Saagar Jha

(replying to Saagar Jha)
Definitely not impossible to fully analyze of course but this is way past your “lol click around in IDA” stuff

(Full disclosure I poked at it with that level of commitment myself because was curious and very quickly abandoned the effort as too much work)
3 replies →
3 replies

Sahil 🐧

(replying to Saagar Jha)

@saagar
IDA costs a fortune!

Saagar Jha

(replying to Sahil 🐧)
@sahil Yeah I actually mostly use Binary Ninja for personal work (including this)

Sahil 🐧

(replying to Saagar Jha)

@saagar
Yeah, I was trying on binary ninja too yesterday but couldn't find anything XD

My attempt on Binary Ninja

Saagar Jha

(replying to Sahil 🐧)
@sahil This is one of those things where the tool matters much less than the person looking at it and the effort they put in

osy

(replying to Saagar Jha)

@saagar wasn't your full time job for almost a whole year to look at Android malware samples for Google

Saagar Jha

(replying to osy)
@osy86 No my job was (…checks half-updated résumé) “developing resilient techniques to thwart bad actors targeting Android by following them into where they operate”

Sahil 🐧

(replying to Saagar Jha)

@saagar
Someone reversed engineered it. It's RCE.
Source: bsky.app/profile/filippo.abyss