ANDROIDOS_DIALER.VTD

 Analysis by: Ocean Feng

 THREAT SUBTYPE:

Premium Service Abuser

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW


This Trojan dials a premium-rate number via an affected system's modem. The dialed number depends upon the user's location, which the user is asked to specify during the installation. As a result, the user is billed for unauthorized calls made.

  TECHNICAL DETAILS

File Size:

645997 bytes

Memory Resident:

Yes

Dialer Routine

This Trojan dials a premium-rate number via an affected system's modem. The dialed number depends upon the user's location, which the user is asked to specify during the installation. As a result, the user is billed for unauthorized calls made.

NOTES:

Once this malware is installed, it places its shortcut in the Home Screen without an icon or caption, tricking users into believing that the installation has failed. It may also delete its own shortcut while starting its service.

It has the ability to execute itself automatically upon system startup, removing the need for user intervention.

It periodically calls the following Premium service Number:

  • 803402470

The number above may be changed by a remote server.

The malware prevents manual removal by forcing a redirection back to the Home Screen should the user attempt to open the System Settings section that pretains to application management.

  SOLUTION

Minimum Scan Engine:

9.700

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.