06 Jul. 2014

This page contains many free resources for tracking a person down, such as checking addresses, reversing phone numbers and doing reverse address lookups. I've personally never seen this, but it appears that the application copied three additional XZ compressed assets, uncompressed them, and then used a DexClassLoader to load them.
If you have ever attempted to reverse an Android application, you've probably noticed that resource identifiers (think "R" values) show up as cryptic constants in disassembled smali code.

Once we start reversing this application, we will likely use apktool (or just baksmali) to disassemble the DEX bytecode.
As the app loaded, I noticed something very interesting - the application was copying additional DEX files, and loading them!

