ANDROIDOS_LOTOOR.G
Rooting Tool, Hacking/Cracking Tool
Android OS

Threat Type: Others
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This malware checks if the main executable is executed by root and the file name is "boomsh". If so, it then takes ownership and sets the permission (Read only, Execute Only, Full) to /data/local/tmp/sh. It then copies itself to /data/local/tmp/boomsh and the system shell's binary, from /system/bin/sh to /data/local/tmp/sh.
It obtains certain operating system information.
This malware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
47,016 bytes
Other
No
03 Aug 2011
Steals information
Arrival Details
This malware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
More information on this vulnerability can be found below:
NOTES:
This malware checks if the main executable is executed by root and the file name is "boomsh". If so, it then takes ownership and sets the permission (Read only, Execute Only, Full) to /data/local/tmp/sh. It then copies itself to /data/local/tmp/boomsh and the system shell's binary, from /system/bin/sh to /data/local/tmp/sh.
It obtains the following operating system information:
- Build ID
- Build Version Release
It opens /proc/net/netlink and scans it to find /system/bin/void. It opens the file /system/bin/vold and locates the .GOT addresses range in it, which is used for the exploit.
It checks what type of device is used and calculate the correct index value for mPartMinors array.
It then attempts to exploit the addresses within the .GOT range and uses a NetLink socket to send the malicious message that contains the exploit allowing users to gain root privileges and triggers memory corruption.
SOLUTION
8.900
1.125.00
14 Aug 2011
Step 1
Trend Micro Mobile Security Solution
Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.
Download and install the Trend Micro Mobile Security App via Google Play.
Step 2
Remove unwanted apps on your Android mobile device
Did this description help? Tell us how we did.