Automatic malicious APK extraction from phishing sites

Extracting malicious APKs
Behavior-based detection
Easy integration construction
Product Overview
GetAPK is Korea's first automated malicious APK extraction solution that automatically detects, extracts, and analyzes malicious mobile applications (APKs) linked to phishing sites. It is a malicious APK response solution that identifies and secures malicious APKs through phishing URL analysis and user behavior-based simulation techniques, and prevents personal information leaks in advance.

Key Advantages

01. Patent registration for related technology
METHOD, DEVICE AND SYSTEM FOR MALWARE EXTRACTION AND MANAGING FROM PHISING WEBSITE (Patent No. 10-2673878)
02. Responding to various types of phishing
Support for extended analysis techniques that include both targeted phishing attacks requiring user input and general phishing.
03. User Behavior-Based Simulation
Simulates actual user behavior to learn the optimal download path and automatically extracts malicious APKs based on this.
04. Flexible integration options
Easy integration with corporate assets and security systems through on-premise deployment, REST API, etc.
05. Support for safe storage and follow-up analysis
The extracted APK is safely stored in a designated storage, and various information can be extracted for future reverse engineering or threat intelligence analysis.

Analysis Process

APK Extraction Request 1 URL Normalization 2 Access to Phishing Site 3 Phishing Site Analysis 4 Phishing Site Attack 5 APK Download 6 APK Storage and Analysis 7
APK Extraction Request 1 URLNormalization 2 Access to Phishing Site 3 Phishing Site Analysis 4 Phishing Site Attack 5 APK Download 6 APK Storage and Analysis 7

Core Functions

Phishing URL normalization and analysis
Cleans up similar and special characters and automatically tracks redirects to their final destination.
APK linkage detection based on phishing source code
Automatically identify APK download connection points through HTML, script, and link analysis.
Path pattern-based APK download
Automatic APK download by generating simulation paths based on user behavior
Download exploiting security vulnerability attack vectors
Analyze phishing site structure and vulnerabilities to secure APKs through optimal routes.
Extract and save APK information
Extract and store key APK threat information such as hash, certificate, and C2 IP.
REST API and integration services
Automatic integration with security, forensics, and SIEM systems based on API