A preserved archive of the Logical Gamers community forums, 2009-2025. The original threads and posts, served read-only. Registration, posting and private messages are gone for good.

ScarePakage

979 views · started by Isonyx ·
#1
ScarePakage
A friend brought a phone to me with what I think is the ScarePakage
ransomware.

Apparently a "friend of his" looked up animal porn on his phone.

It's running android and I kind of want to extract the source code
and take a look at how this shit works.

Anyone down to check it out w/me?
this is a rare opportunity for security enthusiasts to get experience in the wild

http://i.imgur.com/D8cBaaY.jpg
#2
I'm not an expert, but I imagine you would need to install a virtual box to run Android and copy the entire drive over to be able to read it in an environment where said virus isn't in control.
#3
I was thinking of this

Droidbox - For dynamic analysis of what the app is doing
Android Emulator - from the Android SDK (run the APK file through this)
JD-GUI - displays source code of .jars
#4
There is an android x84 .iso that works with vm-ware. >.>

interesting development.
#5
It looks like the old moneypak virus, adapted for android. I say follow the steps that have already been given to you, but run RogueKiller once everything is copied over. I have had that virus a few times from...ya know...because of research...and RogueKiller cleared it up almost instantly.
ScarePakage | Logical Gamers Archive