ANDROIDOS_CODE4HK.A


 THREAT SUBTYPE:

Information Stealer, Malicious Downloader, Spying Tool

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

211266 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

30 Sep 2014

Payload:

Steals information

NOTES:

This malware is distributed via social networking sites that leveraged the Umbrella Revolution protesters in Hong Kong.

When users unknowingly install and open it, the malware is hidden from the launcher. However, it is running in background and boots at startup.

It connects to remote C&C server,{BLOCKED}m.v1lady.com, located in China.

It tracks user location with accurate GPS coordinates to /data/data/com.v1/gps.txt.

It receives commands to immediately take control of the infected device and to upload contacts, text messages, call logs, location, read or write file, display messages, make phone call, open rooted shell backdoor, record voice, steal emails and browser history, record user outgoing/incoming call and phone number.

  SOLUTION

Minimum Scan Engine:

9.700

TMMS Pattern File:

1.819.00

TMMS Pattern Date:

09 Oct 2014

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.