Football Fans: Download the 2012 Schedule App from Google Play!


Go Back   Android Forums > Android Discussion > Android Lounge

Android Lounge A place for general Android discussion and questions.



Reply
 
LinkBack Thread Tools
Old June 7th, 2011, 10:10 AM   #1 (permalink)
Junior Member
 
Join Date: Jan 2010
Posts: 27
 
Device(s):
Thanks: 8
Thanked 1 Time in 1 Post
Default Another Android Malware Utilizing a Root Exploit

Another Android malware utilizing the root exploit "Rage Against The Cage" has been found, and we detect it as Trojan:Android/DroidKungFu.A. This new malware was embedded on a trojanized application that may require a root access in order to conceal itself. The infection occurs in two parts:

Infection: Part 1

The first part is the installation of a trojanized application that would gain root privilege and install the com.google.ssearch application. This application points to the Trojan:Android/DroidKungFu.A's service component that will start a service com.google.ssearch.Receiver. On the creation of this service, it will call the function getPermission() that will install an embedded APK.





This will call for checkPermission() that will check if com.google.ssearch.apk already exists. If not, it will install the "legacy" file, which is an APK file, to the "system/app" (the application folder).



Infection: Part 2

The second part deals with the main malware component, com.google.ssearch.apk. As we may recall, this component was also present in the trojanized application.

Here is a screenshot showing the com.google.ssearch.apk installed.



The malware appears to have a backdoor functionality. Here are some of its capabilities that we have seen:

• execDelete — execute command to delete a supplied file
• execHomepage — execute a command to open a supplied homepage
• execInstall — download and install a supplied APK
• execOpenUrl — open a supplied URL
• execStartApp — run or start a supplied application package

Trojan:Android/DroidKungFu.A can also obtain the following information and post it to a remote server:

• imei — IMEI number
• ostype — Build version release, e.g., 2.2
• osapi — SDK version
• mobile — users' mobile number
• mobilemodel — Phone model
• netoperator — Network Operator
• nettype — Type of Net Connectivity
• managerid — hard-coded value which is "sp033"
• sdmemory — SD card available memory
• aliamemory — Phone available memory

Root is set to 1 as to signify with root, and these information are then sent to "http://search.gong[...].php."

The malware obtains the commands from "http://search.gong[...].php" by posting in the "imei," "managerid" and root value. It also reports the status of the commands on "http://search.gong[...].php" by posting in "imei," "taskid," "state" and "comment."

Threat Solutions post by — Zimry


Another Android Malware Utilizing a Root Exploit - F-Secure Weblog : News from the Lab

4ndr01d is offline  
Reply With Quote
The Following User Says Thank You to 4ndr01d For This Useful Post:
cds0699 (June 8th, 2011)
Sponsors
Old June 7th, 2011, 11:04 AM   #2 (permalink)
Senior Member
 
A.Nonymous's Avatar
 
Join Date: Jun 2010
Posts: 5,251
 
Device(s): Incredible 2, Kindle Fire, Galaxy Tab 10.1 I/O edition
Thanks: 52
Thanked 773 Times in 552 Posts
Default

I'm kind of a noob when it comes to these things. Is this a threat on non-rooted phones? Does it require a user to install the malicious program in the first place or can it install without user intervention? On rooted phones with the SU app installed, will this malware ask permissions from said app or does it circumvent that?
A.Nonymous is online now  
Last edited by A.Nonymous; June 7th, 2011 at 11:10 AM.
Reply With Quote
Old June 7th, 2011, 11:09 AM   #3 (permalink)
Senior Member
 
AndroidSPCS's Avatar
 
Join Date: Nov 2009
Location: USA
Posts: 3,168
 
Device(s): Evo 3D & 4G, Epic Touch, Epic 4G slide, Captivate. (Moment, LG Optimus S, Vibrant)
Thanks: 483
Thanked 464 Times in 338 Posts
Default

I suspect this is a risk only if you side-loap apps from an unfamiliar source. OP please correct me if I'm wrong.
__________________
Big thanks to lunatic59 for my awesome Android avatars!!
cool Android phone sizing comparison page
Vital Android guide for permissions!
AndroidSPCS is offline  
Reply With Quote
Old June 7th, 2011, 11:38 AM   #4 (permalink)
Subtitles are available!
 
jerofld's Avatar
 
Join Date: May 2011
Location: Over there <points>
Posts: 4,669
 
Device(s): EVO 3D and Acer A500
Thanks: 1,045
Thanked 2,178 Times in 1,459 Posts
jerofld
Default

The last batch of malicious apps were on the Market. They were copies of legit apps with slightly different names. I suspect that the current threat apps are also on the Market.

Just reinforces the safe practices everyone should use when getting apps from the Market. There is a thread on these forums (somewhere...) that lists, in great detail, how to stay safe from malware.
jerofld is offline  
Reply With Quote
Old June 7th, 2011, 11:39 AM   #5 (permalink)
Senior Member
 
wayrad's Avatar
 
Join Date: May 2010
Location: Long Island
Posts: 1,162
 
Device(s): HTC Rezound, NookColor
Thanks: 63
Thanked 145 Times in 119 Posts
Default

Quote:
Originally Posted by 4ndr01d View Post
Another Android malware utilizing the root exploit "Rage Against The Cage" has been found
What is the precise meaning of "found" in this context?

From the following link (caution: hilarious machine translation ahead) it looks like it's not in the Market: http://www.asbigo.com/android/android-droiddream-nightmare-continues/
wayrad is offline  
Last edited by wayrad; June 7th, 2011 at 11:43 AM.
Reply With Quote
Old June 7th, 2011, 11:46 AM   #6 (permalink)
Senior Member
 
AndroidSPCS's Avatar
 
Join Date: Nov 2009
Location: USA
Posts: 3,168
 
Device(s): Evo 3D & 4G, Epic Touch, Epic 4G slide, Captivate. (Moment, LG Optimus S, Vibrant)
Thanks: 483
Thanked 464 Times in 338 Posts
Default

FYI this was fixed by Google in Gingerbread. There is also a patch for pre-Gingerbread phones: [Patch]Malware Exploit for all pre-Gingerbread phones - xda-developers
AndroidSPCS is offline  
Reply With Quote
The Following User Says Thank You to AndroidSPCS For This Useful Post:
ardchoille (June 7th, 2011)
Old June 8th, 2011, 02:21 PM   #7 (permalink)
Junior Member
 
Join Date: Mar 2011
Posts: 28
 
Device(s):
Thanks: 2
Thanked 4 Times in 4 Posts
kwheeler@quest-comm.com
Default

My Lookout found the first batch of Droiddream. I have been running MyLookout since I saw the nifty droid commercial that said it was exclusive to the droid lol. It auto updates its list of infected apps, and other malware, and will scan my hone once a day, and any app that I download. I know a lot of people will say that a virus/spyware/malware program is useless on an android, but I would rather take that extra step. also it has the nifty locate, lock, and sound an alarm feature that alot of cellular insurace companies (mostly Asurion) has been adding for an extra fee, free to us (minus the lock and wipe feature, thats for premium)
Questkev is offline  
Reply With Quote
Old June 8th, 2011, 02:52 PM   #8 (permalink)
Senior Member
 
A.Nonymous's Avatar
 
Join Date: Jun 2010
Posts: 5,251
 
Device(s): Incredible 2, Kindle Fire, Galaxy Tab 10.1 I/O edition
Thanks: 52
Thanked 773 Times in 552 Posts
Default

Lookout is generally worthless and they weren't the first ones to find Droid dream. Anti-virus programs on any mobile platform are basically scareware at this point.
A.Nonymous is online now  
Reply With Quote
Old June 8th, 2011, 03:03 PM   #9 (permalink)
Junior Member
 
Join Date: Mar 2011
Posts: 28
 
Device(s):
Thanks: 2
Thanked 4 Times in 4 Posts
kwheeler@quest-comm.com
Default

I could have sworn every release about the Droid Dream scare a few months ago stated that the malware was brought to the proper attention by MyLookout, after one of thier employees discovered it and posted it on Reddit? I could be confused though...

I would rather have it and not need it, than need it and not have it. usually when you need an antispyware/malware/anti-virus its usually too late. Not to mention, with everybody having access to everything on thier phones now, and the need for a computer has gone down a little bit, whats to stop virus writers from converting from pc to say android or iOS formats?
Questkev is offline  
Reply With Quote
Old June 8th, 2011, 04:04 PM   #10 (permalink)
Senior Member
 
A.Nonymous's Avatar
 
Join Date: Jun 2010
Posts: 5,251
 
Device(s): Incredible 2, Kindle Fire, Galaxy Tab 10.1 I/O edition
Thanks: 52
Thanked 773 Times in 552 Posts
Default

Quote:
Originally Posted by Questkev View Post
I could have sworn every release about the Droid Dream scare a few months ago stated that the malware was brought to the proper attention by MyLookout, after one of thier employees discovered it and posted it on Reddit? I could be confused though...

I would rather have it and not need it, than need it and not have it. usually when you need an antispyware/malware/anti-virus its usually too late. Not to mention, with everybody having access to everything on thier phones now, and the need for a computer has gone down a little bit, whats to stop virus writers from converting from pc to say android or iOS formats?
Nothing TBH, but at the moment, it's not there. There are many reasons why not to have it - is merely a placebo, offers no protection, consumes resources, slows down the phone, etc.....
A.Nonymous is online now  
Reply With Quote
Sponsors
Old February 10th, 2012, 08:28 AM   #11 (permalink)
Member
 
socrates0's Avatar
 
Join Date: May 2011
Location: Mumbai
Posts: 227
 
Device(s): Samsung Galaxy Ace ver 2.3.6
Thanks: 50
Thanked 46 Times in 38 Posts
Default

Android malware gives itself root access

Connection to botnet and premium rate calls are next step
Quote:

A piece of Android malware has been discovered that steals money by giving itself root access then connecting to a botnet to make premium rate texts and calls.
The malware has been named RootSmart by the research team led by Xuxian Jiang, assistant professor of NC State University's department of computer science.
Android malware gives itself root access | News | TechRadar
__________________
BE WHAT YOU ARE AND SAY WHAT YOU FEEL BCOZ
THOSE WHO MIND, DON'T MATTER AND THOSE WHO MATTER, DON'T MIND !! And remember to click on the 'Thanks' if you feel an answer helped you solve your problem so that others can be guided to the right post to solve theirs too.
socrates0 is offline  
Reply With Quote
Old February 10th, 2012, 08:34 AM   #12 (permalink)
Senior Member
 
A.Nonymous's Avatar
 
Join Date: Jun 2010
Posts: 5,251
 
Device(s): Incredible 2, Kindle Fire, Galaxy Tab 10.1 I/O edition
Thanks: 52
Thanked 773 Times in 552 Posts
Default

The only way you can get it is from side loading or from a Chinese marketplace, not the official market.
A.Nonymous is online now  
Reply With Quote
The Following User Says Thank You to A.Nonymous For This Useful Post:
Crashdamage (February 10th, 2012)
Old February 10th, 2012, 08:51 AM   #13 (permalink)
Member
 
socrates0's Avatar
 
Join Date: May 2011
Location: Mumbai
Posts: 227
 
Device(s): Samsung Galaxy Ace ver 2.3.6
Thanks: 50
Thanked 46 Times in 38 Posts
Default

Yes, as of now
socrates0 is offline  
Reply With Quote
Reply

Bookmarks


Go Back   Android Forums > Android Discussion > Android Lounge User CP
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -5. The time now is 02:45 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Custom vBulletin Skins by: Relivo