Source |
Fortinet |
Identifiant |
382289 |
Date de publication |
2017-07-09 14:06:00 (vue: 2017-07-09 14:06:00) |
Titre |
Unmasking Android Malware: A Deep Dive into a New Rootnik Variant, Part II |
Texte |
In part I of this blog, I finished the analysis of the native layer of a newly discovered Rootnik malware variant, and got the decrypted real DEX file. Here in part II, we will continue our analysis.
A look into the decrypted real DEX file
The entry of the decrypted DEX file is the class demo.outerappshell.OuterShellApp. The definition of the class OuterShellApp is shown below.
Figure 1. The class demo.outerappshell.OuterShellApp
We will first analyze the function attachBaseContext(). The following is the function aBC() in the class... |
Notes |
|
Envoyé |
Oui |
Condensat |
abc analysis analyze android attachbasecontext below blog class continue decrypted deep definition demo dex discovered dive entry figure file finished first following function got here layer look malware malware: native new newly outerappshell outershellapp part real rootnik shown unmasking variant will |
Tags |
|
Stories |
|
Move |
|