I know what's that about, but don't have actual binary. If I manage to find sample, I will share with you ;)
-
-
-
Tiny.z rings a bell somewhere, in a far distance though. Thank you, I appreciate it!
End of conversation
New conversation -
-
-
Indeed. It is an Android Trojan "Cronbot" that was offered for sale on underground; assuming they refer to the mal users as the "Cron" gang.
-
Makes sense. Do you have any IOCs per chance? Hadn't heard about this one. Thanks :)
- Show replies
New conversation -
-
-
It's faking the bank? My guess would be a yara retro hunt for bank name/package identifier less the correctly signed apks?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
all banking malware targeting Russia targets Sberbank since 2013-2014, it is not a distinctive feature)
-
https://www.virustotal.com/ru/file/170169cbe94675c3453a586cc7113e29036259f63d4f0aa08a776e2a2aae4db2/analysis/ … I think this is the malware you was looking for. Some old shit, really
End of conversation
New conversation -
-
-
Overlay apps + sends SMS.Without traces, it's hard to assign binary,many Bankers have implemented this functionalityhttps://pastebin.com/nktqERUC
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.