Тёмный

Analysis of CryCryptor Android Ransomware and how I created decryptor | fake COVID-19 tracing app 

Android Infosec
Подписаться 392 тыс.
Просмотров 8 тыс.
50% 1

Code and vulnerability analysis of CryCryptor Android Ransomware that was distributed via malicious websites as COVID-19 Tracing app in Canada.
More information: www.welivesecurity.com/2020/0...
In this video you will see:
(0:00): Intro
(0:39): Distribution of CryCryptor
(1:45): Code analysis
(6:47): Running ransomware
(9:24): Discovered vulnerability
(10:44): Decryption tool

Наука

Опубликовано:

 

1 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 22   
@mobilehacker
@mobilehacker 4 года назад
(0:00) ⏩ Intro (0:39) ⏩ Distribution of CryCryptor (1:45) ⏩ Code analysis (6:47) ⏩ Running ransomware (8:13) ⏩ CryCryptor is open-source (9:24) ⏩ Discovered vulnerability (10:44) ⏩ Decryption tool (10:20) ⏩ Outro
@sh4d0wless44
@sh4d0wless44 3 года назад
Awesome analysis, thank you Lukas! I started learning mobile application security and malware analysis topics a few weeks ago and your channel is really helpful for beginners like me. Thanks
@TechnicalHeavenSM
@TechnicalHeavenSM 3 года назад
Super cool.. Would like to see more malware analysis
@erkut931
@erkut931 4 года назад
Awesome! I would to see more code analysis video, thanks Lukas
@mobilehacker
@mobilehacker 4 года назад
You are on the right place then :) There definitely will be more code analysis 💪✌
@GauravYadav-nd9st
@GauravYadav-nd9st 4 года назад
Awesome work 👍👍. Liked your approach straight into the juicy stuff🤩🤩😂😂👌👌
@mobilehacker
@mobilehacker 4 года назад
life's too short to waste your time on not juicy stuff 😀😀
@GauravYadav-nd9st
@GauravYadav-nd9st 4 года назад
@@mobilehacker That's true . Are you sure you are not a philosopher 😂😂😁😁😉😉
@RhaenyraTargaryen-qs4hu
@RhaenyraTargaryen-qs4hu 9 месяцев назад
Great analysis. I see the encryption algorithm is AES-CBC. Was there a hardcoded key?
@paulmichaud7970
@paulmichaud7970 3 года назад
Hi thank you for all your work ! I've been infected by crycryptor (.enc) there is a few days I installed the app but nothing happen when I launch it do you know why ?maybe a new version of ransomware ? thanks
@hm00
@hm00 4 года назад
Thank you! would like to see some deobfuscation videos if you don't mind!
@mobilehacker
@mobilehacker 4 года назад
Most likely I will not publish such video any time soon since I am not using any deobfuscation tool - I dont think there is any universal deobfuscator that really helps. You have to get used to analyze obfuscated code 😕
@CristiVladZ
@CristiVladZ 4 года назад
Really insightful Lukas. How long did it actually take you to analyze this malware?
@mobilehacker
@mobilehacker 4 года назад
Shorter than to create this video. Even shorter than the length of this video, no kidding!
@hermanbrits611
@hermanbrits611 4 года назад
Could you perhaps share the script you ran on your pc to monitor altered files?
@mobilehacker
@mobilehacker 4 года назад
Sure! I used my custom script to monitor file system changes however, this one is more less the same and works perfectly when I tested. Observe file system accesses: codeshare.frida.re/@FrenchYeti/android-file-system-access-hook/
@SylwesterMadej
@SylwesterMadej 4 года назад
Is it common that the malware is based on some open source code?
@mobilehacker
@mobilehacker 4 года назад
Good question. I wouldn't say common but it happens more often these days. From what I have seen so far, there are open-source banking trojans, spyware, ransomware, RATs (Remote Administration Tools) and even commercial spywares which code/builders got leaked. Such open source if the easiest pick for cyber criminals and they either distribute such malware as it is or make changes/updates and then spread it.
@LexAsLex
@LexAsLex 4 года назад
well done!
@mobilehacker
@mobilehacker 4 года назад
Thanks! 💪✌
@kevinwong_2016
@kevinwong_2016 7 месяцев назад
Nice video💀 Blud accidentally made asmr💀
Далее
Hacking Windows TrustedInstaller (GOD MODE)
31:07
Просмотров 413 тыс.
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Webinar: Analyzing recent Android malware
1:23:26
Просмотров 4,5 тыс.
REVERSING MALWARE / Reverse Engineering Android APKs
9:33
Why You NEED a DRIVER (for hacking games)
8:03
Просмотров 446 тыс.
Malware and Machine Learning - Computerphile
20:54
Просмотров 75 тыс.
Android Miner Malware destroys Smartphones
4:32
Просмотров 32 тыс.
11 Signs Your Android Has A Virus & How To Remove Them
16:23
Remotely Control Any Phone and PC with this Free tool!
17:15
How to Create Trojans Using Powershell
15:53
Просмотров 649 тыс.