Javascript must be enabled to continue!
Dynamic Analysis of Android Apps written with PhoneGap Cross-Platform Framework
View through CrossRef
In this paper, we propose an effective technique that can perform dynamic analysis
for Android appwritten with PhoneGap cross-platform framework. For a systematic study,
we have written a maliciousAndroid app using PhoneGap framework. We compare the
structural differences between abasic Android app (a native app) and the other malicious
Android app built in release mode on Phone-Gap framework, and also analyze the malicious
app dynamically. The proposed technique first copiesthe web root directory of the target
malicious app into a writable directory inside the smartphone.When the app is executed,
its web pages and Javascript files are loaded from the copied directoryusing a dynamic
instrumentation. Finally, we dynamically change the flag for WebView debuggingso that a
remote debugger can successfully be attached to the app built in release mode. Using
ourproposed technique, a malware analyst can debug a malicious PhoneGap app built in
release modewithout repackaging, which cannot be debugged as it is by Chrome remote
debugger. She/he canalso utilize the debugging features supported by the remote
debugger. The technique allows the analystto bypass the repackaging detection method
that malicious apps use to avoid antivirus detection.
Centre for Continental Network in Eco-Innovation and Research
Title: Dynamic Analysis of Android Apps written with PhoneGap Cross-Platform
Framework
Description:
In this paper, we propose an effective technique that can perform dynamic analysis
for Android appwritten with PhoneGap cross-platform framework.
For a systematic study,
we have written a maliciousAndroid app using PhoneGap framework.
We compare the
structural differences between abasic Android app (a native app) and the other malicious
Android app built in release mode on Phone-Gap framework, and also analyze the malicious
app dynamically.
The proposed technique first copiesthe web root directory of the target
malicious app into a writable directory inside the smartphone.
When the app is executed,
its web pages and Javascript files are loaded from the copied directoryusing a dynamic
instrumentation.
Finally, we dynamically change the flag for WebView debuggingso that a
remote debugger can successfully be attached to the app built in release mode.
Using
ourproposed technique, a malware analyst can debug a malicious PhoneGap app built in
release modewithout repackaging, which cannot be debugged as it is by Chrome remote
debugger.
She/he canalso utilize the debugging features supported by the remote
debugger.
The technique allows the analystto bypass the repackaging detection method
that malicious apps use to avoid antivirus detection.
Related Results
Playing Pregnancy: The Ludification and Gamification of Expectant Motherhood in Smartphone Apps
Playing Pregnancy: The Ludification and Gamification of Expectant Motherhood in Smartphone Apps
IntroductionLike other forms of embodiment, pregnancy has increasingly become subject to representation and interpretation via digital technologies. Pregnancy and the unborn entity...
User Experience of Cognitive Behavioral Therapy Apps for Depression: An Analysis of App Functionality and User Reviews (Preprint)
User Experience of Cognitive Behavioral Therapy Apps for Depression: An Analysis of App Functionality and User Reviews (Preprint)
BACKGROUND
Hundreds of mental health apps are available to the general public. With increasing pressures on health care systems, they offer a potential way ...
P–469 Period Tracker Applications – are they giving women accurate menstrual cycle information?
P–469 Period Tracker Applications – are they giving women accurate menstrual cycle information?
Abstract
Study question
Are period trackers giving women accurate information about their periods and ovulation?
...
P-469 Period Tracker Applications – are they giving women accurate menstrual cycle information?
P-469 Period Tracker Applications – are they giving women accurate menstrual cycle information?
Abstract
Study question
Are period trackers giving women accurate information about their periods and ovulation?
...
Mobile Phone Apps for Intimate Partner and Sexual Violence Prevention and Response: Systematic Search on App Stores (Preprint)
Mobile Phone Apps for Intimate Partner and Sexual Violence Prevention and Response: Systematic Search on App Stores (Preprint)
BACKGROUND
Since the 2008 advent of the smartphone, more than 180 billion copies of apps have been downloaded from Apple App Store, with more than 2.6 milli...
Mobile Phone Apps for Intimate Partner and Sexual Violence Prevention and Response: Systematic Search on App Stores
Mobile Phone Apps for Intimate Partner and Sexual Violence Prevention and Response: Systematic Search on App Stores
BackgroundSince the 2008 advent of the smartphone, more than 180 billion copies of apps have been downloaded from Apple App Store, with more than 2.6 million apps available for And...
Benefits of Mobile Apps for Cancer Pain Management: Systematic Review (Preprint)
Benefits of Mobile Apps for Cancer Pain Management: Systematic Review (Preprint)
BACKGROUND
Pain ratings reported by patients with cancer continue to increase, and numerous computer and phone apps for managing cancer-related pain have be...
Hook-Up and Dating Apps
Hook-Up and Dating Apps
Hook-up apps are a relatively recent form of digitally mediated dating. They are apps—software programs configured for a specific purpose—that play a role in sociotechnical arrange...

