ANDROIDOS_SMSPAY.HNTA

 Analysis by: Peter Yan

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes


  TECHNICAL DETAILS

NOTES:

Once installed, this malware executes and sends the user's contact list and sends it to certain malicious sites. Analysis of its code reveals a malicious SDK file named zoo.tiger.sdk inserted into the original non-malicious app:

It sends the stolen information to possibly malicious websites:

  • http://{BLOCKED}.{BLOCKED}m.com/sdk/push
  • http://{BLOCKED}.{BLOCKED}y.net/sdk/push
  • http://{BLOCKED}.{BLOCKED}y.com/sdk/push
  • http://{BLOCKED}.{BLOCKED}m.com/sdk/push
  • http://{BLOCKED}.{BLOCKED}m.com/sdk/push

  SOLUTION

Minimum Scan Engine:

9.700

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.