Analysis by: Veo Zhang

 THREAT SUBTYPE:

Information Stealer, Spying Tool

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

File Size: 206017 bytes
File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 24 May 2013

NOTES:
This malware disguises itself as a bank dynamic token generator, which may fraud bank customers.

It is running another background service that monitors user's incoming SMS.

Every incoming SMS is silently sent to a certain number [+447937946912] to either SMS, and the certain website http://{BLOCKED}ammi.com/cp/server.php.

It also actively silently sendS SMS command from remote website http://{BLOCKED}ammi.com/cp/server.php.

The remote malicious user may then initiate unauthorized transaction without user's consent and may incur financial loss.

  SOLUTION

Minimum Scan Engine: 9.300
TMMS Pattern File: 1.479.00
TMMS Pattern Date: 27 May 2013

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.