Analysis by: Yinfeng Qiu

 THREAT SUBTYPE:

Premium Service Abuser

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Infection Channel: Via app stores

This app pretends to be related to Euro 2012. It listens to messages from Android C2DM server and sends out certain text messages according the C2DM message. C2DM is a message pushing architecture provided by Google. For those developers who want to push messages to app users, they first send the messages to Google's C2DM server, which in turn pushes messages to the user's phone.

This Trojan may be manually installed by a user.

  TECHNICAL DETAILS

File Size: 48296 bytes
Memory Resident: Yes
Payload: Sends SMS to premium service

Arrival Details

This Trojan may be manually installed by a user.

NOTES:

This app pretends to be related to Euro 2012.

Instead, this app listens to messages from Android C2DM server and sends out certain text messages according the C2DM message. C2DM is a message pushing architecture provided by Google. For those developers who want to push messages to app users, they first send the messages to Google's C2DM server, which in turn pushes messages to the user's phone.

Upon installation, the app requires permissions to send and receive text messages.

When the main activity runs, it registers to receive C2DM messages, as shown in the code:

When messages arrive, the app triggers and sends out text messages. The phone numbers are determined based on the country code and SIM card operator code, so that different victim phones using different carrier operators, or in different countries, will send different text messages in order to book premium service:

  SOLUTION

Minimum Scan Engine: 9.200

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.