Friday, September 30, 2011

Jimm ICQ SMS-Trojan pushed by malicious QR codes

 Russian internet lanscape is fertile not only for windows malware but also for mobile.
There are plenty of SMS trojan variants lurking on sites offering their 'versions' of popular software. A quick search for phone freeware brought a bunch of java and apk sms senders and questionable apps.
Here is one for example
 I will post all the harvested sms senders in one post after this

Name:                    Jimm ICQ for Android and other phones (jar)
File Name:   

File: jimm.apk
MD5:  37A46AEC9AA86831FAA3DDB6B05A05F8
 File: jimm2s.jar
MD5:  B409DB1963DE4287FEB542377B0FE3A1

Sample Credits:     many thanks to anonymous, Sept 30, 2011
Malicious QR Codes Pushing Android Malware by Denis - Kaspersky Lab

Download  (pass infected)

ile name:
Submission date:2011-09-29 02:40:31 (UTC)
Result:11 /43 (25.6%)   

Antiy-AVL     2011.09.29     Trojan/AndroidOS.Jifake
BitDefender     7.2     2011.09.29     Android.Trojan.Jifake1.B
DrWeb     2011.09.29     Android.SmsSend.26
Emsisoft     2011.09.29     Trojan-SMS!IK
F-Secure     9.0.16440.0     2011.09.29     Android.Trojan.Jifake1.B
GData     22     2011.09.29     Android.Trojan.Jifake1.B
Ikarus     T3.     2011.09.29     Trojan-SMS
Kaspersky     2011.09.28     Trojan-SMS.AndroidOS.Jifake.f
Panda     2011.09.28     Trj/Jifake.A
TrendMicro-HouseCall     9.500.0.1008     2011.09.29     AndroidOS_JIFAKE.E
VBA32     2011.09.28     Trojan-SMS.AndroidOS.Jifake.f
MD5   : 37a46aec9aa86831faa3ddb6b05a05f8
SHA1  : 9440bb3da5e1ad862f357248b5da0c59dc7fc96
Submission date:2011-09-10 07:17:55 (UTC)
Result:11 /44 (25.0%)
Antiy-AVL     2011.09.10     Trojan/J2ME.Jifake
Avast     4.8.1351.0     2011.09.09     Other:Malware-gen
Avast5     5.0.677.0     2011.09.09     Other:Malware-gen
AVG     2011.09.09     Java/SMS.AG
Comodo     10058     2011.09.10     UnclassifiedMalware
DrWeb     2011.09.10     Java.SMSSend.221
Emsisoft     2011.09.10     Trojan-SMS!IK
F-Secure     9.0.16440.0     2011.09.10     Riskware:Java/SmsSend.Gen!A
Kaspersky     2011.09.10     Trojan-SMS.J2ME.Jifake.e
VBA32     2011.09.09     Trojan-SMS.J2ME.Jifake.e
MD5   : b409db1963de4287feb542377b0fe3a1

No comments:

Post a Comment