A friend brought a phone to me with what I think is the ScarePakage
ransomware.
Apparently a "friend of his" looked up animal porn on his phone.
It's running android and I kind of want to extract the source code
and take a look at how this shit works.
Anyone down to check it out w/me?
this is a rare opportunity for security enthusiasts to get experience in the wild
http://i.imgur.com/D8cBaaY.jpg
Results 1 to 5 of 5
Thread: ScarePakage
- 13 Sep. 2014 07:34pm #1
ScarePakage
Last edited by Isonyx; 13 Sep. 2014 at 07:39pm.
I don't get tired.
- 13 Sep. 2014 08:09pm #2
I'm not an expert, but I imagine you would need to install a virtual box to run Android and copy the entire drive over to be able to read it in an environment where said virus isn't in control.
- 14 Sep. 2014 03:33am #3
I was thinking of this
Droidbox - For dynamic analysis of what the app is doing
Android Emulator - from the Android SDK (run the APK file through this)
JD-GUI - displays source code of .jarsI don't get tired.
- 15 Sep. 2014 04:32am #4
- Join Date
- Apr. 2013
- Location
- Minnesota
- Posts
- 1,325
- Reputation
- 114
- LCash
- 0.00
There is an android x84 .iso that works with vm-ware. >.>
interesting development.https://discord.gg/TvN6xUb ~ chat on discord pls.
- 21 Sep. 2014 04:17am #5
- Age
- 33
- Join Date
- Mar. 2007
- Location
- Death Star
- Posts
- 6,682
- Reputation
- 757
- LCash
- 0.00
- Awards
It looks like the old moneypak virus, adapted for android. I say follow the steps that have already been given to you, but run RogueKiller once everything is copied over. I have had that virus a few times from...ya know...because of research...and RogueKiller cleared it up almost instantly.
Voted Hottest Male Member
Crowned King of Logical Gamers
10 Years of Logical Service.