Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Tracking Android/Foncy

by RSS Axelle Apvrille  |  June 06, 2012  |  Category: Security Research

Denis Maslennikov reported a new SMS trojan, Android/Mania, which emanates from France. This malware hasn’t any outstanding functionality - it silently sends SMS messages to a short number, something we only see too often in mobile malware - except it happens to clearly originate from France. As our European lab is based in France, we investigated it with particular interest. Thanks Denis for sharing.

What we learned in a few points:

* All samples we got our hands on send 7 SMS messages to the same French short number 84242. This is a “SMS+” short number, and it is legitimately rented to various service providers. The malware sends SMS with the body MANIA, TEL or QUIZ.

* If the infected phone receives a response from 84242 (e.g a notification of service), the malware forwards the incoming SMS to one of 4 French mobile phone numbers. Those 4 phone numbers correspond to prepaid subscriptions and there is strong indication they were bought by the same person.

* Mania is a variant of Foncy: the 4 prepaid mobile phone numbers were used by authors of Android/Foncy.Thus, we detect Mania as Android/Foncy.C!tr.dial.** **

* Intentionally or not, the malware trashes all other incoming SMS messages on the phone. So, if your phone is unable to receive SMS and your subscription goes up, you might be infected with Mania. Check it up!

* The malicious samples include screenshots of a few other apps. Our best guess is that the malware author probably also trojaned those tools, so be extra cautious if you plan on installing an unofficial version of Walk and Text, Mortal Combat 3, The Sims 3 or Parricus. If you believe you have an infected sample, please report to submitvirus (at) fortinet.com.

* The Mania samples we analyzed were very similar among them, and might have been generated by an in-house script. For example, AndroGuard shows that the code of two Android/Mania samples only differ by the message body they send to the short number:

./androdiff.py -i 039.apk D15.apk
Elements:
         IDENTICAL:     6
         SIMILAR:       1
         NEW:           0
         DELETED:       0
         SKIPPED:       0
[ ('Lcom/rvo/plpro/AndroidSecurityActivity;', 'onCreate', '(Landroid/os/Bundle;)V') ]
<-> [ ('Lorg/baole/app/blacklistpro/BlackListProActivity;', 'onCreate', '(Landroid/os/Bundle;)V') ]
onCreate-BB@0x0 onCreate-BB@0x0
Added Elements(1)
        0xa 2 const-string v3 , [ string@ 42 'TEL' ]
Deleted Elements(1)
        0xa 2 const-string v3 , [ string@ 40 'QUIZ' ]

– the Crypto Girl

by RSS Axelle Apvrille  |  June 06, 2012  |  Category: Security Research
Tags: android foncy Malware mania mobile sms
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 7
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

FortiGate mobile phone network security webinar hashdays Research privacy mobile phones microsoft stuxnet reversing Malware exploit symbos/yxes mobile malware derek manky Mobile Security zitmo trojan Cryptography Anti-Spam Anonymous Threat Landscape bredolab botnet virut Windows Zeus google Antivirus BYOD Mac OS X Security iphone sms mobile symbian Firewall adobe facebook hacking challenge android reverse engineering symbianos SpyEye Fortinet conference UTM apple challenge