Advanced APK Investigation | Android Malware
Cyber criminals have started moving towards android malwares to steal OTPs, user information etc. When a victim reports such APK, it needs a reverse engineering to catch the criminal. Here are the steps for the same.
- APK Download and upload on VirusTotal
- Upload the downloaded APK on virustotal.com
2. Use Behavior Tab and click on “Full Reports”
3. Click on Zenbox for seeing the advanced report.
4. Sample link while clicking on Zenbox
5. Network Traffic Information
Investigation Steps:
- Network traffic is seen to be hitting the URL https://kycgigi-22d4c-default-rtdb.firebaseio.com
Firebase is a product of Google, next step would be to seek information through Google LERS portal for above URL seeking details like:
- Google Cloud Project Information
- Google Cloud Customer Information
- Email Address
- Login History
- Payment Mode
This can be further used to get information and exact information of cyber criminal.