ANDROIDOS_FAKEINST.VTD


 THREAT SUBTYPE:

Information Stealer, Premium Service Abuser

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

File Size:

442,698 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

15 Jan 2013

Payload:

Steals information, Sends messages, Collects system information

NOTES:

This malicious app can be downloaded from third-party app stores. It tries to entice the user into installing the app by offering a fetish video.

The malicious routines of the malware are executed after the home page of the app loads.

The app collects device information such as the phone number and IMEI. It sends these information to the following remote server:

  • http://{BLOCKED}tsms.co.uk/andrpingen/generate_v3.php

It sends a request to the following remote server:

  • http://{BLOCKED}ish.co.uk/?c=

Once the server receives this request, it starts sending SMS to the affected phone. When the phone receives the SMS from the remove server, the app forwards the SMS to the phone number 69080. It then deletes the SMS.

It should be noted that the user never sees the received and forwarded SMS.