With more and more techniques of mobile app obfuscation on the market, it is possible that hackers will leverage them to mass-produce mobile malware by repackaging the obfuscation shell around known malicious codes, just like what had happened in PC threat landscape.
In this blog, I will do DEX analysis 101: reverse engineering a few repackaged samples. DEX file contains most program codes of Android application package file (APK). I use 101 Editor as the tool to view DEX files. 010 Editor offers generic interface for various types of file format. In this case, after I downloaded DEX template file and imported it into 010 Editor, I can go throug DEX format, shown as the following:
Afterwards, I submitted them to Mobile Sandbox online service (www.mobile-sandbox.com) .
The output reports showed that they shared the same behavior activities.

It is a simple demo. However, the concern behind it is that we need to keep track of each application coming out of application obfuscators (by certificate?) The "mobile packer" software companies should work with security vendors so that the latter can determine if a submitted sample with a certain certificate is malicious or not. For more details, please refer IEEE taggant system.
1 comment:
Numbers of developers and business are using Mobile application like Android Application which have covered large area of success in technical market. Because of this there are many competitors who are trying to protect their application integrity.
Post a Comment