DroydSeuss: A Mobile Banking Trojan Tracker (Short Paper)

被引:1
作者
Coletta, Alberto [1 ]
van der Veen, Victor [2 ]
Maggi, Federico [1 ]
机构
[1] Politecn Milan, Milan, Italy
[2] Vrije Univ, Amsterdam, Netherlands
来源
FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2016 | 2017年 / 9603卷
关键词
D O I
10.1007/978-3-662-54970-4_14
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
After analyzing several Android mobile banking trojans, we observed the presence of repetitive artifacts that describe valuable information about the distribution of this class of malicious apps. Motivated by the high threat level posed by mobile banking trojans and by the lack of publicly available analysis and intelligence tools, we automated the extraction of such artifacts and created a malware tracker named DroydSeuss. DroydSeuss first processes applications both statically and dynamically, extracting relevant strings that contain traces of communication endpoints. Second, it prioritizes the extracted strings based on the APIs that manipulate them. Finally, DroydSeuss correlates the endpoints with descriptive metadata from the samples, providing aggregated statistics, raw data, and cross-sample information that allow researchers to pinpoint relevant groups of applications. We connected DroydSeuss to the VirusTotal daily feed, consuming Android samples that perform banking-trojan activity. We manually analyzed its output and found supporting evidence to confirm its correctness. Remarkably, the most frequent itemset unveiled a campaign currently spreading against Chinese and Korean bank customers. Although motivated by mobile banking trojans, DroydSeuss can be used to analyze the communication behavior of any suspicious application.
引用
收藏
页码:250 / 259
页数:10
相关论文
共 15 条
[1]  
Andrototal.org, 2015, ANOTH ANDR TROJ SCHE
[2]  
Chebyshev Victor., 2014, Mobile Malware Evolution: 2013
[3]  
Delosieres L, 2012, TECHNICAL REPORT
[4]  
Heyman A., 2011, 1 SPYEYE ATTACK ANDR
[5]  
Hipp Jochen, 2000, ACM SIGKDD Explorations, V2, P58, DOI [10.1145/360402.360421, DOI 10.1145/360402.360421]
[6]  
Kafeine, 2013, KAFEINE NITMO NO DOT
[7]  
Lehtio A., 2015, C C AS A SERVICE ABU
[8]  
Lindorfer M, 2014, LECT NOTES COMPUT SC, V8550, P51
[9]  
Loetprasoetsit A., 2013, CSD 2013
[10]  
Meller I., TECHNICAL REPORT