Mobile Malware and Spyware: Working Through the Bugs. Detective Cindy Murphy 608-267-8824 cmurphy@cityofmadison.com



Similar documents
Rogue Mobile Apps: Nuisance or Legit Threat?

The OWASP Foundation

Security Best Practices for Mobile Devices

Hacking your Droid ADITYA GUPTA

How to easily clean an infected computer (Malware Removal Guide)

Ohio University Computer Services Center October, 2004 Spyware, Adware, and Virus Guide

CYBERCRIMINAL IN BRAZIL SHARES MOBILE CREDIT CARD STORE APP

Protecting against Mobile Attacks

How we keep harmful apps out of Google Play and keep your Android device safe

SECTOR 2015 Malware Activity in Mobile Networks Kevin McNamee (Alcatel-Lucent)

Advanced Online Threat Protection: Defending. Malware and Fraud. Andrew Bagnato Senior Systems Engineer

Bypassing SSL Pinning on Android via Reverse Engineering

What you need to know to keep your computer safe on the Internet

Introduction to Android

Reversing Android Malware

Corporate Account Takeover & Information Security Awareness. Customer Training

What's the difference between spyware and a virus? What is Scareware?

Mifflinburg Bank & Trust. Corporate Account Takeover & Information Security Awareness

Corporate Account Takeover & Information Security Awareness

System Compatibility. Enhancements. Operating Systems. Hardware Requirements. Security

Security A to Z the most important terms

The information contained in this session may contain privileged and confidential information. This presentation is for information purposes only.

Introduction to Computer Security Table of Contents

MOBILE MALWARE REPORT

TRAINING FOR AMERICAN MOMENTUM BANK CLIENTS. Corporate Account Takeover & Information Security Awareness

BEHIND THE SCENES OF A FAKE TOKEN MOBILE APP OPERATION

The Behavioral Analysis of Android Malware

Symptoms of a Data Breach in Your Business

Notices. Copyright 2016 Malwarebytes. All rights reserved.

Management Website User Guide. SecureAnywhere AntiVirus SecureAnywhere Internet Security Plus SecureAnywhere Complete

Mobile Malware Network View. Kevin McNamee : Alcatel-Lucent

Backing Up and Restoring the Database

Web. Paul Pajares and Max Goncharov. Connection. Edition. ios platform are also at risk, as. numbers via browser-based social.

Mobile security, forensics & malware analysis with Santoku Linux. * Copyright 2013 viaforensics, LLC. Proprietary Information.

ANDRA ZAHARIA MARCOM MANAGER

Get Started Guide - PC Tools Internet Security

Beware! CryptoLocker Ransomware

Versafe TotALL Online Fraud Protection

The Increasing Threat of Malware for Android Devices. 6 Ways Hackers Are Stealing Your Private Data and How to Stop Them

Sophos Enterprise Console Help

Corporate Account Takeover & Information Security Awareness

THE HOME LOAN SAVINGS BANK. Corporate Account Takeover & Information Security Awareness

Agenda. John Veldhuis, Sophos The playing field Threats Mobile Device Management. Pagina 2

Malware, Spyware, Adware, Viruses. Gracie White, Scott Black Information Technology Services

Mobile Malware in the Enterprise

How to Install Applications (APK Files) on Your Android Phone

ITSC Training Courses Student IT Competence Programme SIIS1 Information Security

BE SAFE ONLINE: Lesson Plan

How Secure is My Device

How to Configure Sophos Anti-Virus for Home Systems

Android Security Evaluation Framework

COMPUTER-INTERNET SECURITY. How am I vulnerable?

Mobile App Reputation

An Oracle Technical White Paper May How to Configure Kaspersky Anti-Virus Software for the Oracle ZFS Storage Appliance

Practical Attacks against Mobile Device Management Solutions

G Data Mobile MalwareReport. Half-Year Report July December G Data SecurityLabs

Information Security Awareness

Comodo Mobile Security for Android Software Version 2.5

Sophos for Microsoft SharePoint Help

How Secure is My Device. APCUG Virtual Technology Conference 21 February 2015

MALWARE THREATS AND TRENDS. Chris Blow, Director Dustin Hutchison, Director

Comparing Android Applications to Find Copying

Secure Your Mobile Workplace

Sophos for Microsoft SharePoint Help. Product version: 2.0

Malware Analysis for Android Operating

Mobile Security: Controlling Growing Threats with Mobile Device Management

A Crawler-based Study of Spyware in the Web. Alex Moshchuk, Tanya Bragin, Steve Gribble, Hank Levy

The Challenges of Implementing a Bring Your Own Device Policy

Understanding Spyware

G DATA MOBILE MALWARE REPORT THREAT REPORT: Q1/2015

G DATA MOBILE MALWARE REPORT THREAT REPORT: Q1/2015

User's Guide. Copyright 2014 Bitdefender

Two Trends in Mobile Malware: Financial Motives and Transitioning from Static to Dynamic Analysis

2016 Trends in Cybersecurity: A Quick Guide to the Most Important Insights in Security

NQ Mobile Security Frequently Asked Questions (FAQs) for Android

Sophos Enterprise Console Help. Product version: 5.1 Document date: June 2012

F-Secure Mobile Security. Android

Trend Micro Incorporated Research Paper Adding Android and Mac OS X Malware to the APT Toolbox

OCT Training & Technology Solutions Training@qc.cuny.edu (718)

Beginners Guide to Android Reverse Engineering

Smartphone Pentest Framework v0.1. User Guide

Mobile Application Hacking for Android and iphone. 4-Day Hands-On Course. Syllabus

Report on Consumer Behaviors and Perceptions of Mobile Security. Presented by NQ Mobile & NCSA January 25, 2012

ASEC REPORT VOL AhnLab Monthly Security Report. Malicious Code Trend Security Trend Web Security Trend

thriller INTERNET SECURITY

Analysis of advanced issues in mobile security in android operating system

Symantec's Secret Sauce for Mobile Threat Protection. Jon Dreyfus, Ellen Linardi, Matthew Yeo

Oracle FLEXCUBE Direct Banking Android Tab Client Installation Guide Release

Mobile Application Security Sharing Session May 2013

Zscaler Cloud Web Gateway Test

F-Secure Labs. Protection around the clock. Mobile Threat Report Q4 2012

CHECK POINT Mobile Security Revolutionized. [Restricted] ONLY for designated groups and individuals

Outpost Pro PC security products Security Suite, Antivirus, Firewall

A Practical Guide to creating, compiling and signing an Android Application using Processing for Android.

How To Use Secureanything On A Mac Or Ipad (For A Mac)

U.S. Cellular Mobile Data Security. User Guide Version 00.01

INFOCOMM SEC RITY. is INCOMPLETE WITHOUT. Be aware, responsible. secure!

How to Configure Symantec Protection Engine for Network Attached Storage for the Oracle ZFS Storage Appliance

Transcription:

Mobile Malware and Spyware: Working Through the Bugs Detective Cindy Murphy 608-267-8824 cmurphy@cityofmadison.com

The Mobile Malware Threat 155% increase in mobile malware from 2010 to 2011 614% increase in mobile malware from March 2012 to March 2013 Total samples across all platforms Android represents for 92% all known mobile malware infections Year to Year Change in Number of Mobile Malware Samples 11138 28472 38689 276259 Feb 2010 Feb 2011 March 2012 March 2013 http://www.juniper.net/us/en/local/pdf/additional-resources/3rdjnpr-mobile-threats-report-exec-summary.pdf

Types of Mobile Malware & Potentially Unwanted Applications Malware Backdoor Trojan Worm Ransomware Potentially Unwanted Applications (PUA) Adware Trackware Spyware

Mobile Malware Infection Vectors Third-party App Store repositories Androids with outdated OS versions Jailbroken iphones Unlocked Windows Phones Malicious websites - drive-by download installation Direct victim targeting through e-mail, SMS, and MMS Smishing Official App Stores Emerging Methods QR Codes NFC Chips

Signs & Symptoms of Mobile Malware Infection Poor Battery Life Dropped Calls and Call Disruption Unusually Large Phone Bills Data Plan Spikes Performance Problems Unexpected Device Behaviors RISKY user behavior Pirated apps for free Porn surfing Free Money Apps AT RISK users

OUCH!? What are the implications of + hits on a case? Can the presence of malware or spyware actually potentially help the investigation?

Mobile Malware Detection Cellebrite Physical Analyzer Bit Defender With Other AV Tools: Perform a file system extraction Scan the file system extraction with one or more AV tools If the extraction is a.zip, be sure to unzip first!

If you still suspect a problem Don t Stop Digging!! Beyond scanning for malware: Check Installed Apps for suspicious.apk files Check Downloads folder(s) for suspicious files Check browser history for visits to BAD sites Check for links from SMS, MMS, & Email Examine activity on phone around the suspected time of infection Research any error messages or notifications that might give you clues about infection Malware scanning won t always catch the BAD Spyware and for pay applications often considered legitimate

Finding the BAD Root\App folder contains downloaded.apk files Most.apk files will be legitimate applications Individual suspicious.apk files can be exported for further examination ANY.apk file can be unpacked and decompiled or submitted to a sandbox site for analysis

Mobile Malware Reverse Engineering & Analysis Mobile Malware Analysis & Reverse Engineering Tools: Dexter Anubis / Andrubis APK Inspector Dex2Jar jd-gui Santoku

Locating Problem.apk files Phone errors may give important clues about infection with malware or spyware. Check for the associated.apk file in Root\Apps Export the suspicious application for further analysis

.apk Analysis using Online Sandboxes Export suspected malware.apk files to a well marked folder such as Suspected Malware Submit suspicious files for analysis Review results to determine what the.apk file is doing

Static Analysis of.apk Files.apk files can be analyzed locally in a static manner.apk File Format: The.apk file is a zipped package based on JAR file format It contains compiled programming code and additional information We can look inside to see what the.apk is programmed to do! Unpacking & Decompiling

Static Analysis Step 1: Unpacking the.apk file The contents of an.apk file can be viewed by unpacking it Simply rename the file to.zip and open it to unpack the.apk file The classes.dex file is needed for the next step.

Static Analysis Step 2: Decompiling the.apk file Locate and copy the classes.dex file Copy the classes.dex file into dex2jar directory Open a command prompt and navigate to the dex2jar folder Execute the batch file dex2jar.bat classes.dex This command will create a file named classes_dex2jar.jar in the dex2jar directory

Static Analysis Step 3: Viewing Decompiled Code Use jd-gui Java Decompiler to view the data you unpacked and decompiled in the previous steps Navigate to and open the classes_dex2jar.jar created in the previous step View contents to reveal the underlying code and see what the.apk file is doing

Mobile Spyware Generally advertised for Catching cheating spouses Monitoring and protecting children Monitoring employees Must have physical control of the target device to install Many, Many, Many varieties mostly cheap or free Mobile malware scans may or may not detect the presence of spyware

Carrier Family Monitoring Tools Verizon Family Locator Plan US Cellular Family Protector Plan AT&T Family Tracker Sprint Family Locator

???? Detective Cindy Murphy 608-267-8824 cmurphy@cityofmadison.com