Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Sunday, February 20, 2011

Newly Discovered Chinese Virus for Android Sends Private Data via SMS

NetQin Mobile, one of the leading mobile security software providers has just announced that it has recently identified a new virus on Android devices. According to NetQin, the virus known as “MSO.PJApps” is said to be causing private data leaks and to secretly subscribe users to paid services. 

It seems that the virus was repackaged into some of the most popular mobile applications available for download from an application download site in China. 

As soon as the user installs the application containing the virus on his mobile device, “MSO.PJApps” will connect to certain sites and start sending text messages containing the mobile device's IMEI number, as well as other data to designated numbers controlled by a remote server, 

Besides the above mentioned actions, the virus receives commands from the remote server to download and install software without user's permission, which may lead to unintended service subscription charges. 

According to NetQin, “the "MSO.PJApps" virus is injected into legitimate mobile applications and modifies the application entry in Manifest.xml to add certain modules. It is activated in the background with a change in signal and when the relevant program starts automatically.” 

“It encrypts the domain names of the site which is connected to. The virus author disguises the malicious URLs as being encrypted with BASE64, while the URLs are actually encrypted with an algorithm designed by himself,” concluded the Mobile Security Center of NetQin Mobile Inc. 

The mobile software security developer that identified the virus also found a solution to the threat within 12 hours and updated its virus database to ensure that Android device users are protected against the intrusion. 

Even though the virus seems to be limited to Chinese market for the moment, there's no telling if this spreads to other application markets


Sunday, February 20, 2011 by Rishikesh · 0

Saturday, February 5, 2011

"BOHU"-Trojan to Disable Cloud-Based Antivirus

"BOHU"-Trojan to Disable Cloud-Based Antivirus 

A recent blog entry from the Microsoft Malware Protection Center details information about a new malware (called Win32/Bohu.A) which is specifically designed to disable and mislead cloud-based antivirus software. Cloud-based antivirus software differs from traditional antivirus software in that the antivirus client (running on the PC) sends important threat data to a server for backend analysis, and subsequently receives further detection and removal instruction. 

The Bohu Trojan originates in China where there is a predominate use of cloud-based antivirus software. Once a Windows based machine is infected the malware installs different network level filters to disrupt and block the antivirus client accessing the backend antivirus services on the Internet. As well as writing random data at the end of its key payload components to avoid hash-based detection, Bohu also installs a Windows Sockets service provider interface (SPI) filter to block the antivirus network traffic as well as a Network Driver Interface Specification (NDIS) filter. The NDIS filter then stops the antivirus client from uploading data to the server by looking for the server addresses in the data packets.

Saturday, February 5, 2011 by Rishikesh · 0

All Rights Reserved GprsBay | Blogger Template by Bloggermint