This section walks you through the process of identifying Android malware in forensic images using antivirus scanners, VirusTotal, and YARA rules.
Android malware identification
Android malware identification using antivirus scanners
Using antivirus scanners is a typical way to find known pieces of malware, so it's a recommended first step for picking low-hanging fruit. There are a multitude of antivirus scanners, with many of them having free versions that can be used by mobile forensic examiners to complete such tasks. Most of them are Windows-based, so the first step is to mount a previously created physical image so that it will be accessible to the operating system and antivirus scanner.
As you already know, most...