This malware uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, it disguises as a mobile web browser Opera Mini. Once the user agreed with the services of the fake browser, it sends SMS messages to premium numbers.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This application disguises itself as the mobile web browser, Opera Mini.
While running, it checks if the mobile phone uses any of the specific service centers.
If it uses any of these, it proceeds to sending SMS to a number encoded in data.res.
It sends the message “424626 357 OX” to specific premium numbers via SMS.
This Trojan may be unknowingly downloaded by a user while visiting malicious websites. It may be manually installed by a user.
It bears the file icons of certain applications to avoid easy detection and consequent removal.
File size: 20,480 bytes
Memory resident: No
Initial samples received date: 28 Sep 2011
Payload: Sends text messages
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting malicious websites.
It may be manually installed by a user.
Installation
This Trojan bears the file icons of the following applications:
NOTES:
This application disguises itself as the mobile web browser, Opera Mini.
While running, it checks if the mobile phone uses any of the following service centers:
- +79202909090
- +79206909090
- +79219909090
- +79222909090
- +79232909090
- +79242000690
- +79262909090
- +79272909090
- +79282000002
- +79289900028
- +89282000002
- +78129600096
- +89282000002
- +78129600096
If it uses one of the above, it proceeds to sending SMS to a number encoded in data.res.
It sends the message “424626 357 OX” to the following premium numbers via SMS:
It affects the following mobile devices that support MIDlets:
- Nokia
- Sony Ericsson
- Samsung
- Motorola
- Siemens
Connect with us on
| | | |