<div id="contenttxt"><h2>背景介绍</h2><p><strong style="color: rgb(0, 176, 80);">Anubis(阿努比斯)是古埃及神话中的死神，以胡狼头、人身的形象出现在法老的壁画中。同时Anubis也是一种Android银行恶意软件，自2017年以来已经为全球100多个国家，300多家金融机构带来了相当大的麻烦。Anubis截止到目前为止，爆发地主要为欧洲国家，国内暂未发现该银行木马。</strong></p><p>Anubis主要通过伪装成金融应用、手机游戏、购物应用、软件更新、邮件应用、浏览器应用甚至物流应用等，从而渗透进谷歌应用商店，诱骗用户下载安装。</p><p>Anubis木马功能强大，自身结合了钓鱼、远控、勒索木马的功能。Anubis通过仿冒各种应用诱骗用户安装使用，当软件被激活后，会展现给用户一个仿冒的钓鱼页面，从而获取用户敏感信息，如银行账号密码、个人身份信息等。Anubis具备一般银行木马的功能，包括屏蔽用户短信，获取转发用户短信等功能。Anubis同时可以从服务端获取远控指令，对用户手机进行进一步控制。Anubis还是第一个集成勒索软件功能的Android银行木马。Anubis功能之多、之强大，甚至可以作为间谍软件进行使用。</p><p>近期有国外安全研究者发现一款仿冒为西班牙邮政运营商Correos的恶意软件，该恶意软件运行后会释放仿冒为Google Play Service Updater V2.1的Anubis木马程序，诱骗用户安装更新。</p><p><span class="highslide-image"><img src="https://ti.qianxin.com/uploads/2019/05/05/0de0c764b106e43964b75830922cbf61.png" alt="" style="display: block;"/></span></p><h2>诱饵关联</h2><p>本次Anubis的载体为仿冒为西班牙邮政运营商Correos的恶意软件：</p><p><span class="highslide-image"><img src="https://ti.qianxin.com/uploads/2019/05/05/6077e0a7fb865cdbf25adcdd0de5c254.png" alt="" style="display: block;"/></span></p><p>Correos官网：</p><p><span class="highslide-image"><img src="https://ti.qianxin.com/uploads/2019/05/05/3af625deb1f402761b30c7a6f49ca5bc.png" alt="" style="display: block;"/></span></p><p>经过盘古团队的Janus系统关联分析，我们发现了最新的12个Anubis载体，其图标去重后如下：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/46ced050ae7d40a18adcc01eaa8c2145.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/a7c518da4213b1a0fa9d1791bf884d32.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/27a3af37a049f19ffc2e677dbbff7a5c.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/143ca4f4b0dc3b9d7bd7b286fc4d1e5d.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/8432134a5d87bbdfc9b41fe031f2d487.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/4365a8fa433f7d9aca287279425fe409.png" alt="" style="display: block;"/></p><p>本次Anubis载体代码结构也基本相同：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/c860ff9f47e81c3c93a60d30b3d2b19c.png" alt="" style="display: block;"/></p><h2>样本分析</h2><table><thead><tr><th>文件名称</th><th>Correos Rastreo.apk</th></tr></thead><tbody><tr><td>软件名称</td><td>Correos Rastreo</td></tr><tr><td>软件包名</td><td>com.consultar.rastero</td></tr><tr><td>MD5</td><td>04D94228021B73E44261ADCCAD4173F3</td></tr><tr><td>安装图标</td><td><img src="https://ti.qianxin.com/uploads/2019/05/05/483bd9f28f57c0def4e7e705c38d404c.png" alt="" style="display: block;"/></td></tr></tbody></table><p>Anubis银行木马到目前为止功能大同小异，虽然仿冒的种类繁多，但核心代码结构并未有巨大的改变。Anubis代码核心以远控为主体，钓鱼、勒索等其它功能为辐，目的则为获取用户关键信息，窃取用户财产。</p><p>仿冒为Correos的程序运行后，会诱骗用户安装更新Google Play，而该更新软件即为Anubis木马程序。</p><p>仿冒为Correos的样本运行界面：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/4b43ae2f00d937dd4032c37361aaae1e.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/3932edcd0209070fa227aa6952357c99.png" alt="" style="display: block;"/></p><p>诱骗用户安装仿冒为Google Play Service Updater V2.1的Anubis木马程序：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/ee298c8182100bb976cff835c9731ae7.png" alt="" style="display: block;"/></p><p>通过拼接字符串获取下载链接：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/dff3e1b42944f88cdb314f4b45862c50.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/2a5e8d16ddd6d86fd65fdc689caa9500.png" alt="" style="display: block;"/></p><p>访问数据：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/3f7b265432c281c361ad80b2e564d264.png" alt="" style="display: block;"/></p><p>获取到的Anubis木马程序：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/12f08b0ba5341c1ce11d2a73e38d6586.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/b44e8fe76d42c92db688cee8b9eae9fc.png" alt="" style="display: block;"/></p><p>当Anubis木马运行后，依然延续了恶意软件的“做贼心虚”的本质，先隐藏自身，达到保护自身的目的：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/e246aa4cb4708bacc8227fbc1241027a.png" alt="" style="display: block;"/></p><p>通过服务器可以下发30多种指令，获取对用户手机的全面控制权，其中主要功能有，获取键盘记录、加密用户手机文件、开启VNC远程、打开指定web界面等。</p><p>获取指令及上传获取到的用户信息的URL拼接：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/4185420d882325fbd02a6973b77fcd80.png" alt=""/><img src="https://ti.qianxin.com/uploads/2019/05/05/2211bb02e17c913907136c995c1392de.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/10bcc771a39fecc08a018b04dc2fe0aa.png" alt="" style="display: block;"/></p><p>主要远控指令分析：</p><table><thead><tr><th>主要远控指令</th><th>指令对应的功能</th></tr></thead><tbody><tr><td>Send_GO_SMS</td><td>向指定电话号码发送指定内容</td></tr><tr><td>nymBePsG0</td><td>获取用户手机通讯录</td></tr><tr><td>GetSWSGO</td><td>获取用户手机短信</td></tr><tr><td><br/></td><td>telbookgotext=</td></tr><tr><td>getapps</td><td>获取用户手机已安装应用</td></tr><tr><td>getpermissions</td><td>获取已有的权限信息</td></tr><tr><td>startaccessibility</td><td>权限请求</td></tr><tr><td>startpermission</td><td>权限请求</td></tr><tr><td>=ALERT|</td><td>提示消息</td></tr><tr><td>=PUSH|</td><td>推送通知</td></tr><tr><td>startAutoPush</td><td>根据不同国家，推送不同的消息</td></tr><tr><td>RequestPermissionGPS</td><td>请求获取地理位置权限</td></tr><tr><td>|ussd=</td><td>呼叫转移</td></tr><tr><td>|recordsound=</td><td>录音</td></tr><tr><td>|replaceurl=</td><td>替换URL</td></tr><tr><td>|startapplication=</td><td>启动指定应用</td></tr><tr><td>getkeylogger</td><td>获取键盘记录</td></tr><tr><td>stopsound</td><td>停止录音</td></tr><tr><td>startsound</td><td>开始录音</td></tr><tr><td>startscreenVNC</td><td>开启VNC远控</td></tr><tr><td>deletefilefolder:</td><td>删除文件</td></tr><tr><td>downloadfile:</td><td>下载文件</td></tr><tr><td>opendir:</td><td>获取文件路径</td></tr><tr><td>startforward=</td><td>启动呼叫转移功能到指定号码</td></tr><tr><td>stopforward</td><td>停止呼叫转移功能</td></tr><tr><td>|openbrowser=</td><td>打开浏览器</td></tr><tr><td>|openactivity=</td><td>启动ActivityURL,打开一个web页面</td></tr><tr><td>|cryptokey=</td><td>对用户手机对应文件进行加密操作</td></tr><tr><td>|decryptokey=</td><td>对用户手机对应文件进行解密操作</td></tr><tr><td>getip</td><td>获取用户IP地址</td></tr></tbody></table><p>指令 “Send_GO_SMS”：向指定电话号码发送指定内容。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/7fa2140d74cb12dc4b6a09690c5a8df2.png" alt="" style="display: block;"/></p><p>指令 “nymBePsG0”：获取用户手机通讯录。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/211114f46383e863f058eeb682cd3d29.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/0155d81aec8106ef32c68a1a17e61229.png" alt="" style="display: block;"/></p><p>指令 “GetSWSGO”：获取用户手机短信。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/e260ec7bf02d320867e4f8ca1de4f528.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/5f8f926fb2f6a0eccb57071576bd3bee.png" alt="" style="display: block;"/></p><p>指令 “|telbookgotext=”：获取用户手机通讯录。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/7cb899672f4eac0e4675374cf7fa60fd.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/0155d81aec8106ef32c68a1a17e61229.png" alt="" style="display: block;"/></p><p>指令 “getapps”：获取用户手机已安装应用。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/d91fbf057c089f0ff1340e5a608298a8.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/5362d3540279d86df8b34b7413044ba0.png" alt="" style="display: block;"/></p><p>指令 “getpermissions”：获取已有的权限信息。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/b5e6c4a1158c2935250a42740dac8ab7.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/30a016a56585a422a2b5a0953976897e.png" alt="" style="display: block;"/></p><p>指令 “startaccessibility”：权限请求。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/0a0bedfdbd4f90b0dda62d8f3428ffc2.png" alt="" style="display: block;"/></p><p>指令 “startpermission”：权限请求。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/0a0bedfdbd4f90b0dda62d8f3428ffc2.png" alt="" style="display: block;"/></p><p>指令 “=ALERT|”：提示消息。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/bd8d071941636638d8be400c9d1c4db9.png" alt="" style="display: block;"/></p><p>指令 “=PUSH|”：推送通知。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/c1976b00d3ff8072b55264991295ba1c.png" alt="" style="display: block;"/></p><p>指令 “startAutoPush”：根据不同国家，推送不同的消息。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/6286d553cc28a82f48dd2a0aacce20d7.png" alt="" style="display: block;"/></p><p>指令 “RequestPermissionGPS”：请求获取地理位置权限。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/ba3e80273c96567544bddba4ba9b8387.png" alt="" style="display: block;"/></p><p>指令 “|ussd=”：呼叫转移。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/1827446d85976ea8b08a35e4c7b17cd1.png" alt="" style="display: block;"/></p><p>指令 “|recordsound=”：录音。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/740058de1e025103f5f21646ab0a52aa.png" alt="" style="display: block;"/></p><p>指令 “|replaceurl=”：替换URL。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/2b41f602fa6d94fcfd9c69703a28c9d5.png" alt="" style="display: block;"/></p><p>指令 “|startapplication=”：启动指定应用。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/28a0121471137cddc282063e93b49ecf.png" alt="" style="display: block;"/></p><p>指令 “getkeylogger”：获取键盘记录。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/1345dddef526e2dc188e7dc7f0daad6e.png" alt="" style="display: block;"/></p><p>指令 “stopsound”：停止录音。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/83f28afef7687055d1cb55b58339ec9d.png" alt="" style="display: block;"/></p><p>指令 “startsound”：开始录音。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/241b1b3c6438f0d8f7fa5cb493dab369.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/4f6a70119106626fac1708381324b754.png" alt="" style="display: block;"/></p><p>指令 “startscreenVNC”：开启VNC远控。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/b925a339d3aef2fac5d173d74e00c1a1.png" alt="" style="display: block;"/></p><p>指令”deletefilefolder:”：删除文件。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/2a82f8098ff9ef29d02b99716a67eb99.png" alt="" style="display: block;"/></p><p>指令 “downloadfile:”：下载文件。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/bab55c3927a0d5575072f50b1d7d3713.png" alt="" style="display: block;"/></p><p>指令 “opendir:”：获取文件路径。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/50f4ee591b112f456223850a94638911.png" alt="" style="display: block;"/></p><p>指令 “startforward=”：启动呼叫转移功能到指定号码。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/e3dec09557c80fbf27c044511cc597db.png" alt="" style="display: block;"/></p><p>指令 “stopforward”：停止呼叫转移功能。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/244092b5bdd5cfc60785a13f9b021f4c.png" alt="" style="display: block;"/></p><p>指令 “|openbrowser=”：打开浏览器。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/093eceebc5db52676d326f09250e229b.png" alt="" style="display: block;"/></p><p>指令 “|openactivity=”：启动ActivityURL,打开一个web页面。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/41ed2863310787972f4e0d1a69cfc3ce.png" alt="" style="display: block;"/></p><p>指令 “|cryptokey=”：对用户手机对应文件进行加密操作。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/bc59b2f9e32762ffc63ad971da9e9ef2.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/3b1c8a8b7e2f2af805b8088f7a9be5f4.png" alt="" style="display: block;"/></p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/1e2980f3ebe944c0607c77afbcaae2bf.png" alt="" style="display: block;"/></p><p>指令 “|decryptokey=”：对用户手机对应文件进行解密操作。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/b31e72bb578e5b870bacc7e4fe284a94.png" alt="" style="display: block;"/></p><p>指令 “getip”：获取用户IP地址。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/87ae9fceafcc1437369fb1d0091cf8e4.png" alt="" style="display: block;"/></p><h2>同源分析</h2><p>通过分析样本远控代码，我们可以发现其功能繁多且全面，对应不同的指令功能，我们不难理解整个木马的运作流程及各个功能的目的。值得注意的是，木马有打开WEB页面的操作，虽然目前该URL已经失效，但我们结合之前的同源样本分析结果，可以发现要打开的URL即为钓鱼页面。</p><p>同源样本中，打开推特链接：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/ef1b25ca7b320a7c57cb297284d0a83c.png" alt="" style="display: block;"/></p><p>现已失效：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/122d8df5307ef8ee401d42d5d3b43258.png" alt="" style="display: block;"/></p><p>同源样本中之前国外的分析结果，打开推特获取备份C2:</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/101e0db3e9f0a5a8603a804c804d856a.png" alt="" style="display: block;"/></p><p>打开解析后的链接，即为仿冒银行的登录页面：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/0029544b5f1870a85c3d6a4631d3e271.png" alt="" style="display: block;"/></p><p>新发现的Anubis相比于以前的做了加固处理，但是脱壳之后代码结构与之前的没有多大改变。</p><p>经过加固的代码结构：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/e47f5e293b80ad1e6d8d6f8750577793.png" alt="" style="display: block;"/></p><p>脱壳后的代码结构：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/8eb2127b758dcfc0acbb13fd49174e02.png" alt="" style="display: block;"/></p><p>Anubis旧版本代码结构：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/d5d9acc6f18a16e0edd1c820cbd0c489.png" alt="" style="display: block;"/></p><h2>新近活动</h2><p>我们对2019年后的Anubis样本进行了数据统计，以便后期可以更好的进行监控。</p><p>统计Anubis仿冒的主要图标，我们可以发现，Anubis木马主要通过仿冒一些主流的应用或者浏览器插件，诱骗用户进行更新，从而可以最大限度的迷惑用户，使木马本身可以顺利安装到用户手机中。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/08323787abbfc04c1bc5d53132d02a63.png" alt="" style="display: block;"/></p><p>通过统计2019年前4个月Anubis数量变化，我们可以发现，Anubis并没有因去年在国外大规模的爆发，被谷歌进行清理封杀而彻底消失或数量减少，其仍然一直存活着而且数量并没有减少，不间断的仍然会有人中木马病毒，虽然其域名被大量封杀，但并不能说明Anubis对用户手机已没有任何威胁，我们依然要谨防新的变种出现。</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/1114e366b1933f3e357f3f266cd2a5bb.png" alt="" style="display: block;"/></p><p>通过统计主要受害国家，我们可以看到受害国家主要集中在欧美地区，而土耳其与美国受害者最多，虽然目前国内暂未发现Anubis木马病毒，但我们也不能大意：</p><p><img src="https://ti.qianxin.com/uploads/2019/05/05/7e65cd19e888155ca9c061cb875bee4f.png" alt="" style="display: block;"/></p><p>此外附上由Threatfabric总结的，Anubis自爆发以来仿冒全球378个金融机构应用程序信息：</p><table><thead><tr><th>Package name</th><th>Application name</th></tr></thead><tbody><tr><td>MyING.be</td><td>ING Smart Banking</td></tr><tr><td>alior.bankingapp.android</td><td>Usługi Bankowe</td></tr><tr><td>at.bawag.mbanking</td><td>BAWAG P.S.K.</td></tr><tr><td>at.easybank.mbanking</td><td>easybank</td></tr><tr><td>at.easybank.securityapp</td><td>easybank Security App</td></tr><tr><td>at.easybank.tablet</td><td>easybank app</td></tr><tr><td>at.psa.app.bawag</td><td>BAWAG P.S.K. SmartPay</td></tr><tr><td>at.spardat.bcrmobile</td><td>Touch 24 Banking BCR</td></tr><tr><td>at.spardat.netbanking</td><td>ErsteBank/Sparkasse netbanking</td></tr><tr><td>at.volksbank.volksbankmobile</td><td>Volksbank Banking</td></tr><tr><td>au.com.bankwest.mobile</td><td>Bankwest</td></tr><tr><td>au.com.cua.mb</td><td>CUA</td></tr><tr><td>au.com.ingdirect.android</td><td>ING Australia Banking</td></tr><tr><td>au.com.mebank.banking</td><td>ME Bank</td></tr><tr><td>au.com.nab.mobile</td><td>NAB Mobile Banking</td></tr><tr><td>au.com.newcastlepermanent</td><td>NPBS Mobile Banking</td></tr><tr><td>au.com.suncorp.SuncorpBank</td><td>Suncorp Bank</td></tr><tr><td>biz.mobinex.android.apps.cep_sifrematik</td><td>Garanti Cep Şifrematik</td></tr><tr><td>by.st.alfa</td><td>Альфа-Бизнес Мобайл Беларусь</td></tr><tr><td>com.DijitalSahne.EnYakinHalkbank</td><td>Halkbank Nerede</td></tr><tr><td>com.FubonMobileClient</td><td>Fubon HK</td></tr><tr><td>com.MobileTreeApp</td><td>Dah Sing Bank</td></tr><tr><td>com.Plus500</td><td>Plus500: CFD Online Trading on Forex and Stocks</td></tr><tr><td>com.SifrebazCep</td><td>Halkbank Şifrebaz Cep</td></tr><tr><td>com.abnamro.nl.mobile.payments</td><td>ABN AMRO Mobiel Bankieren</td></tr><tr><td>com.advantage.RaiffeisenBank</td><td>Raiffeisen Smart Mobile</td></tr><tr><td>com.aff.otpdirekt</td><td>OTP SmartBank</td></tr><tr><td>com.akbank.android.apps.akbank_direkt</td><td>Akbank Direkt</td></tr><tr><td>com.akbank.android.apps.akbank_direkt_tablet</td><td>Akbank Direkt Tablet</td></tr><tr><td>com.akbank.softotp</td><td>Akbank Direkt Şifreci</td></tr><tr><td>com.amazon.mShop.android.shopping</td><td>Amazon Shopping</td></tr><tr><td>com.amazon.windowshop</td><td>Amazon for Tablets</td></tr><tr><td>com.anz.android</td><td>ANZ Mobile Taiwan</td></tr><tr><td>com.anz.android.gomoney</td><td>ANZ Australia</td></tr><tr><td>com.anzspot.mobile</td><td>ANZ Spot</td></tr><tr><td>com.arubanetworks.atmanz</td><td>Atmosphere ANZ</td></tr><tr><td>com.axis.mobile</td><td>Axis Mobile- Fund Transfer,UPI,Recharge & Payment</td></tr><tr><td>com.bankaustria.android.olb</td><td>Bank Austria MobileBanking</td></tr><tr><td>com.bankia.wallet</td><td>Bankia Wallet</td></tr><tr><td>com.bankinter.launcher</td><td>Bankinter Móvil</td></tr><tr><td>com.bankofamerica.cashpromobile</td><td>CashPro® + Token</td></tr><tr><td>com.bankofqueensland.boq</td><td>BOQ Mobile</td></tr><tr><td>com.barclays.android.barclaysmobilebanking</td><td>Barclays Mobile Banking</td></tr><tr><td>com.barclays.ke.mobile.android.ui</td><td>Barclays Kenya</td></tr><tr><td>com.bawagpsk.securityapp</td><td>BAWAG P.S.K. Security App</td></tr><tr><td>com.bbva.bbvacontigo</td><td>BBVA Spain</td></tr><tr><td>com.bbva.bbvawallet</td><td>BBVA Wallet Spain. Mobile Payment</td></tr><tr><td>com.bbva.netcash</td><td>BBVA Net cash</td></tr><tr><td>com.bendigobank.mobile</td><td>Bendigo Bank</td></tr><tr><td>com.binance.dev</td><td>Binance – Cryptocurrency Exchange</td></tr><tr><td>com.binance.odapplications</td><td>Binance: Cryptocurrency & Bitcoin Exchange</td></tr><tr><td>com.bitcoin.ss.zebpayindia</td><td>Zebpay India</td></tr><tr><td>com.bitfinex.bfxapp</td><td>Bitfinex</td></tr><tr><td>com.bitmarket.trader</td><td>Aplikacja Bitmarket</td></tr><tr><td>com.blockfolio.blockfolio</td><td>Blockfolio – Bitcoin and Cryptocurrency Tracker</td></tr><tr><td>com.bmo.mobile</td><td>BMO Mobile Banking</td></tr><tr><td>com.boursorama.android.clients</td><td>Boursorama Banque</td></tr><tr><td>com.bssys.VTBClient</td><td>Mobile Client VTB</td></tr><tr><td>com.bssys.vtb.mobileclient</td><td>MobileClientVTB</td></tr><tr><td>com.btcturk</td><td>BtcTurk Bitcoin Borsası</td></tr><tr><td>com.caisseepargne.android.mobilebanking</td><td>Banque</td></tr><tr><td>com.cba.android.netbank</td><td>CommBank app for tablet</td></tr><tr><td>com.chase.sig.android</td><td>Chase Mobile</td></tr><tr><td>com.cibc.android.mobi</td><td>CIBC Mobile Banking®</td></tr><tr><td>com.citi.citimobile</td><td>Citi Mobile®</td></tr><tr><td>com.citibank.mobile.au</td><td>Citibank Australia</td></tr><tr><td>com.citibank.mobile.uk</td><td>Citi Mobile UK</td></tr><tr><td>com.clairmail.fth</td><td>Fifth Third Mobile Banking</td></tr><tr><td>com.cleverlance.csas.servis24</td><td>SERVIS 24 Mobilni banka</td></tr><tr><td>com.cm_prod.bad</td><td>Crédit Mutuel</td></tr><tr><td>com.cm_prod.epasal</td><td>Epargne Salariale CM</td></tr><tr><td>com.cm_prod.nosactus</td><td>Crédit Mutuel – Nos Actus</td></tr><tr><td>com.cm_prod_tablet.bad</td><td>Crédit Mutuel pour Tablettes</td></tr><tr><td>com.coin.profit</td><td>Coin Profit</td></tr><tr><td>com.coinbase.android</td><td>Coinbase – Buy Bitcoin & more. Secure Wallet.</td></tr><tr><td>com.coins.bit.local</td><td>LocalBitCoins</td></tr><tr><td>com.coins.ful.bit</td><td>LocalBitCoins NEW</td></tr><tr><td>com.comarch.mobile.banking.bgzbnpparibas.biznes</td><td>Mobile BiznesPl@net</td></tr><tr><td>com.comarch.security.mobilebanking</td><td>INGBusiness</td></tr><tr><td>com.commbank.netbank</td><td>CommBank</td></tr><tr><td>com.crowdcompass.appSQ0QACAcYJ</td><td>ANZ Investor Tour</td></tr><tr><td>com.crypter.cryptocyrrency</td><td>Crypto App – Widgets, Alerts, News, Bitcoin Prices</td></tr><tr><td>com.csam.icici.bank.imobile</td><td>iMobile by ICICI Bank</td></tr><tr><td>com.db.mm.deutschebank</td><td>Meine Bank</td></tr><tr><td>com.db.mm.norisbank</td><td>norisbank App</td></tr><tr><td>com.db.pwcc.dbmobile</td><td>Deutsche Bank Mobile</td></tr><tr><td>com.dbs.hk.dbsmbanking</td><td>DBS digibank Hong Kong</td></tr><tr><td>com.de.dkb.portalapp</td><td>DKB-Banking</td></tr><tr><td>com.ebay.mobile</td><td>Fashion & Tech Deals – Shop, Sell & Save with eBay</td></tr><tr><td>com.edsoftapps.mycoinsvalue</td><td>My CryptoCoins Portfolio – All Coins</td></tr><tr><td>com.empik.empikapp</td><td>Empik</td></tr><tr><td>com.empik.empikfoto</td><td>Empik Foto</td></tr><tr><td>com.entersekt.authapp.sparkasse</td><td>S-ID-Check</td></tr><tr><td>com.fi6122.godough</td><td>TSB Mobile</td></tr><tr><td>com.finansbank.mobile.cepsube</td><td>QNB Finansbank Cep Şubesi</td></tr><tr><td>com.finanteq.finance.ca</td><td>CA24 Mobile</td></tr><tr><td>com.fragment.akbank</td><td>Akbank Sanat</td></tr><tr><td>com.fusion.ATMLocator</td><td>People’s Choice Credit Union</td></tr><tr><td>com.garanti.cepbank</td><td>Garanti CepBank</td></tr><tr><td>com.garanti.cepsubesi</td><td>Garanti Mobile Banking</td></tr><tr><td>com.garantibank.cepsubesiro</td><td>GarantiBank</td></tr><tr><td>com.garantiyatirim.fx</td><td>Garanti FX Trader</td></tr><tr><td>com.getingroup.mobilebanking</td><td>Getin Mobile</td></tr><tr><td>com.grppl.android.shell.BOS</td><td>Bank of Scotland Mobile Banking: secure on the go</td></tr><tr><td>com.grppl.android.shell.CMBlloydsTSB73</td><td>Lloyds Bank Mobile Banking</td></tr><tr><td>com.grppl.android.shell.halifax</td><td>Halifax: the banking app that gives you extra</td></tr><tr><td>com.hangseng.rbmobile</td><td>Hang Seng Personal Banking</td></tr><tr><td>com.htsu.hsbcpersonalbanking</td><td>HSBC Mobile Banking</td></tr><tr><td>com.idamob.tinkoff.android</td><td>Tinkoff</td></tr><tr><td>com.idbi.mpassbook</td><td>IDBI Bank mPassbook</td></tr><tr><td>com.idbibank.abhay_card</td><td>Abhay by IDBI Bank Ltd</td></tr><tr><td>com.ideomobile.hapoalim</td><td>בנק הפועלים – ניהול החשבון‎</td></tr><tr><td>com.ifs.banking.fiid4202</td><td>TSBBank Mobile Banking</td></tr><tr><td>com.imb.banking2</td><td>IMB.Banking</td></tr><tr><td>com.infonow.bofa</td><td>Bank of America Mobile Banking</td></tr><tr><td>com.infrasofttech.indianBank</td><td>IndPay</td></tr><tr><td>com.ing.diba.mbbr2</td><td>ING-DiBa Banking + Brokerage</td></tr><tr><td>com.ing.mobile</td><td>ING Bankieren</td></tr><tr><td>com.ingbanktr.ingmobil</td><td>ING Mobil</td></tr><tr><td>com.isis_papyrus.raiffeisen_pay_eyewdg</td><td>Raiffeisen ELBA</td></tr><tr><td>com.jackpf.blockchainsearch</td><td>Bitcoin Blockchain Explorer</td></tr><tr><td>com.jamalabbasii1998.localbitcoin</td><td>Local BitCoin</td></tr><tr><td>com.jiffyondemand.user</td><td>Jiffy</td></tr><tr><td>com.konylabs.capitalone</td><td>Capital One® Mobile</td></tr><tr><td>com.kryptokit.jaxx</td><td>Jaxx Blockchain Wallet</td></tr><tr><td>com.kutxabank.android</td><td>Kutxabank</td></tr><tr><td>com.kuveytturk.mobil</td><td>Mobil Şube</td></tr><tr><td>com.latuabanca_tabperandroid</td><td>La tua banca per Tablet</td></tr><tr><td>com.latuabancaperandroid</td><td>Intesa Sanpaolo Mobile</td></tr><tr><td>com.localbitcoins.exchange</td><td>LocalBitcoins – Buy and sell Bitcoin</td></tr><tr><td>com.localbitcoinsmbapp</td><td>LocalBitCoins Official</td></tr><tr><td>com.lynxspa.bancopopolare</td><td>YouApp</td></tr><tr><td>com.magiclick.FinansPOS</td><td>FinansPOS</td></tr><tr><td>com.magiclick.odeabank</td><td>Odeabank</td></tr><tr><td>com.mal.saul.coinmarketcap</td><td>Coin Market-Bitcoin Prices,Currencies,BTC,EUR,ICO</td></tr><tr><td>com.matriksdata.finansyatirim</td><td>QNB Finansinvest</td></tr><tr><td>com.matriksdata.ziraatyatirim.pad</td><td>Ziraat Trader HD</td></tr><tr><td>com.matriksmobile.android.ziraatTrader</td><td>Ziraat Trader</td></tr><tr><td>com.mobikwik_new</td><td>Mobile Recharge,Bill Payments,UPI & Money Transfer</td></tr><tr><td>com.mobillium.papara</td><td>Papara Cüzdan</td></tr><tr><td>com.moneybookers.skrillpayments</td><td>Skrill</td></tr><tr><td>com.moneybookers.skrillpayments.neteller</td><td>NETELLER</td></tr><tr><td>com.monitise.isbankmoscow</td><td>ISBANK Online</td></tr><tr><td>com.mtel.androidbea</td><td>BEA 東亞銀行</td></tr><tr><td>com.mycelium.wallet</td><td>Mycelium Bitcoin Wallet</td></tr><tr><td>com.oxigen.oxigenwallet</td><td>Bill Payment & Recharge,Wallet</td></tr><tr><td>com.palatine.android.mobilebanking.prod</td><td>ePalatine Particuliers</td></tr><tr><td>com.paypal.android.p2pmobile</td><td>PayPal Cash App: Send and Request Money Fast</td></tr><tr><td>com.phyder.engage</td><td>RBS</td></tr><tr><td>com.plunien.poloniex</td><td>Poloniex</td></tr><tr><td>com.portfolio.coinbase_tracker</td><td>Coinbase Tracker (3rd party)</td></tr><tr><td>com.pozitron.albarakaturk</td><td>Albaraka Mobil Şube</td></tr><tr><td>com.pozitron.iscep</td><td>İşCep</td></tr><tr><td>com.pozitron.vakifbank</td><td>VakıfBank Cep Şifre</td></tr><tr><td>com.quickmobile.anzirevents15</td><td>ANZ Investor Relations Events</td></tr><tr><td>com.rbc.mobile.android</td><td>RBC Mobile</td></tr><tr><td>com.rbs.mobile.android.natwest</td><td>NatWest Mobile Banking</td></tr><tr><td>com.rbs.mobile.android.natwestbandc</td><td>NatWest Business Banking</td></tr><tr><td>com.rbs.mobile.android.natwestoffshore</td><td>NatWest International</td></tr><tr><td>com.rbs.mobile.android.rbs</td><td>Royal Bank of Scotland Mobile Banking</td></tr><tr><td>com.rbs.mobile.android.rbsbandc</td><td>RBS Business Banking</td></tr><tr><td>com.rbs.mobile.android.ubr</td><td>Ulster Bank RI Mobile Banking</td></tr><tr><td>com.rbs.mobile.investisir</td><td>RBS Investor & Media Relations</td></tr><tr><td>com.redrockdigimark</td><td>QNB National Day</td></tr><tr><td>com.rsi</td><td>ruralvía</td></tr><tr><td>com.santander.app</td><td>Santander Brasil</td></tr><tr><td>com.sbi.SBIFreedomPlus</td><td>SBI Anywhere Personal</td></tr><tr><td>com.scb.breezebanking.hk</td><td>SC Mobile Hong Kong</td></tr><tr><td>com.scotiabank.mobile</td><td>Scotiabank Mobile Banking</td></tr><tr><td>com.snapwork.IDBI</td><td>IDBI Bank GO Mobile+</td></tr><tr><td>com.snapwork.hdfc</td><td>HDFC Bank MobileBanking</td></tr><tr><td>com.softtech.isbankasi</td><td>İşTablet</td></tr><tr><td>com.softtech.iscek</td><td>ÇEKSOR</td></tr><tr><td>com.sovereign.santander</td><td>Santander Bank US</td></tr><tr><td>com.starfinanz.mobile.android.pushtan</td><td>S-pushTAN</td></tr><tr><td>com.starfinanz.smob.android.sbanking</td><td>Sparkasse+ Finanzen im Griff</td></tr><tr><td>com.starfinanz.smob.android.sfinanzstatus</td><td>Sparkasse Ihre mobile Filiale</td></tr><tr><td>com.starfinanz.smob.android.sfinanzstatus.tablet</td><td>Sparkasse fürs Tablet</td></tr><tr><td>com.suntrust.mobilebanking</td><td>SunTrust Mobile App</td></tr><tr><td>com.targo_prod.bad</td><td>TARGOBANK Mobile Banking</td></tr><tr><td>com.td</td><td>TD Canada</td></tr><tr><td>com.teb</td><td>CEPTETEB</td></tr><tr><td>com.tecnocom.cajalaboral</td><td>Banca Móvil Laboral Kutxa</td></tr><tr><td>com.thunkable.android.manirana54.LocalBitCoins</td><td>LocalBitCoins</td></tr><tr><td>com.thunkable.android.manirana54.LocalBitCoins_unblock</td><td>UNBLOCK Local BitCoins</td></tr><tr><td>com.thunkable.android.santoshmehta364.UNOCOIN_LIVE</td><td>UNOCOIN LIVE</td></tr><tr><td>com.tmob.denizbank</td><td>MobilDeniz</td></tr><tr><td>com.tmob.tabletdeniz</td><td>MobilDeniz Tablet</td></tr><tr><td>com.tmobtech.halkbank</td><td>Halkbank Mobil</td></tr><tr><td>com.tnx.apps.coinportfolio</td><td>Coin Portfolio for Bitcoin & Altcoin tracker</td></tr><tr><td>com.triodos.bankingnl</td><td>Triodos Bankieren NL</td></tr><tr><td>com.unicredit</td><td>Mobile Banking UniCredit</td></tr><tr><td>com.unionbank.ecommerce.mobile.android</td><td>Union Bank Mobile Banking</td></tr><tr><td>com.unionbank.ecommerce.mobile.commercial.legacy</td><td>Union Bank Commercial Clients</td></tr><tr><td>com.unocoin.unocoinmerchantPoS</td><td>Unocoin Merchant PoS</td></tr><tr><td>com.unocoin.unocoinwallet</td><td>Unocoin Wallet</td></tr><tr><td>com.usaa.mobile.android.usaa</td><td>USAA Mobile</td></tr><tr><td>com.usbank.mobilebanking</td><td>U.S. Bank</td></tr><tr><td>com.vakifbank.mobile</td><td>VakıfBank Mobil Bankacılık</td></tr><tr><td>com.veripark.ykbaz</td><td>YapıKredi Azərbaycan MobilBank</td></tr><tr><td>com.vipera.ts.starter.QNB</td><td>QNB Mobile</td></tr><tr><td>com.vtb.mobilebank</td><td>VTB Mobile Georgia</td></tr><tr><td>com.wellsFargo.ceomobile</td><td>Wells Fargo CEO Mobile®</td></tr><tr><td>com.wf.wellsfargomobile</td><td>Wells Fargo Mobile</td></tr><tr><td>com.wf.wellsfargomobile.tablet</td><td>Wells Fargo for Tablet</td></tr><tr><td>com.yinzcam.facilities.verizon</td><td>Capital One Arena Mobile</td></tr><tr><td>com.ykb.android</td><td>Yapı Kredi Mobile</td></tr><tr><td>com.ykb.android.mobilonay</td><td>Yapı Kredi Corporate-For Firms</td></tr><tr><td>com.ykb.androidtablet</td><td>Yapı Kredi Mobil Şube</td></tr><tr><td>com.ykb.avm</td><td>Yapı Kredi Cüzdan</td></tr><tr><td>com.yurtdisi.iscep</td><td>JSC İŞBANK</td></tr><tr><td>com.ziraat.ziraatmobil</td><td>Ziraat Mobil</td></tr><tr><td>com.ziraat.ziraattablet</td><td>Ziraat Tablet</td></tr><tr><td>cz.airbank.android</td><td>My Air</td></tr><tr><td>cz.csob.smartbanking</td><td>ČSOB SmartBanking</td></tr><tr><td>cz.sberbankcz</td><td>Smart Banking</td></tr><tr><td>de.comdirect.android</td><td>comdirect mobile App</td></tr><tr><td>de.commerzbanking.mobil</td><td>Commerzbank Banking App</td></tr><tr><td>de.consorsbank</td><td>Consorsbank</td></tr><tr><td>de.dkb.portalapp</td><td>DKB-Banking</td></tr><tr><td>de.fiducia.smartphone.android.banking.vr</td><td>VR-Banking</td></tr><tr><td>de.fiducia.smartphone.android.securego.vr</td><td>VR-SecureGo</td></tr><tr><td>de.postbank.finanzassistent</td><td>Postbank Finanzassistent</td></tr><tr><td>de.schildbach.wallet</td><td>Bitcoin Wallet</td></tr><tr><td>es.bancopopular.nbmpopular</td><td>Popular</td></tr><tr><td>es.bancosantander.apps</td><td>Santander</td></tr><tr><td>es.cm.android</td><td>Bankia</td></tr><tr><td>es.cm.android.tablet</td><td>Bankia Tablet</td></tr><tr><td>es.evobanco.bancamovil</td><td>EVO Banco móvil</td></tr><tr><td>es.lacaixa.mobile.android.newwapicon</td><td>CaixaBank</td></tr><tr><td>eu.eleader.mobilebanking.invest</td><td>plusbank24</td></tr><tr><td>eu.eleader.mobilebanking.pekao</td><td>Pekao24Makler</td></tr><tr><td>eu.eleader.mobilebanking.pekao.firm</td><td>PekaoBiznes24</td></tr><tr><td>eu.eleader.mobilebanking.raiffeisen</td><td>Mobile Bank</td></tr><tr><td>eu.inmite.prj.kb.mobilbank</td><td>Mobilni Banka</td></tr><tr><td>eu.newfrontier.iBanking.mobile.Halk.Retail</td><td>Halkbank Mobile App</td></tr><tr><td>eu.unicreditgroup.hvbapptan</td><td>HVB Mobile B@nking</td></tr><tr><td>finansbank.enpara</td><td>Enpara.com Cep Şubesi</td></tr><tr><td>finansbank.enpara.sirketim</td><td>Enpara.com Şirketim Cep Şubesi</td></tr><tr><td>fr.axa.monaxa</td><td>Mon AXA</td></tr><tr><td>fr.banquepopulaire.cyberplus</td><td>Banque Populaire</td></tr><tr><td>fr.creditagricole.androidapp</td><td>Ma Banque</td></tr><tr><td>fr.laposte.lapostemobile</td><td>La Poste – Services Postaux</td></tr><tr><td>fr.laposte.lapostetablet</td><td>La Poste HD – Services Postaux</td></tr><tr><td>fr.lcl.android.customerarea</td><td>Mes Comptes – LCL</td></tr><tr><td>hdfcbank.hdfcquickbank</td><td>HDFC Bank MobileBanking LITE</td></tr><tr><td>hk.com.hsbc.hsbchkmobilebanking</td><td>HSBC HK Mobile Banking</td></tr><tr><td>hr.asseco.android.jimba.mUCI.ro</td><td>Mobile Banking</td></tr><tr><td>in.co.bankofbaroda.mpassbook</td><td>Baroda mPassbook</td></tr><tr><td>info.blockchain.merchant</td><td>Blockchain Merchant</td></tr><tr><td>io.getdelta.android</td><td>Delta – Bitcoin & Cryptocurrency Portfolio Tracker</td></tr><tr><td>it.bnl.apps.banking</td><td>BNL</td></tr><tr><td>it.bnl.apps.enterprise.bnlpay</td><td>BNL PAY</td></tr><tr><td>it.bpc.proconl.mbplus</td><td>MB+</td></tr><tr><td>it.copergmps.rt.pf.android.sp.bmps</td><td>Banca MPS</td></tr><tr><td>it.gruppocariparma.nowbanking</td><td>Nowbanking</td></tr><tr><td>it.ingdirect.app</td><td>ING DIRECT Italia</td></tr><tr><td>it.nogood.container</td><td>UBI Banca</td></tr><tr><td>it.popso.SCRIGNOapp</td><td>SCRIGNOapp</td></tr><tr><td>it.secservizi.mobile.atime.bpaa</td><td>Volksbank per tablet</td></tr><tr><td>it.volksbank.android</td><td>Volksbank · Banca Popolare</td></tr><tr><td>jp.co.aeonbank.android.passbook</td><td>イオン銀行通帳アプリ かんたんログイン＆残高・明細の確認</td></tr><tr><td>jp.co.netbk</td><td>住信SBIネット銀行</td></tr><tr><td>jp.co.rakuten_bank.rakutenbank</td><td>楽天銀行 -個人のお客様向けアプリ</td></tr><tr><td>jp.co.sevenbank.AppPassbook</td><td>App Bankbook</td></tr><tr><td>jp.co.smbc.direct</td><td>三井住友銀行アプリ</td></tr><tr><td>jp.mufg.bk.applisp.app</td><td>三菱UFJ銀行</td></tr><tr><td>me.doubledutch.hvdnz.cbnationalconference2016</td><td>CB Conference 2018</td></tr><tr><td>mobi.societegenerale.mobile.lappli</td><td>L’Appli Société Générale</td></tr><tr><td>mobile.santander.de</td><td>Santander Mobile Banking</td></tr><tr><td>net.bnpparibas.mescomptes</td><td>Mes Comptes BNP Paribas</td></tr><tr><td>nl.asnbank.asnbankieren</td><td>ASN Mobiel Bankieren</td></tr><tr><td>nl.snsbank.mobielbetalen</td><td>SNS Mobiel Betalen</td></tr><tr><td>nz.co.anz.android.mobilebanking</td><td>ANZ goMoney New Zealand</td></tr><tr><td>nz.co.asb.asbmobile</td><td>ASB Mobile Banking</td></tr><tr><td>nz.co.bnz.droidbanking</td><td>BNZ Mobile</td></tr><tr><td>nz.co.kiwibank.mobile</td><td>Kiwibank Mobile Banking</td></tr><tr><td>nz.co.westpac</td><td>Westpac One (NZ) Mobile Banking</td></tr><tr><td>org.banksa.bank</td><td>BankSA Mobile Banking</td></tr><tr><td>org.bom.bank</td><td>Bank of Melbourne Mobile Banking</td></tr><tr><td>org.stgeorge.bank</td><td>St.George Mobile Banking</td></tr><tr><td>org.westpac.bank</td><td>Westpac Mobile Banking</td></tr><tr><td>piuk.blockchain.android</td><td>Blockchain Wallet. Bitcoin, Bitcoin Cash, Ethereum</td></tr><tr><td>pl.aliorbank.aib</td><td>Alior Bank</td></tr><tr><td>pl.allegro</td><td>Allegro</td></tr><tr><td>pl.bosbank.mobile</td><td>BOŚBank24</td></tr><tr><td>pl.bph</td><td>BusinessPro Lite</td></tr><tr><td>pl.bps.bankowoscmobilna</td><td>BPS Mobilnie</td></tr><tr><td>pl.bzwbk.bzwbk24</td><td>Santander mobile</td></tr><tr><td>pl.bzwbk.ibiznes24</td><td>iBiznes24 mobile</td></tr><tr><td>pl.bzwbk.mobile.tab.bzwbk24</td><td>BZWBK24 mobile (tablet)</td></tr><tr><td>pl.ceneo</td><td>Ceneo – zakupy i promocje</td></tr><tr><td>pl.com.rossmann.centauros</td><td>Rossmann PL</td></tr><tr><td>pl.fmbank.smart</td><td>Nest Bank</td></tr><tr><td>pl.ideabank.mobilebanking</td><td>Idea Bank PL</td></tr><tr><td>pl.ing.mojeing</td><td>Moje ING mobile</td></tr><tr><td>pl.ipko.mobile</td><td>Token iPKO</td></tr><tr><td>pl.mbank</td><td>mBank PL</td></tr><tr><td>pl.millennium.corpApp</td><td>Bank Millennium for Companies</td></tr><tr><td>pl.orange.mojeorange</td><td>Mój Orange</td></tr><tr><td>pl.pkobp.iko</td><td>IKO</td></tr><tr><td>pl.pkobp.ipkobiznes</td><td>iPKO biznes</td></tr><tr><td>posteitaliane.posteapp.apppostepay</td><td>Postepay</td></tr><tr><td>ro.btrl.mobile</td><td>Banca Transilvania</td></tr><tr><td>ru.alfabank.mobile.android</td><td>Альфа-Банк (Alfa-Bank)</td></tr><tr><td>ru.alfabank.oavdo.amc</td><td>Альфа-Бизнес</td></tr><tr><td>ru.alfabank.sense</td><td>Sense от Альфа-Банка</td></tr><tr><td>ru.alfadirect.app</td><td>Alfa-Direct</td></tr><tr><td>ru.bm.mbm</td><td>ВТБ Банк Москвы</td></tr><tr><td>ru.mw</td><td>QIWI Wallet</td></tr><tr><td>ru.sberbank.mobileoffice</td><td>Сбербанк Бизнес Онлайн</td></tr><tr><td>ru.sberbank.sberbankir</td><td>Sberbank IR</td></tr><tr><td>ru.sberbank.spasibo</td><td>Спасибо от Сбербанка</td></tr><tr><td>ru.sberbank_sbbol</td><td>Сбербанк Бизнес Онлайн</td></tr><tr><td>ru.sberbankmobile</td><td>Сбербанк Онлайн</td></tr><tr><td>ru.tcsbank.c2c</td><td>Card 2 Card</td></tr><tr><td>ru.tinkoff.goabroad</td><td>FSSP FNS Russia</td></tr><tr><td>ru.tinkoff.mgp</td><td>Tinkoff Play: apply for a card</td></tr><tr><td>ru.tinkoff.sme</td><td>Тинькофф Бизнес</td></tr><tr><td>ru.vtb24.mobilebanking.android</td><td>VTB-Online</td></tr><tr><td>sk.sporoapps.accounts</td><td>Účty</td></tr><tr><td>sk.sporoapps.skener</td><td>Platby</td></tr><tr><td>src.com.idbi</td><td>IDBI Bank GO Mobile</td></tr><tr><td>tr.com.hsbc.hsbcturkey</td><td>HSBC Turkey</td></tr><tr><td>tr.com.sekerbilisim.mbank</td><td>ŞEKER MOBİL ŞUBE</td></tr><tr><td>tr.com.tradesoft.tradingsystem.gtpmobile.halk</td><td>Halk Trade</td></tr><tr><td>uk.co.bankofscotland.businessbank</td><td>Bank of Scotland Business Mobile Banking</td></tr><tr><td>uk.co.santander.businessUK.bb</td><td>Business Banking</td></tr><tr><td>uk.co.santander.santanderUK</td><td>Santander Mobile Banking</td></tr><tr><td>wit.android.bcpBankingApp.millenniumPL</td><td>Bank Millennium</td></tr><tr><td>wos.com.zebpay</td><td>Zebpay Calculator – Profit/Loss Management</td></tr><tr><td>zebpay.Application</td><td>Zebpay Bitcoin and Cryptocurrency Exchange</td></tr><tr><td>aib.ibank.android</td><td>AIB Mobile</td></tr><tr><td>com.att.myWireless</td><td>myAT&T</td></tr><tr><td>com.bbnt</td><td>BB&T PlanTrac Mobile</td></tr><tr><td>com.bestbuy.android</td><td>Best Buy</td></tr><tr><td>com.discoverfinancial.mobile</td><td>Discover Mobile</td></tr><tr><td>com.eastwest.mobile</td><td>EastWest Mobile</td></tr><tr><td>com.fi6256.godough</td><td>Commercial Bank for Android</td></tr><tr><td>com.fi6543.godough</td><td>Community Bank NA Mobile</td></tr><tr><td>com.fi6665.godough</td><td>Fifth District Mobile Banking</td></tr><tr><td>com.fi9228.godough</td><td>CNB Mobile Banking</td></tr><tr><td>com.fi9908.godough</td><td>First US Bank Anywhere Access</td></tr><tr><td>com.fuib.android.spot.online</td><td>PUMB Online</td></tr><tr><td>com.idamobile.android.hcb</td><td>Мобильный банк – Хоум Кредит</td></tr><tr><td>com.ifs.banking.fiid1369</td><td>Fulton Bank Mobile Banking</td></tr><tr><td>com.ifs.mobilebanking.fiid3919</td><td>Associated Credit Union Mobile</td></tr><tr><td>com.jackhenry.rockvillebankct</td><td>United Bank – Mobile Banking</td></tr><tr><td>com.jackhenry.washingtontrustbankwa</td><td>WTB Mobile</td></tr><tr><td>com.jpm.sig.android</td><td>J.P. Morgan Mobile</td></tr><tr><td>com.sterling.onepay</td><td>Sterling OnePay</td></tr><tr><td>com.svb.mobilebanking</td><td>SVB Mobile Banking-Commercial</td></tr><tr><td>com.ukrsibbank.client.android</td><td>UKRSIB online</td></tr><tr><td>com.vkontakte.android</td><td>VK</td></tr><tr><td>com.vzw.hss.myverizon</td><td>My Verizon</td></tr><tr><td>logo.com.mbanking</td><td>ПСБ</td></tr><tr><td>org.usemployees.mobile</td><td>U.S. Employees Credit Union</td></tr><tr><td>pinacleMobileiPhoneApp.android</td><td>PINACLE®</td></tr><tr><td>ru.alfabank.mobile.ua.android</td><td>Alfa-Mobile Ukraine</td></tr><tr><td>ru.avangard</td><td>Банк Авангард</td></tr><tr><td>ru.rosbank.android</td><td>ROSBANK Online</td></tr><tr><td>ru.simpls.brs2.mobbank</td><td>Моб. банк Русский Стандарт</td></tr><tr><td>ru.simpls.mbrd.ui</td><td>МТС Банк</td></tr><tr><td>ru.taxovichkof.android</td><td>TaxovichkoF: order a taxi in St Petersburg online</td></tr><tr><td>ua.aval.dbo.client.android</td><td>Raiffeisen Online Ukraine</td></tr><tr><td>ua.com.cs.ifobs.mobile.android.otp</td><td>OTP Smart</td></tr><tr><td>ua.com.cs.ifobs.mobile.android.pivd</td><td>Pivdenny MyBank</td></tr><tr><td>ua.oschadbank.online</td><td>Ощад 24/7</td></tr><tr><td>ua.privatbank.ap24</td><td>Privat24</td></tr><tr><td>xmr.org.freewallet.app</td><td>Monero Wallet</td></tr><tr><td>com.ubercab</td><td>Uber</td></tr><tr><td>com.avito.android</td><td>Объявления Авито: авто, работа, квартиры, вещи</td></tr><tr><td>com.instagram.android</td><td>Instagram</td></tr><tr><td>com.openbank</td><td>Банк Открытие</td></tr><tr><td>com.twitter.android</td><td>Twitter</td></tr><tr><td>com.viber.voip</td><td>Viber Messenger</td></tr><tr><td>com.whatsapp</td><td>WhatsApp Messenger</td></tr><tr><td>org.telegram.messenger</td><td>Telegram</td></tr><tr><td>ru.auto.ara</td><td>Авто.ру: купить и продать авто</td></tr><tr><td>ru.ok.android</td><td>OK</td></tr><tr><td>ru.rutaxi.vezet</td><td>Везёт – заказ такси онлайн</td></tr><tr><td>ru.yandex.taxi</td><td>Yandex.Taxi Ride-Hailing Service</td></tr><tr><td>cb.ibank</td><td>УБРиР</td></tr><tr><td>com.bifit.mobile.otpbank</td><td>ОТПбизнес</td></tr><tr><td>com.bifit.mobile.ubrr</td><td>УБРиР Pro</td></tr><tr><td>com.bifit.mobile.zenit</td><td>ЗЕНИТ Бизнес</td></tr><tr><td>com.bssys.mbcphone.akbars</td><td>АК БАРС Мобильный для Бизнеса</td></tr><tr><td>com.bssys.mbcphone.mts</td><td>MTS Bank. Business Client</td></tr><tr><td>com.bssys.mbcphone.rsbank</td><td>РС Бизнес Онлайн</td></tr><tr><td>com.bssys.mbcphone.ubrir</td><td>УБРиР Light</td></tr><tr><td>com.bssys.mbcphone.vostochny</td><td>Восточный Корпоративный</td></tr><tr><td>com.citibank.mobile.ru</td><td>Citibank RU</td></tr><tr><td>com.isimplelab.ibank.kazan</td><td>Банк Казани</td></tr><tr><td>com.isimplelab.isimpleceo.kazan</td><td>БК Бизнес</td></tr><tr><td>com.isimplelab.isimpleceo.minb</td><td>МИнБанк Бизнес</td></tr><tr><td>cz.bsc.rc</td><td>Ренессанс Кредит</td></tr><tr><td>ru.akbars.mobile</td><td>Ак Барс Онлайн 3.0</td></tr><tr><td>ru.avangard.legal</td><td>Авангард Бизнес</td></tr><tr><td>ru.bankuralsib.mb.android</td><td>Мобильный банк УРАЛСИБ</td></tr><tr><td>ru.beeline.card</td><td>Карта Билайн</td></tr><tr><td>ru.bspb</td><td>BSPB Mobile</td></tr><tr><td>ru.ftc.faktura.expressbank</td><td>Восточный мобайл</td></tr><tr><td>ru.gazprombank.android.mobilebank.app</td><td>Телекард 2.0</td></tr><tr><td>ru.kykyryza</td><td>Кукуруза</td></tr><tr><td>ru.mdm.app</td><td>Бинбанк Бизнес</td></tr><tr><td>ru.minbank.android</td><td>МИнБ</td></tr><tr><td>ru.mkb.business</td><td>МКБ Бизнес</td></tr><tr><td>ru.mkb.mobile</td><td>МКБ Мобайл</td></tr><tr><td>ru.otpbank</td><td>ОТПкредит</td></tr><tr><td>ru.psbank.msb.dev.psb_appstore</td><td>PSB Мой Бизнес</td></tr><tr><td>ru.raiffeisen.android.rbo</td><td>Райффайзен Бизнес</td></tr><tr><td>ru.raiffeisennews</td><td>Raiffeisen Online Russia</td></tr><tr><td>ru.rocketbank.r2d2</td><td>Рокетбанк</td></tr><tr><td>ru.rshb.dbo</td><td>Мобильный банк, Россельхозбанк</td></tr><tr><td>ru.rshb.dboul</td><td>Россельхозбанк Бизнес-Онлайн</td></tr><tr><td>ru.skbbank.ib</td><td>СКБ Онлайн</td></tr><tr><td>ru.skbbank.ibank</td><td>СКБ-банк</td></tr><tr><td>ru.stepup.MDMmobileBank</td><td>Бинбанк online 2.0</td></tr><tr><td>ru.ucb.android</td><td>Mobile.UniCredit</td></tr><tr><td>ru.vtb24.biz.client.android</td><td>ВТБ Бизнес Онлайн</td></tr><tr><td>ru.zenit.android</td><td>ЗЕНИТ Онлайн 2.0</td></tr><tr><td>de.ingdiba.bankingapp</td><td>ING-DiBa Banking to go</td></tr><tr><td>btc.org.freewallet.app</td><td>Bitcoin Wallet by Freewallet</td></tr><tr><td>com.alibaba.aliexpresshd</td><td>AliExpress – Smarter Shopping, Better Living</td></tr><tr><td>com.bitcoin.mwallet</td><td>Bitcoin Wallet</td></tr><tr><td>com.bitpay.wallet</td><td>BitPay – Secure Bitcoin Wallet</td></tr><tr><td>com.blocktrail.mywallet</td><td>BTC.com – Bitcoin Wallet</td></tr><tr><td>com.booking</td><td>Booking.com Travel Deals</td></tr><tr><td>com.electroneum.mobile</td><td>Electroneum</td></tr><tr><td>com.gettaxi.android</td><td>Gett</td></tr><tr><td>com.google.android.play.games</td><td>Google Play Games</td></tr><tr><td>com.samsung.android.spay</td><td>Samsung Pay</td></tr><tr><td>io.totalcoin.wallet</td><td>Bitcoin Wallet Totalcoin – Buy and Sell Bitcoin</td></tr><tr><td>ru.aviasales</td><td>Aviasales — авиабилеты дешево</td></tr><tr><td>ru.tutu.tutu_emp</td><td>Tutu.ru – flights, Russian railway and bus tickets</td></tr><tr><td>ru.yandex.money</td><td>Yandex.Money—wallet, cards, transfers, and fines</td></tr><tr><td>com.google.android.apps.walletnfcrel</td><td>Google Pay</td></tr></tbody></table><h2>总结</h2><p>Anubis自爆发以来，其主要活动区域在欧美等地，虽然目前国内暂时没有发现此类银行木马，但其代码字符串混淆中，含有中文混淆方案，所以依然值得我们警惕。</p><p>Anubis主要以渗透进入谷歌商店为主要传播平台，木马本身以仿冒金融机构、主流应用程序、浏览器插件为主要伪装手段。</p><p>Anubis是结合了钓鱼、远控、勒索等功能的银行木马，其功能强大到甚至可以作为一款间谍软件的存在。虽然谷歌商店一直在清理相关恶意木马，但仍然有残留的软件在活跃，此次西班牙发现Anubis通过仿冒邮政运营商Correos进行传播，也说明了Anubis一直都在并没有消失，而且其数量也并没有减少，所以我们依然要对Anubis木马提高警惕，我们也会时刻关注Anubis最新变种的出现。</p><h2>IOC</h2><table><thead><tr><th>MD5</th></tr></thead><tbody><tr><td>3D3EC2C2F81FE4EE582DCA2E69752EE1</td></tr><tr><td>04D94228021B73E44261ADCCAD4173F3</td></tr><tr><td>D2C8F0D197A14EEFBDB9643DDB898477</td></tr><tr><td>e5141d3f2a3bd6ecf64089401b015f0c</td></tr><tr><td>1e8870eb6f141df9b8d9f4dd295188be</td></tr><tr><td>d045e6d5c9b493dbe35aa4cb94652072</td></tr><tr><td>e6ab7d099bd4f01eca83075c55eb94e1</td></tr><tr><td>9c7187266b2c881570cdf69af714252b</td></tr><tr><td>0943a47985a0b33018877676cfef6c47</td></tr><tr><td>6bb24ad97a777a6ced82199fa3d2e656</td></tr><tr><td>3590baefdcf54c69e0a363b8adaf74b9</td></tr><tr><td>7b7f0041263f4a6bf3d648e19e8f5201</td></tr><tr><td>02dd7a6fb1fc0587bdd85cc267c733a4</td></tr><tr><td>390674bdb17d77c9b32bd7780a176f4c</td></tr><tr><td>4fbeaa50b11bf58418efc8ee9eb1e2aa</td></tr><tr><td>93f3c95243b347f446a54ce219307bec</td></tr><tr><td>0ff2626fe3a449ba0ee97e68d87c9249</td></tr><tr><td>7ebe35cbf1eff3702f06e54a432e6f39</td></tr><tr><td>a519c9d681a76702cd5827a428e2fbdc</td></tr><tr><td>5425eb81ac515a2ee169cf748b00badb</td></tr><tr><td>6d15674a905941be2675ec1b4c658d94</td></tr><tr><td>35967f792d7f0e0fad821a34e720731e</td></tr><tr><td>0135026d9f4fb41466e44abcb3e03752</td></tr><tr><td>dc4db1997889d2aeea18e60ee6d0f9e4</td></tr><tr><td>17091e2d6af45fc65c46c4a5d9a54de2</td></tr><tr><td>53035f67f5f07bf39856f02589727b30</td></tr><tr><td>bcb2f691e6291e80f97dcdbece8bef4f</td></tr><tr><td>fb6ee9be6feaf5784e9f6ab3f8751b07</td></tr><tr><td>6c8e24bb040abe91f99f0624eba68615</td></tr><tr><td>e29f8dbba94d6402d03d06c8308dcd03</td></tr><tr><td>ac0e66262d431a170f2ab9cef2a96dd1</td></tr><tr><td>ba5daf527a6efcc8223812961267960c</td></tr><tr><td>df98cd6a1200a8f51791b2f06aabad88</td></tr><tr><td>68c72bdd2c3289613a0b649c5f67c066</td></tr><tr><td>028336c0f5360d9c635ff0ecc6a6b528</td></tr><tr><td>659aebc9b8e9a6f447ef6343893643c6</td></tr><tr><td>91b7f1fa55cf08adee79116d76bf4dc4</td></tr><tr><td>01bc9a13dd0b091b2ddce9ee2e682c0c</td></tr><tr><td>fd5010347cd2157604caa990f1454800</td></tr><tr><td>ae0bd650536ac6dcc1e98978293e5926</td></tr><tr><td>aa8202f424ad998c36c4b91d7db2a5ec</td></tr><tr><td>C778267F160B97CBB4A970F837C61FF9</td></tr><tr><td>dfeae0b92e2addac132ce0a941bc9651</td></tr><tr><td>c1419376bfbd84b94b1547003706e89d</td></tr><tr><td>a8b8eb22302139a0a76b8ff16bb589c6</td></tr></tbody></table><table><thead><tr><th>C&C</th></tr></thead><tbody><tr><td>hxxps://twitter.com/wadaishere5</td></tr><tr><td>hxxps://twitter.com/wadaishere11</td></tr><tr><td>hxxps://twitter.com/scotyhall</td></tr><tr><td>hxxps://twitter.com/ruyas_s</td></tr><tr><td>hxxps://twitter.com/qweqweqwe</td></tr><tr><td>hxxps://twitter.com/PelinSN10495193</td></tr><tr><td>hxxps://twitter.com/mrzabibus</td></tr><tr><td>hxxps://twitter.com/force19994</td></tr><tr><td>hxxps://twitter.com/Donald19532</td></tr><tr><td>hxxps://twitter.com/Alexey31405753</td></tr><tr><td>hxxps://t.me/appqltkjsaa</td></tr><tr><td>hxxps://nasistemeafk.sc.ug</td></tr><tr><td>hxxps://188dyz.com/sett</td></tr><tr><td>hxxp://wadascx1wesa.club/admin_panel</td></tr><tr><td>hxxp://wadaishere.tk/admin_panel</td></tr><tr><td>hxxp://translationutility.tk</td></tr><tr><td>hxxp://services32.website</td></tr><tr><td>hxxp://schvhost.us</td></tr><tr><td>hxxp://sasaz.ru</td></tr><tr><td>hxxp://mining.ltd.ua</td></tr><tr><td>hxxp://colbrte.top</td></tr><tr><td>hxxp://batikantognas.com.tr</td></tr><tr><td>hxxp://aktivierung-342675-deustchland-services.ru</td></tr><tr><td>hxxp://45.76.42.67</td></tr><tr><td>hxxp://185.254.121.24</td></tr><tr><td>hxxp://185.235.128.44</td></tr><tr><td>hxxp://185.139.70.135</td></tr><tr><td>hxxp://181.174.166.106</td></tr><tr><td>87600.ooo</td></tr><tr><td>12313.ooo</td></tr></tbody></table><br/><p><strong style="color: rgb(159, 163, 168);">*本文作者：奇安信威胁情报中信，转载来自FreeBuf</strong></p></div>