mvt-project / mvt

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
https://mvt.re
Other
10.34k stars 967 forks source link

mvt-android check-adb #245

Closed free-doughnuts closed 2 years ago

free-doughnuts commented 2 years ago

Laptop = dell OS = kali linux 2021.04 Terminal Emulator = tilda 1.5.4 Shell = zsh Phone = samsung galaxy j7 Android Verstion = 6.0.1 (marshmellow)

mvt-android version = 1.4.10 libusb-1.0-0 = installed sqlite3 = installed adb kill-server = done adb shell pm list packages = getting a list with all the installed packages.

once running: sudo mvt-android check-adb, i'm getting the output:

    MVT - Mobile Verification Toolkit
            https://mvt.re
            Version: 1.4.10

18:13:46 INFO [mvt.android.cli] Checking Android through adb bridge
INFO [mvt.android.cli] Loaded a total of 0 unique indicators
INFO [mvt.android.modules.adb.chrome_history] Running module ChromeHistory...
INFO [mvt.android.modules.adb.chrome_history] Insufficient privileges for module ChromeHistory: This module is optionally available in
case the device is already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.sms] Running module SMS...
INFO [mvt.android.modules.adb.sms] Insufficient privileges for module SMS: This module is optionally available in case the device is
already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.whatsapp] Running module Whatsapp...
INFO [mvt.android.modules.adb.whatsapp] Insufficient privileges for module Whatsapp: This module is optionally available in case the
device is already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.processes] Running module Processes...
INFO [mvt.android.modules.adb.processes] Extracted records on a total of 0 processes
INFO [mvt.android.modules.adb.processes] The Processes module does not support checking for indicators
INFO [mvt.android.modules.adb.getprop] Running module Getprop...
18:13:47 INFO [mvt.android.modules.adb.getprop] Extracted 434 Android system properties
INFO [mvt.android.modules.adb.getprop] The Getprop module does not support checking for indicators
INFO [mvt.android.modules.adb.settings] Running module Settings...
INFO [mvt.android.modules.adb.dumpsys_battery_history] Running module DumpsysBatteryHistory...
INFO [mvt.android.modules.adb.dumpsys_battery_history] Extracted 24 records from battery history
Traceback (most recent call last): File "/usr/local/bin/mvt-android", line 8, in sys.exit(cli()) File "/usr/lib/python3/dist-packages/click/core.py", line 1128, in call return self.main(args, kwargs) File "/usr/lib/python3/dist-packages/click/core.py", line 1053, in main rv = self.invoke(ctx) File "/usr/lib/python3/dist-packages/click/core.py", line 1659, in invoke return _process_result(sub_ctx.command.invoke(sub_ctx)) File "/usr/lib/python3/dist-packages/click/core.py", line 1395, in invoke return ctx.invoke(self.callback, ctx.params) File "/usr/lib/python3/dist-packages/click/core.py", line 754, in invoke return __callback(args, *kwargs) File "/usr/lib/python3/dist-packages/click/decorators.py", line 26, in new_func return f(get_current_context(), args, **kwargs) File "/usr/local/lib/python3.9/dist-packages/mvt/android/cli.py", line 148, in check_adb run_module(m) File "/usr/local/lib/python3.9/dist-packages/mvt/common/module.py", line 169, in run_module module.check_indicators() File "/usr/local/lib/python3.9/dist-packages/mvt/android/modules/adb/dumpsys_battery_history.py", line 24, in check_indicators ioc = self.indicators.check_app_id(result["package_name"]) AttributeError: 'NoneType' object has no attribute 'check_app_id'

Any ideas? Thanks :)

botherder commented 2 years ago

Bug, my bad. Should be fixed now on git.

botherder commented 2 years ago

Just pushed v1.4.11. You shouldn't have this issue anymore. If so, let me know here. Thanks.

free-doughnuts commented 2 years ago

Thanks. I pulled the changes, and now i'm getting this:

mvt-android check-adb

    MVT - Mobile Verification Toolkit
            https://mvt.re
            Version: 1.4.11

12:47:26 INFO [mvt.android.cli] Checking Android through adb bridge
INFO [mvt.android.cli] Loaded a total of 0 unique indicators
INFO [mvt.android.modules.adb.chrome_history] Running module ChromeHistory...
INFO [mvt.android.modules.adb.chrome_history] Insufficient privileges for module ChromeHistory: This module is optionally available in
case the device is already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.sms] Running module SMS...
INFO [mvt.android.modules.adb.sms] Insufficient privileges for module SMS: This module is optionally available in case the device is
already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.whatsapp] Running module Whatsapp...
INFO [mvt.android.modules.adb.whatsapp] Insufficient privileges for module Whatsapp: This module is optionally available in case the
device is already rooted. Do NOT root your own device!
INFO [mvt.android.modules.adb.processes] Running module Processes...
12:47:27 INFO [mvt.android.modules.adb.processes] Extracted records on a total of 0 processes
INFO [mvt.android.modules.adb.processes] The Processes module does not support checking for indicators
INFO [mvt.android.modules.adb.getprop] Running module Getprop...
INFO [mvt.android.modules.adb.getprop] Extracted 436 Android system properties
INFO [mvt.android.modules.adb.getprop] The Getprop module does not support checking for indicators
INFO [mvt.android.modules.adb.settings] Running module Settings...
INFO [mvt.android.modules.adb.dumpsys_battery_history] Running module DumpsysBatteryHistory...
INFO [mvt.android.modules.adb.dumpsys_battery_history] Extracted 24 records from battery history
INFO [mvt.android.modules.adb.dumpsys_battery_daily] Running module DumpsysBatteryDaily...
12:47:28 INFO [mvt.android.modules.adb.dumpsys_battery_daily] Extracted 20 records from battery daily stats
INFO [mvt.android.modules.adb.dumpsys_receivers] Running module DumpsysReceivers...
12:47:29 INFO [mvt.android.modules.adb.dumpsys_activities] Running module DumpsysActivities...
12:47:30 INFO [mvt.android.modules.adb.dumpsys_accessibility] Running module DumpsysAccessibility...
INFO [mvt.android.modules.adb.dumpsys_accessibility] Found installed accessibility service "com.sec.android.app.camera/.CameraTTSService" INFO [mvt.android.modules.adb.dumpsys_accessibility] Found installed accessibility service
"com.google.android.marvin.talkback/.TalkBackService"
INFO [mvt.android.modules.adb.dumpsys_accessibility] Found installed accessibility service
"com.google.android.marvin.talkback/com.google.android.accessibility.selecttospeak.SelectToSpeakService"
INFO [mvt.android.modules.adb.dumpsys_accessibility] Found installed accessibility service
"com.google.android.marvin.talkback/com.android.switchaccess.SwitchAccessService"
INFO [mvt.android.modules.adb.dumpsys_accessibility] Identified a total of 4 accessibility services
INFO [mvt.android.modules.adb.dumpsys_dbinfo] Running module DumpsysDBInfo...
12:47:33 INFO [mvt.android.modules.adb.dumpsys_dbinfo] Extracted a total of 0 records from database information
INFO [mvt.android.modules.adb.dumpsys_full] Running module DumpsysFull...
12:47:56 INFO [mvt.android.modules.adb.dumpsys_full] The DumpsysFull module does not support checking for indicators
INFO [mvt.android.modules.adb.packages] Running module Packages...
12:57:05 INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.studioyeti.citybynight.appicon" installed by "None" on
2020-08-31 03:58:54
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.samsung.knox.knoxtrustagent" installed by "None" on
2019-02-20 03:06:06
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.onmobile.YearOfTheRooster.home" installed by "None" on
2020-08-31 02:09:19
INFO [mvt.android.modules.adb.packages] Found non-system package with name "il.co.orange.mytv" installed by "com.android.vending" on
2021-12-03 11:58:56
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.onmobile.YearOfTheRooster" installed by
"com.samsung.android.themecenter" on 2020-08-31 02:09:16
INFO [mvt.android.modules.adb.packages] Found non-system package with name "us.zoom.videomeetings" installed by "com.android.vending" on
2022-01-28 15:42:18
INFO [mvt.android.modules.adb.packages] Found non-system package with name "woainikejifeng.zooking" installed by
"com.samsung.android.themecenter" on 2020-08-31 02:47:01
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.samsung.upsmtheme.home" installed by "None" on 2016-09-08 11:44:29
INFO [mvt.android.modules.adb.packages] Found non-system package with name "woainikejifeng.zooking.appicon" installed by "None" on
2020-08-31 02:47:13
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.google.android.instantapps.supervisor" installed by
"com.android.vending" on 2021-12-08 11:36:04
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.knox.bluetooth" installed by "None" on 2019-02-20
03:07:08
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.samsung.knox.kss" installed by "None" on 2019-02-20
03:05:43
INFO [mvt.android.modules.adb.packages] Found non-system package with name "woainikejifeng.zooking.home" installed by "None" on 2020-08-31 02:47:07
INFO [mvt.android.modules.adb.packages] Found non-system package with name "org.videolan.vlc" installed by "com.android.vending" on
2022-01-07 01:08:02
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.Funbox.common.appicon" installed by "None" on
2020-08-31 02:10:37
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.Funbox.common" installed by
"com.samsung.android.themecenter" on 2020-08-31 02:10:31
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.Funbox.common.home" installed by "None" on 2020-08-31 02:10:34
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.knox.shortcutsms" installed by "None" on 2019-02-20
03:06:59
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.knox.containeragent2" installed by "None" on
2019-02-20 03:05:35
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.studioyeti.citybynight.wallpaper" installed by "None" on
2020-08-31 03:58:57
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.Funbox.common.wallpaper" installed by "None" on
2020-08-31 02:10:36
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.blackout.word" installed by "com.android.vending" on
2021-10-31 08:20:57
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.cisco.webex.meetings" installed by "com.android.vending"
on 2022-01-09 19:06:11
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.android.easyMover" installed by "com.android.vending" on 2022-01-31 18:30:33
INFO [mvt.android.modules.adb.packages] Found non-system package with name "woainikejifeng.zooking.wallpaper" installed by "None" on
2020-08-31 02:47:17
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.samsung.android.bbc.fileprovider" installed by "None" on
2019-02-20 03:06:55
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.studioyeti.citybynight" installed by
"com.samsung.android.themecenter" on 2020-08-31 03:58:51
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.onmobile.YearOfTheRooster.wallpaper" installed by "None"
on 2020-08-31 02:09:21
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.samsung.upsmtheme.appicon" installed by "None" on
2016-09-08 11:44:29
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.peoplefun.wordstacks" installed by "com.android.vending"
on 2022-01-09 19:09:05
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.onmobile.YearOfTheRooster.appicon" installed by "None" on 2020-08-31 02:09:20
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.studioyeti.citybynight.home" installed by "None" on
2020-08-31 03:58:55
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.provisiontwo.isr" installed by "com.android.vending" on
2022-01-25 12:52:27
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.holmesplace" installed by "com.android.vending" on
2021-11-21 10:24:07
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.microsoft.teams" installed by "com.android.vending" on
2022-01-30 20:17:59
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.gamma.bubblelevel" installed by "com.android.vending" on
2021-12-29 03:30:13
INFO [mvt.android.modules.adb.packages] Found non-system package with name "com.sec.enterprise.knox.shareddevice.keyguard" installed by
"None" on 2019-02-20 03:07:09
ERROR [mvt.android.lookups.virustotal] Unfortunately VirusTotal lookup is disabled until further notice, due to unresolved issues with the API service.
INFO [mvt.android.lookups.koodous] Looking up all extracted files on Koodous (www.koodous.com)
INFO [mvt.android.lookups.koodous] This might take a while...
Looking up 37 packages... _____ 0% -:--:-- 12:57:06 ERROR [mvt.android.modules.adb.packages] Error in running extraction from module Packages: [Errno Expecting value] <html lang="en"
class="backgroundsize bgpositionshorthand bgpositionxy bgrepeatround bgrepeatspace bgsizecover borderradius cssanimations csscalc
csstransforms supports csstransforms3d csstransitions no-flexboxtweener fontface inlinesvg localstorage multiplebgs preserve3d
sessionstorage smil svgclippaths svgfilters svgforeignobject canvas todataurljpeg todataurlpng todataurlwebp no-touch">

                 <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">                                             
                 <meta name="description" content="Koodous android malware analysis community">                                                    
                 <meta name="keywords" content="Koodous, android, malware, analysis, community">                                                   
                 <title>Koodous - Page not found</title>                                                                                           

                 <link rel="stylesheet" href="//maxcdn.bootstrapcdn.com/bootstrap/3.3.2/css/bootstrap.min.css">                                    
                 <link rel="stylesheet" href="//maxcdn.bootstrapcdn.com/font-awesome/4.3.0/css/font-awesome.min.css">                              

              </head>                                                                                                                              

              <body>                                                                                                                               
                 <div class="wrapper">                                                                                                             
                    <div class="abs-center wd-xl">                                                                                                 
                       <!-- START panel-->                                                                                                         
                       <div class="text-center mb-xl">                                                                                             
                          <div class="text-lg mb-lg">404</div>                                                                                     
                          <p class="lead m0">We couldn't find this page.</p>                                                                       
                          <p>The page you are looking for does not exists.</p>                                                                     
                       </div>                                                                                                                      
                       <ul class="list-inline text-center text-sm mb-xl">                                                                          
                          <li><a href="/" class="text-muted">Dashboard</a>                                                                         
                          </li>                                                                                                                    
                          <li class="text-muted">|</li>                                                                                            
                          <li><a href="/login" class="text-muted">Login</a>                                                                        
                          </li>                                                                                                                    
                          <li class="text-muted">|</li>                                                                                            
                          <li><a href="/register" class="text-muted">Register</a>                                                                  
                          </li>                                                                                                                    
                       </ul>                                                                                                                       
                       <div class="p-lg text-center">                                                                                              
                          <span>Koodous &copy; 2022</span>                                                                                         
                       </div>                                                                                                                      
                    </div>                                                                                                                         
                 </div>                                                                                                                            
              </body>                                                                                                                              
              </html>: 0                                                                                                                           
              Traceback (most recent call last):                                                                                                   
                File "/usr/local/lib/python3.9/dist-packages/requests/models.py", line 910, in json                                                
                  return complexjson.loads(self.text, **kwargs)                                                                                    
                File "/usr/lib/python3/dist-packages/simplejson/__init__.py", line 525, in loads                                                   
                  return _default_decoder.decode(s)                                                                                                
                File "/usr/lib/python3/dist-packages/simplejson/decoder.py", line 370, in decode                                                   
                  obj, end = self.raw_decode(s)                                                                                                    
                File "/usr/lib/python3/dist-packages/simplejson/decoder.py", line 400, in raw_decode                                               
                  return self.scan_once(s, idx=_w(s, idx).end())                                                                                   
              simplejson.errors.JSONDecodeError: Expecting value: line 1 column 1 (char 0)                                                         

              During handling of the above exception, another exception occurred:                                                                  

              Traceback (most recent call last):                                                                                                   
                File "/usr/local/lib/python3.9/dist-packages/mvt/common/module.py", line 152, in run_module                                        
                  module.run()                                                                                                                     
                File "/usr/local/lib/python3.9/dist-packages/mvt/android/modules/adb/packages.py", line 242, in run                                
                  koodous_lookup(packages_to_lookup)                                                                                               
                File "/usr/local/lib/python3.9/dist-packages/mvt/android/lookups/koodous.py", line 34, in koodous_lookup                           
                  report = res.json()                                                                                                              
                File "/usr/local/lib/python3.9/dist-packages/requests/models.py", line 917, in json                                                
                  raise RequestsJSONDecodeError(e.msg, e.doc, e.pos)                                                                               
              requests.exceptions.JSONDecodeError: [Errno Expecting value] <html lang="en" class="backgroundsize bgpositionshorthand bgpositionxy  
              bgrepeatround bgrepeatspace bgsizecover borderradius cssanimations csscalc csstransforms supports csstransforms3d csstransitions     
              no-flexboxtweener fontface inlinesvg localstorage multiplebgs preserve3d sessionstorage smil svgclippaths svgfilters svgforeignobject
              canvas todataurljpeg todataurlpng todataurlwebp no-touch"><head>                                                                     
                 <meta charset="utf-8">                                                                                                            
                 <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1">                                             
                 <meta name="description" content="Koodous android malware analysis community">                                                    
                 <meta name="keywords" content="Koodous, android, malware, analysis, community">                                                   
                 <title>Koodous - Page not found</title>                                                                                           

                 <link rel="stylesheet" href="//maxcdn.bootstrapcdn.com/bootstrap/3.3.2/css/bootstrap.min.css">                                    
                 <link rel="stylesheet" href="//maxcdn.bootstrapcdn.com/font-awesome/4.3.0/css/font-awesome.min.css">                              

              </head>                                                                                                                              

              <body>                                                                                                                               
                 <div class="wrapper">                                                                                                             
                    <div class="abs-center wd-xl">                                                                                                 
                       <!-- START panel-->                                                                                                         
                       <div class="text-center mb-xl">                                                                                             
                          <div class="text-lg mb-lg">404</div>                                                                                     
                          <p class="lead m0">We couldn't find this page.</p>                                                                       
                          <p>The page you are looking for does not exists.</p>                                                                     
                       </div>                                                                                                                      
                       <ul class="list-inline text-center text-sm mb-xl">                                                                          
                          <li><a href="/" class="text-muted">Dashboard</a>                                                                         
                          </li>                                                                                                                    
                          <li class="text-muted">|</li>                                                                                            
                          <li><a href="/login" class="text-muted">Login</a>                                                                        
                          </li>                                                                                                                    
                          <li class="text-muted">|</li>                                                                                            
                          <li><a href="/register" class="text-muted">Register</a>                                                                  
                          </li>                                                                                                                    
                       </ul>                                                                                                                       
                       <div class="p-lg text-center">                                                                                              
                          <span>Koodous &copy; 2022</span>                                                                                         
                       </div>                                                                                                                      
                    </div>                                                                                                                         
                 </div>                                                                                                                            
              </body>                                                                                                                              
              </html>: 0                                                                                                                           
     INFO     [mvt.android.modules.adb.root_binaries] Running module RootBinaries...                                                               
     INFO     [mvt.android.modules.adb.root_binaries] The RootBinaries module does not support checking for indicators                             
     INFO     [mvt.android.modules.adb.logcat] Running module Logcat...                                                                            

^C Aborted!

it took a long time, so i had to abort it.

After that, i tried to run anyway: sudo mvt-android download-apks -v -k -o /home/dell_user2022/samsung_apks

and i'm getting the same error as #240

Thanks again :)