ANDROIDOS_FAKEAV.F


 THREAT SUBTYPE:

Premium Service Abuser

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This app pretends to be an antivirus app. It requires the user to install it with administrator privileges, which adds to the difficulty in removal of this app.

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

It bears the file icons of certain applications to avoid easy detection and consequent removal.

  TECHNICAL DETAILS

File Size:

1,574,257 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

24 Mar 2013

Arrival Details

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

Installation

This Trojan bears the file icons of the following applications:

  • Skype

NOTES:

This app pretends to be an antivirus app. It requires the user to install it with administrator privileges, which adds to the difficulty in removal of this app.

Similar to rogue antivirus on desktops, it attempts to perform a fake scan on the device and shows fake results:

When the user clicks on the REMOVE ALL THREATS NOW option, the app requires the user to purchase the full version:

Note that on this screen the home, menu, or back phone options do not work. This traps the user to purchase the app to be able to exit from the program.

When a user opens another app, this malware shows a popup message over the other app. This malware then tags the other app as infected.

When the user clicks Remove button, this app leads the user to the purchase screen. When the user clicks Stay unptotected button, this app leads the user to the phone desktop.