50

G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 2: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 3: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 4: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 5: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 6: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Malware sammeln

Malware analysieren

Malware erkennen

Fehler vermeiden

Signaturen ausrollen

Page 7: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 8: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 9: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

0%

5%

10%

15%

20%

25%

30%

35%

40%

45%

50%

Q3 2011 Q3 2012

Samsung

Apple

RIM

HTC

Andere

Page 10: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

0%

10%

20%

30%

40%

50%

60%

70%

80%

Q3 2011 Q3 2012

Android iOS Blackberry Symbian Windows Phone Linux andere

Page 11: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

http://developer.android.com/about/dashboards/index.html

Page 12: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 13: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 14: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 15: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

http://maps.google.de/

Page 16: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Register basiert

Optimiert für geringen Speicherverbrauch

Optimiert für langsame CPUs

Kein Swap-Space

Kein JIT

Page 17: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Unix

Page 18: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 19: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Quelle: openclipart.org

Page 20: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Quelle: openclipart.org

Page 21: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Quelle: openclipart.org + Firmen

Page 22: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Quelle: openclipart.org + Firmen

Page 23: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

2010.08 Fakeplayer

2010.12 Geinimi

Page 24: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

o

o

o

Page 25: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 26: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 27: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 28: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 29: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 30: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 31: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 32: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 33: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 34: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 35: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 36: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Quelle: GI60s

Page 37: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

201.09 Gone in 60 seconds

Quelle: GI60s

Page 38: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 39: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 40: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 41: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 42: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 43: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 44: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 45: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

AccuTrack Ackpost Ackposts Acnetdoor AcnetSteal Actehc Adrd AdSms Adware.Airpush Adware.Copycat Agent AgentH AgentP AgentX AgileBinary Aks

AndrAgent AndrExp Android Android_AdSMS Android_AntaresSpy Android_AntivirusTESTVIRUS Android_Asroot Android_BaseBridge Android_BaseBridge1

Android_BaseBridge2 Android_Bgserv Android_Cosha Android_DDLight Android_DDLight2 Android_Dogowar Android_DroidDream Android_DroidKungFu

Android_DroidKungFu3 Android_DroidKungFu4 Android_DroidLive Android_DroidSheep Android_Ewalls Android_Exploid Android_Faceniff Android_FakeAngry

Android_FakeApp Android_FakeAV Android_FakeBattBoost Android_FakeFlash Android_FakeIM Android_FakeInst Android_Fakelogo Android_Fakeneflic

Android_FakePlayer Android_FakeTimer Android_FakeUpdates Android_Flexispy Android_Foncy Android_Gamex Android_Geinimi Android_Geinimi1

Android_GGTracker Android_GingerBreak Android_GingerMaster Android_GoldDream Android_GoldenEagle Android_GoManag Android_HippoSMS

Android_Iconosys Android_InfoStealer Android_Jifake Android_Jifake1 Android_Jifake2 Android_JSmsHider Android_KuSaseSMS Android_LoicDOS

Android_Lotoor Android_Mania Android_Mobistealth Android_Moghava Android_Monitor_FarmBaby Android_Monitor_GpsSpyTracker Android_Monitor_KidLogger

Android_Monitor_LifeMonitor Android_Monitor_Lovetrap Android_Monitor_MobileSpy Android_Monitor_Pdaspy Android_Monitor_Prospero Android_Monitor_Spyera

Android_Monitor_SpyMe Android_Monitor_SpySat Android_Nickispy Android_Pirates Android_PJApps Android_PjApps1 Android_PjApps2 Android_Plankton

Android_Qicsomos Android_ReFake Android_Retinax Android_Riskware_Boxer Android_Riskware_RemoteControlPhone Android_Riskware_Seaweed

Android_Riskware_SmsReg Android_RogueSPPush Android_Rooter Android_Ropin Android_RuFraud Android_SMSBomber Android_Smspacem

Android_SMSReplicator Android_SMSSend Android_SmsSpy Android_SndApps Android_SpyBubble Android_SpyHasb Android_Spyoo Android_StealthLight

Android_Steek Android_TattooHack Android_Walkinwat Android_Wallive Android_YZHCSMS Android_Zitmo Android_Zsone AndromedaEdit AndroScan

AndSpy AndTheft Ansaca AnSmCon Antares Anti Anudow Application.Kiser Application.Rooter Application.WifiSniff Arspam Asroot Backstab Bacsta

BacSta BaseBrid BaseBridg BaseBridge Batterydoctor BeanBot BGServ Biige Booster Bosm Boxer BoxerSMS Cawitt CellSpy CgFinder Cheatact

Cobblerone Coogos Copycat CopyCat Cosha CrWind Cshark Dabom Dcoman DDreamLight Denofow Dialer DogWar DorDae DorDrae Dougalek

DrdDream DroidCoupon DroidKungFuU DroidLive DroidRooter DroidSheep DropDialer Ecobatry EICAR Test EicarTest EICAR-Test-File Exploid

ExploitRATC FaceNiff FakeAngry Fakeapp FakeAV FakeBrows FakeDoc FakeFlash FakeGuard FakeInst Fakelogo FakeLogo Fakelook Fakeneflic

Fakengry FakeNotify FakeOS FakePlayer FakePrin Fakerun FakeRun FakeTimer Faketoken FakeUpd FakeUpdate FakeUpdates Fatakr Fauxcopy FeeBG

Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm Fujacks Gamex Gapev Gappusin Gapusin Gapussin Gedma Geimini Geinimi

Genome GgTrack GingerBreak GingerMaster GinMaster Glodream Gmuse GoldDream GoldEagle GoManag GoneSixty Gongfu Gploc GPspy GPSpy

GueSpy GugeSpy HackAV HackTool Hamob Hippo HippoSMS Hispo Hoax Horofa Huxre Iconosis Iconosys IGirl Imlog Infostealer InfoStealer Jifake

JifakeB JSmsHider JxAgent Kidlogger KidLogger Kiser KiserHack Kmin Koomer Ksaap Ksapp KungFu KuSaseSMS Lambs LdPinch Leadbolt LeadBot

Lemon Lien LifeMon Lightdd Ligshar Lootor Lotoor LoveTrap Luckycat LuckyCat Lypro MailStealer Maistealer Malformed Malware Mania Mavms

Maxbet Maxit MMarketPay Mobigapp Mobilespy MobileSpy MobileTrck MobileTx Mobinauten MobiStealth Moghava Mpsy MTracker Multi Nandrobox

Netisend NetSpoof NickiSpy NickyRCP NickySpy Nisev NotCom Nyearleaker Nyleaker Opfake OpFake OpfakeA OpfakeBO Osmino PdaSpy Penethbo

Penetho PFraud Pholoc PhoneSpy Pirates PJApps Placms Placsms Plangton Plankton Plasms Pmixi PocketLuxus PowAlar Proreso Qdplugin QPlus

Rabbhome Raden RageCage Ratc RediAssi Replicator RootChanger Rooter Rootsmart RootSmart Routerpwn RuFraud Saiva Sakezon Script Sdisp

SeaWeth SendPay ShastroSms SheriDroid SilTracker Skypwned Smbcheck SmBox SmForw SMForw SMSAgent SMSBomber SMSBoxer SmsC

Smscom SmsControl SmsForw SmsHippo Smspacem SMSPlac SMSreg SmsReplicator SmsSend SMSSend SmsSender Smssp SmsSpy SmsWatcher

SmsYou SMSZombie Sndand Sonus Spartams Spitmo SpyBubble SpyGeinimi SpyHasb SpyMob Spyoo SpyPhone Spyset Ssmsp Stealer Stealthcell

Steek Stesec Stinit Stiniter Stinitr Stoqx SuBatt Sumzand Tapsnake TapSnake Tesbo TESTVIRUS Thebe Tiger Trackplus Trojan.Agentblk

Trojan.CarrierIQ Trojan.Fidall Trojan.Gappusin Trojan.Ginmaster Trojan.Lozfoon Trojan.Plangton Trojan.Plankton Trojan.Steek TrojanSMS Trojan-SMS.Agent

Typstu Uapush Unispy Unknown UpdBot Updtbot UpdtKiller Uranico URoot VChanger Vdloader Vidro Walksteal Webim Whapsni WifiKill WWebDdos

Xsider YcChar YouB Yzhc Zitmo Zsone

Page 46: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 47: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 48: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm

Page 49: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm
Page 50: G Data Presentation 2011 Redesign SK2 - EICAR2016.eicar.org/files/eicar_wg2_2012_-_gdata_-_android_malware.pdf · Feebs Fidall FinFisher FinSpy Fjcon FlexiSpy Fls Foncy Foran Fsm