ANDROIDOS_MAILSTEALER.A

 Analysis by: Bob Pan

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Downloaded from the Internet

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

  TECHNICAL DETAILS

File Size:

541123 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

20 Mar 2013

Payload:

Steals information

Arrival Details

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

Infection Points

This Trojan arrives as a file downloaded from the following URLs:

  • http://{BLOCKED}9.com/icamera/?code=c28

NOTES:
Upon installation, the malware adds a shortcut on the affected device's home page:

Clicking on the icon displays the following loading screen. The message is translated as "Identifying client information...":

It steals the contact list of the affected device and saves it as /sdcard/adresscap/list.png.

It sends the saved file to a possibly malicious URL:

  • http://{BLOCKED}2.com/data/main.php

It also attempts to send SMS messages to each contact if their number starts with the numbers 090 or 080.

  SOLUTION

Minimum Scan Engine:

9.300

VSAPI OPR PATTERN File:

1.435.00

VSAPI OPR PATTERN Date:

22 Mar 2013

Step 1

Scan your computer with your Trend Micro product to delete files detected as ANDROIDOS_MAILSTEALER.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.