
أداة تحليل برمجيات أندرويد الخبيثة تُنشئ ملفات تعريف شاملة لوقت التشغيل من خلال الربط بسلوك التطبيق عبر التشفير وأنظمة الملفات وقواعد البيانات واتصالات الشبكة وعمليات المعالجة.
متتبع واجهات برمجة التطبيقات الثنائية لنظام أندرويد
Dexray Intercept هو جزء من الصندوق الرملي الديناميكي Sandroid. الغرض منه هو إنشاء ملفات تعريف وقت التشغيل لتتبع سلوك تطبيق أندرويد. يتم ذلك باستخدام frida.
قم بتثبيته ببساطة باستخدام pip:
python3 -m pip install dexray-intercept
سيؤدي هذا إلى تثبيت Dexray Intercept كأداة سطر أوامر ammm أو dexray-intercept.
علاوة على ذلك، سيوفر حزمة dexray_intercept. المزيد حول كيفية استخدام الحزمة أدناه.
تأكد من أن جهاز أندرويد الخاص بك مُروّت (rooted). سيتم تثبيت frida-server إلى أحدث إصدار تلقائيًا. ثم يمكنك استخدام Dexray Intercept بمجرد استدعاء الأمر التالي:
dexray-intercept <target app>
# or using its old name:
ammm <target app>
جميع الخطافات معطلة افتراضيًا للحصول على الأداء الأمثل. قم بتمكين الخطافات بناءً على احتياجات التحليل الخاصة بك:
# Enable specific hooks
dexray-intercept --enable-aes <app_name> # Enable AES crypto hooks
dexray-intercept --enable-web <app_name> # Enable web/HTTP hooks
dexray-intercept --enable-aes --enable-web <app_name> # Enable multiple hooks
# Enable hook groups
dexray-intercept --hooks-crypto <app_name> # Enable all crypto hooks
dexray-intercept --hooks-network <app_name> # Enable all network hooks
dexray-intercept --hooks-filesystem <app_name> # Enable all file system hooks
# Enable all hooks (performance impact)
dexray-intercept --hooks-all <app_name> # Enable all available hooks
# Use package identifier instead of app name
dexray-intercept -s com.example.package --hooks-crypto
--hooks-crypto (AES، الترميزات، مخزن المفاتيح، الشهادات)--hooks-network (HTTP، المقابس، SSL/TLS)--hooks-filesystem (عمليات الملفات، قواعد البيانات، التفضيلات المشتركة)--hooks-ipc (النوايا، البث، binder، التفضيلات المشتركة)--hooks-process (فك حزم DEX، المكتبات الأصلية، وقت التشغيل)--hooks-services (الكاميرا، الموقع، الهاتف، البلوتوث)إليك مثال على مراقبة تطبيق chrome على AVD الخاص بنا:
dexray-intercept Chrome
Dexray Intercept
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
[*] starting app profiling
[*] press Ctrl+C to stop the profiling ...
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7ac6b67540,8)
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7fcb41c990,8
قم بتثبيت Dexray Intercept كحزمة واستخدم البنية المعيارية الجديدة:
from dexray_intercept import AppProfiler, setup_frida_device
from dexray_intercept.services.hook_manager import HookManager
# Connect to device and get process
device = setup_frida_device()
process = device.attach("com.example.app")
# Configure hooks (all disabled by default for performance)
hook_config = {
'aes_hooks': True,
'web_hooks': True,
'file_system_hooks': True,
'keystore_hooks': True
}
# Create profiler with new architecture
profiler = AppProfiler(
process,
verbose_mode=True,
output_format="JSON",
hook_config=hook_config,
enable_stacktrace=True
)
# Start profiling
script = profiler.start_profiling()
# ... let app run and collect data ...
# Get results
profile_data = profiler.get_profile_data()
json_output = profiler.get_profiling_log_as_json()
# Runtime hook management
profiler.enable_hook('socket_hooks', True) # Enable more hooks at runtime
enabled_hooks = profiler.get_enabled_hooks() # Check what's enabled
# Stop profiling
profiler.stop_profiling()
قم بتمكين مجموعات خطافات محددة بناءً على احتياجات التحليل الخاصة بك:
# Crypto hooks
hook_config = {
'aes_hooks': True,
'encodings_hooks': True,
'keystore_hooks': True
}
# Network hooks
hook_config = {
'web_hooks': True,
'socket_hooks': True
}
# File system hooks
hook_config = {
'file_system_hooks': True,
'database_hooks': True
}
# Enable all hooks (performance impact)
profiler.enable_all_hooks()
# Enable hook groups
profiler.enable_hook_group('crypto') # Enable all crypto-related hooks
لا تزال واجهة برمجة التطبيقات القديمة متاحة للتوافق مع الإصدارات السابقة:
from dexray_intercept import AppProfilerLegacy
# OR use environment variable: DEXRAY_FORCE_OLD_ARCH=true
profiler = AppProfilerLegacy(process_session, verbose=True, output_format="CMD",
base_path=None, deactivate_unlink=False)
profiler.instrument() # Old method name
# ...
profiler.finish_app_profiling() # Old method name
من أجل تشغيله كحزمة في Sandroid، تأكد من أنك قمت أيضًا بتثبيت JobManager من AndroidFridaManager. هذا يسمح بتشغيل جلسات frida متعددة في خيوط مختلفة.
كل ما عليك فعله هو تشغيل الكود التالي:
from AndroidFridaManager import JobManager
from dexray_intercept import AppProfiler
job_manager = JobManager()
app_package = "net.classwindexampleyear.bookseapiececountry"
profiler = AppProfiler(job_manager.process_session, True, output_format="JSON", base_path=None, deactivate_unlink=False)
frida_script_path = profiler.get_frida_script()
job_manager.setup_frida_session(app_package, profiler.on_appProfiling_message)
job = job_manager.start_job(frida_script_path, custom_hooking_handler_name=profiler.on_appProfiling_message)
# close only the job and the frida session keeps active to run other frida scripts
# job_manager.stop_job_with_id(job.job_id)
job_manager.stop_app_with_closing_frida(app_package) # stops the frida session and the app and all frida jobs
profiler.write_profiling_log() # write the log data to profile.json
# instead of writing it to a file the JSON output will just be returned
# profiler.get_profiling_log_as_JSON()
تأكد من أن أي جزء آخر من الكود الخاص بك لا يحاول الاتصال بخادم frida (لا توجد جلسة frida أخرى).
من أجل اختبار هذا، يمكنك تجربة النموذج التالي: catelites_2018_01_19.apk. اسم الحزمة هو net.classwindexampleyear.bookseapiececountry. تأكد من أن AVD الخاص بك يعمل على Android 9، حتى يتمكن النموذج من تنفيذ كل الكود الخبيث الخاص به. يمكنك تثبيت هذا النموذج ببساطة باستخدام adb install samples/unpacking/catelites_2018_01_19.apk.
من أجل تجميع هذا المشروع، تأكد من أن npm و frida-compile يعملان على نظامك ومثبتان في مسارك. منذ إصدار frida 17.0، يتم تثبيت frida-compile عبر pip install frida-tools.
ثم قم ببساطة باستدعاء الأمر التالي للحصول على أحدث وكيل frida مُجمّع:
$ cd <AppProfiling-Project>
> Dexray [email protected] build
> frida-compile agent/hooking_profile_loader.ts -o src/dexray_intercept/profiling.js
$ npm install frida-java-bridge@latest --save
$ npm install --save-dev @types/frida-gum@latest
> Dexray [email protected] prepare
> npm run build
up to date, audited 75 packages in 6s
19 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
هذا يضمن استخدام أحدث نصوص/خطافات frida في dexray-intercept.
من أجل إجراء تعديلات في كود python، يوصى بتثبيت dexray-intercept باستخدام pip في الوضع القابل للتحرير:
python3 -m pip install -e .
بهذه الطريقة، تنعكس التغييرات المحلية في كود python دون إنشاء إصدار جديد من الحزمة.
يتوفر توثيق شامل يغطي التثبيت والاستخدام ومرجع واجهة برمجة التطبيقات والتطوير:
بمجرد استدعاء الأمر التالي في هذا الدليل، يجب استخدام setup.py لتثبيت dexray-intercept كحزمة python محلية على نظامك:
python3 -m pip install .
من أجل تجميع خطافات frida المكتوبة بـ TypeScript، نحتاج إلى مشروع frida-compile (الرابط). والذي سيتم تضمينه مع frida-tools.
python3 -m pip install frida-tools
بالإضافة إلى ذلك، نحتاج أيضًا إلى دعم frida-java-bridge وأنواع frida الداخلية:
npm install frida-java-bridge@latest --save
npm install --save-dev @types/frida-gum@latest
عند فك الحزم، قد تقوم التطبيقات بتحميل DexCode—الذي كان يشير سابقًا إلى كتل ذاكرة مميزة—إلى DexFile، والذي يمثل الكود الذي يتم تنفيذه. على سبيل المثال، قد تستعيد بعض التطبيقات التعليمات مباشرة قبل التنفيذ. في مثل هذه الحالات، لا يستطيع Sandroid إرجاع التعليمات مرة أخرى إلى DexFile. هناك حاجة إلى مزيد من البحث لحل هذه المشكلة
يعتمد Dexray Intercept على العمل الممتاز لمشاريع مفتوحة المصدر وباحثين مختلفين في مجتمع أمن أندرويد والتحليل الديناميكي. نود أن نشكر المشاريع التالية التي ألهمت أو ساهمت في تنفيذنا:
نعرب عن امتناننا لهذه المشاريع والقائمين عليها لتقدمهم في مجال تحليل أمن أندرويد وإتاحة أعمالهم للمجتمع.