Android Banker Deep Dive (Part 5)

  Рет қаралды 1,278

LaurieWired

LaurieWired

Күн бұрын

Part 5 of our Android Banker Deep Dive! In this video, we continue our analysis of the Android banking trojan by executing the sample and manually triggering broadcasts. We find multiple dynamically dropped files including the Shared Preferences settings and a SQL database.
---
In this [RE]laxing new series, I fully reverse a difficult Android Banker trojan from start to finish.
These extensive "Deep Dive" segments concentrate on dissecting malware specimens and delving into the individual approaches employed to fully reverse them. Throughout the journey, I attempt to provide explanations of my techniques as much as possible, however, if any ambiguities arise, please feel free to post a comment below.
Timestamps:
00:00 Intro
00:36 Booting Emulator
03:35 Watching the Dropper
05:05 Accessiblity Abuse
06:16 Can't click the button?
08:50 Drawing over other apps
09:45 Switching to an old Android version
11:02 Trying Android 8
13:00 Successful Install!
14:02 Dropped APK?
16:32 Broadcast Triggers
18:48 SMS Trigger
20:24 Dropping back to host
21:39 Database Creation
23:00 Web Data SQL
25:15 Shared Preferences XML
27:33 Recap
---
Software Links Mentioned in Video:
JADX: github.com/skylot/jadx
---
Malware Examined in the video (Banker/Anubis):
sha256:cae0c0d33e68be9cf81099680b815eb714d8296cb219b7a6247f7f081820f39a
MalwareBazaar Link:
bazaar.abuse.ch/sample/cae0c0...
---
laurieWIRED Twitter:
/ lauriewired
laurieWIRED Website:
lauriewired.com
laurieWIRED Github:
github.com/LaurieWired
laurieWIRED HN:
news.ycombinator.com/user?id=...
laurieWIRED Reddit:
/ lauriewired

Пікірлер: 5
@MohammedShuayb
@MohammedShuayb 3 ай бұрын
Another underrated youtube gem i just found thanks. Edit: oh a question what do you use to emulate androif
@frankjansson7563
@frankjansson7563 10 ай бұрын
Great video :) Getting into the workings of the app and uncover it's secrets, pure gold. I learn alot about Android in every video, thank you.
@sqaxomonophonen5998
@sqaxomonophonen5998 10 ай бұрын
"Web Data" can be explored with the sqlite3 command-line tool. But maybe I would be paranoid enough to only do it from a "secure malware analysis environment" :-)
@NTxC
@NTxC 10 ай бұрын
Lol'd at the system itself not letting you click Allow xD
@zg9xUmvV
@zg9xUmvV 2 ай бұрын
why do you still use windows? why?
Android Banker Deep Dive (Part 6)
27:54
LaurieWired
Рет қаралды 1,7 М.
Cybersecurity "Experts" suck at coding.  It's a problem.
15:12
LaurieWired
Рет қаралды 94 М.
Do you have a friend like this? 🤣#shorts
00:12
dednahype
Рет қаралды 45 МЛН
Cat story: from hate to love! 😻 #cat #cute #kitten
00:40
Stocat
Рет қаралды 14 МЛН
Tremendo troyano descubierto en Android
1:00
Isa Marcial
Рет қаралды 6 МЛН
NITEPUNK - FLOW
3:21
Nitepunk
Рет қаралды 11 М.
The Magic of RISC-V Vector Processing
16:56
LaurieWired
Рет қаралды 67 М.
Most overpowered way to build mobile apps?
8:33
Beyond Fireship
Рет қаралды 700 М.
5 New AI Tools You Should Try
9:18
Skill Leap AI
Рет қаралды 8 М.
Getting Started with Adalo | No-Code App Builder
5:41
Adalo
Рет қаралды 120 М.
What ACTUALLY happens during a Stack Overflow?
12:43
LaurieWired
Рет қаралды 122 М.
как спасти усилитель?
0:35
KS Customs
Рет қаралды 504 М.
Apple watch hidden camera
0:34
_vector_
Рет қаралды 51 МЛН
Обзор игрового компьютера Макса 2в1
23:34
How Neuralink Works 🧠
0:28
Zack D. Films
Рет қаралды 32 МЛН