fkie-cad/Sandroid_Dexray-Insight
GitHub: fkie-cad/Sandroid_Dexray-Insight
Dexray Insight 是一款 Android APK 静态分析与恶意软件检测工具,通过模块化流水线对应用执行权限审查、签名检测、字符串分析、安全评估等多层分析。
Stars: 2 | Forks: 1
Android Binary Static Analysis
# Sandroid - Dexray Insight
 [](https://badge.fury.io/py/dexray-insight) [](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/ci.yml)
[](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/lint.yml)
[](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/publish.yml)
Dexray Insight 是动态 Sandbox Sandroid 的一部分。其目的是对 Android 应用程序文件 (APK) 执行静态分析。该工具由不同的分析模块组成:
## 功能特性
- **签名检测模块**:使用 VirusTotal、Koodous 和 Triage API 执行基于签名的分析
- **权限分析模块**:针对关键权限列表提取并过滤权限
- **字符串分析模块**:提取并分类字符串(IP、域名、URL、电子邮件地址、Android 属性)
- **API 调用分析模块**:分析 API 调用和反射用法
- **Manifest 分析模块**:从 AndroidManifest.xml 中提取 intent 过滤器、activities、services 和 receivers
- **APKID 集成**:检测 packers、混淆和反分析技术
- **Kavanoz 集成**:对加壳的 Android 恶意软件进行静态脱壳
- **安全分析**:OWASP 移动 Top 10 评估,加上经过验证的 PII/隐私分类法、FileProvider 路径范围分析、广告 SDK 风险面映射、检测到的库的 CVE 扫描,以及(在 `--deep` 下)基于 xref 的数据流和 PII 流审查队列。标题风险得分是*已确认子集*的得分;未确认的线索将作为单独的审查队列展示,而不会使其虚高。
## 安装
你可以使用 pip 安装 Dexray Insight:
```
python3 -m pip install dexray-insight
```
这会将 Dexray Insight 安装为命令行工具,可通过命令 `dexray-insight` 访问。
此外,它还提供了 `dexray_insight` 包,你可以在你的代码中将其作为库使用(参见下面关于作为包使用的部分)。
## 使用 Docker 运行
要在 Docker 容器中运行 Dexray Insight,首先构建 Docker 镜像:
```
docker build -t dexray-insight .
```
*注意*:这是一个旧的容器,我们没有测试它是否仍然有效
构建完成后,你可以使用 Docker 来分析 APK 文件。将包含 APK 文件的本地目录挂载到容器中并运行分析:
```
docker run -v /path/to/local/apk/directory:/app/ dexray-insight /app/yourfile.apk
```
例如,这可以是用 Docker 分析 `Sara.apk` 的过程:
```
$ unzip -P androidtrainingpassword samples/Sara_androidtrainingpassword.zip
Archive: samples/Sara_androidtrainingpassword.zip
inflating: Sara.apk
$ docker run -v $(pwd):/app/ dexray-insight /app/Sara.apk
Dexray Insight
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿SanDroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
version: 0.1.0.0
apkstaticanalysismonitor.api_invocation_analysis.api_analysis_modulerunning
apkstaticanalysismonitor.signature_detection.signature_detection_modulerunning
Signature detection module running
triage hashcheck failed
{'error': 'NOT_FOUND', 'message': 'No such endpoint'}
apkstaticanalysismonitor.string_analysis.string_analysis_modulerunning
string analysis module running
apkstaticanalysismonitor.manifest_analysis.manifest_analysis_modulerunning
apkstaticanalysismonitor.permission_analysis.permission_analysis_modulerunning
Missing list of Critical Permissions, using default list instead
Results for /app/Sara.apk:
Found these intent Filters:
Found the following (critical) Permissions:
android.permission.READ_CONTACTS
android.permission.ACCESS_FINE_LOCATION
android.permission.CAMERA
android.permission.READ_EXTERNAL_STORAGE
android.permission.READ_SMS
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.SYSTEM_ALERT_WINDOW
Signature check results:
{'koodous': None, 'vt': None, 'triage': None}
found IPs:
found Email adresses:
[]
found Domains:
found URLs:
Activities found:
['com.termuxhackers.id.MainActivity']
Receivers found:
Services found:
['com.termuxhackers.id.MyService']
Thx for using Dexray Insight and have a great day!
$
```
## 用法
### 基本分析
要直接从命令行运行 Dexray Insight,请使用以下命令:
```
dexray-insight
```
### 高级选项
**启用调试日志:**
```
dexray-insight -d DEBUG
```
**启用详细输出(完整 JSON 结果):**
```
dexray-insight -v
```
**启用签名检查:**
```
dexray-insight -sig
```
**启用 OWASP Top 10 安全分析:**
```
dexray-insight -s
```
**APK 差异分析:**
```
dexray-insight --diffing_apk
```
**排除特定的 .NET 库:**
```
dexray-insight --exclude_net_libs
```
**使用自定义配置文件:**
```
dexray-insight -c
```
### 输出示例
当你运行 `dexray-insight ` 时,你会看到类似这样的、对分析师友好的摘要:
```
📱 DEXRAY INSIGHT ANALYSIS SUMMARY
================================================================================
📋 APK INFORMATION
----------------------------------------
App Name: System Application
Package: net.example.app
Main Activity: com.example.MainActivity
Version: 1.0
File Size: 160273
MD5: 5f81d45ceae3441e...
🔐 PERMISSIONS (25 total)
----------------------------------------
⚠️ Critical Permissions:
• android.permission.RECEIVE_SMS
• android.permission.READ_PHONE_STATE
• android.permission.SEND_SMS
... and 2 more critical permissions
ℹ️ Other Permissions: 20 (see full JSON for details)
🔍 STRING ANALYSIS (URLs: 3, Domains: 13)
----------------------------------------
🌐 IP Addresses: 2
• 192.168.1.1
• 10.0.0.1
🏠 Domains: 13
• example.com
• google.com
• facebook.com
... and 10 more
🔗 URLs: 3
• https://api.example.com
• http://test.org
🔧 COMPILER & APKID ANALYSIS
----------------------------------------
🎯 Primary DEX Compiler: dexlib 2.x
⚠️ WARNING: dexlib 2.x detected - APK may be repacked/modified
🛠️ All Compiler(s) Detected:
• dexlib 2.x ⭐ (Primary DEX)
📦 PACKING ANALYSIS
----------------------------------------
✅ APK does not appear to be packed
🏗️ COMPONENTS
----------------------------------------
Activities: 8
Services: 7
Receivers: 5
```
### 大型 APK 文件
分析大型 APK 文件可能会产生大量输出。你可以通过管道将输出传递给 `less` 以便更容易滚动查看:
```
dexray-insight | less
```
### 执行安全分析
当我们仅仅对应用程序的安全性感兴趣时,我们可以使用 `-s` 标志,以便通过安全扫描来扩展分析:
```
dexray-insight -d DEBUG -s 67673216-93c35cc190d1713fb37f9b04894a4c1e.apk
Dexray Insight
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
version: 0.1.0.0
[*] Analyzing APK: 67673216-93c35cc190d1713fb37f9b04894a4c1e.apk
[*] OWASP Top 10 Security Assessment: Enabled
[*] Parallel Execution: Enabled
[*] Initializing Androguard analysis...
...
+] Starting OWASP Top 10 security assessment
[+] Running injection assessment
[+] injection completed with 1 findings
[+] A03:2021-Injection - Potential SQL Injection Vulnerability
Description: SQL query patterns found in strings that may indicate SQL injection vulnerabilities if user input is...
[+] Running broken_access_control assessment
[+] broken_access_control completed with 1 findings
[+] A01:2021-Broken Access Control - Potentially Unsafe Exported Components
Description: Components that may be exported without proper access controls, allowing unauthorized access from ot...
[+] Running sensitive_data assessment
[+] sensitive_data completed with 3 findings
[+] A02:2021-Cryptographic Failures - 🟠 HIGH: 1 API Keys and Tokens Exposed
Description: Discovered 1 high-risk credentials including API keys, authentication tokens, and service credential...
[+] A02:2021-Cryptographic Failures - 🔵 LOW: 25 Suspicious Patterns Detected
Description: Found 25 low-risk patterns with high entropy or specific formats that may indicate encoded secrets o...
[+] A02:2021-Cryptographic Failures - Weak Cryptographic Algorithms Detected
Description: Usage of weak or deprecated cryptographic algorithms that may be vulnerable to attacks.
[+] Security assessment completed with 5 total findings, risk score: 5.80
[+] Security Assessment Summary:
Total findings: 5
Risk score: 5.80
OWASP categories affected: A02:2021-Cryptographic Failures, A03:2021-Injection, A01:2021-Broken Access Control
...
Analysis completed in 32.29 seconds
Results saved to: dexray_67673216-93c35cc190d1713fb37f9b04894a4c1e_2025-08-05_22-18-06.json
Security analysis results saved to: dexray_67673216-93c35cc190d1713fb37f9b04894a4c1e_security_2025-08-05_22-18-06.json
```
这意味着结果将被保存到一个额外的安全 JSON 文件中。
## 作为 Python 包运行
除了将 Dexray Insight 用作 CLI 工具外,你还可以在自己的 Python 脚本中导入 `dexray_insight` 包,以实现灵活的集成和自动化分析工作流。
```
from dexray_insight import asam
# 运行 APK 静态分析
results, result_file_name, security_result_file_name = asam.start_apk_static_analysis(
apk_file_path="",
do_signature_check=False, # Enable signature checks (VirusTotal, Koodous, Triage)
apk_to_diff=None, # Optional: provide a second APK for diffing analysis
print_results_to_terminal=False, # Disable printing results to the terminal
is_verbose=False, # Disable verbose output (show analyst summary instead)
do_sec_analysis=False, # Enable OWASP Top 10 security assessment
exclude_net_libs=None # Optional: path to .NET library exclusion file
)
# 访问 results 对象
results.print_results() # Prints complete JSON results
results.print_analyst_summary() # Prints analyst-friendly summary
# 获取不同格式的结果
json_output = results.to_json() # Complete results as JSON string
dict_output = results.to_dict() # Complete results as dictionary
```
### 结果结构
返回的结果对象是 `FullAnalysisResults` 类的一个实例,它提供了对所有分析模块的结构化访问:
**主要字段:**
- `apk_overview`:常规 APK 元数据(文件信息、组件、权限、证书)
- `in_depth_analysis`:详细分析结果(字符串、权限、签名、intent)
- `apkid_analysis`:APKID 结果(编译器检测、packer 分析、混淆技术)
- `kavanoz_analysis`:Kavanoz 结果(加壳检测和脱壳尝试)
**关键方法:**
- `to_dict() -> Dict[str, Any]`:以字典形式返回合并后的结果
- `to_json() -> str`:以 JSON 字符串形式返回合并后的结果
- `print_results()`:在终端打印完整的 JSON 结果
- `print_analyst_summary()`:打印包含关键发现的对分析师友好的摘要
- `update_from_dict(updates: Dict[str, Any])`:从字典更新特定字段
### 输出文件
分析会生成带有时间戳的、包含全面结果的 JSON 文件:
- **主要结果**:`dexray_{apk_name}_{timestamp}.json`
- **安全评估**(如果启用):专注于安全的额外结果
### 结果访问示例
```
# 访问特定分析结果
emails = results.in_depth_analysis.strings_emails
domains = results.in_depth_analysis.strings_domain
compiler = results.apkid_analysis.files[0].matches.get('compiler', [])
permissions = results.apk_overview.permissions
# 检查分析状态
if results.apkid_analysis.apkid_version:
print(f"APKID version: {results.apkid_analysis.apkid_version}")
```
## 开发和安装
### 开发安装
为了进行开发和修改代码,请以可编辑模式安装 Dexray Insight:
```
# 安装 editable 模式以进行开发
python3 -m pip install -e .
# 仅安装依赖项
python3 -m pip install -r requirements.txt
```
这样,Python 代码中的本地更改就会直接生效,而无需创建新版本的包。
### 标准安装
```
# 标准安装
python3 -m pip install .
```
## 系统要求
### 系统要求
- **Python 3.6+** - 核心运行时环境
- **Docker**(可选) - 用于容器化部署
### Python 依赖项
核心依赖项通过 pip 自动安装:
- `androguard` - Android 应用分析库
- `apkid` - Packer 和编译器检测
- `kavanoz` - 静态脱壳工具
- `loguru` - 高级日志记录
- `requests` - HTTP API 通信
安装所有依赖项:
```
python3 -m pip install -r requirements.txt
```
### SSDeep 问题
在带有 M1 芯片的 MacOS 上将 ssdeep 安装为 python 包时,你可能会遇到一些问题。如果你已经通过 `brew` 安装了 ssdeep,通常以下命令会有所帮助:
```
$ brew ls ssdeep
/usr/local/Cellar/ssdeep/2.14.1/bin/ssdeep
/usr/local/Cellar/ssdeep/2.14.1/include/ (2 files)
/usr/local/Cellar/ssdeep/2.14.1/lib/libfuzzy.2.dylib
/usr/local/Cellar/ssdeep/2.14.1/lib/ (2 other files)
/usr/local/Cellar/ssdeep/2.14.1/share/man/man1/ssdeep.1
$ export LDFLAGS="-L/usr/local/Cellar/ssdeep/2.14.1/lib/"
$ export C_INCLUDE_PATH=/usr/local/Cellar/ssdeep/2.14.1/include/
$ python3 -m pip install ssdeep
```
在较新的版本上:
```
$ brew ls ssdeep
/usr/local/Cellar/ssdeep/2.14.1/bin/ssdeep
/usr/local/Cellar/ssdeep/2.14.1/include/ (2 files)
/usr/local/Cellar/ssdeep/2.14.1/lib/libfuzzy.2.dylib
/usr/local/Cellar/ssdeep/2.14.1/lib/ (2 other files)
/usr/local/Cellar/ssdeep/2.14.1/share/man/man1/ssdeep.1
$ export LDFLAGS="-L/usr/local/Cellar/ssdeep/2.14.1/lib"
$ export C_INCLUDE_PATH=/opt/homebrew/Cellar/ssdeep/2.14.1/include
$ brew install libtool automake
$ brew --prefix
$ ln -s /usr/local/bin/glibtoolize /usr/local/Homebrew/bin/libtoolize #adjust to the output of brew --prefix
$ BUILD_LIB=1 pip install ssdeep
$ stat libtoolize # if this can't be found you have to fix that
$ ln -s /usr/local/bin/glibtoolize $HOME/bin/libtoolize
$ BUILD_LIB=1 pip install ssdeep
```
更多信息请访问以下[链接](https://stackoverflow.com/questions/75302631/installing-ssdeep-package-from-pypi-on-m1-macbook)。
## 使用的项目和依赖项
Dexray Insight 建立在几个优秀的开源项目和工具之上:
### 核心分析库
- **[Androguard](https://github.com/androguard/androguard)** - 用于 DEX/APK 解析和操作的 Android 应用分析库
- **[APKID](https://github.com/rednaga/APKiD)** - 用于 packer 和编译器检测的 Android 应用标识符
- **[Kavanoz](https://github.com/eybisi/kavanoz)** - 针对加壳 Android 恶意软件的静态脱壳工具
### 安全分析 API
- **[VirusTotal API](https://www.virustotal.com/)** - 恶意软件检测和分析服务
- **[Koodous API](https://koodous.com/)** - 用于 Android 恶意软件分析的协作平台
- **[Triage API](https://tria.ge/)** - 自动化恶意软件分析沙箱
### Python 库
- **[loguru](https://github.com/Delgan/loguru)** - Python 的高级日志记录库
- **[requests](https://github.com/psf/requests)** - 用于 API 通信的 HTTP 库
- **[ssdeep](https://github.com/DinoTools/python-ssdeep)** - 用于相似性分析的模糊哈希库
- **[yara-python](https://github.com/VirusTotal/yara-python)** - YARA 模式匹配的 Python 绑定
### 静态分析工具
- **[droidlysis](https://github.com/cryptax/droidlysis)** - Android 应用的属性提取器(计划集成)
- **[LibRadar](https://github.com/pkumza/LibRadar)** - 第三方库识别(计划集成)
- **[mariana-trench](https://github.com/facebook/mariana-trench)** - 专注于安全的静态分析器(计划集成)
### 隐私分析工具
- **[exodus-core](https://github.com/Exodus-Privacy/exodus-core)** - 隐私追踪器检测(计划集成)
- **[Pithus](https://beta.pithus.org/)** - Android 恶意软件分析平台(计划集成)
### 开发和构建工具
- **Python 3.6+** - 核心运行时环境
- **setuptools** - 包构建和分发
- **Docker** - 容器化部署支持
### 特别感谢
我们在此确认并感谢所有这些项目的维护者和贡献者,是他们让安全社区能够使用先进的 Android 静态分析技术。
## 路线图
- [x] 创建基于签名的检测模块。正在为 triage 进行中
- [x] 创建权限模块
- [x] 创建字符串分析模块
- [ ] 创建 API 调用模块。正在进行中
- [x] 创建 Android manifest 分析模块
- [x] 作为包运行时,每个输出默认应为 JSON 格式。所以每个模块都有其自己的 JSON 格式
- [ ] 改进 Intent 分析
- [ ] 改进并向源文件添加文档(doc strings)
- [ ] 将 [Androguard](https://github.com/androguard/androguard) 集成为独立的 JSON 元素
- [ ] 将 [mariana-trench](https://github.com/facebook/mariana-trench) 集成为用于安全分析的独立 JSON 元素
- [ ] 将 [droidlysis](https://github.com/cryptax/droidlysis/tree/master) 集成为独立的 JSON 元素,以获取组件的详细概述
- [ ] 将 [exodus-core](https://github.com/Exodus-Privacy/exodus-core/blob/v1/exodus_core/analysis ) 集成为独立的 JSON 元素,以分析隐私跟踪问题
- [ ] 将 [Pithus](https://beta.pithus.org/about/) 集成为独立的 JSON 元素
- [ ] 改进字符串分析模块(例如,域名识别存在大量误报),并为 base64 字符串添加功能
- [ ] 添加功能以识别 apk 中具有特定大小且很可能是加壳二进制文件(例如,高熵)的所有文件
- [ ] 对于以后的安全分析,这种检查很有用:https://github.com/Hrishikesh7665/Android-Pentesting-Checklist
- [x] 常见 Android 加壳恶意软件的静态脱壳。[更多](https://github.com/eybisi/kavanoz)。
- [ ] 集成 FAME 框架的一些功能。[更多](https://github.com/certsocietegenerale/fame)。
- [ ] 我们应该 fork [LibRadar](https://github.com/pkumza/LibRadar) 以识别 Android 中的第三方库,并将其迁移(和扩展)到 python3([这里](https://github.com/7homasSutter/LibRadar-Refactoring)已经有一个有限的 python3 版本)。我们应该进一步将其功能与 [apk-anal](https://github.com/mhelwig/apk-anal) 的功能合并。该模块的开发应在 [GitHub 上的 APKInsight](https://github.com/fkie-cad/APKInsight) 下进行。
- [ ] 在运行 ammm 之后,我们应该利用它跟踪的运行时行为,以便能够检测仅靠静态分析可能无法发现的恶意活动。
- [ ] 也许可以集成类似 https://github.com/struppigel/PortEx 的东西
- [ ] 应该对新样本进行分析,使其获得与 https://www.apklab.io/apk.html?download=1&hash=72888975925abd4f55b2dd0c2c17fc68670dd8dee1bae2baabc1de6299e6cc05&tab=dynamic&dynamic=feature-history 相同的结果
- 也许每个模块应该在其独立的线程中运行?标签:Android, DAST, DSL, Python, 云安全监控, 云资产清单, 恶意软件分析, 指令注入, 无后门, 请求拦截, 逆向工具, 逆向工程, 静态分析