rednaga / APKiD

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
Other
1.95k stars 286 forks source link

[DETECTION] Add libmsaoaidsec.so (no idea about name) #357

Open enovella opened 10 months ago

enovella commented 10 months ago

Blog

Further info

> ls -la tv*
-rw-r--r--@ 1 enovella  enovella   99703321 Aug 19 01:47 tv.danmaku.bili-6.89.0.apk
-rw-r--r--@ 1 enovella  enovella  111331669 Aug 19 02:03 tv.danmaku.bili_7.31.0.apk
-rw-r--r--@ 1 enovella  enovella  107958314 Aug 19 02:15 tv.danmaku.bili_v7.16.0.apk
> apkid tv.danmaku.bili_v7.16.0.apk
[+] APKiD 2.1.5 :: from RedNaga :: rednaga.io
[*] tv.danmaku.bili_v7.16.0.apk!classes.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, SIM operator check, device ID check, emulator file check, network operator name check, possible Build.SERIAL check, ro.kernel.qemu check, ro.product.device check, subscriber ID check
 |-> compiler : r8
[*] tv.danmaku.bili_v7.16.0.apk!classes10.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check, SIM operator check, possible Build.SERIAL check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes11.dex
 |-> anti_vm : Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes12.dex
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes13.dex
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes14.dex
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes15.dex
 |-> anti_vm : Build.MANUFACTURER check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes16.dex
 |-> anti_vm : Build.MANUFACTURER check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes17.dex
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes18.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.HARDWARE check, Build.MANUFACTURER check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes19.dex
 |-> anti_vm : Build.MANUFACTURER check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes2.dex
 |-> anti_vm : Build.MANUFACTURER check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes3.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, SIM operator check, device ID check, possible Build.SERIAL check, subscriber ID check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes4.dex
 |-> anti_vm : Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, possible Build.SERIAL check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes5.dex
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes6.dex
 |-> anti_vm : Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes7.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.MANUFACTURER check, SIM operator check, subscriber ID check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes8.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.MANUFACTURER check, possible ro.secure check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!classes9.dex
 |-> anti_vm : Build.BOARD check, Build.FINGERPRINT check, Build.MANUFACTURER check, Build.MODEL check, Build.PRODUCT check, Build.TAGS check, emulator file check, possible Build.SERIAL check, possible VM check, subscriber ID check
 |-> compiler : r8 without marker (suspicious)
[*] tv.danmaku.bili_v7.16.0.apk!lib/arm64-v8a/libbili.so
 |-> obfuscator : Obfuscator-LLVM version 5.0 (string encryption)

Package names

Yehh22 commented 10 months ago

See LibChecker's rules: https://github.com/LibChecker/LibChecker-Rules/blob/master/native-libs/libmsaoaidsec.so.json