Analysis by: Veo Zhang

 THREAT SUBTYPE:

Click Fraud

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  TECHNICAL DETAILS

File Size: 408576 bytes
Memory Resident: Yes
Initial Samples Received Date: 07 Aug 2014
Payload: Encrypts data, Connects to URLs/IPs

NOTES:

This ransomware arrives via a malicious link in porn websites. After a user installs and opens it, it kills all apps except itself and system setting. It then displays a warning informing users that they supposedly violated certain federal laws hence their device is locked. In the background, however, the malware encrypts all data in SDCard and ask for ransom to decrypt their data.

The malware connects to the following remote server:

  • http://{BLOCKED}y-terms.com/admcp/api.php

  SOLUTION

Minimum Scan Engine: 9.700
VSAPI OPR PATTERN File: 1.781.00
VSAPI OPR PATTERN Date: 04 Aug 2014

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.