This Symbian malware can infect mobile devices running Symbian OS. It may be downloaded from certain Web site as the archive file COMMWARRIOR.ZIP, which contains the malware installer COMMWARRIOR.SIS. It propagates via Bluetooth using random file names.
When it arrives, the following message, which warns the user of the possible malicious nature of the file, appears before finally being installed:
Accepting the message allows the malware copy to enter the Inbox:
The following messages then appear, further warning the user of the malicious nature of the file:
Once installed and active, it drops the following files:
These files can then be viewed from the list of applications:
After several delays, it also drops the following components:
This malware attempts to spread via MMS messages. It is the first Symbian malware that attempts to use this propagation routine.
It attempts to create an MMS that contains any of the following details:
Subject: Norton AntiVirus
Message: Released now for mobile, install it!
Message: 3DGame from me. It is FREE !
Message: 3DNow!(tm) mobile emulator for *GAMES*.
Subject: Audio driver
Message: Live3D driver with polyphonic virtual speakers!
Message: *FREE* CheckDisk for SymbianOS released!MobiComm
Subject: Desktop manager
Message: Official Symbian desctop manager.
Subject: Display driver
Message: Real True Color mobile display driver!
Message: New Dr.Web antivirus for Symbian OS. Try it!
Subject: Free SEX!
Message: Free *SEX* software for you!
Subject: Happy Birthday!
Message: Happy Birthday! It is present for you!
Subject: Internet Accelerator
Message: Internet accelerator, SSL security update #7.
Subject: Internet Cracker
Message: It is *EASY* to *CRACK* provider accounts!
Message: MS-DOS emulator for SymbvianOS. Nokia series 60 only. Try it!
Message: Matrix has you. Remove matrix!
Subject: Nokia ringtoner
Message: Nokia RingtoneManager for all models.
Message: PocketPC *REAL* emulator for Symbvian OS! Nokia only.
Subject: Porno images
Message: Porno images collection with nice viewer!
Subject: PowerSave Inspector
Message: Save you battery and *MONEY*!
Subject: Security update #12
Message: Significant security update. See www.symbian.com
Subject: Symbian security update
Message: See security news at www.symbian.com
Subject: SymbianOS update
Message: OS service pack #1 from Symbian inc.
Subject: Virtual SEX
Message: Virtual SEX mobile engine from Russian hackers!
Subject: WWW Cracker
Message: Helps to *CRACK* WWW sites like hotmail.com
It also attempts to attach a copy of its .SIS installer in these MMS messages. A sample MMS message by the malware may look as follows:
This malware affects mobile phones running Symbian OS Series 60, such as the following:
- Nokia 3650, 3600
- Nokia 3660, 3620
- Nokia 6600
- Nokia 6620
- Nokia 7610
- Nokia 7650
- Nokia N-Gage
- Panasonic X700
- Sendo X
- Siemens SX1
This malware contains the following strings in its codes:
Moreover, its code contains the following message:
CommWarrior v1.0 (c) 2005 by e10d0r
CommWarrior is freeware product. You may freely distribute it in it's original unmodified form.
Analysis By: Michael de Leon Lactaotao