Purple computer monitor icon displaying binary code made of ones and zeros on a light background.

Conference/Workshop:
17th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob)

Published: 2021

Primary Author: Chen Shi

Secondary Authors: Chris Chao-Chun, Yong Guan

Research Area: Digital

Android is the most popular operating system among mobile devices and the malware targeted explicitly for Android is rapidly growing and spreading across the mobile ecosystem. In this paper, we propose a hybrid analysis of Android malware to retrieve evidential data, generated from or accessed by such mobile malware, which can be adopted as critical evidence for civil and criminal cases. We target on Android malware from Joker Family where we collected and analyzed 62 recently discovered malicious apps, we found that: 11 apps access and store user’s location information, 17 apps track user’s SMS text messages and 58 apps send out user personal information to remote servers. Our proposed approach found that, evidence data including location, timestamp, IP address are still able to be identified from the local file system and logging system. Our main contribution in this research is to provide an effective forensic analysis report on Android malware that can extract critical evidence from the local file systems as well as system logs.


Related Resources

A thick gray wavy line forming an abstract, looping shape on a light gray background.

An Introduction to the Forensic Handwriting Analysis Software handwriter

July 18, 2025

Blue shoeprint with a tread pattern on a white background.

Forensic Footwear: A Retrospective of the Development of the MANTIS Shoe Scanning System

July 10, 2025

There currently are no shoe-scanning devices developed in the United States that can operate in a real-world, variable-weather environment in …

A green fingerprint icon on a light gray background.

Examiner consistency in perceptions of fingerprint minutia rarity

July 10, 2025

Friction ridge examiners (FREs) identify distinctive features (minutiae) in fingerprints and consider how rare these observed minutiae are in their …