ANDROIDOS_XBANK.HBT
Information Stealer, Click Fraud, Spying Tool
Android OS

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
TECHNICAL DETAILS
NOTES:
This family is from a scam campaign named as Emmental. It spoofs many banks including ZKB, CreditSuisse, LUKB, BankAustria, Raiffeisen, and Sparkasse among others. Users are tricked into using this app to generate passwords in the fake banking website for entering the banking session.
When users run it, repeating at every 15 minutes, it tries to access the remote malicious server, http://www.{BLOCKED}ell.ch/cart/3.php or http://edda-mally.at/css/3.phpto get updated server configuration.
If the updated configuration includes DEL command, it uninstalls itself every 1 minute.
It runs in background to monitor all received SMS, and send all SMS to the remote server http://www.{BLOCKED}ell.ch/cart/2.php or http://edda-mally.at/css/2.php which may be updated in above mentioned routine.
SOLUTION
Trend Micro has released an integrated solution for mobile devices, which provides automatic, real-time scanning to protect wireless devices against malicious code and viruses on the Web or hidden inside files.
For Trend Micro customers: You need to make sure that the Trend Micro Security Solution engine version you are using is 7.460 or later and that your scan pattern is updated the latest version. You may also want to download the latest pattern file for smartphones running on Windows from this site.
Did this description help? Tell us how we did.