Monday, 25 September 2017

Mobile Threats targeting Russian Banks

Targets (banks): 
ru.sberbankmobile (Sberbank of Russia / Сбербанк Онлайн), ru.alfabank.mobile.android (Alfa Bank / Альфа-Банк), ru.vtb24.mobilebanking.android (VTB24 / ВТБ24-Онлайн)

Friday, 23 June 2017

More on Android Trojan spying on Iranian users controlled via Telegram


IOCs

More samples with host URL and new Telegram Bots, details below:

0CFF8D65002CD6DFF2A6F79EEE6A25996AC7622452BC7A08BF55E4C540320812
https://navidtwobottt.000webhostapp.com/rat/
https://api.telegram.org/bot374463427

1D0770AC48F8661A5D1595538C60710F886C254205B8CF517E118C94B256137D
https://navidtwobottt.000webhostapp.com/rat
https://api.telegram.org/bot339912423

12A89CEF7D400222C61651ED5DF57A9E8F54FE42BC72ECEB756BB1315731F72D
https://navidtwobottt.000webhostapp.com/rat
https://api.telegram.org/bot391779082

47419E7E531C12C50134D21F486F6C4BF3A11983628D349599C6500ABCDB30F5
https://navidtwobottt.000webhostapp.com/rat
https://api.telegram.org/bot382578708

BFEB978B3998A18F852BE7012D82CB5C6F14DE67CD4C4521F3D5ACF0B01F987F
https://navidtwobottt.000webhostapp.com/rat
https://api.telegram.org/bot314010881

Hosting

NoteNo one of the names reported here are to be accused for anything. That's a collection of correlated info.

The samples shared by drweb, contain a URL the is registered to the details below. Will also be listed connected info found online:
  • Name: arash raso******h, آرش رسول زاده , 
  • E-mails: moh*******1396@gmail.com, arashrasoulzadeh@gmail.com
  • Hosts registered or connected:
    • dlappdev.ir
    • telememberapp.ir
    • http://varnacorp.com/
  • GitHub:
    • https://github.com/arashr*******deh?utf8=%E2%9C%93&tab=repositories&q=&type=fork&language=
    • Telegram related forks


Android binaries downloaded from dlappdev.ir have similarities with binaries that contain telememberapp.ir:



- Update - July 19, 2017

More info gathered by Iranian citizens here:
http://telescam.ir/home/2017/06/30/%D8%B1%D8%A7%D8%AA%D8%B1%D8%AA-%D8%A7%D9%86%D8%AF%D8%B1%D9%88%DB%8C%D8%AF-%D8%A7%DB%8C%D8%B1%D8%A7%D9%86%DB%8C-%D8%A8%D8%A7-%D8%B9%D9%86%D9%88%D8%A7%D9%86-%D8%A7%DB%8C%D9%86%D8%B3%D8%AA%D8%A7-%D9%85/

Developing ..

p.s. No one of the names reported here are to be accused for anything. That's a collection of correlated info.

Monday, 3 April 2017

Mobile Security Research - 2017 Q1

Mobile Security Research - 2017 Quarter 1 (Jan, Febr and March)


Presentations, articles, papers, ML (machine learning) on Mobile Security for the first quarter of 2017.

Enjoy!

Friday, 5 December 2014

Snippet : DeathRing Android Malware AES URL Decryption




In this blog post we'll be looking at a new malware named DeathRing that discovered recently by Lookout. Main focus of this post will be to describe briefly the decryption process (through source code re-construction) of the AES encrypted base URL that malware uses to communicate with the server.


Sunday, 28 September 2014

Android WipeLocker - Obey or be hacked





"Elite has hacked you.Obey or be hacked"

That's the message that you will see after this malware infection,
in your Inbox.

Malware Name: WipeLocker (?)
Operating System (OS): Android
SHA256: F75678B7E7FA2ED0F0D2999800F2A6A66C717EF76B33A7432F1CA3435B4831E0

Sunday, 22 June 2014

An introduction to gikdbg.art (aka Android Ollydbg) attaching Towelroot



gikdbg.art (Android Ollydbg)




This post will provide the following:
  • Introduction to gikdbg.art
  • Setup of the environment
  • Quick introduction on attaching the TowelRoot exploit (libexploit.so)

Thursday, 5 June 2014

Inside SimpLocker




Malware Name: Simplocker
Operating System (OS): Android
Credits to: ESET and Robert Lipovsky.


Thursday, 20 March 2014

Dex to Java decompiler (jadx)

Description from the site:
Command line and GUI tools for produce Java source code from Android Dex and Apk files
Note: jadx-gui now in experimental stage
A new decompiler that helps to translate dex files into a human readable Java code. In the current stage of development the exported results are impressive. In addition is fast and reliable. So check it out.

In addition it comes with an experimental gui. Testing it out with some dex files its stable for some fast malware analysis.

More info:


Saturday, 13 July 2013

Android Malware Analysis Distros














If you are a security researcher and you want to to do malware analysis on the Android platform, you must check the following Linux Distros.

  • REMnux [website]

    REMnux is a lightweight Linux distribution for assisting malware analysts with reverse-engineering malicious software.
  • Santoku  [website]

    Santoku is dedicated to mobile forensics, analysis, and security, and packaged in an easy to use, Open Source platform. 
     
  • Android Tamer [website] (added 21/06/14)
    Android Tamer is a Virtual / Live Platform for Android Security professionals.