fkie-cad/Sandroid_Dexray-Insight

GitHub: fkie-cad/Sandroid_Dexray-Insight

Dexray Insight 是一款 Android APK 静态分析与恶意软件检测工具,通过模块化流水线对应用执行权限审查、签名检测、字符串分析、安全评估等多层分析。

Stars: 2 | Forks: 1

Dexray Insight Logo

Android Binary Static Analysis

# Sandroid - Dexray Insight ![版本](https://img.shields.io/badge/version-2.0.0-blue) [![PyPI 版本](https://badge.fury.io/py/dexray-insight.svg)](https://badge.fury.io/py/dexray-insight) [![CI](https://static.pigsec.cn/wp-content/uploads/repos/cas/ad/ad5834178f7599af9fdda11629d49cae07f2997beec49821b2920eff5bfd50e7.svg)](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/ci.yml) [![Ruff](https://static.pigsec.cn/wp-content/uploads/repos/cas/bb/bbe2a01f3b853fa5896bb9b6d5a18e6abb5f79cf02cb77d7bb3431fbc4dd90cd.svg)](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/lint.yml) [![发布状态](https://static.pigsec.cn/wp-content/uploads/repos/cas/06/0638d019e5f8c081f3381077367c428c148a4e3143a21182b27fb972066b6b89.svg)](https://github.com/fkie-cad/Sandroid_Dexray-Insight/actions/workflows/publish.yml) Dexray Insight 是动态 Sandbox Sandroid 的一部分。其目的是对 Android 应用程序文件 (APK) 执行静态分析。该工具由不同的分析模块组成: ## 功能特性 - **签名检测模块**:使用 VirusTotal、Koodous 和 Triage API 执行基于签名的分析 - **权限分析模块**:针对关键权限列表提取并过滤权限 - **字符串分析模块**:提取并分类字符串(IP、域名、URL、电子邮件地址、Android 属性) - **API 调用分析模块**:分析 API 调用和反射用法 - **Manifest 分析模块**:从 AndroidManifest.xml 中提取 intent 过滤器、activities、services 和 receivers - **APKID 集成**:检测 packers、混淆和反分析技术 - **Kavanoz 集成**:对加壳的 Android 恶意软件进行静态脱壳 - **安全分析**:OWASP 移动 Top 10 评估,加上经过验证的 PII/隐私分类法、FileProvider 路径范围分析、广告 SDK 风险面映射、检测到的库的 CVE 扫描,以及(在 `--deep` 下)基于 xref 的数据流和 PII 流审查队列。标题风险得分是*已确认子集*的得分;未确认的线索将作为单独的审查队列展示,而不会使其虚高。 ## 安装 你可以使用 pip 安装 Dexray Insight: ``` python3 -m pip install dexray-insight ``` 这会将 Dexray Insight 安装为命令行工具,可通过命令 `dexray-insight` 访问。 此外,它还提供了 `dexray_insight` 包,你可以在你的代码中将其作为库使用(参见下面关于作为包使用的部分)。 ## 使用 Docker 运行 要在 Docker 容器中运行 Dexray Insight,首先构建 Docker 镜像: ``` docker build -t dexray-insight . ``` *注意*:这是一个旧的容器,我们没有测试它是否仍然有效 构建完成后,你可以使用 Docker 来分析 APK 文件。将包含 APK 文件的本地目录挂载到容器中并运行分析: ``` docker run -v /path/to/local/apk/directory:/app/ dexray-insight /app/yourfile.apk ``` 例如,这可以是用 Docker 分析 `Sara.apk` 的过程: ``` $ unzip -P androidtrainingpassword samples/Sara_androidtrainingpassword.zip Archive: samples/Sara_androidtrainingpassword.zip inflating: Sara.apk $ docker run -v $(pwd):/app/ dexray-insight /app/Sara.apk Dexray Insight ⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀ ⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀ ⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀ ⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀ ⣿⣿⡇⢸⣿⣿⣿SanDroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀ ⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ version: 0.1.0.0 apkstaticanalysismonitor.api_invocation_analysis.api_analysis_modulerunning apkstaticanalysismonitor.signature_detection.signature_detection_modulerunning Signature detection module running triage hashcheck failed {'error': 'NOT_FOUND', 'message': 'No such endpoint'} apkstaticanalysismonitor.string_analysis.string_analysis_modulerunning string analysis module running apkstaticanalysismonitor.manifest_analysis.manifest_analysis_modulerunning apkstaticanalysismonitor.permission_analysis.permission_analysis_modulerunning Missing list of Critical Permissions, using default list instead Results for /app/Sara.apk: Found these intent Filters: Found the following (critical) Permissions: android.permission.READ_CONTACTS android.permission.ACCESS_FINE_LOCATION android.permission.CAMERA android.permission.READ_EXTERNAL_STORAGE android.permission.READ_SMS android.permission.WRITE_EXTERNAL_STORAGE android.permission.SYSTEM_ALERT_WINDOW Signature check results: {'koodous': None, 'vt': None, 'triage': None} found IPs: found Email adresses: [] found Domains: found URLs: Activities found: ['com.termuxhackers.id.MainActivity'] Receivers found: Services found: ['com.termuxhackers.id.MyService'] Thx for using Dexray Insight and have a great day! $ ``` ## 用法 ### 基本分析 要直接从命令行运行 Dexray Insight,请使用以下命令: ``` dexray-insight ``` ### 高级选项 **启用调试日志:** ``` dexray-insight -d DEBUG ``` **启用详细输出(完整 JSON 结果):** ``` dexray-insight -v ``` **启用签名检查:** ``` dexray-insight -sig ``` **启用 OWASP Top 10 安全分析:** ``` dexray-insight -s ``` **APK 差异分析:** ``` dexray-insight --diffing_apk ``` **排除特定的 .NET 库:** ``` dexray-insight --exclude_net_libs ``` **使用自定义配置文件:** ``` dexray-insight -c ``` ### 输出示例 当你运行 `dexray-insight ` 时,你会看到类似这样的、对分析师友好的摘要: ``` 📱 DEXRAY INSIGHT ANALYSIS SUMMARY ================================================================================ 📋 APK INFORMATION ---------------------------------------- App Name: System Application Package: net.example.app Main Activity: com.example.MainActivity Version: 1.0 File Size: 160273 MD5: 5f81d45ceae3441e... 🔐 PERMISSIONS (25 total) ---------------------------------------- ⚠️ Critical Permissions: • android.permission.RECEIVE_SMS • android.permission.READ_PHONE_STATE • android.permission.SEND_SMS ... and 2 more critical permissions ℹ️ Other Permissions: 20 (see full JSON for details) 🔍 STRING ANALYSIS (URLs: 3, Domains: 13) ---------------------------------------- 🌐 IP Addresses: 2 • 192.168.1.1 • 10.0.0.1 🏠 Domains: 13 • example.com • google.com • facebook.com ... and 10 more 🔗 URLs: 3 • https://api.example.com • http://test.org 🔧 COMPILER & APKID ANALYSIS ---------------------------------------- 🎯 Primary DEX Compiler: dexlib 2.x ⚠️ WARNING: dexlib 2.x detected - APK may be repacked/modified 🛠️ All Compiler(s) Detected: • dexlib 2.x ⭐ (Primary DEX) 📦 PACKING ANALYSIS ---------------------------------------- ✅ APK does not appear to be packed 🏗️ COMPONENTS ---------------------------------------- Activities: 8 Services: 7 Receivers: 5 ``` ### 大型 APK 文件 分析大型 APK 文件可能会产生大量输出。你可以通过管道将输出传递给 `less` 以便更容易滚动查看: ``` dexray-insight | less ``` ### 执行安全分析 当我们仅仅对应用程序的安全性感兴趣时,我们可以使用 `-s` 标志,以便通过安全扫描来扩展分析: ``` dexray-insight -d DEBUG -s 67673216-93c35cc190d1713fb37f9b04894a4c1e.apk Dexray Insight ⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀ ⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀ ⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀ ⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀ ⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀ ⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀ ⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ version: 0.1.0.0 [*] Analyzing APK: 67673216-93c35cc190d1713fb37f9b04894a4c1e.apk [*] OWASP Top 10 Security Assessment: Enabled [*] Parallel Execution: Enabled [*] Initializing Androguard analysis... ... +] Starting OWASP Top 10 security assessment [+] Running injection assessment [+] injection completed with 1 findings [+] A03:2021-Injection - Potential SQL Injection Vulnerability Description: SQL query patterns found in strings that may indicate SQL injection vulnerabilities if user input is... [+] Running broken_access_control assessment [+] broken_access_control completed with 1 findings [+] A01:2021-Broken Access Control - Potentially Unsafe Exported Components Description: Components that may be exported without proper access controls, allowing unauthorized access from ot... [+] Running sensitive_data assessment [+] sensitive_data completed with 3 findings [+] A02:2021-Cryptographic Failures - 🟠 HIGH: 1 API Keys and Tokens Exposed Description: Discovered 1 high-risk credentials including API keys, authentication tokens, and service credential... [+] A02:2021-Cryptographic Failures - 🔵 LOW: 25 Suspicious Patterns Detected Description: Found 25 low-risk patterns with high entropy or specific formats that may indicate encoded secrets o... [+] A02:2021-Cryptographic Failures - Weak Cryptographic Algorithms Detected Description: Usage of weak or deprecated cryptographic algorithms that may be vulnerable to attacks. [+] Security assessment completed with 5 total findings, risk score: 5.80 [+] Security Assessment Summary: Total findings: 5 Risk score: 5.80 OWASP categories affected: A02:2021-Cryptographic Failures, A03:2021-Injection, A01:2021-Broken Access Control ... Analysis completed in 32.29 seconds Results saved to: dexray_67673216-93c35cc190d1713fb37f9b04894a4c1e_2025-08-05_22-18-06.json Security analysis results saved to: dexray_67673216-93c35cc190d1713fb37f9b04894a4c1e_security_2025-08-05_22-18-06.json ``` 这意味着结果将被保存到一个额外的安全 JSON 文件中。 ## 作为 Python 包运行 除了将 Dexray Insight 用作 CLI 工具外,你还可以在自己的 Python 脚本中导入 `dexray_insight` 包,以实现灵活的集成和自动化分析工作流。 ``` from dexray_insight import asam # 运行 APK 静态分析 results, result_file_name, security_result_file_name = asam.start_apk_static_analysis( apk_file_path="", do_signature_check=False, # Enable signature checks (VirusTotal, Koodous, Triage) apk_to_diff=None, # Optional: provide a second APK for diffing analysis print_results_to_terminal=False, # Disable printing results to the terminal is_verbose=False, # Disable verbose output (show analyst summary instead) do_sec_analysis=False, # Enable OWASP Top 10 security assessment exclude_net_libs=None # Optional: path to .NET library exclusion file ) # 访问 results 对象 results.print_results() # Prints complete JSON results results.print_analyst_summary() # Prints analyst-friendly summary # 获取不同格式的结果 json_output = results.to_json() # Complete results as JSON string dict_output = results.to_dict() # Complete results as dictionary ``` ### 结果结构 返回的结果对象是 `FullAnalysisResults` 类的一个实例,它提供了对所有分析模块的结构化访问: **主要字段:** - `apk_overview`:常规 APK 元数据(文件信息、组件、权限、证书) - `in_depth_analysis`:详细分析结果(字符串、权限、签名、intent) - `apkid_analysis`:APKID 结果(编译器检测、packer 分析、混淆技术) - `kavanoz_analysis`:Kavanoz 结果(加壳检测和脱壳尝试) **关键方法:** - `to_dict() -> Dict[str, Any]`:以字典形式返回合并后的结果 - `to_json() -> str`:以 JSON 字符串形式返回合并后的结果 - `print_results()`:在终端打印完整的 JSON 结果 - `print_analyst_summary()`:打印包含关键发现的对分析师友好的摘要 - `update_from_dict(updates: Dict[str, Any])`:从字典更新特定字段 ### 输出文件 分析会生成带有时间戳的、包含全面结果的 JSON 文件: - **主要结果**:`dexray_{apk_name}_{timestamp}.json` - **安全评估**(如果启用):专注于安全的额外结果 ### 结果访问示例 ``` # 访问特定分析结果 emails = results.in_depth_analysis.strings_emails domains = results.in_depth_analysis.strings_domain compiler = results.apkid_analysis.files[0].matches.get('compiler', []) permissions = results.apk_overview.permissions # 检查分析状态 if results.apkid_analysis.apkid_version: print(f"APKID version: {results.apkid_analysis.apkid_version}") ``` ## 开发和安装 ### 开发安装 为了进行开发和修改代码,请以可编辑模式安装 Dexray Insight: ``` # 安装 editable 模式以进行开发 python3 -m pip install -e . # 仅安装依赖项 python3 -m pip install -r requirements.txt ``` 这样,Python 代码中的本地更改就会直接生效,而无需创建新版本的包。 ### 标准安装 ``` # 标准安装 python3 -m pip install . ``` ## 系统要求 ### 系统要求 - **Python 3.6+** - 核心运行时环境 - **Docker**(可选) - 用于容器化部署 ### Python 依赖项 核心依赖项通过 pip 自动安装: - `androguard` - Android 应用分析库 - `apkid` - Packer 和编译器检测 - `kavanoz` - 静态脱壳工具 - `loguru` - 高级日志记录 - `requests` - HTTP API 通信 安装所有依赖项: ``` python3 -m pip install -r requirements.txt ``` ### SSDeep 问题 在带有 M1 芯片的 MacOS 上将 ssdeep 安装为 python 包时,你可能会遇到一些问题。如果你已经通过 `brew` 安装了 ssdeep,通常以下命令会有所帮助: ``` $ brew ls ssdeep /usr/local/Cellar/ssdeep/2.14.1/bin/ssdeep /usr/local/Cellar/ssdeep/2.14.1/include/ (2 files) /usr/local/Cellar/ssdeep/2.14.1/lib/libfuzzy.2.dylib /usr/local/Cellar/ssdeep/2.14.1/lib/ (2 other files) /usr/local/Cellar/ssdeep/2.14.1/share/man/man1/ssdeep.1 $ export LDFLAGS="-L/usr/local/Cellar/ssdeep/2.14.1/lib/" $ export C_INCLUDE_PATH=/usr/local/Cellar/ssdeep/2.14.1/include/ $ python3 -m pip install ssdeep ``` 在较新的版本上: ``` $ brew ls ssdeep /usr/local/Cellar/ssdeep/2.14.1/bin/ssdeep /usr/local/Cellar/ssdeep/2.14.1/include/ (2 files) /usr/local/Cellar/ssdeep/2.14.1/lib/libfuzzy.2.dylib /usr/local/Cellar/ssdeep/2.14.1/lib/ (2 other files) /usr/local/Cellar/ssdeep/2.14.1/share/man/man1/ssdeep.1 $ export LDFLAGS="-L/usr/local/Cellar/ssdeep/2.14.1/lib" $ export C_INCLUDE_PATH=/opt/homebrew/Cellar/ssdeep/2.14.1/include $ brew install libtool automake $ brew --prefix $ ln -s /usr/local/bin/glibtoolize /usr/local/Homebrew/bin/libtoolize #adjust to the output of brew --prefix $ BUILD_LIB=1 pip install ssdeep $ stat libtoolize # if this can't be found you have to fix that $ ln -s /usr/local/bin/glibtoolize $HOME/bin/libtoolize $ BUILD_LIB=1 pip install ssdeep ``` 更多信息请访问以下[链接](https://stackoverflow.com/questions/75302631/installing-ssdeep-package-from-pypi-on-m1-macbook)。 ## 使用的项目和依赖项 Dexray Insight 建立在几个优秀的开源项目和工具之上: ### 核心分析库 - **[Androguard](https://github.com/androguard/androguard)** - 用于 DEX/APK 解析和操作的 Android 应用分析库 - **[APKID](https://github.com/rednaga/APKiD)** - 用于 packer 和编译器检测的 Android 应用标识符 - **[Kavanoz](https://github.com/eybisi/kavanoz)** - 针对加壳 Android 恶意软件的静态脱壳工具 ### 安全分析 API - **[VirusTotal API](https://www.virustotal.com/)** - 恶意软件检测和分析服务 - **[Koodous API](https://koodous.com/)** - 用于 Android 恶意软件分析的协作平台 - **[Triage API](https://tria.ge/)** - 自动化恶意软件分析沙箱 ### Python 库 - **[loguru](https://github.com/Delgan/loguru)** - Python 的高级日志记录库 - **[requests](https://github.com/psf/requests)** - 用于 API 通信的 HTTP 库 - **[ssdeep](https://github.com/DinoTools/python-ssdeep)** - 用于相似性分析的模糊哈希库 - **[yara-python](https://github.com/VirusTotal/yara-python)** - YARA 模式匹配的 Python 绑定 ### 静态分析工具 - **[droidlysis](https://github.com/cryptax/droidlysis)** - Android 应用的属性提取器(计划集成) - **[LibRadar](https://github.com/pkumza/LibRadar)** - 第三方库识别(计划集成) - **[mariana-trench](https://github.com/facebook/mariana-trench)** - 专注于安全的静态分析器(计划集成) ### 隐私分析工具 - **[exodus-core](https://github.com/Exodus-Privacy/exodus-core)** - 隐私追踪器检测(计划集成) - **[Pithus](https://beta.pithus.org/)** - Android 恶意软件分析平台(计划集成) ### 开发和构建工具 - **Python 3.6+** - 核心运行时环境 - **setuptools** - 包构建和分发 - **Docker** - 容器化部署支持 ### 特别感谢 我们在此确认并感谢所有这些项目的维护者和贡献者,是他们让安全社区能够使用先进的 Android 静态分析技术。 ## 路线图 - [x] 创建基于签名的检测模块。正在为 triage 进行中 - [x] 创建权限模块 - [x] 创建字符串分析模块 - [ ] 创建 API 调用模块。正在进行中 - [x] 创建 Android manifest 分析模块 - [x] 作为包运行时,每个输出默认应为 JSON 格式。所以每个模块都有其自己的 JSON 格式 - [ ] 改进 Intent 分析 - [ ] 改进并向源文件添加文档(doc strings) - [ ] 将 [Androguard](https://github.com/androguard/androguard) 集成为独立的 JSON 元素 - [ ] 将 [mariana-trench](https://github.com/facebook/mariana-trench) 集成为用于安全分析的独立 JSON 元素 - [ ] 将 [droidlysis](https://github.com/cryptax/droidlysis/tree/master) 集成为独立的 JSON 元素,以获取组件的详细概述 - [ ] 将 [exodus-core](https://github.com/Exodus-Privacy/exodus-core/blob/v1/exodus_core/analysis ) 集成为独立的 JSON 元素,以分析隐私跟踪问题 - [ ] 将 [Pithus](https://beta.pithus.org/about/) 集成为独立的 JSON 元素 - [ ] 改进字符串分析模块(例如,域名识别存在大量误报),并为 base64 字符串添加功能 - [ ] 添加功能以识别 apk 中具有特定大小且很可能是加壳二进制文件(例如,高熵)的所有文件 - [ ] 对于以后的安全分析,这种检查很有用:https://github.com/Hrishikesh7665/Android-Pentesting-Checklist - [x] 常见 Android 加壳恶意软件的静态脱壳。[更多](https://github.com/eybisi/kavanoz)。 - [ ] 集成 FAME 框架的一些功能。[更多](https://github.com/certsocietegenerale/fame)。 - [ ] 我们应该 fork [LibRadar](https://github.com/pkumza/LibRadar) 以识别 Android 中的第三方库,并将其迁移(和扩展)到 python3([这里](https://github.com/7homasSutter/LibRadar-Refactoring)已经有一个有限的 python3 版本)。我们应该进一步将其功能与 [apk-anal](https://github.com/mhelwig/apk-anal) 的功能合并。该模块的开发应在 [GitHub 上的 APKInsight](https://github.com/fkie-cad/APKInsight) 下进行。 - [ ] 在运行 ammm 之后,我们应该利用它跟踪的运行时行为,以便能够检测仅靠静态分析可能无法发现的恶意活动。 - [ ] 也许可以集成类似 https://github.com/struppigel/PortEx 的东西 - [ ] 应该对新样本进行分析,使其获得与 https://www.apklab.io/apk.html?download=1&hash=72888975925abd4f55b2dd0c2c17fc68670dd8dee1bae2baabc1de6299e6cc05&tab=dynamic&dynamic=feature-history 相同的结果 - 也许每个模块应该在其独立的线程中运行?
标签:Android, DAST, DSL, Python, 云安全监控, 云资产清单, 恶意软件分析, 指令注入, 无后门, 请求拦截, 逆向工具, 逆向工程, 静态分析