吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 14053|回复: 38
收起左侧

[移动样本分析] 最近收到了个带链接的短信,自己研究了好久都没整明白,求路过大神帮忙

[复制链接]
ja45521 发表于 2015-10-24 14:49
使用论坛附件上传样本压缩包时必须使用压缩密码保护,压缩密码:52pojie,否则会导致论坛被杀毒软件等误报,论坛有权随时删除相关附件和帖子!
病毒分析分区附件样本、网址谨慎下载点击,可能对计算机产生破坏,仅供安全人员在法律允许范围内研究,禁止非法用途!
禁止求非法渗透测试、非法网络攻击、获取隐私等违法内容,即使对方是非法内容,也应向警方求助!
样品是前阵子 一个陌生的手机号发来的
网上搜索了各种软件,用改之理打开 看教程慢慢摸索才明白了点
这是个APK木马,监听手机状态,秘密发送手机内容至指定的号码跟邮箱作者好像用了des加密,无法看出他设定的手机号码,跟邮箱。求大神指点怎么找出作者设定的des加密的key  然后找出他的手机号码跟邮箱?


附上样品链接:链接: http://pan.baidu.com/s/1bnhXVDP 密码: tu8b



package com.phone.stop.db;

import android.content.Context;
import android.content.SharedPreferences;
import android.content.SharedPreferences.Editor;

public class a
{
  private static a a = null;
  private SharedPreferences b;

  private a(Context paramContext)
  {
    this.b = paramContext.getSharedPreferences("configurations_data", 0);
  }

  public static a a(Context paramContext)
  {
    if (a == null) {
      a = new a(paramContext);
    }
    return a;
  }

  public void a(int paramInt)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putInt("app_intercept_type", paramInt);
    localEditor.commit();
  }

  public void a(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("last_delete_sms_time", paramString);
    localEditor.commit();
  }

  public void a(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("have_app_jihuo", paramBoolean);
    localEditor.commit();
  }

  public boolean a()
  {
    return this.b.getBoolean("have_app_jihuo", false);
  }

  public String b()
  {
    return this.b.getString("last_delete_sms_time", "000000000");
  }

  public void b(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("i_want_xxoo", paramString);
    localEditor.commit();
  }

  public void b(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("have_init_phone_number", paramBoolean);
    localEditor.commit();
  }

  public String c()
  {
    return this.b.getString("i_want_xxoo", "215f2456d6695e950f79ac191b64b034");
  }

  public void c(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("app_end_time", paramString);
    localEditor.commit();
  }

  public void c(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("is_init_end_time", paramBoolean);
    localEditor.commit();
  }

  public void d(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("send_email_account", paramString);
    localEditor.commit();
  }

  public void d(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_delete_message", paramBoolean);
    localEditor.commit();
  }

  public boolean d()
  {
    return this.b.getBoolean("have_init_phone_number", false);
  }

  public String e()
  {
    return this.b.getString("app_end_time", "f836c71f8d6fa6d0957f3215d8b6f13fcef7f91916798b69");
  }

  public void e(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("receive_email_account", paramString);
    localEditor.commit();
  }

  public void e(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_send_phone_info", paramBoolean);
    localEditor.commit();
  }

  public void f(String paramString)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putString("send_email_pwd", paramString);
    localEditor.commit();
  }

  public void f(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_send_contacts", paramBoolean);
    localEditor.commit();
  }

  public boolean f()
  {
    return this.b.getBoolean("is_init_end_time", false);
  }

  public int g()
  {
    return this.b.getInt("app_intercept_type", 1);
  }

  public void g(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_send_message", paramBoolean);
    localEditor.commit();
  }

  public void h(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_set_send_email_account", paramBoolean);
    localEditor.commit();
  }

  public boolean h()
  {
    return this.b.getBoolean("has_delete_message", false);
  }

  public void i(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_set_receive_email_account", paramBoolean);
    localEditor.commit();
  }

  public boolean i()
  {
    return this.b.getBoolean("has_send_phone_info", false);
  }

  public void j(boolean paramBoolean)
  {
    SharedPreferences.Editor localEditor = this.b.edit();
    localEditor.putBoolean("has_set_send_email_pwd", paramBoolean);
    localEditor.commit();
  }

  public boolean j()
  {
    return this.b.getBoolean("email_message_contacts_switch", true);
  }

  public boolean k()
  {
    return this.b.getBoolean("send_email_message_switch", false);
  }

  public boolean l()
  {
    return this.b.getBoolean("has_send_contacts", false);
  }

  public boolean m()
  {
    return this.b.getBoolean("has_send_message", false);
  }

  public String n()
  {
    return this.b.getString("send_email_account", "215f2456d6695e95ad5600b886284a1a42c4667d5d21f62b");
  }

  public boolean o()
  {
    return this.b.getBoolean("has_set_send_email_account", false);
  }

  public String p()
  {
    return this.b.getString("receive_email_account", "215f2456d6695e95ad5600b886284a1a42c4667d5d21f62b");
  }

  public boolean q()
  {
    return this.b.getBoolean("has_set_receive_email_account", false);
  }

  public String r()
  {
    return this.b.getString("send_email_pwd", "a1f0ff12d492b607beceac79a44fa743d0c3804faf7f793c");
  }

  public boolean s()
  {
    return this.b.getBoolean("has_set_send_email_pwd", false);
  }
}


1.jpg

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

905422897 发表于 2015-10-24 15:37
本帖最后由 905422897 于 2015-10-24 15:51 编辑

19MB  ..........................
↑刚刚下载错了 上面是屁话 请无视- -

 楼主| ja45521 发表于 2015-10-24 16:31
905422897 发表于 2015-10-24 16:29
key 是 s开头的 6位数  我把样本删了...忘记了  以前一位大牛教我的  然后用key 解密一下 就可以了....

我研究研究。可以加我QQ 403609356,指导下么
asdfgasd 发表于 2015-10-24 14:53
wuhua2009 发表于 2015-10-24 15:11
坐等大神解答,希望能看短信截图。
2317909768 发表于 2015-10-24 15:39
楼下是大神
905422897 发表于 2015-10-24 15:44
加密内容是这几个
13679738524
13679738524@163.com
szzxbsyuugzvdnsq         邮箱密码已失效
2015-09-08 09:08:22    这个是软件的到期时间
905422897 发表于 2015-10-24 15:46
本帖最后由 905422897 于 2015-10-24 15:52 编辑

话说 今天貌似没开放注册  楼主是怎么注册的
楼主是南宁的?
 楼主| ja45521 发表于 2015-10-24 15:53
细瞧、潇洒哥 发表于 2015-10-24 15:06
你应该把那短信内容截图。

一个月多月前的短信了,恢复出厂设置啥都没了
xiduosi 发表于 2015-10-24 15:53
2015年10月24日注册
 楼主| ja45521 发表于 2015-10-24 15:54
905422897 发表于 2015-10-24 15:46
话说 今天貌似没开放注册  楼主是怎么注册的
楼主是南宁的?

我也不知道咋注册的,买个邀请码  注册的啊
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-4-25 21:41

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表