Home / malwarePDF  

Android.Scartibro


First posted on 09 August 2014.
Source: Symantec

Aliases :

There are no other names known for Android.Scartibro.

Explanation :

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.android.locker
Name: Norton Internet Security

Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
Prevent processor from sleeping or screen from dimmingGet information about the currently or recently running tasksCall killBackgroundProcesses(String)Allow applications to disable the keyguardStart once the device has finished bootingOpen network connectionsWrite to external storage devicesCheck the phone's current stateAccess information about networks
Installation
Once installed, the application will display an icon with the text of "Norton Internet Security" below a yellow circle with a black check mark inside of it, attempting to mimic the appearance of the Norton logo.



Functionality
When the Trojan is executed it simulates an antivirus scan, locks the phone, and demands a fee to unlock it.

Last update 09 August 2014

 

TOP