ANDROIDOS_USARMY.A

 Analysis by: Weichao Sun

 THREAT SUBTYPE:

Click Fraud

 PLATFORM:

AndroidOS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Adware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW


It pretends to be a legitimate game app.

It acquires a Javascript Objection Notation from a site and installs shortcuts on the affected device.

Should the created shortcut be clicked, a download page will open. This malware will also push certain notifications at specific times in order to trick the user into downloading other apps.

This adware may be manually installed by a user.

  TECHNICAL DETAILS

Arrival Details

This adware may be manually installed by a user.

NOTES:

After installation, it pretends to be a game app through the use of a similar-looking icon.

This is the Trend Micro detection for legitimate apps that have been trojanized by cybercriminals. Therefore, the icon used may be different.

The malware connects to certain malicious encrypted URLS in order to get information about which ads to push.

  • http://{BLOCKED}.{BLOCKED}y.in:60456/client.php?action=soft&soft_id=
  • {BLOCKED}.{BLOCKED}g.in:60456

Based on the information received from the server, the malware then creates shortcuts on the home screen.

Should any of the shortcuts be clicked, an app download page will be opened.

Constant notifications are displayed in order to trick the user into downloading more apps.

  SOLUTION

Minimum Scan Engine:

9.200

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.