This backdoor application monitors the Short Message System (SMS) messages of an affected Symbian phone and forwards the message if the sender is listed in its monitored list. It interprets a specific list of messages as its backdoor commands.
It sends and receives information from a specific phone number. It sends a list of messages to the said number to notify the remote malicious user of the malware's current status.
This spyware may be dropped by other malware.
File size: 74,632 bytes
File type: PE
Memory resident: Yes
Initial samples received date: 27 Sep 2010
Payload: Steals information, Compromises system security
Arrival Details
This spyware may be dropped by the following malware:
Installation
This spyware creates the following folders:
Dropping Routine
This spyware drops the following files wherein it saves the information it gathers:
- C:\private\20022B8E\NumbersDB.db
- C:\private\20022B8E\settings2.dat
- C:\private\20022B8E\firststart.dat
Other Details
Based on analysis of the codes, it has the following capabilities:
- It monitors the Short Message System (SMS) messages of an affected Symbian phone and forwards the message if the sender is listed in its monitored list.
- It interprets the following messages as its backdoor commands:
- Server ON
- Server OFF
- BLOCK ON
- BLOCK OFF
- SET ADMIN
- ADD SENDER
- ADD SENDER ALL
- REM SENDER
- REM SENDER ALL
- SET SENDER
- It sends and receives information from the following phone number:
- It sends any of the following messages to the said number to notify the remote malicious user of the malware's current status:
- state is On
- state is Off
- monitoring all
- blocking is on
- blocking is off
- App installed ok
- The file C:\private\20022B8E\NumberDB.dat contains the following information:
- tbl_contact
- index
- name
- descr
- pb_cont
- act_id
- tbl_phone_number
- contact_id
- phone_number
- tbl_history
- event_id
- pn_id
- date
- description
- contact_info
- contact_id
Connect with us on
| | | |