静析安卓恶意APK

原名:analyzing-android-malware-with-apktool

用 apktool 反编译资源,jadx 恢复 Java 源码,androguard 检查 manifest、危险权限组合、混淆代码、动态加载和反射调用,静态分析可疑 APK 无需执行,或用于构建移动端恶意软件检测规则。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-24
TRACE 评分
3.2 / 5

内容概览

Android malware distributed as APK files can be statically analyzed to extract permissions, activities, services, broadcast receivers, and suspicious API calls without executing the sample. This skill uses androguard for programmatic APK analysis, identifying dangerous permission combinations, obfuscated code patterns, dynamic code loading, reflection-based API calls, and network communication indicators. - When investigating security incidents that require analyzing android malware with apktool - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Python 3.9+ with androguard - apktool (for resource decompilation) - jadx (for Java source recovery, optional) - Isolated analysis environment (VM or sandbox) - Sample APK file…

查看 SKILL 详情