Analysis by: Veo Zhang

 THREAT SUBTYPE:

Information Stealer

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

Infection Channel: Downloaded from the Internet

This malware is downloaded from a site that mimics Google Play. The app names it uses copy legitimate app names and uses legitimate apps' descriptions to further trick users into downloading and installing the apps.

It steals the user's phone number and contacts. The stolen information are sent to two different URLs.

  TECHNICAL DETAILS

File Size: 41728 bytes
File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 09 Jan 2013
Payload: Connects to URLs/IPs

Arrival Details

This Trojan may be downloaded from the following remote sites:

  • http://{BLOCKED}trctrbcbrd.com/play/ebifriday.php
  • http://{BLOCKED}trctrbcbrd.com/play/saisokujyuuden.php
  • http://{BLOCKED}trctrbcbrd.com/play/check.php
  • http://{BLOCKED}trctrbcbrd.com/play/kantannenga.php
  • http://{BLOCKED}trctrbcbrd.com/play/miracleface.php
  • http://{BLOCKED}trctrbcbrd.com/play/100zettaikisyo.php
  • http://{BLOCKED}trctrbcbrd.com/play/fukubukuro.php
  • http://{BLOCKED}trctrbcbrd.com/play/iPhone_Converter.php
  • http://{BLOCKED}trctrbcbrd.com/play/safe_battery.php
  • http://{BLOCKED}trctrbcbrd.com/play/install/wrehifsdkjs.apk

NOTES:

Once user installs this malware, it displays アプリの初期設定を行っています、しばらくお待ちください.., which is loosely translated as Under default setting of the app. Please kindly wait for a while.. While it fake installs on the phone, it steals information such as the user's phone number and contacts.

The stolen phone number is sent to https://ftukguhilcom.{BLOCKED}t.com/cgi-bin/confirmUserData.php, while the stolen contacts are sent to https://ftukguhilcom.{BLOCKED}t.com/cgi-bin/registerAddressData.php.

  SOLUTION

Minimum Scan Engine: 9.300

Step 1

Remove unwanted apps on your Android mobile device

[ Learn More ]

Step 2

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.