Analysis by: Veo Zhang

 THREAT SUBTYPE:

Information Stealer, Malicious Downloader

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

File Size: 255,952 bytes
File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 30 Oct 2013
Payload: Connects to URLs/IPs, Downloads files

Mobile Malware Routine

Upon installation, it poses as the following application(s):

  • Flash Player

It accesses the following malicious URL(s) to download file(s):

  • http://{BLOCKED}cnew.net/install3_traf.php

NOTES:

When user installs this app, it hides as a background service.

It automatically verifies a user's SMS message by sending and receiving a verify code from these numbers:

  • 5013
  • 5014
  • 1161
  • 1121
  • 7259
  • 7030
  • 1141
  • 1899
  • 7019
  • 7099
  • 3652
  • 3698
  • 7015
  • 5581
  • 7050
  • 3121
  • 5370
  • 4125
  • 4124
  • 6681
  • 1017
  • 1231
  • 3747
  • 1131
  • 1151
  • 9191
  • 0077
  • 1312
  • 5537
  • 5373
  • 1953
  • 8353
  • 7781
  • 7250
  • 4012
  • 3381
  • 4016
  • 4015
  • 4481
  • 1005

  SOLUTION

Minimum Scan Engine: 9.300
TMMS Pattern File: 1.597.00
TMMS Pattern Date: 01 Nov 2013

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.