本文へ移動
cccskills
無料GitHub で公開

analyzing-android-dex-malware

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.1 KB
  • LICENSE340 B
  • references/api-reference.md1.1 KB
  • scripts/analyst.py2.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Analyzing Android DEX Malware

When to Use

  • You have a suspicious .apk (or bare .dex) and need to understand its behavior.
  • You need to audit the manifest for dangerous permissions, exported components, and the declared entry points.
  • The app loads code dynamically (DexClassLoader) or ships a native .so you must locate.

Do not use this workflow for iOS apps — DEX/APK tooling does not apply to Mach-O/IPA.

Prerequisites

  • jadx (or apktool + a decompiler) and unzip; an Android emulator/sandbox for dynamic runs.
  • aapt/manifest parsing for permissions and components.

Workflow

Step 1: Unpack the APK

An APK is a ZIP. Extract and inventory the DEX files, native libraries, and assets:

python scripts/analyst.py inspect sample.apk
dex      : classes.dex, classes2.dex
native   : lib/arm64-v8a/libpayload.so
assets   : assets/config.enc  (possible encrypted payload)
manifest : AndroidManifest.xml (binary)

Step 2: Audit the manifest

Decode AndroidManifest.xml and review requested permissions (SMS, accessibility, device admin, REQUEST_INSTALL_PACKAGES), exported components, and the launcher/BOOT_COMPLETED receivers.

Step 3: Decompile DEX

Run jadx to recover Java. Start at the launcher activity and any BroadcastReceiver/Service declared in the manifest.

Step 4: Find dynamic and native code

Search for DexClassLoader/loadDex, asset decryption, and System.loadLibrary. Dump and recurse on dynamically loaded DEX; analyze native .so separately if needed.

Step 5: Extract behavior and IOCs

Recover C2 URLs, overlay/accessibility abuse, SMS interception, and config; map to ATT&CK for mobile in the report.

Validation

  • Every DEX and native library in the APK is accounted for.
  • Dangerous permissions are tied to concrete code paths (not just declared).
  • Dynamically loaded payloads are dumped and analyzed, not just noted.

Pitfalls

  • Reading only classes.dex and missing classes2.dex/classes3.dex.
  • Trusting the manifest alone; behavior may hide behind dynamic loading.
  • Ignoring encrypted assets that become the real payload at runtime.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Reverses .NET/managed malware: decompiling MSIL back to C#, defeating common .NET protectors and string encryptors, and tracing reflection-based loaders to recover the real payload. Activates for requests to analyze a .NET sample, decompile MSIL, or unpack a managed loader.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する