Provide package name, version, APK SHA-256, certificate SHA-256, official download location, observation time, and exact label. For legitimate rotation, include publicly verifiable platform or store documentation and explain the relationship between old and new releases.
Verify installation and critical flows and confirm that no genuine malicious behavior is present before appealing. Remove email addresses, user identifiers, internal logs, keystores, and passwords that are not required. After a vendor update, retest the unchanged original sample so the outcome remains attributable.