Profile picture
Elliot Alderson @fs0c131y
, 13 tweets, 6 min read Read on Twitter
I’m analysing #KevDroid samples the new #Android #malware discovered several days ago by #ESTSecurity
blog.alyac.co.kr/1587
The samples are available on @koodous_project and @virusbay_io
28c69801929f0472cef346880a295cdf4956023cd3d72a1b6e72238f5b033aca
679d6ad1dd6d1078300e24cf5dbd17efea1141b0a619ff08b6cc8ff94cfbb27e
990d278761f87274a427b348f09475f5da4f924aa80023bf8d2320d981fb3209
In the 1st downloader, in the OnCreate method of the MainActivity, they checked if the package called com.cool.pu is installed. If not, they display a message prompting the user to update the application
In the downloadapk method, they retrieves the payload from cgalim[.]com and saves it to the external device memory as AppName.apk
I like their log: Log.i("aaaaa", "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa”)
Interesting, the 2nd downloader is checking if the package com.aykuttasil.callrecorder is installed
Yeah, more samples to analyse!!!
2 more samples signed by the same “kevin”:
* b318ec859422cbb46322b036d5e276cf7a6afc459622e845461e40a328ca263e
* f33aedfe5ebc918f5489e1f8a9fe19b160f112726e7ac2687e429695723bca6a
I uploaded them to @virusbay_io
Nothing shady here: the launcher activity of the payload is called MainTransparentActivity and start a RootingTask :D
To give you an idea of the payload capabilities, this screenshot is the list of all the available actions
This is the list of the command types, in this sample not everything is used
unroll
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Elliot Alderson
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($3.00/month or $30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!