{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T12:07:55Z","timestamp":1768738075573,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,5,27]],"date-time":"2018-05-27T00:00:00Z","timestamp":1527379200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,5,27]]},"DOI":"10.1145\/3197231.3197239","type":"proceedings-article","created":{"date-parts":[[2018,7,23]],"date-time":"2018-07-23T13:02:25Z","timestamp":1532350945000},"page":"2-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["ARES"],"prefix":"10.1145","author":[{"given":"Luciano","family":"Bello","sequence":"first","affiliation":[{"name":"IBM Research"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marco","family":"Pistoia","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,5,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Avast: Android banker trojan preys on credit card information (2016) https:\/\/blog.avast.com\/android-banker-trojan-preys-on-credit-card-information\/  Avast: Android banker trojan preys on credit card information (2016) https:\/\/blog.avast.com\/android-banker-trojan-preys-on-credit-card-information\/"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23465"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.30"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30579-8_23"},{"key":"e_1_3_2_1_5_1","unstructured":"Gilboy M.R.: Fighting Evasive Malware with DVasion. Master's thesis University of Maryland College Park USA (2016)  Gilboy M.R.: Fighting Evasive Malware with DVasion. Master's thesis University of Maryland College Park USA (2016)"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/2486788.2486799"},{"key":"e_1_3_2_1_7_1","unstructured":"Google: UI\/application exerciser monkey | android studio. https:\/\/developer.android.com\/studio\/test\/monkey.html (2017) accessed: 2017-06-08  Google: UI\/application exerciser monkey | android studio. https:\/\/developer.android.com\/studio\/test\/monkey.html (2017) accessed: 2017-06-08"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/356651.356652"},{"key":"e_1_3_2_1_9_1","unstructured":"Jiang X.: Security alert: New Android malware - DroidCoupon - found in alternative Android markets (2017) https:\/\/www.csc.ncsu.edu\/faculty\/jiang\/DroidCoupon\/  Jiang X.: Security alert: New Android malware - DroidCoupon - found in alternative Android markets (2017) https:\/\/www.csc.ncsu.edu\/faculty\/jiang\/DroidCoupon\/"},{"key":"e_1_3_2_1_10_1","unstructured":"Kaufman J.: icdiff - side-by-side highlighted command line diffs. http:\/\/www.jefftk.com\/icdiff accessed: 2017-06-08  Kaufman J.: icdiff - side-by-side highlighted command line diffs. http:\/\/www.jefftk.com\/icdiff accessed: 2017-06-08"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813642"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 23rd USENIX Conference on Security Symposium. pp. 287--301. SEC'14, USENIX Association","author":"Kirat D.","year":"2014"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046740"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.48"},{"key":"e_1_3_2_1_15_1","unstructured":"Koriat O.: In the wild: Google can't close the door on android malware | check point blog. http:\/\/blog.checkpoint.com\/2016\/04\/22\/in-the-wild-google-cant-close-the-door-on-android-malware\/ (2016)  Koriat O.: In the wild: Google can't close the door on android malware | check point blog. http:\/\/blog.checkpoint.com\/2016\/04\/22\/in-the-wild-google-cant-close-the-door-on-android-malware\/ (2016)"},{"key":"e_1_3_2_1_16_1","unstructured":"Kruegel C.: Full system emulation: Achieving successful automated dynamic analysis of evasive malware  Kruegel C.: Full system emulation: Achieving successful automated dynamic analysis of evasive malware"},{"key":"e_1_3_2_1_17_1","unstructured":"Mobile N.: Fee-deduction malware targeting android devices spotted in the wild. https:\/\/www.netqin.com\/en\/security\/newsinfo<sub>4<\/sub>202<sub>1<\/sub>.html (2011) accessed: 2017-06-08  Mobile N.: Fee-deduction malware targeting android devices spotted in the wild. https:\/\/www.netqin.com\/en\/security\/newsinfo<sub>4<\/sub>202<sub>1<\/sub>.html (2011) accessed: 2017-06-08"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.17"},{"key":"e_1_3_2_1_19_1","unstructured":"Mourad H.: Sleeping your way out of the sandbox. SANS Institute InfoSec Reading Room (2015)  Mourad H.: Sleeping your way out of the sandbox. SANS Institute InfoSec Reading Room (2015)"},{"key":"e_1_3_2_1_20_1","unstructured":"Musil S.: Malware went undiscovered for weeks on google play (2012) https:\/\/www.cnet.com\/news\/malware-went-undiscovered-for-weeks-on-google-play\/  Musil S.: Malware went undiscovered for weeks on google play (2012) https:\/\/www.cnet.com\/news\/malware-went-undiscovered-for-weeks-on-google-play\/"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818036"},{"key":"e_1_3_2_1_22_1","unstructured":"Oberheide J. Miller C.: Dissecting the android bouncer. https:\/\/duo.com\/blog\/dissecting-androids-bouncer (2012) accessed: 2017-06-08  Oberheide J. Miller C.: Dissecting the android bouncer. https:\/\/duo.com\/blog\/dissecting-androids-bouncer (2012) accessed: 2017-06-08"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2592791.2592796"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Rasthofer S. Arzt S. Miltenberger M. Bodden E.: Harvesting runtime values in android applications that feature anti-analysis techniques. In: NDSS (2016)  Rasthofer S. Arzt S. Miltenberger M. Bodden E.: Harvesting runtime values in android applications that feature anti-analysis techniques. In: NDSS (2016)","DOI":"10.14722\/ndss.2016.23066"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 6<sup>th<\/sup> European Workshop on System Security (EUROSEC). Prague, Czech Republic (April 2013)","author":"Reina A."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_3_2_1_27_1","unstructured":"Singh A. Bu Z.: Hot knives through butter: Evading file-based sandboxes. Threat Research Blog (2013)  Singh A. Bu Z.: Hot knives through butter: Evading file-based sandboxes. Threat Research Blog (2013)"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Smaragdakis Y. Balatsouras G. Kastrinis G. Bravenboer M.: More Sound Static Handling of Java Reflection pp. 485--503. Springer International Publishing Cham (2015) <sub>2<\/sub>6  Smaragdakis Y. Balatsouras G. Kastrinis G. Bravenboer M.: More Sound Static Handling of Java Reflection pp. 485--503. Springer International Publishing Cham (2015) <sub>2<\/sub>6","DOI":"10.1007\/978-3-319-26529-2_26"},{"key":"e_1_3_2_1_29_1","unstructured":"Strazzere T.: Security alert: Malware found targeting custom ROMs (jSMSHider). https:\/\/blog.lookout.com\/blog\/2011\/06\/15\/security-alert-malware-found-targeting-custom-roms-jsmshider\/ (2017)  Strazzere T.: Security alert: Malware found targeting custom ROMs (jSMSHider). https:\/\/blog.lookout.com\/blog\/2011\/06\/15\/security-alert-malware-found-targeting-custom-roms-jsmshider\/ (2017)"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590325"},{"key":"e_1_3_2_1_31_1","volume-title":"Usenix Security.","author":"Wang T.","year":"2013"},{"key":"e_1_3_2_1_32_1","unstructured":"web: APKTool - a tool for reverse engineering android apk files. https:\/\/ibotpeaches.github.io\/Apktool\/ accessed: 2017-06-08  web: APKTool - a tool for reverse engineering android apk files. https:\/\/ibotpeaches.github.io\/Apktool\/ accessed: 2017-06-08"},{"key":"e_1_3_2_1_33_1","unstructured":"web: VirusTotal - free online virus malware and url scanner. https:\/\/www.virustotal.com\/ accessed: 2017-06-08  web: VirusTotal - free online virus malware and url scanner. https:\/\/www.virustotal.com\/ accessed: 2017-06-08"},{"key":"e_1_3_2_1_34_1","unstructured":"web: ASM kernel description. http:\/\/asm.objectweb.org\/ (2017) accessed: 2017-06-08  web: ASM kernel description. http:\/\/asm.objectweb.org\/ (2017) accessed: 2017-06-08"},{"key":"e_1_3_2_1_35_1","unstructured":"web: Dila - dynamic load-time instrumentation library for java. http:\/\/wala.sourceforge.net\/wiki\/index.php\/GettingStarted:wala.dila (2017) accessed: 2017-06-08  web: Dila - dynamic load-time instrumentation library for java. http:\/\/wala.sourceforge.net\/wiki\/index.php\/GettingStarted:wala.dila (2017) accessed: 2017-06-08"},{"key":"e_1_3_2_1_36_1","unstructured":"web: WALA - T.J. Watson libraries for analysis. http:\/\/wala.sourceforge.net\/(2017) accessed: 2017-06-08  web: WALA - T.J. Watson libraries for analysis. http:\/\/wala.sourceforge.net\/(2017) accessed: 2017-06-08"},{"key":"e_1_3_2_1_37_1","first-page":"5","article-title":"Andrubis: Android malware under the magnifying glass. Vienna University of Technology","volume":"1","author":"Weichselbaum L.","year":"2014","journal-title":"Tech. Rep. TRISECLAB-0414"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/2818754.2818793"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699105"},{"key":"e_1_3_2_1_40_1","unstructured":"Zhou Y. Jiang X.: An analysis of the anserverbot trojan (2011)  Zhou Y. Jiang X.: An analysis of the anserverbot trojan (2011)"}],"event":{"name":"ICSE '18: 40th International Conference on Software Engineering","location":"Gothenburg Sweden","acronym":"ICSE '18","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE-CS Computer Society"]},"container-title":["Proceedings of the 5th International Conference on Mobile Software Engineering and Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3197231.3197239","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3197231.3197239","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:07:17Z","timestamp":1750212437000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3197231.3197239"}},"subtitle":["triggering payload of evasive Android malware"],"short-title":[],"issued":{"date-parts":[[2018,5,27]]},"references-count":40,"alternative-id":["10.1145\/3197231.3197239","10.1145\/3197231"],"URL":"https:\/\/doi.org\/10.1145\/3197231.3197239","relation":{},"subject":[],"published":{"date-parts":[[2018,5,27]]},"assertion":[{"value":"2018-05-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}