Analysis by: Yang Yang

 PLATFORM:

Android OS

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Adware

  • Destructiveness: No

  • Encrypted:

  • In the wild: No

  OVERVIEW

This Android malware contains an ad fraud SDK. The creator developed this malware to mimic actual user behavior. It can create bot ad traffic and blend bot traffic with existing human traffic. The traffic mix helps defeat systems built to detect fake traffic because both fake and real traffic almost look exactly the same. This allows this malware to earn additional revenue by the ads being viewed by the bot.

This Adware may be downloaded from app stores/third party app stores.

This is the Trend Micro detection for Android applications bundled with malicious code.

  TECHNICAL DETAILS

File Type: APK
Memory Resident: Yes
Initial Samples Received Date: 30 May 2018

Arrival Details

This Adware may be downloaded from app stores/third party app stores.

Mobile Malware Routine

This is the Trend Micro detection for Android applications bundled with malicious code.

NOTES:

This Android malware contains an ad fraud SDK. The creator developed this malware to mimic actual user behavior. It can create bot ad traffic and blend bot traffic with existing human traffic. The traffic mix helps defeat systems built to detect fake traffic because both fake and real traffic almost look exactly the same. This allows this malware to earn additional revenue by the ads being viewed by the bot.

  SOLUTION

Minimum Scan Engine: 9.850

Step 1

Trend Micro Mobile Security Solution

Trend Micro Mobile Security Personal Edition protects Android and iOS smartphones and tablets from malicious and Trojanized applications. It blocks access to malicious websites, increase device performance, and protects your mobile data. You may download the Trend Micro Mobile Security apps from the following sites:

Step 2

Scan your computer with your Trend Micro product to delete files detected as AndroidOS_FakeBundle.HRXB. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:


Did this description help? Tell us how we did.