ANDROIDOS_XBANK.HBT

 Analysis by: Veo Zhang

 THREAT SUBTYPE:

Information Stealer, Click Fraud, Spying Tool

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

File Size:

209236 bytes

File Type:

APK

Memory Resident:

Yes

Initial Samples Received Date:

04 Jun 2014

NOTES:

This family is from a scam campaign named as Emmental. It spoofs many banks including ZKB, CreditSuisse, LUKB, BankAustria, Raiffeisen, and Sparkasse among others. Users are tricked into using this app to generate passwords in the fake banking website for entering the banking session.

When users run it, repeating at every 15 minutes, it tries to access the remote malicious server, http://www.{BLOCKED}ell.ch/cart/3.php or http://edda-mally.at/css/3.phpto get updated server configuration.

If the updated configuration includes DEL command, it uninstalls itself every 1 minute.

It runs in background to monitor all received SMS, and send all SMS to the remote server http://www.{BLOCKED}ell.ch/cart/2.php or http://edda-mally.at/css/2.php which may be updated in above mentioned routine.

  SOLUTION

Minimum Scan Engine:

9.700

TMMS Pattern File:

1.745.00

TMMS Pattern Date:

09 Jun 2014

Trend Micro has released an integrated solution for mobile devices, which provides automatic, real-time scanning to protect wireless devices against malicious code and viruses on the Web or hidden inside files.

For Trend Micro customers: You need to make sure that the Trend Micro Security Solution engine version you are using is 7.460 or later and that your scan pattern is updated the latest version. You may also want to download the latest pattern file for smartphones running on Windows from this site.


Did this description help? Tell us how we did.