From 60a17381a253c1eb75c2c711c4a3c098da4f1f6d Mon Sep 17 00:00:00 2001 From: Nex Date: Tue, 21 Sep 2021 22:27:35 +0200 Subject: [PATCH] Standardized code --- mvt/android/modules/adb/packages.py | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/mvt/android/modules/adb/packages.py b/mvt/android/modules/adb/packages.py index 343d997..30e0821 100644 --- a/mvt/android/modules/adb/packages.py +++ b/mvt/android/modules/adb/packages.py @@ -54,16 +54,15 @@ class Packages(AndroidExtraction): self.detected.append(result) if result["package_name"] in self.indicators.ioc_app_ids: self.log.warning("Found a malicious package name: \"%s\"", - result["package_name"]) + result["package_name"]) self.detected.append(result) - for f in result["files"]: - if f["sha256"] in self.indicators.ioc_files_sha256: - self.log.warning("Found a malicious app: \"%s\" %s", - result["package_name"], - f["sha256"]) + for file in result["files"]: + if file["sha256"] in self.indicators.ioc_files_sha256: + self.log.warning("Found a malicious APK: \"%s\" %s", + result["package_name"], + file["sha256"]) self.detected.append(result) - def _get_files_for_package(self, package_name): output = self._adb_command(f"pm path {package_name}") output = output.strip().replace("package:", "")