ANDROIDOS_ENERGY.A

 Analysis by: Weichao Sun

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Via app stores

This malware poses as a security app or battery app. However, it steals email addresses from the user's contact list, which may be used for malicious purposes such as spamming.

To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be manually installed by a user.

It sends the information it gathers to remote sites.

  TECHNICAL DETAILS

File Size:

340,992 bytes

File Type:

APK

Initial Samples Received Date:

28 Sep 2012

Payload:

Steals information, Connects to URLs/IPs

Arrival Details

This Trojan may be manually installed by a user.

Information Theft

This Trojan sends the information it gathers to remote sites.

NOTES:

Upon installation, it appears as a security app or battery app.

Once the app is launched, it displays an image that indicates virus scanning or battery charging.

However, it actually searches for email addresses in the user’s contact list and uploads them to a server located at the following domains:

  • {BLOCKED}ppli.com
  • {BLOCKED}id.com

  SOLUTION

Minimum Scan Engine:

9.300

TMMS Pattern File:

1.329.00

TMMS Pattern Date:

12 Oct 2012

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.