feat: MariBank 风控 bypass、澳洲银行 Hook 与 reverse 逆向工作区
新增 MariBank/SeaBank PH Root 与 SHPSSDK bypass、riskToken 净化及 Up/Suncorp/ubank 消息 Hook;整理 reverse/ 脚本与 Frida 工具链,并补充当日工作说明文档。
This commit is contained in:
22
reverse/scripts/find_detection_classes.py
Normal file
22
reverse/scripts/find_detection_classes.py
Normal file
@@ -0,0 +1,22 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
import re
|
||||
import zipfile
|
||||
|
||||
APK = r"C:\Users\Administrator\Desktop\notiMessage\reverse\apks\seabank_ph_base.apk"
|
||||
with zipfile.ZipFile(APK) as zf:
|
||||
for name in sorted(zf.namelist()):
|
||||
if not name.endswith(".dex"):
|
||||
continue
|
||||
data = zf.read(name)
|
||||
found = set()
|
||||
for m in re.finditer(rb"L[a-zA-Z0-9_$/]+;", data):
|
||||
s = m.group().decode()[1:-1].replace("/", ".")
|
||||
low = s.lower()
|
||||
if any(k in low for k in ("rootdetect", "emulatordetect", "safemode", "risk", "integrity", "xposed", "hookdetect")):
|
||||
found.add(s)
|
||||
if "WBRoot" in s or "WBEmulator" in s:
|
||||
found.add(s)
|
||||
if found:
|
||||
print("=== %s ===" % name)
|
||||
for s in sorted(found):
|
||||
print(s)
|
||||
Reference in New Issue
Block a user