
Androidマルウェア解析ツール。暗号化、ファイルシステム、データベース、ネットワーク通信、プロセス操作にわたるアプリケーションの動作にフックすることで、包括的なランタイムプロファイルを作成します。
Android バイナリ API トレーサー
Dexray Intercept は動的サンドボックス Sandroid の一部です。その目的は、Android アプリケーションの動作を追跡するためのランタイムプロファイルを作成することです。これは frida を利用して行われます。
pip でインストールするだけです:
python3 -m pip install dexray-intercept
これにより、Dexray Intercept がコマンドラインツール ammm または dexray-intercept としてインストールされます。
さらに、パッケージ dexray_intercept が提供されます。パッケージの使用方法については以下で詳しく説明します。
Android デバイスが root 化されていることを確認してください。frida-server は自動的に最新バージョンにインストールされます。その後、以下のコマンドを実行するだけで Dexray Intercept を使用できます:
dexray-intercept <target app>
# または旧名を使用:
ammm <target app>
すべてのフックは最適なパフォーマンスのためにデフォルトで無効になっています。分析のニーズに応じてフックを有効にしてください:
# 特定のフックを有効化
dexray-intercept --enable-aes <app_name> # AES 暗号化フックを有効化
dexray-intercept --enable-web <app_name> # Web/HTTP フックを有効化
dexray-intercept --enable-aes --enable-web <app_name> # 複数のフックを有効化
# フックグループを有効化
dexray-intercept --hooks-crypto <app_name> # すべての暗号化フックを有効化
dexray-intercept --hooks-network <app_name> # すべてのネットワークフックを有効化
dexray-intercept --hooks-filesystem <app_name> # すべてのファイルシステムフックを有効化
# すべてのフックを有効化(パフォーマンスに影響)
dexray-intercept --hooks-all <app_name> # 利用可能なすべてのフックを有効化
# アプリ名の代わりにパッケージ識別子を使用
dexray-intercept -s com.example.package --hooks-crypto
--hooks-crypto(AES、エンコーディング、キーストア、証明書)--hooks-network(HTTP、ソケット、SSL/TLS)--hooks-filesystem(ファイル操作、データベース、共有設定)--hooks-ipc(インテント、ブロードキャスト、バインダー、共有設定)--hooks-process(DEX アンパック、ネイティブライブラリ、ランタイム)--hooks-services(カメラ、位置情報、テレフォニー、Bluetooth)以下は、AVD 上で Chrome アプリを監視する例です:
dexray-intercept Chrome
Dexray Intercept
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
[*] starting app profiling
[*] press Ctrl+C to stop the profiling ...
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7ac6b67540,8)
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7fcb41c990,8
Dexray Intercept をパッケージとしてインストールし、新しいモジュラーアーキテクチャを使用します:
from dexray_intercept import AppProfiler, setup_frida_device
from dexray_intercept.services.hook_manager import HookManager
# Connect to device and get process
device = setup_frida_device()
process = device.attach("com.example.app")
# Configure hooks (all disabled by default for performance)
hook_config = {
'aes_hooks': True,
'web_hooks': True,
'file_system_hooks': True,
'keystore_hooks': True
}
# Create profiler with new architecture
profiler = AppProfiler(
process,
verbose_mode=True,
output_format="JSON",
hook_config=hook_config,
enable_stacktrace=True
)
# Start profiling
script = profiler.start_profiling()
# ... let app run and collect data ...
# Get results
profile_data = profiler.get_profile_data()
json_output = profiler.get_profiling_log_as_json()
# Runtime hook management
profiler.enable_hook('socket_hooks', True) # Enable more hooks at runtime
enabled_hooks = profiler.get_enabled_hooks() # Check what's enabled
# Stop profiling
profiler.stop_profiling()
分析のニーズに基づいて特定のフックグループを有効にします:
# Crypto hooks
hook_config = {
'aes_hooks': True,
'encodings_hooks': True,
'keystore_hooks': True
}
# Network hooks
hook_config = {
'web_hooks': True,
'socket_hooks': True
}
# File system hooks
hook_config = {
'file_system_hooks': True,
'database_hooks': True
}
# Enable all hooks (performance impact)
profiler.enable_all_hooks()
# Enable hook groups
profiler.enable_hook_group('crypto') # Enable all crypto-related hooks
古い API は後方互換性のために引き続き利用可能です:
from dexray_intercept import AppProfilerLegacy
# OR use environment variable: DEXRAY_FORCE_OLD_ARCH=true
profiler = AppProfilerLegacy(process_session, verbose=True, output_format="CMD",
base_path=None, deactivate_unlink=False)
profiler.instrument() # Old method name
# ...
profiler.finish_app_profiling() # Old method name
Sandroid でパッケージとして実行するには、AndroidFridaManager から JobManager もインストールされていることを確認してください。これにより、異なるスレッドで複数の frida セッションを実行できます。
必要な作業は、以下のコードを実行するだけです:
from AndroidFridaManager import JobManager
from dexray_intercept import AppProfiler
job_manager = JobManager()
app_package = "net.classwindexampleyear.bookseapiececountry"
profiler = AppProfiler(job_manager.process_session, True, output_format="JSON", base_path=None, deactivate_unlink=False)
frida_script_path = profiler.get_frida_script()
job_manager.setup_frida_session(app_package, profiler.on_appProfiling_message)
job = job_manager.start_job(frida_script_path, custom_hooking_handler_name=profiler.on_appProfiling_message)
# close only the job and the frida session keeps active to run other frida scripts
# job_manager.stop_job_with_id(job.job_id)
job_manager.stop_app_with_closing_frida(app_package) # stops the frida session and the app and all frida jobs
profiler.write_profiling_log() # write the log data to profile.json
# instead of writing it to a file the JSON output will just be returned
# profiler.get_profiling_log_as_JSON()
コードの他の部分が frida サーバーに接続しようとしていないこと(他の frida セッションがないこと)を確認してください。
これをテストするには、以下のサンプルを試すことができます:catelites_2018_01_19.apk。パッケージ名は net.classwindexampleyear.bookseapiececountry です。サンプルが悪意のあるコードのすべてを実行できるように、AVD が Android 9 で実行されていることを確認してください。このサンプルは adb install samples/unpacking/catelites_2018_01_19.apk で簡単にインストールできます。
このプロジェクトをコンパイルするには、npm と frida-compile がシステム上で実行され、パスにインストールされていることを確認してください。frida バージョン 17.0 以降、frida-compile は pip install frida-tools でインストールされます。
その後、最新の frida エージェントをコンパイルするために、以下のコマンドを実行するだけです:
$ cd <AppProfiling-Project>
> Dexray [email protected] build
> frida-compile agent/hooking_profile_loader.ts -o src/dexray_intercept/profiling.js
$ npm install frida-java-bridge@latest --save
$ npm install --save-dev @types/frida-gum@latest
> Dexray [email protected] prepare
> npm run build
up to date, audited 75 packages in 6s
19 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
これにより、最新の frida スクリプト/フックが dexray-intercept で使用されることが保証されます。
Python コードを調整するには、編集可能モードで pip を使用して dexray-intercept をインストールすることをお勧めします:
python3 -m pip install -e .
この方法では、パッケージの新しいバージョンを作成することなく、Python コードのローカルな変更が反映されます。
インストール、使用方法、API リファレンス、開発を網羅した包括的なドキュメントが利用可能です:
このディレクトリで以下のコマンドを実行するだけで、setup.py を使用して dexray-intercept をローカル Python パッケージとしてシステムにインストールできます:
python3 -m pip install .
TypeScript の frida フックをコンパイルするには、frida-compile(リンク)プロジェクトが必要です。これは frida-tools にバンドルされています。
python3 -m pip install frida-tools
さらに、frida-java-bridge と内部 frida 型のサポートも必要です:
npm install frida-java-bridge@latest --save
npm install --save-dev @types/frida-gum@latest
アンパック時、アプリケーションは以前は別々のメモリブロックを指していた DexCode を、実行されるコードを表す DexFile にロードする場合があります。例えば、一部のアプリケーションは実行直前に命令を復元する場合があります。このような場合、Sandroid は命令を DexFile に戻すことができません。この問題を解決するにはさらなる研究が必要です。
Dexray Intercept は、Android セキュリティと動的解析コミュニティにおける様々なオープンソースプロジェクトと研究者の優れた成果の上に構築されています。私たちの実装にインスピレーションを与えた、または貢献した以下のプロジェクトに感謝します:
Android セキュリティ解析の現状を前進させ、その成果をコミュニティに公開してくださったこれらのプロジェクトとそのメンテナーの皆様に感謝の意を表します。