ANDROID PACKERS: FACING THE CHALLENGES, BUILDING SOLUTIONS
Rowland Yu · 2014
Recently, SophosLabs has noticed an increase in the use of Android packers on APK fi les. Android packers are able to encrypt an original classes.dex fi le, use an ELF binary to decrypt the dex fi le to memory at runtime, and then execute via DexclassLoader. In other words, Android packers have the ability to change the overall structure and fl ow of an Android APK fi le ‐ which is more complicated than obfuscation techniques such as the use of ProGuard, DexGuard and junk byte injection. Android packers were originally created to prevent the intellectual property of applications being copied or altered by others for profi t. ApkProtect.com and Bangcle.com are the fi rst two legitimate providers of online packing services. Bangcle.com even employs virus-scanning engines in an attempt to prevent malicious applications being packed. However, the developers’ centralized measuring systems and scanning engines have not been able to prevent malware authors from using their services. A growing percentage of malware, including Zeus, SMSSend, and re-packaged applications, are packed by their services. SophosLabs has also found malware packed with a customized packer. As a result, security researchers are facing a great challenge in overcoming these packers’ complex anti-decompiler and anti-debugging strategies. Existing reverse engineering (RE) tools are not able to unpack and inspect hidden payloads within packed applications. Android sandboxes have trouble offering dynamic analysis information, as packed applications on Android Emulator keep crashing. Therefore, distinguishing Android malware from a group of packed applications is much harder than it is from a number of obfuscated applications. This paper attempts to address the anti-decompiler and anti-debugging techniques of the above packers, reveal the latest statistics on Android packed malware, use static RE utilities to analyse their logic fl ow and data structures, and demonstrate runtime behaviours via dynamic tools. Furthermore, we are building solutions to investigate hidden payloads via restoration of the original Android dex fi les from memory dump. Finally, the paper will present a generic method to detect packed Android malware.