Android Banker Deep Dive (Part 6)

  Рет қаралды 1,767

LaurieWired

LaurieWired

Күн бұрын

Part 6 of our Android Banker Deep Dive! In this video, we inspect multiple class entrypoints defined in the Manifest of the application to clean up and summarize their behavior.
---
In this [RE]laxing new series, I fully reverse a difficult Android Banker trojan from start to finish.
These extensive "Deep Dive" segments concentrate on dissecting malware specimens and delving into the individual approaches employed to fully reverse them. Throughout the journey, I attempt to provide explanations of my techniques as much as possible, however, if any ambiguities arise, please feel free to post a comment below.
Timestamps:
00:00 Intro
00:39 Begin Analysis
01:19 Naming Activities
03:23 JADX Decompliation Settings
05:11 Service Investigation
08:17 Decoding Strings
09:55 Cleaning up Classes
13:25 More String Decoding!
17:35 Receivers
18:27 More Activites and Classes
21:47 Fixing Nested Classes
25:47 Editing Shared Preferences
27:20 Recap
---
Software Links Mentioned in Video:
JADX: github.com/skylot/jadx
---
Malware Examined in the video (Banker/Anubis):
sha256:cae0c0d33e68be9cf81099680b815eb714d8296cb219b7a6247f7f081820f39a
---
laurieWIRED Twitter:
/ lauriewired
laurieWIRED Website:
lauriewired.com
laurieWIRED Github:
github.com/LaurieWired
laurieWIRED HN:
news.ycombinator.com/user?id=...
laurieWIRED Reddit:
/ lauriewired

Пікірлер: 14
@randommoosebrains
@randommoosebrains 9 ай бұрын
Laurie on a roll with these videos
@Me.n_n
@Me.n_n 9 ай бұрын
Great 👍 Lauri , keep going ^^
@chrisking7603
@chrisking7603 2 ай бұрын
OK, it's evident that it scrapes user input and output and augments databases, but then what? The breadcrumbs to the perpetrators is most interesting part.
@muxerous
@muxerous 9 ай бұрын
Laurie can you make a series of videos about you smali for android app modifying?
@fredleckie5880
@fredleckie5880 9 ай бұрын
Huzzah!
@Spider0x00
@Spider0x00 7 ай бұрын
I figured out that the "write" that you wanted to reach is actually writing the settings that you showed not a second apk, now I wonder, Is that all?!!
@ethicalmath3963
@ethicalmath3963 9 ай бұрын
LET’S FUCKING GOOOOO
@NTxC
@NTxC 9 ай бұрын
15:13 Hate it too
@Heccintech
@Heccintech 9 ай бұрын
Have you considered making a discord
@noureddineziani9067
@noureddineziani9067 9 ай бұрын
What is your end game Laurie ?
@nickiascerinschi206
@nickiascerinschi206 2 ай бұрын
Aaaaaand she gave up ...
@gvnsvn9294
@gvnsvn9294 9 ай бұрын
Is this one of these channels where the guy is creating all the stuff or a team and they take a "pretty" face in the video to generate clicks? anyways it is good programming content.
@nbudzinski
@nbudzinski 9 ай бұрын
Could you elaborate? It's clear she's the one interacting with the machine, so "the guy is creating all the stuff or a team" is sort of out of the question. Does she use some help to edit the content? Nothing wrong with that if she does, many creators do just that.
@gvnsvn9294
@gvnsvn9294 9 ай бұрын
If i stand in front of a painting and have a pen in my hand it dosent mean that I painted it. @@nbudzinski
Cybersecurity "Experts" suck at coding.  It's a problem.
15:12
LaurieWired
Рет қаралды 96 М.
WorkManager - Android Basics 2023
34:22
Philipp Lackner
Рет қаралды 47 М.
Why You Should Always Help Others ❤️
00:40
Alan Chikin Chow
Рет қаралды 47 МЛН
WHY THROW CHIPS IN THE TRASH?🤪
00:18
JULI_PROETO
Рет қаралды 3,1 МЛН
Эффект Карбонаро и бесконечное пиво
01:00
История одного вокалиста
Рет қаралды 6 МЛН
Hot Ball ASMR #asmr #asmrsounds #satisfying #relaxing #satisfyingvideo
00:19
Oddly Satisfying
Рет қаралды 24 МЛН
Why didn't the Angular team just use RxJS instead of Signals?
8:15
Joshua Morony
Рет қаралды 85 М.
Mastering Memory: Allocation Techniques in C, C++, and ARM Assembly
17:05
What ACTUALLY happens during a Stack Overflow?
12:43
LaurieWired
Рет қаралды 129 М.
Why You Should Use Pydantic in 2024 | Tutorial
13:56
ArjanCodes
Рет қаралды 59 М.
The Magic of RISC-V Vector Processing
16:56
LaurieWired
Рет қаралды 168 М.
Use Arc Instead of Vec
15:21
Logan Smith
Рет қаралды 134 М.
How Android Security Works (in a nutshell)
0:43
LaurieWired
Рет қаралды 22 М.
A Competition for Unreadable Code?
12:33
LaurieWired
Рет қаралды 136 М.
How charged your battery?
0:14
V.A. show / Магика
Рет қаралды 3,9 МЛН
Где раздвижные смартфоны ?
0:49
Не шарю!
Рет қаралды 599 М.
Main filter..
0:15
CikoYt
Рет қаралды 1,3 МЛН