The samples are available on @koodous_project and @virusbay_io
28c69801929f0472cef346880a295cdf4956023cd3d72a1b6e72238f5b033aca
679d6ad1dd6d1078300e24cf5dbd17efea1141b0a619ff08b6cc8ff94cfbb27e
990d278761f87274a427b348f09475f5da4f924aa80023bf8d2320d981fb3209
In the 1st downloader, in the OnCreate method of the MainActivity, they checked if the package called com.cool.pu is installed. If not, they display a message prompting the user to update the application
In the downloadapk method, they retrieves the payload from cgalim[.]com and saves it to the external device memory as AppName.apk
I like their log: Log.i("aaaaa", "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa”)
Interesting, the 2nd downloader is checking if the package com.aykuttasil.callrecorder is installed
Yeah, more samples to analyse!!!
2 more samples signed by the same “kevin”:
* b318ec859422cbb46322b036d5e276cf7a6afc459622e845461e40a328ca263e
* f33aedfe5ebc918f5489e1f8a9fe19b160f112726e7ac2687e429695723bca6a
I uploaded them to @virusbay_io
Nothing shady here: the launcher activity of the payload is called MainTransparentActivity and start a RootingTask :D
To give you an idea of the payload capabilities, this screenshot is the list of all the available actions
This is the list of the command types, in this sample not everything is used
unroll
• • •
Missing some Tweet in this thread? You can try to
force a refresh
First thing first, we are talking about this app "Bolo Messenger - Secure Chat, Voice & Video Calls" which is the new version of the #Kimbho app play.google.com/store/apps/det…
When you send a message with the #Bolo app, it is checking if your contact is online with this request. The endpoint is taking the "contact userId" (the 1st black rectangle in the picture)
Time for a new thread. The #android#application called @moinsbete is one of the most downloaded applications in France. This app is sending without your consent your personal data to @mopub:
- location
- operator
- mcc
- mnc
- country
- screen size
Yes, all these requests to @mopub are HTTP requests... Welcome to 2018...
This is a very good example of data abuse. Every time you open the @moinsbete#android#app with location on, your location is send without your consent to an US based server owned by @mopub
Yesterday, I spent part of my day learning about Martin Luther King Jr's life, John Lewis, activists around them, about the 60's America, the Selma March. Following this, I have thousands of questions about America today, my country France and more generally about the world today
When I think about the current situation, the political landscape of my country, France, I do not see any equivalent to these extraordinary people, to these heroes. These women, these men, of all races and all religions have marked History by their pacifist fight.
They did it because the time had come. It was time to shake the unjust status quo. This fight was dangerous, deadly, insurmountable, but they did it. These "ordinary" people have outdone themselves for the common good, the good of their people and their nation.