davinci1012/pinduoduo_backdoor_unpacker

Samples and Unpacker of malicious backdoors and exploits developed and used by Pinduoduo

JavaPython

Stars and forks stats for /davinci1012/pinduoduo_backdoor_unpacker

0 forks on 2023-01-010 forks on 2023-01-020 forks on 2023-01-030 forks on 2023-01-040 forks on 2023-01-050 forks on 2023-01-060 forks on 2023-01-070 forks on 2023-01-080 forks on 2023-01-090 forks on 2023-01-100 forks on 2023-01-110 forks on 2023-01-120 forks on 2023-01-130 forks on 2023-01-140 forks on 2023-01-150 forks on 2023-01-160 forks on 2023-01-170 forks on 2023-01-180 forks on 2023-01-190 forks on 2023-01-200 forks on 2023-01-210 forks on 2023-01-220 forks on 2023-01-230 forks on 2023-01-240 forks on 2023-01-250 forks on 2023-01-260 forks on 2023-01-270 forks on 2023-01-280 forks on 2023-01-290 forks on 2023-01-300 forks on 2023-01-310 forks on 2023-02-010 forks on 2023-02-020 forks on 2023-02-030 forks on 2023-02-040 forks on 2023-02-050 forks on 2023-02-060 forks on 2023-02-070 forks on 2023-02-080 forks on 2023-02-090 forks on 2023-02-100 forks on 2023-02-110 forks on 2023-02-120 forks on 2023-02-130 forks on 2023-02-140 forks on 2023-02-150 forks on 2023-02-160 forks on 2023-02-170 forks on 2023-02-180 forks on 2023-02-190 forks on 2023-02-200 forks on 2023-02-210 forks on 2023-02-220 forks on 2023-02-230 forks on 2023-02-240 forks on 2023-02-250 forks on 2023-02-260 forks on 2023-02-270 forks on 2023-02-280 forks on 2023-03-010 forks on 2023-03-020 forks on 2023-03-030 forks on 2023-03-040 forks on 2023-03-050 forks on 2023-03-060 forks on 2023-03-070 forks on 2023-03-080 forks on 2023-03-090 forks on 2023-03-100 forks on 2023-03-11148 forks on 2023-03-12212 forks on 2023-03-13275 forks on 2023-03-14292 forks on 2023-03-15299 forks on 2023-03-16307 forks on 2023-03-17311 forks on 2023-03-18313 forks on 2023-03-19313 forks on 2023-03-20316 forks on 2023-03-21330 forks on 2023-03-22340 forks on 2023-03-23340 forks on 2023-03-24342 forks on 2023-03-25342 forks on 2023-03-26342 forks on 2023-03-27385 forks on 2023-03-28404 forks on 2023-03-29422 forks on 2023-03-30423 forks on 2023-03-31

423forks in total +275last 90 days

0 stars on 2023-01-010 stars on 2023-01-020 stars on 2023-01-030 stars on 2023-01-040 stars on 2023-01-050 stars on 2023-01-060 stars on 2023-01-070 stars on 2023-01-080 stars on 2023-01-090 stars on 2023-01-100 stars on 2023-01-110 stars on 2023-01-120 stars on 2023-01-130 stars on 2023-01-140 stars on 2023-01-150 stars on 2023-01-160 stars on 2023-01-170 stars on 2023-01-180 stars on 2023-01-190 stars on 2023-01-200 stars on 2023-01-210 stars on 2023-01-220 stars on 2023-01-230 stars on 2023-01-240 stars on 2023-01-250 stars on 2023-01-260 stars on 2023-01-270 stars on 2023-01-280 stars on 2023-01-290 stars on 2023-01-300 stars on 2023-01-310 stars on 2023-02-010 stars on 2023-02-020 stars on 2023-02-030 stars on 2023-02-040 stars on 2023-02-050 stars on 2023-02-060 stars on 2023-02-070 stars on 2023-02-080 stars on 2023-02-090 stars on 2023-02-100 stars on 2023-02-110 stars on 2023-02-120 stars on 2023-02-130 stars on 2023-02-140 stars on 2023-02-150 stars on 2023-02-160 stars on 2023-02-170 stars on 2023-02-180 stars on 2023-02-190 stars on 2023-02-200 stars on 2023-02-210 stars on 2023-02-220 stars on 2023-02-230 stars on 2023-02-240 stars on 2023-02-250 stars on 2023-02-260 stars on 2023-02-270 stars on 2023-02-280 stars on 2023-03-010 stars on 2023-03-020 stars on 2023-03-030 stars on 2023-03-040 stars on 2023-03-050 stars on 2023-03-060 stars on 2023-03-070 stars on 2023-03-080 stars on 2023-03-090 stars on 2023-03-100 stars on 2023-03-11310 stars on 2023-03-12481 stars on 2023-03-13612 stars on 2023-03-14671 stars on 2023-03-15684 stars on 2023-03-16701 stars on 2023-03-17709 stars on 2023-03-18716 stars on 2023-03-19716 stars on 2023-03-20731 stars on 2023-03-21758 stars on 2023-03-22770 stars on 2023-03-23770 stars on 2023-03-24777 stars on 2023-03-25782 stars on 2023-03-26782 stars on 2023-03-27874 stars on 2023-03-28934 stars on 2023-03-29990 stars on 2023-03-30991 stars on 2023-03-31

991stars in total +681last 90 days

This is stars and forks stats for /davinci1012/pinduoduo_backdoor_unpacker repository. As of 31 Mar, 2023 this repository has 991 stars and 423 forks.

详细分析报告 Detailed Analysis Report English version see Report, 中文分析报告见分析报告 Pinduoduo恶意代码样本和脱壳机 听说PDD今天开始发律师函删帖抵赖了,那就放点新东西出来。 拼多多的两个壳,manwe和nvwa脱壳脚本。适用于样本中.mw1 .nw0文件。.nw0要用nvwa脱壳脚本,.mw1用manwe脚本。 拼多多manwe一键脱壳脚本 代码在manwe_unpacker目录,用法如下,或自己改路径: /tmp/mw1.bin放解压出来的文件,在/tmp/final_java/会生成脱壳后的java class文件,压缩一下拖到jadx里看。 public class ManweVmpLoader { public static void main(String[] args) throws Throwable { String firmwarePath = "/tmp/mw1.bin"; ManweVmpDataInputStream inputStream = new ManweVmpDataInputStream(Files.newInputStream(Paths.get(firmwarePath))); ManweVmpDex manweVmpDex = new ManweVmpDex(inputStream); System.out.printf("Load %d class%n", manweVmpDex.manweVmpClazzes.length); if (inputStream.available() != 0) { throw new RuntimeException(String.format("%d bytes remaining", inputStream.available())); } inputStream.close(); if (Files.notExists(Paths.get("/tmp/final_java/"))) { new File("/tmp/final_java/").mkdirs(); } manweVmpDex.writeClazzes("/tmp/final_java/"); } } 拼多多nvwa一键脱壳脚本 代码见nvwa_unpacker目录 提取出的恶意样本 PDD的恶意代码以加壳后的文件形式组织,APK自带AliveBaseAbility,其他的都是远程下发,以下称为“样本”。因为有些样本是动态下发,不一定全,如果有这里没有的,欢迎Pull Request补充。 样本在samples目录中,包含PDD APK自带的样本,以及其动态下发的样本。动态样本为3.2日之前从安装了PDD的手机里/data/data/com.xunmeng.pinduoduo/files/bot/, /data/data/com.xunmeng.pinduoduo/files/.components/提取出,现在新版本可能被PDD删掉了,有兴趣的可以找下装了之前的版本的手机看下,顺便看下app_mango目录,里面是配置文件,有惊喜。 带符号的样本为PDD 6.2.0提取出(samples/old_alive_base_ability_with_symbol/mw1.bin),新版本的APP携带的样本去掉了符号。 样本各个都是干货,值得看看。AliveBaseAbility是第一步,davinci仓库中提到的dex只是这个evil plan的第三步,这里其他的是第二步。 其他 一视同仁,平等对待才是好的营商环境,纵容、包庇不是。 据说PDD搞这个的100多号人的团队连夜解散了,删库跑路,是吗?又听说PDD这些漏洞手段被曝光停了之后,DAU出现明显下跌,是吗? 等下,有人敲门说查水表了,我先出 免责声明 仅用于研究用途,禁止和PDD一样作恶,没靠山别学
Read on GithubGithub Stats Page
repotechsstarsweeklyforksweekly
questdb/rust-maven-pluginJavaPythonRust86040
zendesk/maxwellJavaANTLRShell3.6k09570
Haleydu/CimocJavaOther2.1k02080
caesarHQ/textSQLJavaScriptPythonCSS7340650
jtydhr88/sd-3dmodel-loaderJavaScriptPython118080
ponlponl123/AIVTuberJavaScriptHTML1390170
warengonzaga/css-text-portrait-builderJavaScriptSCSSHTML2150640
Pylogmon/potJavaScriptRustCSS1530100
airtai/fastkafkaJupyter NotebookPythonOther268030
huawei-noah/HEBOJupyter NotebookPythonOther65501340