FireEye new malware comes as Google Play

Security researchers from FireEye have discovered a new threat for Android devices. This time he comes as his clone Play.

FireEye researchers Jinjian Zhai and Jimmy Su analyzed the behavior of the malware and determined that the attacker uses a dynamic DNS server with Gmail's SSL protocol to collect the data sent by the application.

activate FireEye

Μόλις η ψεύτικο εφαρμογή αρχίσει να τρέχει, (ονομάζεται “googl app stoy,” ζητάει δικαιώματα διαχειριστή και, αντί να ανοίξει ένα παράθυρο του UI, παρουσιάζει λάθους και ενημερώνει το χρήστη ότι η googl app stoy έχει διαγραφεί και η δραστηριότητα της έχει σταματήσει.

desktop1

After a closer examination, the researchers noticed that it only deletes the application icon, but the application itself continues to work in the background and is starting to use a range of five services. It has access to the list of apps running on the device and can not be removed or uninstalled.

setting-download

This is particularly important because victims need to run it only once to activate and begin to eliminate traces of suspicious activity they carry out. This is almost invisible, since the actual Google Play icon is still in place.

The malware appears to hide the malware with and . Οι ερευνητές της FireEye κατάφεραν να το αποκρυπτογραφήσουν και κατέληξαν στο συμπέρασμα ότι τα στοιχεία που αποστέλλονται στους εγκληματίες του κυβερνοχώρου είναι σύντομα μηνύματα κειμένου, τις ψηφιακές υπογραφές των πιστοποιητικών, και τους κωδικούς πρόσβασης τραπεζικών λογαριασμών.

The two researchers could confirm that the digital signatures and other sensitive data were sent to the website "dhfjhewjhsldie.xicp.net."

They also found the SMS transmission data replacing a cached file on the phone with one that contained their own Gmail address.

An important research information is that only three scan engines from VirusTotal detected the sample as malicious.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).