-1981 01:01   assets/docentViewer/dist/polyfills-legacy-f244a7cd.js
    31677  01-01-1981 01:01   assets/docentViewer/dist/polyfills-legacy.feff12f7.js
   437788  01-01-1981 01:01   assets/drawingViewer/dist/Drawing.js
      224  01-01-1981 01:01   assets/drawingViewer/dist/Drawing.js.LICENSE.txt
   157333  01-01-1981 01:01   assets/drawingViewer/dist/app.js
      448  01-01-1981 01:01   assets/drawingViewer/dist/index.html
   182505  01-01-1981 01:01   assets/epubViewer/dist/app.js
   130163  01-01-1981 01:01   assets/epubViewer/dist/app_eink.js
   345701  01-01-1981 01:01   assets/epubViewer/dist/ePub.js
      528  01-01-1981 01:01   assets/epubViewer/dist/index.html
      471  01-01-1981 01:01   assets/epubViewer/dist/index_eink.html
    28532  01-01-1981 01:01   assets/feather-webfont.ttf
     4131  01-01-1981 01:01   assets/flutter_assets/AssetManifest.json
      344  01-01-1981 01:01   assets/flutter_assets/FontManifest.json
    79118  01-01-1981 01:01   assets/flutter_assets/NOTICES.Z
     4656  01-01-1981 01:01   assets/flutter_assets/assets/fonts/NotoserifKR-Bold.otf
   350844  01-01-1981 01:01   assets/flutter_assets/assets/fonts/SpoqaHanSansNeo-Bold.otf
   349036  01-01-1981 01:01   assets/flutter_assets/assets/fonts/SpoqaHanSansNeo-Regular.otf
      155  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_action_bar.svg
      703  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_alert.svg
      983  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_apple.svg
      311  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_arrow_down.svg
      487  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_arrow_left.svg
    37022  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_blank.svg
      580  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_camera.svg
      216  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check.svg
      187  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_off.svg
      187  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_off_danger.svg
      187  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_off_primary.svg
      187  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_off_secondary.svg
      337  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_on.svg
      342  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_on_danger.svg
      342  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_on_secondary.svg
      188  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_false.svg
      188  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_false_danger.svg
      188  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_false_primary.svg
      188  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_false_secondary.svg
      338  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_true.svg
      343  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_true_danger.svg
      343  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_check_box_round_true_secondary.svg
     1772  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_dot.svg
      392  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_facebook.svg
     1518  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_google.svg
      286  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_input_delete.svg
     2708  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_kakao.svg
      381  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_naver.svg
      265  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_notice_dot.svg
      566  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_photo.svg
     1799  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_rank1.svg
     2659  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_rank2.svg
     3613  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_rank3.svg
     1604  01-01-1981 01:01   assets/flutter_assets/assets/ic/ic_whale.svg
    26914  01-01-1981 01:01   assets/flutter_assets/assets/img/img_background_book.png
    29412  01-01-1981 01:01   assets/flutter_assets/assets/img/img_background_time.png
   179719  01-01-1981 01:01   assets/flutter_assets/assets/img/img_box_illust.svg
     2609  01-01-1981 01:01   assets/flutter_assets/assets/img/img_hoban.png
    74616  01-01-1981 01:01   assets/flutter_assets/assets/img/img_illust_door.svg
     6750  01-01-1981 01:01   assets/flutter_assets/assets/img/img_millieLogo.svg
     9819  01-01-1981 01:01   assets/flutter_assets/assets/img/img_sample_book.png
    47760  01-01-1981 01:01   assets/flutter_assets/assets/img/img_sample_book2.png
      699  01-01-1981 01:01   assets/flutter_assets/assets/translations/en-US.json
      699  01-01-1981 01:01   assets/flutter_assets/assets/translations/en.json
      769  01-01-1981 01:01   assets/flutter_assets/assets/translations/ko-KO.json
      769  01-01-1981 01:01   assets/flutter_assets/assets/translations/ko.json
     1684  01-01-1981 01:01   assets/flutter_assets/fonts/MaterialIcons-Regular.otf
      195  01-01-1981 01:01   assets/flutter_assets/packages/easy_localization/i18n/ar-DZ.json
      195  01-01-1981 01:01   assets/flutter_assets/packages/easy_localization/i18n/ar.json
      185  01-01-1981 01:01   assets/flutter_assets/packages/easy_localization/i18n/en-US.json
      185  01-01-1981 01:01   assets/flutter_assets/packages/easy_localization/i18n/en.json
     1688  01-01-1981 01:01   assets/flutter_assets/packages/flutter_inappwebview/t_rex_runner/t-rex.css
    82244  01-01-1981 01:01   assets/flutter_assets/packages/flutter_inappwebview/t_rex_runner/t-rex.html
     1337  01-01-1981 01:01   assets/flutter_assets/packages/fluttertoast/assets/toastify.css
     5272  01-01-1981 01:01   assets/flutter_assets/packages/fluttertoast/assets/toastify.js
  6865728  01-01-1981 01:01   assets/fonts/DaehanB.ttf
  1652220  01-01-1981 01:01   assets/fonts/DaehanR.ttf
   403792  01-01-1981 01:01   assets/fonts/NotoSansKR-Black-Hestia.otf
   364276  01-01-1981 01:01   assets/fonts/NotoSansMedium.ttf
  1517972  01-01-1981 01:01   assets/fonts/koPub_Batang_Bold_subset.ttf
  1630840  01-01-1981 01:01   assets/fonts/koPub_Batang_Light_subset.ttf
  1581528  01-01-1981 01:01   assets/fonts/koPub_Batang_Medium_subset.ttf
   367940  01-01-1981 01:01   assets/fonts/notokr-regular.ttf
     2148  01-01-1981 01:01   assets/icomoon.ttf
     9210  01-01-1981 01:01   assets/icon_offline.png
    30783  01-01-1981 01:01   assets/images/PagesCenter.png
     1185  01-01-1981 01:01   assets/images/PagesStack.png
     5134  01-01-1981 01:01   assets/images/img_reading.png
 12980596  01-01-1981 01:01   assets/libffmpeg.so
    10010  01-01-1981 01:01   assets/lottie-reading.json
  2445592  01-01-1981 01:01   assets/m7a.   // AppGuard
  2872248  01-01-1981 01:01   assets/m8a.    // AppGuard
  2445592  01-01-1981 01:01   assets/mbi.      // AppGuard
     7182  01-01-1981 01:01   assets/millie_viewer_lottie_loading.json
       90  01-01-1981 01:01   assets/nPlayerSDK.lic
    36484  01-01-1981 01:01   assets/outlined-iconset.ttf
   516713  01-01-1981 01:01   assets/pdfViewer/dist/PDF.js
      941  01-01-1981 01:01   assets/pdfViewer/dist/PDF.js.LICENSE.txt
   101409  01-01-1981 01:01   assets/pdfViewer/dist/app.js
      778  01-01-1981 01:01   assets/pdfViewer/dist/index.html
   944598  01-01-1981 01:01   assets/pdfViewer/dist/js/pdf.worker.min.js
     1660  01-01-1981 01:01   assets/playliststest.xml
   170126  01-01-1981 01:01   assets/snow_fall.json
     1524  01-01-1981 01:01   assets/sql/Books.sql
      692  01-01-1981 01:01   assets/sql/book.ddl
      343  01-01-1981 01:01   assets/sql/bookmark.ddl
      434  01-01-1981 01:01   assets/sql/highlight.ddl
      205  01-01-1981 01:01   assets/sql/itemRef.ddl
      362  01-01-1981 01:01   assets/sql/paging.ddl
     1445  01-01-1981 01:01   assets/sql/setting.ddl
      136  01-01-1981 01:01   assets/supplierconfig.json
     1905  01-01-1981 01:01   assets/viewer_network.html
     1919  01-01-1981 01:01   assets/viewer_offline.html
     1106  01-01-1981 01:01   assets/viewer_online.html
     1561  01-01-1981 01:01   assets/viewer_system.html
        0  01-01-1981 01:01   assets/voice/ko_kr/18_millie_pttsM.key
       78  01-01-1981 01:01   assets/voice/ko_kr/config/config.0
       80  01-01-1981 01:01   assets/voice/ko_kr/config/config.1
       78  01-01-1981 01:01   assets/voice/ko_kr/config/config.4
       74  01-01-1981 01:01   assets/voice/ko_kr/config/config.7
      355  01-01-1981 01:01   assets/voice/ko_kr/config/config.eff
      309  01-01-1981 01:01   assets/voice/ko_kr/config/config.opt
  3531736  01-01-1981 01:01   assets/voice/ko_kr/db.maru.160316.160315/hcihts.db
   246484  01-01-1981 01:01   assets/voice/ko_kr/db.maru.160316.160315/hcihts.tr
  1168624  01-01-1981 01:01   assets/voice/ko_kr/db.maru.160316.160315/hcihtsw.db
    83736  01-01-1981 01:01   assets/voice/ko_kr/db.maru.160316.160315/hcihtsw.tr
  3372120  01-01-1981 01:01   assets/voice/ko_kr/db.minjun.130314.130321/hcihts.db
   202608  01-01-1981 01:01   assets/voice/ko_kr/db.minjun.130314.130321/hcihts.tr
  1436328  01-01-1981 01:01   assets/voice/ko_kr/db.minjun.130314.130321/hcihtsw.db
    94848  01-01-1981 01:01   assets/voice/ko_kr/db.minjun.130314.130321/hcihtsw.tr
  3045392  01-01-1981 01:01   assets/voice/ko_kr/db.sujin.130129.140905/hcihts.db
   194232  01-01-1981 01:01   assets/voice/ko_kr/db.sujin.130129.140905/hcihts.tr
  1297576  01-01-1981 01:01   assets/voice/ko_kr/db.sujin.130129.140905/hcihtsw.db
    74452  01-01-1981 01:01   assets/voice/ko_kr/db.sujin.130129.140905/hcihtsw.tr
  6598880  01-01-1981 01:01   assets/voice/ko_kr/db.yujin.130408.121226/hcihts.db
   676812  01-01-1981 01:01   assets/voice/ko_kr/db.yujin.130408.121226/hcihts.tr
  1054520  01-01-1981 01:01   assets/voice/ko_kr/db.yujin.130408.121226/hcihtsw.db
    78744  01-01-1981 01:01   assets/voice/ko_kr/db.yujin.130408.121226/hcihtsw.tr
      677  01-01-1981 01:01   assets/voice/ko_kr/dict/0pronB.dat.new
      677  01-01-1981 01:01   assets/voice/ko_kr/dict/1pronB.dat.new
      677  01-01-1981 01:01   assets/voice/ko_kr/dict/4pronB.dat.new
      677  01-01-1981 01:01   assets/voice/ko_kr/dict/7pronB.dat.new
   234072  01-01-1981 01:01   assets/voice/ko_kr/dict/pron_new.FST
   206165  01-01-1981 01:01   assets/voice/ko_kr/dict/pron_new.dat.new
     5224  01-01-1981 01:01   assets/voice/ko_kr/dict/pronsd0.FST
      137  01-01-1981 01:01   assets/voice/ko_kr/dict/pronsd0.dat.new
    10256  01-01-1981 01:01   assets/voice/ko_kr/dict/pronsd1.FST
      419  01-01-1981 01:01   assets/voice/ko_kr/dict/pronsd1.dat.new
     1175  01-01-1981 01:01   assets/voice/ko_kr/dict/user.dic
     9064  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/CnxtUniProb.dat.new
     7505  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/CnxtUniProb.idx
     5952  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/Connect.FST
      210  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/Connect.dat.new
     3721  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/Connect.idx
   133600  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/name.FST
    15741  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/name.dat.new
    18701  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/post.dat
    31504  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/pre.FST
    25254  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/pre.dat.new
   698640  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/sait.FST
   615834  01-01-1981 01:01   assets/voice/ko_kr/kmorphdic/sait.dat.new
    11656  01-01-1981 01:01   assets/voice/ko_kr/kor_effdb/effectdata/e1.pcm
    13646  01-01-1981 01:01   assets/voice/ko_kr/kor_effdb/effectdata/e2.pcm
    16486  01-01-1981 01:01   assets/voice/ko_kr/kor_effdb/effectdata/e3.pcm
       54  01-01-1981 01:01   assets/voice/ko_kr/kor_effdb/effectidx.txt
     8651  01-01-1981 01:01   assets/voice/ko_kr/kor_pros/korprd.bin0
     8651  01-01-1981 01:01   assets/voice/ko_kr/kor_pros/korprd.bin1
     8651  01-01-1981 01:01   assets/voice/ko_kr/kor_pros/korprd.bin4
     8651  01-01-1981 01:01   assets/voice/ko_kr/kor_pros/korprd.bin7
     4063  01-01-1981 01:01   assets/voice/ko_kr/prsc/bigram.idx
   126688  01-01-1981 01:01   assets/voice/ko_kr/prsc/casef.FST
   127290  01-01-1981 01:01   assets/voice/ko_kr/prsc/casef.dat.new
    34701  01-01-1981 01:01   assets/voice/ko_kr/prsc/grammar.idx
   142512  01-01-1981 01:01   assets/voice/ko_kr/prsc/sm_dic.FST
   119504  01-01-1981 01:01   assets/voice/ko_kr/prsc/sm_dic.dat.new
     7076  01-01-1981 01:01   assets/voice/ko_kr/table/VH.tbl0
     7076  01-01-1981 01:01   assets/voice/ko_kr/table/VH.tbl1
     7076  01-01-1981 01:01   assets/voice/ko_kr/table/VH.tbl4
     7076  01-01-1981 01:01   assets/voice/ko_kr/table/VH.tbl7
     4348  01-01-1981 01:01   assets/voice/ko_kr/table/VV.tbl0
     4348  01-01-1981 01:01   assets/voice/ko_kr/table/VV.tbl1
     4348  01-01-1981 01:01   assets/voice/ko_kr/table/VV.tbl4
     4348  01-01-1981 01:01   assets/voice/ko_kr/table/VV.tbl7
    24579  01-01-1981 01:01   assets/voice/ko_kr/table/cdp.dat.new
     3536  01-01-1981 01:01   assets/voice/ko_kr/table/english.bg
enovella commented 10 months ago

Some NHN AppGuard applied apps lack classesN.jet / zip files. https://apkcombo.com/밀리의서재/kr.co.millie.millieshelf/download/phone-5.8.0.0-apk Modifying rule appguard_b like below might solve the issue...?

  condition:
    is_apk and (1 of ($b*) and 1 of ($c*)) 

It doesn't. Let me check why its not matching my sample and your new sample.

No classes.jet or classes.zip at all @dustty0


> apkid sample2.apk
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] sample2.apk
 |-> packer : AppGuard (TOAST-NHNent)
[*] sample2.apk!classes.dex
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes2.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, network operator name check, possible VM check, ro.kernel.qemu check
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes3.dex
 |-> anti_debug : Debug.isDebuggerConnected() check
 |-> anti_vm : Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, device ID check, network operator name check, possible VM check
 |-> compiler : dexlib 2.x
 |-> protector : WhiteCryption
[*] sample2.apk!classes4.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.TAGS check
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes5.dex
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes6.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, possible VM check
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes7.dex
 |-> compiler : dexlib 2.x
[*] sample2.apk!classes8.dex
 |-> anti_vm : Build.BOARD check, Build.MANUFACTURER check, device ID check, possible VM check
 |-> compiler : dexlib 2.x
[*] sample2.apk!lib/arm64-v8a/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] sample2.apk!lib/armeabi-v7a/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] sample2.apk!lib/x86/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
[*] sample2.apk!lib/x86_64/libSecureKeyBoxJava.so
 |-> protector : WhiteCryption
enovella commented 10 months ago

Got it fixed thanks @dustty0 !

> apkid Project_WorldChampion_2.6.0_apkcombo.com.apk
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] Project_WorldChampion_2.6.0_apkcombo.com.apk
 |-> packer : AppGuard (TOAST-NHNent)
[*] Project_WorldChampion_2.6.0_apkcombo.com.apk!classes.dex
 |-> compiler : dexlib 2.x
[*] Project_WorldChampion_2.6.0_apkcombo.com.apk!classes2.dex
 |-> anti_debug : Debug.isDebuggerConnected() check
 |-> anti_vm : Build.BRAND check, Build.DEVICE check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, possible VM check
 |-> compiler : unknown (please file detection issue!)
 |-> yara_issue : yara issue - dex file recognized by apkid but not yara module