ANDROIDOS_RISKAPP.A
Android OS

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be downloaded from app stores/third party app stores.
TECHNICAL DETAILS
Arrival Details
This Trojan may be downloaded from app stores/third party app stores.
NOTES:
Once executed, this malicious app checks the phone. If the device is rooted, it will ask for root permission.
The routines below will be triggered when the app gets root permission:
- Delete files (even system files)
- Change files permission
- Copy files to system folder and disguise them as system files
- Kill other apps
- Create daemon services
All the command strings, file names, service names are encrypted in its code:
Figure 1. Encrypted code
Figure 2. Decrypted strings
SOLUTION
Scan your computer with your Trend Micro product to delete files detected as ANDROIDOS_RISKAPP.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.