| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Preiskovanje napada z zlonamerno programsko opremo tipa Anatsa : diplomsko delo visokošolskega študijskega programa Varnost in policijsko delo
Authors:ID Zadnik, Matija (Author)
ID Slak, Boštjan (Mentor) More about this mentor... New window
Files:.pdf VS_Zadnik_Matija_2025.pdf (1,23 MB)
MD5: 14A59073CE22EE37528EC23D0B9CE07C
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:V diplomskem delu je predstavljeno preiskovanje napada z zlonamerno programsko opremo tipa Anatsa. Gre za eno izmed različic zlonamerne programske opreme vrste trojanskega konja, ki se uporabniku predstavlja kot legitimna, a v ozadju izvaja škodljive aktivnosti. Anatsa se uporablja za pridobitev občutljivih bančnih podatkov iz okuženih naprav z operacijskim sistemom Android. Operacijski sistem Android je med napadalci priljubljen, saj je osnovan kot odprtokodni sistem, kar pomeni, da je vsem dostopen za preučevanje in omogoča seznanitev z njegovimi ranljivostmi. Poleg tega mehanizem za distribucijo aplikacij, Google Play trgovina, ravno tako dovoljuje, da svoje aplikacije na trg nalaga kdorkoli, saj ima razmeroma prizanesljive pravilnike o varnosti in zasebnosti. Anatsa je zelo dobro tehnično zasnovana in uporablja večstopenjski način okužbe naprave. Na napravo se ne naloži neposredno, temveč po aktivaciji prvotno naložene, na videz neškodljive aplikacije, in po pridobitvi določenih dovoljenj s strani uporabnika. Ta lastnost storilcem omogoča da svojo aplikacijo naložijo v Google Play trgovino brez, da bi jo tam pri pregledu zaznali kot zlonamerno. Posledično je tudi identifikacija tovrstne zlonamerne aktivnosti v zgodnjih fazah zelo zahtevna, zato mora biti kasnejša forenzična preiskava temeljita in bolj kompleksna.Storilci, ki stojijo za tovrstnimi napadi so dobro organizirani in uporabljajo tehnike s katerimi lahko prekrijejo svojo identiteto in se tako zaščitijo. Njihova lokacija in identiteta je običajno zabrisana z večplastnimi anonimni kripto transakcijami, za razvozlavanje katerih pa je potrebno tesno mednarodno sodelovanje preiskovalnih organov.
Keywords:kibernetska kriminaliteta, zlonamerna programska oprema, Anatsa, diplomske naloge
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:M. Zadnik
Year of publishing:2025
Year of performance:2025
Number of pages:VI f., 30 str.
PID:20.500.12556/DKUM-92932 New window
UDC:343.3/.7:004(043.2)
COBISS.SI-ID:241161731 New window
Publication date in DKUM:02.07.2025
Views:273
Downloads:75
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:27.05.2025

Secondary language

Language:English
Title:Investigation of anatsa-type malware attack
Abstract:The thesis presents an investigation of an attack involving the Anatsa type of malicious software. It is one of the variants of malware belonging to the trojan horse category, which is a type of malware that presents itself to the user as legitimate, while secretly performing harmful activities in the background. Anatsa is used to obtain sensitive banking information form devices running the Android operating system. The Android operating system is popular among perpetrators because it is based on an open-source model, meaning it is accessible for anyone to study and modify. Furthermore, its application distribution mechanism, the Google Play Store, similarly allows anyone to upload applications to the market, as it has relatively lenient security and privacy policies. Anatsa is technically very well designed and employs a multi-stagemethod of infecting the device. It is not immediately installed on the device but only after the activation of an initially installed, seemingly harmless application and after certain permissions are granted by the user. This feature allows perpetrators to upload their app to the Google Play Store without it being detected as malicious during inspection. As a result, identifying such malicious activity in its early stages is very challenging, and subsequent forensic investigation must therefore be thorough and more complex.The perpetrators behind these types of attacks are well-organized and use techniques to conceal their identities and protect themselves. Their location and identity are usually obfuscated through multi-layered anonymous cryptocurrency transactions, the unraveling of which requires close international cooperation among investigative authorities.
Keywords:cybercrime, malware, Anatsa, Android, criminal investigation


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica