ANDROIDOS_WORMHOLE.ESA

 Analysis by: Kenny Ye

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Potentially Unwanted Application

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

The application contains the vulnerable Moplus SDK, from Baidu. The SDK has backdoor like routines such as getting location, getting package information, pushing phishing pages, inserting arbitrary contacts, sending fake SMS, uploading local files to remote servers and installing any applications to the Android devices without user's authorization.

  TECHNICAL DETAILS

File Size:

27235485 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

26 Oct 2015

NOTES:

The application contains the vulnerable Moplus SDK, from Baidu. The SDK has backdoor like routines such as getting location, getting package information, pushing phishing pages, inserting arbitrary contacts, sending fake SMS, uploading local files to remote servers and installing any applications to the Android devices without user's authorization.

When a user launches the application, Moplus SDK automatically sets up a local HTTP server on the device in the background. It keeps monitoring the messages that go through the socket. When a messages sent from remote clients arrives, it is parsed and the SDK start executing the corresponding routines based on the command in the message. Since there is no identity authentication in the local HTTP server, which is set up by Moplus SDK, an attack can be triggered not only by an App developer but by anyone. With just one command, an attacker or cybercriminal can remotely control the device. Applications with this SDK exposes the user under high risk.

  SOLUTION

Minimum Scan Engine:

9.800

Step 1

Remove unwanted apps on your Android mobile device

[ Learn More ]

Step 2

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.