12345

12/16/2011

[Information] Automatic detection and analysis system of malicious Android application

1. Information

INCA Internet Security Response Center's Emergency Response Team has gathered Android malicious files for immediate response since July 2011. To collect and analyze automatically, we developed automation system which is using malicious similarity policy.
With this automation system, we have stocked about 2,000 Android malicious files.
The number of Android malicious apps is more than we thought.
 


We already know that the number of Android malicious file is rapidly increasing from the beginning in the second half; however, certain malicious file aiming at Korean users hasn't been reported.
Therefore, Korean users are not familiar with these security threats.

[Information] Malicious Android app for multiple countries
http://en-erteam.nprotect.com/2011/12/information-malicious-android-app-for.html

[Information] Android malicious application in Europe
http://en-erteam.nprotect.com/2011/12/information-android-malicious.html

[Information] Status for Android-based mobile malicious file
http://en-erteam.nprotect.com/2011/11/information-status-for-android-based.html

INCA Internet Security Response Center's Emergency Response Team has been preparing response system for Android security threats.

2. Status of Android file collection

December 6, 2011, Google announced that the number of cumulative download on Android market passed 10 billion downloads. And APK files are spreading on 3rd party market.


According to Google's announcement, Korea ranked #1, which means that South Korea is the most prevalent country on using smartphone.
The fact that China isn't ranked in this table is peculiar, however, it can mean that the great number of users are using 3rd party in China.

Following figure is top 10 most App-crazed Countries.


INCA Internet Security Response Center's Emergency Response Team has collected various malicious files with the 3rd party market's information.


Chinese 3rd party market

Our automatic APK crawling system has collected about 57,000 files (153Gb) and new apps are downloading every day.

In 2012, the range of 3rd party and processing capacity will be widening.

Following figure shows downloading status of our Automatic collecting system of APK files.
We are using this program to download APK files.

Among we collected, There are about 2,000 malicious APK files including Geinimi, ADRD, BaseBrid, GoldDream, DroidKungFu, SendSMS, FakeInstall, GingerMaster, Rooter and so on. And their various variants are also identified.

Following folder size is our collected APKs and those will be included our nProtect Mobile for ANDROID.


With this program, we succeeded to shorten more than 80% to analyze APK files on classifying its variants automatically.
Following figure shows auto-decompiled and analyzed target file by our automation analysis system.
First of all, it extracts Manifest log and Decompiled code for analyzing code. Then it compares extracted code to INCA Internet's malicious pattern. If it matches each other, those files will be moved to malicious sample folder. (More than 98% files of them were revealed as malicious).


3. Finishing

The fact that Android malicious file has been rapidly increasing is very remarkable. Malicious attackers are aiming at various target; therefore, users need to be careful on using.

Following figure is our detecting status of nProtect Mobile for ANDROID.



To use smartphone safely from security threats of these malicious applications, we recommend following tips "Smartphone security management tips" for general users.


Smartphone security management tips

1. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
2. Download the proven application by multiple users at all times.
3. Use mobile anti-virus SW to check downloaded application before using it.
4. Do not visit suspicious or unknown site via smartphone.
5. Try not to see MMS, text, e-mail from uncertain user.
6. Set strong password on smartphone always.
7. Turn the wireless interfaces like Bluetooth only be used.
8. Do not save important information on phone.
9. Do not try illegal customizing like rooting or jailbreak.

INCA Internet (Security Response Center / Emergency Response Team) provides diagnosis/treatment function with “nProtect Mobile for Android” for mobile such as malicious file stated above and runs responding system against various security threats.

34 comments:

  1. Very informative article thanks a lot for sharing it. Learnt so much about malware detection of android apps.

    ReplyDelete
  2. You can use different application to find really useful info. Just take a look here and you will see useful writing info I found recently.

    ReplyDelete
  3. Hi, great to see your website. I like the content and the research done behind every aspect of your blog. It looks great and very knowledgeable. Keep it up the good work. Little Big City 2 Mod Apk Latest Version

    ReplyDelete
  4. Thanks for sharing, nice post! Post really provice useful information!

    Giaonhan247 chuyên dịch vụ gửi hàng đi pháp, dịch vụ gửi hàng đi anh giá rẻ cũng như gửi hàng đi đài loan giá rẻ và dịch vụ gửi hàng đi singapore cùng với dịch vụ gửi hàng đi thái lan và dịch vụ gửi hàng đi nga giá rẻ, uy tín nhất.

    ReplyDelete
  5. Jane is rolled up, no gangs be throwed up but still Andre got action, they Sweat like Keith, all on my teeth check this out.

    ReplyDelete
  6. If you've decided to pay for essay, there is a great writing service - PayForEssay. We can write any type of paper from essays, assignments, and coursework to research papers and dissertations. Contact us anytime you need and we will provide you with a subject matter expert who will make your essay perfect.

    ReplyDelete

  7. This is really good blog information thanks for sharing .I am really impressed with your writing abilities

    โปรโมชั่นGclub ของทางทีมงานตอนนี้แจกฟรีโบนัส 50%
    เพียงแค่คุณสมัคร Gclub กับทางทีมงานของเราเพียงเท่านั้น
    ร่วมมาเป็นส่วนหนึ่งกับเว็บไซต์คาสิโนออนไลน์ของเราได้เลยค่ะ
    สมัครสล็อตออนไลน์ >>> goldenslot
    สนใจร่วมลงทุนกับเรา สมัครเอเย่น Gclub คลิ๊กได้เลย

    ReplyDelete
  8. Excellent Post as always and you have a great post and i like it thank you for sharing


    เว็บไซต์คาสิโนออนไลน์ที่ได้คุณภาพอับดับ 1 ของประเทศ
    เป็นเว็บไซต์การพนันออนไลน์ที่มีคนมา สมัคร Gclub Royal1688
    และยังมีหวยให้คุณได้เล่น สมัครหวยออนไลน์ ได้เลย
    สมัครสมาชิกที่นี่ >>> Gclub Royal1688
    ร่วมลงทุนสมัครเอเย่นคาสิโนกับทีมงานของเราได้เลย

    ReplyDelete
  9. Another way for you to find the malicious Android application is , Go to the Google Play Store and download and install AVG AntiVirus for Android.Open the app and tap the Scan button.Wait while the app scans and checks your apps and files for any malicious software.If a threat is found, tap Resolve.I think it is also an easy way.

    ReplyDelete
  10. Thank for your writting. It has a lot of knowledge that I need
    return man 2

    ReplyDelete
  11. This is a great blog. Please consider taking a look at our website Online Assignment Expert. We provide students with the best Online assignment help Our team comprises of over 5000 qualified subject experts from various fields and assist students in scoring excellent grades in their assignment. Our Online Nursing assignment help is the newest academic service launched by our Nursing assignment writing experts. Thousands of students rely on us due to our 24*7 availability, high-quality and plagiarism-free dissertations, and 100% timely delivery of work. Now, it’s easy to get professional dissertation writing help from experienced academic helpers!

    ReplyDelete
  12. This article is really fantastic and thanks for sharing the valuable post
    vex 4

    ReplyDelete
  13. The information you shared with us was very helpful.

    ReplyDelete
  14. Useful article, thank you for sharing the article!!!

    Website: bloggiaidap247.com giúp bạn giải đáp bash là gì hay bash idol là gì và nhiều thông tin hữu ích

    ReplyDelete
  15. Your blog was quite informative and will prove to be of value in the lives of the people. I would like to drive your attention to the services that respond to the student’s worries. Our Economics assignment help service is a type of service which has been providing academic assistance to students from the last decade. We have a number of professional experts who can handles all your assignments such as essay, reports, thesis, even academic blog writing help. Students one or the other way do not able to find time for their assignments because their hands become full as soon as they enrol in the universities. With a lot of subjects and less time, they go and search for ‘pay to do my assignment’ queries because they are quite not sure about any such services. However, My Assignment Services is a platform to get a quality economics assignment help at affordable prices.

    ReplyDelete
  16. This article is really fantastic and thanks for sharing the valuable post.
    manga kiss

    ReplyDelete
  17. I would like to thank you for the efforts you have made in writing this article.I would like to thank you for the efforts you have made in writing this article.
    cool math run 2

    ReplyDelete
  18. It is undisputed that Buy Essay Online pose challenges for students since preparation takes into consideration a lot of details, prominent analytical Custom Biology Papers Services and in-depth knowledge on the topic.

    ReplyDelete
  19. Great post i must say and thanks for the information. I appreciate your post and look forward to more.
    My Assignment Help
    Assignment Help

    ReplyDelete
  20. You should not worry too much when you encounter ERROR VIDEO_SCHEDULER_INTERNAL_ERROR IN WINDOWS 10
    After all, this Blue Screen of Death error is a common occurrence on various versions of the Windows operating system. It is easy to find fixes for the Video Scheduler Internal error because many people have been affected by this issue. In this post, we are going to share the solutions with you.

    If you receive the error message “The program cannot start because MSVCP140.dll is missing MSVCP140.dll is missing on the computer” or “The code execution cannot be continued because the system did not detect the MSVCP140.dll” while trying to open a program such as WAMP Server, Skype.

    ReplyDelete
  21. Demek olar axtardıgımız saytı da tapmaq ucun ilk önce axtarıs sistemlerine bas cekirik. Buna gore de axtarıs saytlarından birisi ya ev sehifesi secilir, ya da susmaya gore axtarıs sistemi kimi seçilir ki, yanlıs yazılmış URL sonucunda verilmis saytlardan secim etmek mumkun olsun. Bu axtarıs sistemleri daxil edilmis soze gore axtarısı onceden yaratmıs oldugu bazasında aparır.axtarıs sistemleri
    (search engines) bir cox hallarda internete girisin baslangıc nöqteleri olur.

    ReplyDelete

  22. .

    It is quite simple to get Azerbaijan Visa for British citizens
    , it should only take you about 20 minutes to complete, and you can do it at all hours, day or night.

    The citizens of US who want to travel to Azerbaijan can now apply entirely online. The cost of the Azerbaijan visa for US citizens
    depends on one thing: the processing time. iVisa puts at your disposal three excellent options, and you can choose whichever you find suitable.

    ReplyDelete
  23. You will take a lot of new emotions and lifetime impressions from a day tour. https://private-tours-baku.com/tour/private-baku-city-tour/ are about exploring the capital of Azerbaijan where modern European architecture of the Flame Towers is neighbouring with the ancient Maiden Tower in the Old Town .

    Start exploring Baku with https://private-tours-baku.com/tour/icherisheher-tour/
    . Icheri Sheher is the heart of the city, has a history of thousands of years and is located in the historic centre of ancient Baku. Icherisheher is the pearl of Azerbaijani architecture and culture and many significant restoration works have been undertaken within recent years

    ReplyDelete
  24. This comment has been removed by the author.

    ReplyDelete
  25. Discover the fabulous highlights of Baku on our https://guidedazerbaijan.com/tour/baku-city-tour/
    . Starting in Baku, you will explore the awe-inspiring architectural and cultural legacy of this capital. Explore Baku Old City, the Shirvanshahs’ Palace and the Maiden Tower

    Gabala is a beautiful part of Azerbaijan with a rich and ancient history. We offer you an unforgettable individual (with the private car) https://guidedazerbaijan.com/tour/gabala-tour/
    with our tour guide.

    ReplyDelete
  26. The most convenient issue is that you can access the Affordable Editing Services at any time and location as long as you have Internet connectivity. You are offered the Dissertation Literature Review by the agency.

    ReplyDelete