Home / malwarePDF  

Trojan:AndroidOS/FakeBattScar.A


First posted on 08 November 2011.
Source: SecurityHome

Aliases :

Trojan:AndroidOS/FakeBattScar.A is also known as Fake Android Battery Doctor (other), Andr/BatteryD-A (Sophos), Android.Notifad (Dr.Web).

Explanation :

Trojan:AndroidOS/FakeBattScar.A is a trojan that affects mobile devices running the Android OS operating system. The trojan attempts to gather mobile device data and send it to a remote server for collection by an attacker. The trojan may be distributed as a battery status application for Android devices named "Battery Doctor".
Top

Trojan:AndroidOS/FakeBattScar.A is a trojan that affects mobile devices running the Android OS operating system. The trojan attempts to gather mobile device data and send it to a remote server for collection by an attacker.

Installation
The trojan may be distributed as a battery status application for Android devices named "Battery Doctor". When run, the installation may display a series of graphics such as the following:

Payload
Sends device information to a remote serverThis trojan attempts to collect the following types of device data and sends it to a remote server named "push.mobsqueeze.com" for collection by an attacker:

  • IMEI
  • Phone number
  • Phone ID and model
  • Network operator
  • Application ID
  • API Key


Analysis by Tim Liu

Last update 08 November 2011

 

TOP