ANDROIDOS_EWALLS.A

 Analysis by: Karl Dominguez

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This malware gathers sensitive information about the affected phone and sends the stolen data to a malicious URL.

This spyware may be unknowingly downloaded by a user while visiting malicious websites. It may be manually installed by a user.

  TECHNICAL DETAILS

File Size:

99,472 bytes

Memory Resident:

Yes

Initial Samples Received Date:

18 Mar 2011

Payload:

Collects phone information

Arrival Details

This spyware may be unknowingly downloaded by a user while visiting malicious websites.

It may be manually installed by a user.

NOTES:
This wallpaper application gathers the following information about the affected device:

  • Device id
  • Device software version
  • Build board
  • Build brand
  • Build device
  • Build display
  • Build fingerprint
  • Build model
  • Build product
  • Build tags
  • Build time
  • Build user
  • Build type
  • Build id
  • Build host
  • Build version release
  • Build version sdk int
  • Build version incremental
  • Density
  • Height pixels
  • Scaled density
  • Width pixels
  • Xdpi
  • Ydpi
  • Line1 number
  • Network country iso
  • Network operator
  • Network operator name
  • Network type
  • Phone type
  • Sim country iso
  • Sim operator
  • Sim operator name
  • Sim serial number
  • Sim state
  • Subscriber id
  • Voice mail number
  • Imsi mcc
  • Imsi mnc
  • Total memory
It sends the said information to the following website:
  • http://www.{BLOCKED}t.us

  SOLUTION

Minimum Scan Engine:

8.900

TMMS Pattern File:

1.105.00

TMMS Pattern Date:

13 Jun 2011

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.

Step 2

Remove unwanted apps on your Android mobile device

[ Learn More ]

Did this description help? Tell us how we did.