> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-mcs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-mcs/reverse-engineering/android-static-analysis/exercise-4.md).

# Exercise 4

## Thai Camera is sending SMS?

### Approach

* Extract all code and resources: `jadx-gui`
* Inspect Manifest for suspicious permission (Send SMS): AndroidManifest.XML
* Determine if the app is sending SMS: Check the Java classes, and look for SMS send methods.
* Determine if the SMS is sent without interaction from the user.
  * How are these functions called?
  * What is the call flow?

For a camera application, some permissions are suspicious.

* Including `android.permission.SEND_SMS`
* Therefore, we have indications of possible taints

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2F3vVGc0hUNpfMaaqqLNWG%2FScreenshot%20from%202024-03-03%2020-49-12.png?alt=media&amp;token=21764b00-febe-4f7d-a27b-be69c834f4d9" alt=""><figcaption></figcaption></figure>

In `com.p004cp.camera.loading` and SMS is sent.

* As an action of clicking a button. With static analysis, it seems to be ok.

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2FyPrMzPGVD7LGevZurJqt%2Fimage.png?alt=media&amp;token=f7dfc766-a005-4501-9661-c90e712b8a22" alt=""><figcaption></figcaption></figure>

There is a `SendMessage` method with two arguments (number and text).

* Logs the event to Firebase.
* Splits the message in chunks and submits multiple SMS.
* How is the function called?

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2FE4VnSHLgNkAQAxaxUS1s%2Fimage.png?alt=media&amp;token=3f03425e-f19e-4905-a44d-cad485e9e6ac" alt=""><figcaption></figcaption></figure>

In several places, but one is strange.

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2FMAxdhOodmsTNUk36Z4mo%2FScreenshot%20from%202024-03-04%2015-14-36.png?alt=media&amp;token=58ec919b-b71e-4d55-b499-d380092c6422" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2FEgd9uxo0FMq9qk75PEtb%2FScreenshot%20from%202024-03-04%2015-27-37.png?alt=media&amp;token=dd44b2d0-a90b-4338-a2de-835a48b6592b" alt=""><figcaption><p>Loading::onCreate</p></figcaption></figure>

Going back to the previous location.

* The permission is requested.
* And if authorized and `this.service` is set, an SMS is sent automatically (without user interaction).

<figure><img src="https://1103423335-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FvyEajzuIz0PAtDiV6JcU%2Fuploads%2FfdPVc2p5orKnET7vcKCs%2FScreenshot%20from%202024-03-04%2015-27-37.png?alt=media&amp;token=76d52ad4-290a-45eb-9306-3bd241170589" alt=""><figcaption></figcaption></figure>

## How to improve this process?

### Flow Analysis

The execution flow can be analyzed and reconstructed, allowing us to understand entry and sink points.

* Identify all methods and their callers: Sources/Entry Points.
  * Events, Intent Receivers.
* Identify which arguments are used… eventually do a symbolic analysis.
* Identify which Android APIs are called: Sink Points.
  * Information is sent/registered using the Android API.

### Taint Analysis

Identify patterns which may indicate suspicious behaviour.

* E.g. access contacts, and upload contacts.

### Dynamic Analysis

Actually analyze what the application done, in real-time.

### Tools

#### Android Studio

* If Java code can be obtained, Android Studio creates call flows.
  * Analyze Tab -> Data Flow From Here.

#### Quark

* One of many tools providing Flow Analysis and Taint Analysis.
* Targeted towards malware.
  * Identifies malicious or suspicious behavior, and ranks each taint.
  * Provides limited call graph information through static analysis.
* Based on smali directly from the apk.
* Installing quark:
  * `pip3 install --user quark-engine`
  * `freshquark`
* For testing the apk: `quark -s –a “ThaiCamera_v1.2.apk”`
* Some indicators (remember, it’s a Camera App!)
  * Get calendar information.
  * Read sensitive data(SMS, CALLLOG) and put it into JSON object.
  * Get the network operator name.
  * Get data from HTTP and send SMS.
  * Send IMSI over Internet.
  * Get the network operator name and IMSI.
  * Write SIM card serial number into a file.
  * Write the phone number into a file.
  * Check if successfully sending out SMS.
