In this special episode of our Banker Deep Dive series, Asuka Langley Soryu makes a guest appearance. We finally discover the reference to the call to File.Write() of our malicious payload.
Watch out! Asuka also discovers an incorrectly decompiled method that wasn't dead code.
---
In this [RE]laxing new series, I fully reverse a difficult Android Banker trojan from start to finish.
These extensive "Deep Dive" segments concentrate on dissecting malware specimens and delving into the individual approaches employed to fully reverse them. Throughout the journey, I attempt to provide explanations of my techniques as much as possible, however, if any ambiguities arise, please feel free to post a comment below.
Timestamps:
00:00 Intro
01:20 Begin Analysis
04:41 Decoding Big Strings
07:46 Opening HTML Object
12:30 Suspicious File Written, but not called
16:31 Reading Smali
21:30 Searching Method Signature in Powershell
26:10 Reading Incorrectly Decompiled Code
30:21 Analysing IntentService Class
33:21 Looking at Intent Filters
35:20 Recap
---
Software Links Mentioned in Video:
JADX: https://github.com/skylot/jadx
---
Malware Examined in the video (Banker/Anubis):
sha256:cae0c0d33e68be9cf81099680b815eb714d8296cb219b7a6247f7f081820f39a
MalwareBazaar Link:
https://bazaar.abuse.ch/sample/cae0c0...
---
laurieWIRED Twitter:
/ lauriewired
laurieWIRED Website:
http://lauriewired.com
laurieWIRED HN:
https://news.ycombinator.com/user?id=...
laurieWIRED Reddit:
/ lauriewired