Regex-driven IOC hunter for decompiled Android APK smali files.
Hunt URLs, IPs, secrets, Base64 encoded C2s, and database endpoints - with up to 97% false positive reduction.
Installation · Modes · Flags · Examples · Output
- Overview
- Features
- Installation
- Modes of Operation
- Base64 Filter Levels
- CLI Reference
- Usage Examples
- Output Structure
- False Positive Reduction : How It Works
- License
Hunt Sexy Smali (HSS) is a command-line Dmali forensics tool written in Go for static analysis of decompiled Android applications. It recursively walks .smali files produced by tools like apktool, jadx, or apkeasy and applies regex-based hunting across multiple IOC categories.
The tool is designed for malware analysts, mobile security researchers who need to extract indicators from APKs quickly and with minimal noise.
Note
HSS operates entirely on decompiled smali source - it does not decompile APKs itself. Run apktool d target.apk first, then point HSS at the output folder and then it start hunting recursively for all smali files.
| Category | What It Hunts |
|---|---|
| Network Endpoints | HTTP and HTTPS URLs |
| Database / BaaS | Firebase, Supabase, MongoDB Atlas, MySQL, SQLite, RealmDB, Redis |
| Secrets | Hardcoded API keys, access tokens, auth tokens |
| IP Addresses | IPv4 with port validation (ports 1–65535 only) |
| Email Addresses | Gmail, Outlook/Hotmail/Live, ProtonMail, Yahoo, custom domains |
| Base64 Payloads | Multi-encoding decode: UTF-8, UTF-16 LE/BE, ISO-8859-1, Windows-1252, KOI8-R, GB18030, Shift-JIS, EUC-JP, binary hex fallback |
Directly download it from 👉here👈
OR
Go 1.20 or later is required.
git clone https://github.com/gigachad80/Hunt-Sexy-Smali.git
cd Hunt-Sexy-Smali
go build -o hunt-sexy-smali sexysmali.goVerify the build:
./hunt-sexy-smali -helpHSS offers three operation modes. When using -i, an interactive prompt asks you to choose between Batch and Stream before scanning begins.
HSS recursively walks the decompiled APK folder and hunts for IOCs. At startup, an interactive prompt asks you to select one of two sub-modes:
./hunt-sexy-smali -i /path/to/decompiled_apk -o ./output -h -ip -b -mBatch (prompt choice 1)
- Copies all
.smalifiles into a flatAll_Smali/directory, embedding the original relative path as a header comment inside each file - Hunt runs after full collection is complete
All_Smali/persists on disk, enabling-reloadfor future re-scans without re-copying- Best for: small/medium APKs, repeated analysis sessions
- Disk: HIGH - Memory: LOW
Stream (prompt choice 2)
- No
All_Smali/folder is created - Each file is read into memory, hunted immediately, then discarded if no hits are found
- Only the findings report is written to disk
- Best for: large APKs (100 MB+), one-time scans
- Disk: ZERO - Memory: LOW
Important
Stream Mode is incompatible with -reload. The reload flag requires an existing All_Smali/ folder, which Stream Mode never creates. When -reload is provided, HSS skips the scan mode prompt entirely.
USeful for incase you want to run scan again inf future . Re-hunts an existing All_Smali/ folder from a previous Batch Mode run without re-copying any files. Useful for changing filter levels, hunting new categories, or re-extracting Base64 with a different -fl value.
./hunt-sexy-smali -reload ./HSS_Output/All_Smali -b -fl 2Output is written to HSS_Reload_Output/ next to the All_Smali/ folder.
Note
Reload Mode always operates as Batch - no scan mode prompt is shown. Stream Mode has no reload equivalent since it never persists smali files to disk.
Smali files are dense with Base64-like strings that are not encoded payloads - class descriptors, library signatures, resource identifiers. HSS applies a layered filter system to eliminate this noise when the -b flag is used.
Note
Base64 padding (= or ==) is enforced at the regex level and applies across all filter levels including FL0.
Note
If you use -b without providing -fl, an interactive menu launches automatically. You can also pass -fl directly to skip the prompt.
| Level | Name | What It Removes | Noise Reduction |
|---|---|---|---|
0 |
RAW | Nothing. Every matching string passes through. Use for paranoid research or unknown custom APKs. | 0% |
1 |
BASIC | Strings under 20 characters. Strings with no +, =, or / (not valid base64 structure). Strings with 3+ slashes (path-like). Strings starting with # (resource IDs, hex colors). |
~65% |
2 |
FULL (recommended) | Everything FL1 removes, plus 60+ known Android/JVM/third-party library class descriptor prefixes: Android, AndroidX, Dalvik, Java stdlib, Kotlin, Google GMS/Firebase/Material, OkHttp v2+v3, Okio, Retrofit, RxJava 2+3, ReactiveStreams, Glide, Picasso, Coil, Fresco, Dagger, Facebook SDK, Apache, BouncyCastle, Crashlytics, Mixpanel, AppsFlyer, Timber, JetBrains, Dexter, EasyDeviceInfo, Toasty, Klinker SMS, and more. | ~95–97% |
Multi-encoding decode chain (applied after filtering):
When a valid Base64 string passes all filters, HSS attempts to decode it through this chain in order, stopping at the first successful result:
UTF-8 → UTF-16LE → UTF-16BE → Windows-1252 → ISO-8859-1 → KOI8-R → Shift-JIS → EUC-JP → GB18030 → Hex dump
Usage: hunt-sexy-smali -i <path> [flags]
hunt-sexy-smali -reload <All_Smali_path> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
-i |
string | - | Input path of the decompiled APK folder |
-o |
string | HSS_Output |
Output folder for findings and All_Smali/ |
-reload |
string | - | Re-hunt on existing All_Smali/ folder, skips collection |
-h |
bool | false | Hunt HTTP/HTTPS URLs + Firebase/Supabase/DB endpoints |
-ip |
bool | false | Hunt IPv4 addresses with port validation (1–65535) |
-b |
bool | false | Hunt and decode Base64 strings (multi-encoding aware) |
-m |
bool | false | Hunt email addresses (Gmail, Outlook, Proton, Yahoo, custom) |
-fl |
int | interactive | Base64 filter level: 0=raw, 1=basic, 2=full |
|
Note
If no hunting flags (-h, -ip, -b, -m) are provided, HSS defaults to enabling all four modules.
Full scan, all modules, interactive mode selection:
./hunt-sexy-smali -i ./decompiled_apkHunt only network endpoints and IPs:
./hunt-sexy-smali -i ./decompiled_apk -h -ip -o ./findingsHunt Base64 with full library filter (no prompt):
./hunt-sexy-smali -i ./decompiled_apk -b -fl 2Paranoid raw Base64 scan - no filters, everything included:
./hunt-sexy-smali -i ./decompiled_apk -b -fl 0Re-hunt existing All_Smali with email and IP modules:
./hunt-sexy-smali -reload ./HSS_Output/All_Smali -m -ipBatch Mode:
HSS_Output/
├── All_Smali/
│ ├── smali__com__example__MainActivity.smali
│ ├── smali__com__example__network__ApiClient.smali
│ └── smali_classes2__com__evil__Dropper.smali
│
└── HSS_findings_20260428_153045.txt
Stream Mode:
HSS_Output/
└── HSS_findings_20260428_153045.txt
Reload Mode:
HSS_Reload_Output/
└── HSS_findings_20260428_160012.txt
HSS applies filters in layers. FL1 filters run first; FL2 adds the library prefix layer on top.
| Filter | Level | Technique | Targets |
|---|---|---|---|
| Minimum length 20 | FL1 | Length check | Short noise strings |
No +/=// present |
FL1 | Char check | Plain identifiers with no base64 structure |
| Slash density ≥ 3 | FL1 | Count check | File paths disguised as base64 |
# prefix |
FL1 | Prefix check | Android resource IDs and hex color values |
Smali L descriptor + 2+ slashes |
FL2 | Structural | Generic class paths like Lcom/example/Foo |
| 60+ known library prefixes | FL2 | Prefix list | Landroid/, Ljava/, Lkotlin/, Lokhttp3/, Lcom/google/, Lcom/facebook/, etc. |
Array descriptors [B, [I |
FL2 | Prefix check | Dalvik primitive array type signatures |
Terminating ; |
FL2 | Suffix check | Smali class reference terminators |
| Dot-separated lowercase paths | FL2 | Heuristic | Package paths encoded as strings |
GNU Affero General Public License v3.0 - see LICENSE for details.
Built with Go - Stay sexy.
Contact :
github.com/gigachad80 · pookielinuxuser@tutamail.com