Return to site

Droidjack 2017

broken image


Listen to port 1334 (default) in DroidJack. Check with www.canyouseeme.org whether your port 1334 (default) is open. (Also check if port 1334 (default) is shown open when not listening to port 1334 (default) from DroidJack. This is just to make sure no other software is. Bueno nada, como dice el titulo, nueva version funcional de DJ 4.4, para mi esta limpia, pero PRUEBEN EN VIRTUALES por las dudas, salu2 gente. Pass: indetectab.

A few days back, we wrote about an Android Marcher trojan variant posing as the Super Mario Run game for Android. We have found another instance of malware posing as the Super Mario Run Android app, and this time it has taken the form of DroidJack RAT (remote access trojan). Proofpoint wrote about the DroidJack RAT side-loaded with the Pokemon GO app back in July 2016; the difference here is that there is no game included in the malicious package. The authors are trying to latch onto the popularity of the Super Mario Run game to target eagerly waiting Android users.

Details:

  • Name : Super Mario Run
  • Package Name : net.droidjack.server
  • MD5 : 69b4b32e4636f1981841cbbe3b927560

Technical Analysis:

The malicious package claims to be the Super Mario Run game, as shown in the permissions screenshot below, but in reality this is a malicious RAT called DroidJack (also known as SandroRAT) that is getting installed.

Figure 1: Permissions.

Once installed, the RAT registers the infected device as shown below.

Figure 2: Infected device registration.

DroidJack RAT starts capturing sensitive information like call data, SMS data, videos, photos, etc. Observe below the code routine for call recording.

Figure 3: Call recording.

This RAT records all the calls and stores the recording to an '.amr' file.

The following is the code routine for video capturing.

Figure 4: Video capturing.

Here, the RAT stores all the captured videos in a 'video.3gp' file.

It also harvests call details and SMS logs as shown below.

Figure 5: SMS Logs


Figure 6: Call logs.

Droidjack

Upon further inspection, we have observed that this RAT extracts WhatsApp data too.

Figure 7:Whatsapp data.

The RAT stores all the data in a database (DB) in order to send it to the Command & Control (C&C) server. The following are the DBs created and maintained by the RAT.

Figure 8: Databases.

We saw the following hardcoded C&C server location in the RAT package:

Figure 9: Hardcoded C&C.

Conclusion:

The DroidJack RAT is another example of a growing trend in which malware authors seek to exploit public interest as a way to spread malware. In this case, like others before, the event of a popular game release became an opportunity to trick unsuspecting users into downloading the RAT. As a reminder, it is always a good practice to download apps only from trusted app stores such as Google Play. This practice can be enforced by unchecking the 'Unknown Sources' option under the 'Security' settings of your device.

Zscaler ThreatLabZ is actively monitoring this malware to ensure that Zscaler customers are protected from infection.

My previous post is about How to Hack Android Phone using Metasploit as you can see how easily anyone can hack android smartphone using metasploit but the whole thing was in Linux and everyone is not familiar and comfortable with Linux.But no worries ,this time we came back with another tutorial ' How to Hack android phone – Droid Jack and How to protect ourself ? ' which is totally based on Windows .

Also checkout: Lucky Patcher Apk

Why Windows ?

Droidjack 2017

Windows is fully GUI(Graphical User Interface) based as you all know .In Linux you have to get familiar with terminals and other developer things which are lack of GUI and thats why most of the people gives up with Linux .Even if you are going to install a program over Linux then you have to install it via Terminal .It doesn't mean Linux not worths ,see our post on How to get familiar with Linux easily .

Why we are writing this tutorial ?

Previously we've posted a article about ' Malicious Android adware campaign tries to exploit root access ' and thats ridiculously true everything written on that post .After analyzing whole scenario we decided to write a tutorial on exploiting and defending android devices to aware innocent victims .We recommend you to take a look of that post and understand the hazards of third party malicious apps.

What is Droid Jack ?

Droid Jack is what you need for that. Droid Jack gives you the power to establish control over your beloveds' Android devices with an easy to use GUI and all the features you need to monitor them.Droid Jack is a client/server application developed in Java Android for the client side and in Java/Swing for the Server.

See also : How to Hack android using metasploit in Kali Linux .

Please read disclaimer : Here i'm using RAT[remote administration tool] software in windows for educational use ,all devices have been faked.This tutorial is for learning purposes only and should not be used for any illegal activities.It's only for awareness.Don't break someone privacy who not belongs to you , i'm not liable for any illegal activity…

Following are the requirements to get started.

  1. Internet Enabled Windows Machine.
  2. Java Installed ,if not then download it from here.
  3. Net-framework Installed ,if not then download it from here.
  4. DroidJack (Remote Administration Tool)
  5. Dynamic IP (noip.com host)
  6. DUC for windows (noip.com client) .Get it from here
  7. Android Device for testing.

Droidjack 2017 Version

Features of this Android HACK :

  • Get contacts from remote android device.
  • Click snaps using front or back camera.
  • Get real-time pin point location.
  • Record real-time sound by using microphone of android device.
  • and lots more…….

Hack Android using Droid Jack

Step 1 : Download Droid Jack from here and make sure all requirements are installed as described above.

Droidjack 2017 Pc

Step 2 : Now open Droid Jack.jar and jump to ' Generate apk ' tab .Now it's time to create a app for over tutorial ,basically it's a pre-configured payload .

  • App name : stack4 // anything you want
  • File name : stack4 // anything you want
  • Dynamic DNS : 192.168.1.4 // LAN IP
  • Port : 1337 // you can use any port but it should be available or open for listening
  • Bind with another apk : Leaving blank.You can bind this apk with another apk like whatsapp , viber , or any other android package.Here i'm not using this feature.
  • Stealth mode : Leaving blank.You can hide this app from launcher.Make it hidden.
  • Use custom icon : leaving blank.Use as desired app icon.

Step 3 : After successfully generating newly apk.Send and install it on Android device.

Step 4 : Goto ‘Devices' tab.Enter you port and turn on reception .Now leave your system open and wait for device capture on our droidjack dashboard .As soon victim opens the app on his mobile ,it will immediately reflects in devices section .

Step 5 : Open app in Android device.As soon as you open the app in the device, you can see the connected device in Droid jack device console.

See also : How to root android without PC

Step 6 : Now you have full access over victim device.You grab messages ,call log,pin point location , listen real time calls , access data from file manager and much more .

Droidjack 2017 Torrent

Conclusion :

Telecharger Droidjack 2017

Droidjack 2017 torrent

Upon further inspection, we have observed that this RAT extracts WhatsApp data too.

Figure 7:Whatsapp data.

The RAT stores all the data in a database (DB) in order to send it to the Command & Control (C&C) server. The following are the DBs created and maintained by the RAT.

Figure 8: Databases.

We saw the following hardcoded C&C server location in the RAT package:

Figure 9: Hardcoded C&C.

Conclusion:

The DroidJack RAT is another example of a growing trend in which malware authors seek to exploit public interest as a way to spread malware. In this case, like others before, the event of a popular game release became an opportunity to trick unsuspecting users into downloading the RAT. As a reminder, it is always a good practice to download apps only from trusted app stores such as Google Play. This practice can be enforced by unchecking the 'Unknown Sources' option under the 'Security' settings of your device.

Zscaler ThreatLabZ is actively monitoring this malware to ensure that Zscaler customers are protected from infection.

My previous post is about How to Hack Android Phone using Metasploit as you can see how easily anyone can hack android smartphone using metasploit but the whole thing was in Linux and everyone is not familiar and comfortable with Linux.But no worries ,this time we came back with another tutorial ' How to Hack android phone – Droid Jack and How to protect ourself ? ' which is totally based on Windows .

Also checkout: Lucky Patcher Apk

Why Windows ?

Windows is fully GUI(Graphical User Interface) based as you all know .In Linux you have to get familiar with terminals and other developer things which are lack of GUI and thats why most of the people gives up with Linux .Even if you are going to install a program over Linux then you have to install it via Terminal .It doesn't mean Linux not worths ,see our post on How to get familiar with Linux easily .

Why we are writing this tutorial ?

Previously we've posted a article about ' Malicious Android adware campaign tries to exploit root access ' and thats ridiculously true everything written on that post .After analyzing whole scenario we decided to write a tutorial on exploiting and defending android devices to aware innocent victims .We recommend you to take a look of that post and understand the hazards of third party malicious apps.

What is Droid Jack ?

Droid Jack is what you need for that. Droid Jack gives you the power to establish control over your beloveds' Android devices with an easy to use GUI and all the features you need to monitor them.Droid Jack is a client/server application developed in Java Android for the client side and in Java/Swing for the Server.

See also : How to Hack android using metasploit in Kali Linux .

Please read disclaimer : Here i'm using RAT[remote administration tool] software in windows for educational use ,all devices have been faked.This tutorial is for learning purposes only and should not be used for any illegal activities.It's only for awareness.Don't break someone privacy who not belongs to you , i'm not liable for any illegal activity…

Following are the requirements to get started.

  1. Internet Enabled Windows Machine.
  2. Java Installed ,if not then download it from here.
  3. Net-framework Installed ,if not then download it from here.
  4. DroidJack (Remote Administration Tool)
  5. Dynamic IP (noip.com host)
  6. DUC for windows (noip.com client) .Get it from here
  7. Android Device for testing.

Droidjack 2017 Version

Features of this Android HACK :

  • Get contacts from remote android device.
  • Click snaps using front or back camera.
  • Get real-time pin point location.
  • Record real-time sound by using microphone of android device.
  • and lots more…….

Hack Android using Droid Jack

Step 1 : Download Droid Jack from here and make sure all requirements are installed as described above.

Droidjack 2017 Pc

Step 2 : Now open Droid Jack.jar and jump to ' Generate apk ' tab .Now it's time to create a app for over tutorial ,basically it's a pre-configured payload .

  • App name : stack4 // anything you want
  • File name : stack4 // anything you want
  • Dynamic DNS : 192.168.1.4 // LAN IP
  • Port : 1337 // you can use any port but it should be available or open for listening
  • Bind with another apk : Leaving blank.You can bind this apk with another apk like whatsapp , viber , or any other android package.Here i'm not using this feature.
  • Stealth mode : Leaving blank.You can hide this app from launcher.Make it hidden.
  • Use custom icon : leaving blank.Use as desired app icon.

Step 3 : After successfully generating newly apk.Send and install it on Android device.

Step 4 : Goto ‘Devices' tab.Enter you port and turn on reception .Now leave your system open and wait for device capture on our droidjack dashboard .As soon victim opens the app on his mobile ,it will immediately reflects in devices section .

Step 5 : Open app in Android device.As soon as you open the app in the device, you can see the connected device in Droid jack device console.

See also : How to root android without PC

Step 6 : Now you have full access over victim device.You grab messages ,call log,pin point location , listen real time calls , access data from file manager and much more .

Droidjack 2017 Torrent

Conclusion :

Telecharger Droidjack 2017

This demonstration is really intense and describes about how anyone can easily take control over your device .We are pentester ,it's our formal and social duty to spread awareness about security flaws .

Droidjack 2017 Full

Jimi hendrix hey baby berkeley concert. Now it's time to tighten your device security to defend such type of malware and attacks .Read our quick post about ' How to protect you Android Phone ? '

If you have any doubt about your device security ,please feel free to ask





broken image