mvt/docs/android/download_apks.md

32 lines
1.4 KiB
Markdown
Raw Normal View History

2021-07-18 14:33:34 +00:00
# Downloading APKs from an Android phone
2021-07-16 06:05:01 +00:00
2021-08-17 14:36:48 +00:00
MVT allows to attempt to download all available installed packages (APKs) in order to further inspect them and potentially identify any which might be malicious in nature.
2021-07-16 06:05:01 +00:00
2021-08-17 14:36:48 +00:00
You can do so by launching the following command:
2021-07-16 06:05:01 +00:00
```bash
mvt-android download-apks --output /path/to/folder
```
2021-08-17 14:36:48 +00:00
It might take several minutes to complete. **Please note:** MVT will likely warn you it was unable to download certain installed packages. There is no reason to be alarmed: this is typically expected behavior when MVT attempts to download a system package it has no privileges to access.
Optionally, you can decide to enable lookups of the SHA256 hash of all the extracted APKs on [VirusTotal](https://www.virustotal.com) and/or [Koodous](https://koodous.com). While these lookups do not provide any conclusive assessment on all of the extracted APKs, they might highlight any known malicious ones:
2021-07-16 06:05:01 +00:00
```bash
mvt-android download-apks --output /path/to/folder --virustotal
mvt-android download-apks --output /path/to/folder --koodous
```
Or, to launch all available lookups::
```bash
mvt-android download-apks --output /path/to/folder --all-checks
```
2021-08-17 14:36:48 +00:00
In case you have a previous extraction of APKs you want to later check against VirusTotal and Koodous, you can do so with the following arguments:
```bash
mvt-android download-apks --from-file /path/to/folder/apks.json --all-checks
```