Android.Opfake.B is a trojan horse from disturbing behavior, seems to have been written with an algorithm that can change shape over time, so to avoid any detection by the antivirus.
The virus hides within four. Apk (at least those are the ones detected by Symantec so far): BatteryOptimizer.apk, icq.apk, OperaMini65.apk, SkypeMobile.apk, of course, no risk for those downloads only from the Market; the (full) name of the package is rather com.load.wap. Basically, installing any applications that contain the trojan, install also the same who, as is customary for all applications, ask for confirmation on the following permits:
Access information about networks
Check the phone's current were
Open network connections
Send and receive SMS messages
Write to external storage devices
Install and delete packages
Read contact data
In the time it is executed, the trojan opens a screen with text in Russian (the question should give birth to already strong suspicions about the quality of the application), after confirmation screen shows a list of installed games and applications software. This can be considered the front of the Trojans, despite the undoubted capabilities relative goodness, does much more than bring the user to easily download applications using a single click.
The previous version (identified with the suffix A) did not raise particular concerns as this variant B, discovered last month, on the basis of permits required during installation might be able to open a backdoor on our real smartphone waiting to receive commands via SMS to automatically start some of the following actions:
Send information on devices such as IMEI and IMSI
Remove any filters and send SMS messages to numbers also pay
Send details of the book
Reconfigure the URL that communicates with the server "evil"
Download files. Apk and install on SD card
Potentially, therefore it is a sufficiently serious threat if it were not for the fact that, unlike similar in desktop environment, this virus can be removed simply by removing the package from the application handler of Android.
Symantec recommends that you install the course of its Norton Mobile Security for effectively removing the threat.
As a matter of "political correctness" we refrain from further reflections on the "we all know what" and we hope that the readers of AW to make their thoughts in the comments section.

Comments :
0 komentar to “Opfake: the first polymorphic malware on Android”
Posting Komentar