一款Android恶意软件分析工具,通过挂钩应用程序在密码学、文件系统、数据库、网络通信和进程操作方面的行为,创建全面的运行时配置文件。
Android 二进制 API 追踪器
Dexray Intercept 是动态沙箱 Sandroid 的一部分。其目的是创建运行时配置文件以追踪 Android 应用程序的行为。这是通过使用 frida 来实现的。
只需使用 pip 安装:
python3 -m pip install dexray-intercept
这会将 Dexray Intercept 安装为命令行工具 ammm 或 dexray-intercept。
此外,它还会提供一个名为 dexray_intercept 的包。关于如何使用该包的更多信息见下文。
确保你的 Android 设备已 root。frida-server 将自动安装到最新版本。然后你只需调用以下命令即可使用 Dexray Intercept:
dexray-intercept <target app>
# 或使用其旧名称:
ammm <target app>
所有 hook 默认禁用以获得最佳性能。根据你的分析需求启用 hook:
# 启用特定 hook
dexray-intercept --enable-aes <app_name> # 启用 AES 加密 hook
dexray-intercept --enable-web <app_name> # 启用 web/HTTP hook
dexray-intercept --enable-aes --enable-web <app_name> # 启用多个 hook
# 启用 hook 组
dexray-intercept --hooks-crypto <app_name> # 启用所有加密 hook
dexray-intercept --hooks-network <app_name> # 启用所有网络 hook
dexray-intercept --hooks-filesystem <app_name> # 启用所有文件系统 hook
# 启用所有 hook(影响性能)
dexray-intercept --hooks-all <app_name> # 启用所有可用 hook
# 使用包标识符代替应用名称
dexray-intercept -s com.example.package --hooks-crypto
--hooks-crypto(AES、编码、keystore、证书)--hooks-network(HTTP、socket、SSL/TLS)--hooks-filesystem(文件操作、数据库、shared preferences)--hooks-ipc(intents、broadcasts、binder、shared preferences)--hooks-process(DEX 脱壳、原生库、运行时)--hooks-services(相机、位置、电话、蓝牙)以下是在我们的 AVD 上监控 chrome 应用的示例:
dexray-intercept Chrome
Dexray Intercept
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
[*] starting app profiling
[*] press Ctrl+C to stop the profiling ...
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7ac6b67540,8)
[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7fcb41c990,8
将 Dexray Intercept 安装为包并使用新的模块化架构:
from dexray_intercept import AppProfiler, setup_frida_device
from dexray_intercept.services.hook_manager import HookManager
# Connect to device and get process
device = setup_frida_device()
process = device.attach("com.example.app")
# Configure hooks (all disabled by default for performance)
hook_config = {
'aes_hooks': True,
'web_hooks': True,
'file_system_hooks': True,
'keystore_hooks': True
}
# Create profiler with new architecture
profiler = AppProfiler(
process,
verbose_mode=True,
output_format="JSON",
hook_config=hook_config,
enable_stacktrace=True
)
# Start profiling
script = profiler.start_profiling()
# ... let app run and collect data ...
# Get results
profile_data = profiler.get_profile_data()
json_output = profiler.get_profiling_log_as_json()
# Runtime hook management
profiler.enable_hook('socket_hooks', True) # Enable more hooks at runtime
enabled_hooks = profiler.get_enabled_hooks() # Check what's enabled
# Stop profiling
profiler.stop_profiling()
根据你的分析需求启用特定的 hook 组:
# Crypto hooks
hook_config = {
'aes_hooks': True,
'encodings_hooks': True,
'keystore_hooks': True
}
# Network hooks
hook_config = {
'web_hooks': True,
'socket_hooks': True
}
# File system hooks
hook_config = {
'file_system_hooks': True,
'database_hooks': True
}
# Enable all hooks (performance impact)
profiler.enable_all_hooks()
# Enable hook groups
profiler.enable_hook_group('crypto') # Enable all crypto-related hooks
旧版 API 仍然可用以保持向后兼容:
from dexray_intercept import AppProfilerLegacy
# OR use environment variable: DEXRAY_FORCE_OLD_ARCH=true
profiler = AppProfilerLegacy(process_session, verbose=True, output_format="CMD",
base_path=None, deactivate_unlink=False)
profiler.instrument() # Old method name
# ...
profiler.finish_app_profiling() # Old method name
为了在 Sandroid 中将其作为包运行,请确保你也安装了来自 AndroidFridaManager 的 JobManager。这允许在不同线程中运行多个 frida 会话。
你只需运行以下代码:
from AndroidFridaManager import JobManager
from dexray_intercept import AppProfiler
job_manager = JobManager()
app_package = "net.classwindexampleyear.bookseapiececountry"
profiler = AppProfiler(job_manager.process_session, True, output_format="JSON", base_path=None, deactivate_unlink=False)
frida_script_path = profiler.get_frida_script()
job_manager.setup_frida_session(app_package, profiler.on_appProfiling_message)
job = job_manager.start_job(frida_script_path, custom_hooking_handler_name=profiler.on_appProfiling_message)
# close only the job and the frida session keeps active to run other frida scripts
# job_manager.stop_job_with_id(job.job_id)
job_manager.stop_app_with_closing_frida(app_package) # stops the frida session and the app and all frida jobs
profiler.write_profiling_log() # write the log data to profile.json
# instead of writing it to a file the JSON output will just be returned
# profiler.get_profiling_log_as_JSON()
确保你的代码中没有其他部分尝试连接到 frida server(没有其他 frida 会话)。
为了测试这一点,你可以尝试以下示例:catelites_2018_01_19.apk。包名为 net.classwindexampleyear.bookseapiececountry。确保你的 AVD 运行在 Android 9 上,以便该示例能够执行其所有恶意代码。你可以使用 adb install samples/unpacking/catelites_2018_01_19.apk 简单地安装此示例。
为了编译此项目,请确保 npm 和 frida-compile 在你的系统上运行并已安装到你的路径中。自 frida 17.0 版本起,frida-compile 通过 pip install frida-tools 安装。
然后只需调用以下命令即可编译最新的 frida agent:
$ cd <AppProfiling-Project>
> Dexray [email protected] build
> frida-compile agent/hooking_profile_loader.ts -o src/dexray_intercept/profiling.js
$ npm install frida-java-bridge@latest --save
$ npm install --save-dev @types/frida-gum@latest
> Dexray [email protected] prepare
> npm run build
up to date, audited 75 packages in 6s
19 packages are looking for funding
run `npm fund` for details
found 0 vulnerabilities
这确保 dexray-intercept 中使用最新的 frida 脚本/hook。
为了对 Python 代码进行调整,建议使用可编辑模式通过 pip 安装 dexray-intercept:
python3 -m pip install -e .
这样,Python 代码的本地更改无需创建新版本的包即可生效。
提供全面的文档,涵盖安装、使用、API 参考和开发:
只需在此目录中调用以下命令,setup.py 将用于将 dexray-intercept 作为本地 Python 包安装到你的系统:
python3 -m pip install .
为了编译 TypeScript frida hook,我们需要 frida-compile(链接)项目。它将与 frida-tools 捆绑在一起。
python3 -m pip install frida-tools
此外,我们还需要对 frida-java-bridge 和内部 frida 类型的支持:
npm install frida-java-bridge@latest --save
npm install --save-dev @types/frida-gum@latest
在脱壳时,应用程序可能会将 DexCode(之前指向不同的内存块)加载到 DexFile 中,DexFile 代表正在执行的代码。例如,某些应用程序可能会在执行前立即恢复指令。在这种情况下,Sandroid 无法将指令还原回 DexFile。需要进一步研究以解决此问题。
Dexray Intercept 建立在 Android 安全和动态分析社区中各种开源项目和研究人员的出色工作之上。我们要感谢以下项目,它们启发了我们的实现或为其做出了贡献:
我们感谢这些项目及其维护者为推进 Android 安全分析水平并将他们的工作提供给社区。