ANDROIDOS_FAKEINST.VTD
Information Stealer, Premium Service Abuser
Android OS

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
TECHNICAL DETAILS
442,698 bytes
APK
Yes
15 Jan 2013
Steals information, Sends messages, Collects system information
NOTES:
This malicious app can be downloaded from third-party app stores. It tries to entice the user into installing the app by offering a fetish video.
The malicious routines of the malware are executed after the home page of the app loads.
The app collects device information such as the phone number and IMEI. It sends these information to the following remote server:
- http://{BLOCKED}tsms.co.uk/andrpingen/generate_v3.php
It sends a request to the following remote server:
- http://{BLOCKED}ish.co.uk/?c=
Once the server receives this request, it starts sending SMS to the affected phone. When the phone receives the SMS from the remove server, the app forwards the SMS to the phone number 69080. It then deletes the SMS.
It should be noted that the user never sees the received and forwarded SMS.