Android Banker Deep Dive (Part 1)
LaurieWired
0:00 / 0:00
Android Banker Deep Dive (Part 1)
26 948 просмотров · 3 года назад
LaurieWired
551 тыс. подписчиков
26 948 просмотров · 3 года назад
In this [RE]laxing new series, I fully reverse a difficult Android Banker trojan from start to finish.
These extensive "Deep Dive" segments concentrate on dissecting malware specimens and delving into the individual approaches employed to fully reverse them. Throughout the journey, I attempt to provide explanations of my techniques as much as possible, however, if any ambiguities arise, please feel free to post a comment below.
Timestamps:
00:00 Intro
01:00 Begin Analysis /w JADX
02:38 Main Activity
04:17 Additional Clues
06:31 Pub/Sub Functionality
08:00 Diving Into Code
11:10 Quick Base64 Decode Check
12:01 Decoder Function Methods
18:39 Creating Decoding Script
24:26 Decoding Strings
29:00 Analyzing A Service
31:31 Follow the White Rabbit
35:43 Checking for a file
38:33 Recap
---
Software Links Mentioned in Video:
JADX: https://github.com/skylot/jadx
---
Malware Examined in the video (Banker/Anubis):
sha256:cae0c0d33e68be9cf81099680b815eb714d8296cb219b7a6247f7f081820f39a
MalwareBazaar Link:
https://bazaar.abuse.ch/sample/cae0c0...
---
laurieWIRED Twitter:
/ lauriewired
laurieWIRED Website:
http://lauriewired.com
laurieWIRED HN:
https://news.ycombinator.com/user?id=...
laurieWIRED Reddit:
/ lauriewired