ANDROIDOS_ZDTDOWN.HBT

 Analysis by: Peter Yan

 THREAT SUBTYPE:

Malicious Downloader

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

NOTES:

This Android malware downloads malicious apps without the user's authorization. This routine may result in extra charges to the affected user.

Upon analysis of this Trojanized app, a malicious package named com.zdt.downfile appears to have been inserted into the app itself.

The receivers and services are registered in the .XML file.

Once the Trojanized app is installed in the affected mobile device, it executes its download service. It then connects to a remote website to get a list of malicious apps, which it will also download in the background.

The downloaded malicious routines may then exhibit their routines on the affected device.

  SOLUTION

Minimum Scan Engine:

9.700

Step 1

Remove unwanted apps on your Android mobile device

[ Learn More ]

Step 2

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.