ANDROIDOS_FAKEP.A

 Analysis by: Karl Dominguez

 THREAT SUBTYPE:

Premium Service Abuser

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

It attempts to send text messages to premium numbers 7132 and 4161 that contain specific strings.

As a result, affected users may be charged according to the respective number's rate.

Based on the permissions it requests from users during installation, it is capable of sending text messages.

This Trojan may be unknowingly downloaded by a user while visiting malicious websites. It may be manually installed by a user.

  TECHNICAL DETAILS

File Size:

6,808 bytes

File Type:

DEX

Memory Resident:

Yes

Initial Samples Received Date:

09 Mar 2011

Arrival Details

This Trojan may be unknowingly downloaded by a user while visiting malicious websites.

It may be manually installed by a user.

NOTES:
It attempts to send text messages to premium numbers 7132 and 4161 containing any of the following strings:

  • 846978
  • 845785
  • 844858
  • 846006
As a result, affected users may be charged according to the respective number's rate.

Permissions requested by this malware during installation shows its capability to send text messages:

The icon for this malware is shown in the screenshot below:

  SOLUTION

Minimum Scan Engine:

8.900

TMMS Pattern File:

1.105.00

TMMS Pattern Date:

13 Jun 2011

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.