Thursday, March 15, 2012

Android Opfake aka FakeSMSInstaller

File:  opfake
Sample Credits:   with many thanks to  anonymous, March 12, 2012
Android.Opfake.B Adopts Bot Tactics

Download  - password infected 

  MD5 list

  1. 1) Do not trust Symantec's classification. They don't have a clue how to do exact identification. Use my dexid tool.

    2) Many of these samples contain one and the same thing. The classes.dex files inside the APK packages (this is where the code really is) are identical. Again, my dexid tool would have told you so.

    3) At least one of these isn't an OpFake variant at all. It is a FakeSMSInstaller variant. Again, use my dexid tool.

    4) Many of the sites hosting these malwares use server-site polymorphism, so the variants change almost every day.

  2. Ah, OpFake and FakeSMSInstaller is NOT one and the same thing. They are two different families. It's just that one of these samples belongs to the FakeSMSInstaller family and not to the OpFake family. Just use my dexid tool to list the class names of the samples and you'll see that the two families have very different class structures.