ANDROIDOS_IDOWNLOADER.A

 Analysis by: Ecular Xu

 THREAT SUBTYPE:

Malicious Downloader

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Via app stores


This malware is found in Google Play on August 8, 2015. It was subsequently removed on September 24, 2015.

It downloads and installs malicious apps from http://s.{BLOCKED}eonline.com/api/s2s/tracks/.

  TECHNICAL DETAILS

Payload:

Connects to URLs/IPs, Downloads files

NOTES:

This malware downloads and installs malicious apps from http://s.{BLOCKED}eonline.com/api/s2s/tracks/. It attempts to establish a rootkit that includes the following privilege escalation exploits to execute any code:

It also uses a watchdog, installing two applications into the folder /system to monitor the removal of one of its components and reinstall the component.

This malware was found in Google Play on August 8, 2015. It was subsequently removed on September 24, 2015.

  SOLUTION

Minimum Scan Engine:

9.750

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:


Did this description help? Tell us how we did.