{"id":271,"date":"2013-12-17T18:50:51","date_gmt":"2013-12-18T02:50:51","guid":{"rendered":"http:\/\/www.android-decompiler.com\/blog\/?p=271"},"modified":"2018-12-19T13:40:09","modified_gmt":"2018-12-19T21:40:09","slug":"decompiling-android-mouabad","status":"publish","type":"post","link":"https:\/\/www.pnfsoftware.com\/blog\/decompiling-android-mouabad\/","title":{"rendered":"Decompiling Android Mouabad"},"content":{"rendered":"<p>Lookout has an interesting article about <a href=\"https:\/\/blog.lookout.com\/blog\/2013\/12\/09\/mouabad-p-pocket-dialing-for-profit\/\">Android Mouabad<\/a>. Yet another Korean SMS malware!<\/p>\n<p>The APK fully decompiled by JEB 1.4 can be found here: <a href=\"http:\/\/www.android-decompiler.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_JEB_decomp_20131217.zip\">mouabad_JEB_decomp_20131217.zip<\/a>. I haven&#8217;t refactored or commented the code, these are raw decompiled classes.<\/p>\n<p><a href=\"http:\/\/www.android-decompiler.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_sms_receiver.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-273\" alt=\"mouabad_sms_receiver\" src=\"http:\/\/www.android-decompiler.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_sms_receiver-300x184.jpg\" width=\"300\" height=\"184\" srcset=\"https:\/\/www.pnfsoftware.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_sms_receiver-300x184.jpg 300w, https:\/\/www.pnfsoftware.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_sms_receiver-624x384.jpg 624w, https:\/\/www.pnfsoftware.com\/blog\/wp-content\/uploads\/2013\/12\/mouabad_sms_receiver.jpg 874w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Sample MD5 68DF97CD5FB2A54B135B5A5071AE11CF is available on\u00a0<a href=\"http:\/\/contagiominidump.blogspot.com\/2013\/12\/mouabadp-android-dialer-sms-trojan.html\">Contagio<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lookout has an interesting article about Android Mouabad. Yet another Korean SMS malware! The APK fully decompiled by JEB 1.4 can be found here: mouabad_JEB_decomp_20131217.zip. I haven&#8217;t refactored or commented the code, these are raw decompiled classes. Sample MD5 68DF97CD5FB2A54B135B5A5071AE11CF is available on\u00a0Contagio.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,3,2],"tags":[],"class_list":["post-271","post","type-post","status-publish","format-standard","hentry","category-android","category-decompilation","category-malware"],"_links":{"self":[{"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/posts\/271","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/comments?post=271"}],"version-history":[{"count":0,"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/posts\/271\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/media?parent=271"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/categories?post=271"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pnfsoftware.com\/blog\/wp-json\/wp\/v2\/tags?post=271"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}