Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DETECTION] Chinese protectors and packers #389

Open
enovella opened this issue Jun 9, 2024 · 0 comments
Open

[DETECTION] Chinese protectors and packers #389

enovella opened this issue Jun 9, 2024 · 0 comments
Labels
detection-issue Bad detection or no detection help wanted

Comments

@enovella
Copy link
Collaborator

enovella commented Jun 9, 2024

🛑🛑🛑
通付盾
Tongfu shield
https://tongfudun.com
https://m.tongfudun.com

🟢example:
com.kingdee.zhihuiji 6.25.22

assets/mode
assets/PK
assets/virtual
assets/libegis.a

lib/arm/libegis.so

com/payegis/FirstApplication
com.payegis.entry
egis
egis-x86

🛑🛑🛑
腾讯御安全企业版
Tencent Security Enterprise Edition
https://cloud.tencent.com/product/ms
http://www.fron.com.cn/yaq/

🟢example:
com.qidian.QDReader 7.9.352

assets/dexMethod_00oo1l1l.dat

lib/arm/libshell-supervbasic.2019.so
lib/arm/libshell-superv.2019.so

🛑🛑🛑
腾讯御安全
Tencent Security
https://cloud.tencent.com/product/ms
http://www.fron.com.cn/yaq/

🟢example:
www.imxiaoyu.com.musiceditor 6.6.8

assets/0OO00l111l1l
assets/o0oooOO0ooOo.dat
assets/t86
assets/t86_64
assets/tarm

lib/arm/libshell-super.www.imxiaoyu.com.musiceditor.so
lib/arm/libshella-4.5.4.1.so

www.imxiaoyu.com.musiceditor/MyWrapperProxyApplication
com/wrapper/proxyapplication

🛑🛑🛑
几维安全
Kiwi Security
http://t.www.kiwisec.com/product/android-encrypt.html

🟢example:
com.lynkco.customer 3.4.3

assets/crash
assets/ec_dt.lic
assets/kwpt.lincense

lib/arm/libkiwi_dumper.so
lib/arm/libkiwicrash.so
lib/arm/libKwProtectSDK.so
lib/arm/libkwsdataenc.so
lib/arm/libkadp.so

com/kiwisec/crash
com/kiwivm/security
com/kiwivm/security/StubApplication

🛑🛑🛑
爱加密企业版
iCrypt Enterprise Edition
https://www.ijiami.cn/android

🟢example:
cn.com.changan.cvim 5.2.7
com.xjbank.mbk 4.7.6
com.shinyv.cnr 7.1.5

assets/af.bin
assets/ijiami.ajm
assets/ijiami.dat
assets/IJMDal.Data
assets/signed.bin
assets/InteGration_4.5.1.ttf
assets/libijmDataEncryption.so
assets/libijmDataEncryption_arm64.so
assets/libijmDataEncryption_x86.so

lib/arm/libijm-emulator.so

s.h.e.l.l./

🛑🛑🛑
网易易盾
NetEase EasyShield
https://m.dun.163.com/product/android-reinforce

🟢example:
com.tmri.app.main 3.1.0
com.licaimofang.app 7.5.0
cn.ninebot.ninebot 6.6.0
cn.com.yunma.company.app 5.2.0

assets/nedata.db
assets/nedig.properties

lib/arm/libnesec.so
lib/arm/libnesec-x86.so
lib/arm/libnshelper.so
all libs size before 1kb (very little size)

com/netease/nis/wrapper
com/netease/nis/wrapper/MyApplication
s.h.e.l.l./

🛑🛑🛑
梆梆加固企业版
BangBang Reinforcement Enterprise Edition
https://www.bangcle.com

🟢example:
com.shuxun.autostreets 3.5.5
com.iss.rizhaobank 6.4.4.6
com.csii.ncepbank 5.5
com.cloudpower.netsale.activity 6.22.5
com.citicbank.comb 3.5.9
com.iss.qilubank 6.4.4.8

crypt files?
assets/autostreets.com_cert_chain.cer
assets/da.js
assets/img.autostreetscdn.com_cert.cer
assets/QMUIWebviewBridge.js
assets/info.y
assets/main.js
assets/weex-main-jsfm.js
assets/weex-rax-api.js
assets/weex-rax-extra-api.js

lib/arm/libDexHelper.so
lib/arm/libdexjni.so
lib/arm/libDexHelper-x86.so

com/secneo/apkwrapper

🛑🛑🛑
顶象加固
DingXiang Reinforcement
https://www.dingxiang-inc.com/business/android

🟢example:
com.saicmotor.tocapp 3.0.18
net.crigh.cgsport 2.9.7

com/security/shell/AppStub1
com/security/inner/stub000

@enovella enovella added the detection-issue Bad detection or no detection label Jun 9, 2024
@enovella enovella self-assigned this Jun 9, 2024
@enovella enovella removed their assignment Jul 30, 2024
AbhiTheModder added a commit to AbhiTheModder/APKiD that referenced this issue Nov 20, 2024
Closes
[DETECTION] Chinese protectors and packers rednaga#389
[DETECTION] KiwiSec ApkProtect rednaga#294
[DETECTION] Detect KiwiSec VM-based protector rednaga#234
enovella pushed a commit that referenced this issue Dec 8, 2024
* Add rule for kiwisec

Closes
[DETECTION] Chinese protectors and packers #389
[DETECTION] KiwiSec ApkProtect #294
[DETECTION] Detect KiwiSec VM-based protector #234

* fix indentation

* kiwisec: enhance rule
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
detection-issue Bad detection or no detection help wanted
Projects
None yet
Development

No branches or pull requests

1 participant