Analysis by: Veo Zhang

 THREAT SUBTYPE:

Information Stealer, Premium Service Abuser, Click Fraud

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This backdoor may be unknowingly downloaded by a user while visiting malicious websites.

It uses common file icons to trick a user into thinking that the files are legitimate.

  TECHNICAL DETAILS

File Size: 493,987 bytes
File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 18 Dec 2012

Arrival Details

This backdoor may be unknowingly downloaded by a user while visiting malicious websites.

Installation

This backdoor uses common file icons to trick a user into thinking that the files are legitimate.

It searches for the following folders where it can drop/create files:

  • /sdcard/duplicate.apk

Autostart Technique

This backdoor adds and runs the following services:

  • com.example.smsmessaging.TestService

Backdoor Routine

This backdoor connects to the following URL(s) to send and receive commands from a remote malicious user:

  • http://{BLOCKED}ldierz.com/

NOTES:

This Android malware does the following:

  • Blocks response message from premium phone numbers
  • Grabs target premium phone number and message text from the URL http://{BLOCKED}0ldierz.com/command.php?action=recv
  • Sends SMS to target premium phone number

  SOLUTION

Minimum Scan Engine: 9.300

Step 1

Remove unwanted apps on your Android mobile device

[ Learn More ]

Step 2

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android smartphones and tablets from malicious and Trojanized applications. The App Scanner is free and detects malicious and Trojanized apps as they are downloaded, while SmartSurfing blocks malicious websites using your device's Android browser.

Download and install the Trend Micro Mobile Security App via Google Play.


Did this description help? Tell us how we did.