Skip to content

silverfoxy/TelescamBot

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TelescamBot

Telegram bot, grabs malicious APKs, saves them with their metadata and submits them to Koodous.com

Introduction

This telegram bot is released as part of Telescam (http://telescam.ir) project where we analyze specifically Iranian scam campaigns spreading their malware using Telegram messenger, this bot grabs APK files from telegram groups and also the files directly sent to it.

A local copy of the APK samples are stored locally along with some metadata about when it was submitted, who sent it and if it was forwarded from a channel. It then also submits the samples to https://koodous.com for initial analysis.

Required Modules

Prior to running the bot, you need to install the following modules:

  • telebot
  • sqlalchemy
  • mkdir-p
  • requests

Setup

Then replace the two string values with your telegram bot and koodous api tokens:

self.TELEGRAM_TOKEN = '...'
self.KOODOUS_API_TOKEN = '...' #Personal - MUST NOT BE SHARED

And then run the bot: python Telescam_scanner_bot.py

Aforementioned metadata is stored in a sqlite database named telescam.db and APK samples are stored in ./apk/ directory

To Do

Handle the case when the analysis service is down (Koodous.com here), and save the files locally or put them in a queue mark them for later analysis.

About

Telegram bot, grabs malicious APKs, saves them with their metadata and submits them to Koodous.com

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages