To extend life cycle of malicious application itself, it uses various techniques.
One of the most prevalent techniques is working on background.
Malicious application which is working on background, tries to send SMS and collects information are increasing.
2. Spreading path and symptoms of infection
Since this malicious application hasn't been spread in Korea, special damage case hasn't been reported so far.
This malicious application can spread via various black markets and 3rd party markets and can require various permissions as following.
* Features on installation and granting permission


* Permission explanations
- android:name="android.permission.SEND_SMS"
- android:name="android.permission.READ_SMS"
- android:name="android.permission.WRITE_SMS"
- android:name="android.permission.RECEIVE_SMS"
- android:name="android.permission.DEVICE_POWER"
- android:name="android.permission.WRITE_APN_SETTINGS"
- android:name="android.permission.ACCESS_NETWORK_STATE"
- android:name="android.permission.BROADCAST_PACKAGE_REMOVED"
- android:name="android.permission.BROADCAST_PACKAGE_ADDED"
- android:name="android.permission.ACCESS_WIFI_STATE"
- android:name="android.permission.CHANGE_WIFI_STATE"
- android:name="android.permission.WAKE_LOCK"
- android:name="android.permission.INTERNET"
- android:name="android.permission.WRITE_EXTERNAL_STORAGE"
- android:name="android.permission.READ_PHONE_STATE"
- android:name="android.permission.KILL_BACKGROUND_PROCESSES
- android:name="android.permission.SEND_SMS"
- android:name="android.permission.READ_SMS"
- android:name="android.permission.WRITE_SMS"
- android:name="android.permission.RECEIVE_SMS"
- android:name="android.permission.DEVICE_POWER"
- android:name="android.permission.WRITE_APN_SETTINGS"
- android:name="android.permission.ACCESS_NETWORK_STATE"
- android:name="android.permission.BROADCAST_PACKAGE_REMOVED"
- android:name="android.permission.BROADCAST_PACKAGE_ADDED"
- android:name="android.permission.ACCESS_WIFI_STATE"
- android:name="android.permission.CHANGE_WIFI_STATE"
- android:name="android.permission.WAKE_LOCK"
- android:name="android.permission.INTERNET"
- android:name="android.permission.WRITE_EXTERNAL_STORAGE"
- android:name="android.permission.READ_PHONE_STATE"
- android:name="android.permission.KILL_BACKGROUND_PROCESSES
Malicious application always asks permissions related system internal information such as "SMS", "PHONE_STATE".
"KILL_BACKGROUND_PROCESSES" is for killing background processes.
Because "LAUNCHER" of Main activity is not defined, this malicious application doesn't have run icon.
This kind of malicious application can be found on "Third-party" on its installation status.
* Malicious behaviors
This malicious application can send SMS for advertisement and can collect contacts, IMSI and so on.
Furthermore, collected information can be leaked to certain external URL. Following code shows collecting IMEI, model name, Android platform and SDK version, and contacts.
Sending SMS function
A. Sends SMS
B. Sends MMS
On certain condition, it can send SMS or MMS.
Furthermore, this malicious application can collect running application list and can terminate running application.
With the code above, we can confirm that this can kill running application.
※ Method "killBackgroundProcesses()" can terminate process version 2.2 or higher, however, method "restartPackage()" can terminate process 2.1 or lower version.
3. How to prevent
To use PC safely from security threats of these malicious files, we recommend following "Security management tips" for general users.
Security management tips
1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.
5. Execute downloaded file after scan with anti-virus SW.
1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.
5. Execute downloaded file after scan with anti-virus SW.
INCA Internet (Security Response Center / Emergency Response Team) provides diagnosis/treatment function with nProtect Anti-Virus/Spyware for detecting such as malicious file stated above and runs responding system against various security threats.
Diagnosis name
- Trojan-SMS/Android.AdSms.F
Talking about useful information, I can recommend info from https://justdomyhomework.com/blog/essay-about-yourself for students. You can use these tips in order to write an essay about yourself.
ReplyDeleteSearching to seek Australian students assignment help services from professionals? Then come at StudentsAssignmentHelp.com and receive top quality academic writing help. Our writers achieve all your academic deadlines and make sure you do not miss out any.
ReplyDeleteWalatra Propolis Brazil Original merupakan sumber nutrisi sempurna dan suplemen yang lengkap dengan potensi tak terbatas, yang mampu memberikan manfaat yang baik untuk kesehatan.
ReplyDeleteGet Australian assignment writing service by top Australian academic writers at My Assignment Help OZ. Our team of qualified academic writers help you to get best academic grades.
ReplyDeleteGet Australian assignment services at no.1 Australian assignment writing provider company My Assignment Help OZ. To know more visit us now!
ReplyDeleteWalatra Propolis Brazil merupakan sumber nutrisi sempurna dan suplemen yang lengkap dengan potensi tak terbatas, yang mampu memberikan manfaat yang baik untuk kesehatan.
ReplyDeleteI really like the contents of your site, this is very meaningful for me. Thanks for sharing an amazing post. tarot card reading love prediction
ReplyDeleteI admire this article for the well researched content. I am very impressed with your work skills. Thanks to share this with us. Also, check: Love Tarot Spread
ReplyDeleteThis is really great,unique and very informitive post, I like it.
ReplyDeletepunch newspaper today
punch newspaper
the nation newspaper
tribune newspaper
the punch
punch newspaper headlines today
punch newspaper
sun newspaper nigeria
vanguard newspaper
punch newspapers
This is a great article, with lots of information in it, These types of articles interest users in your site.
ReplyDeleteQuickBooks technical support phone number helps you with everything regarding QuickBooks software. If you are stuck in some general issues related to QuickBooks like installation error or payroll issues then we are here to help you anytime you want.
This is a great article, with lots of information in it, These types of articles interest users in your site.
ReplyDeleteAfter buying a Hp printer if you are stuck in some steps then contact hp setup to get the quick and easy solution.
That is amazing. i really liked the way you have explained about the virus and malware.
ReplyDeleteit was really great reading about it.
ReplyDeleteThank you so much for sharing this amazing information, please keep sharing...
ReplyDeletePG in Bangalore
PG in Noida sector 62
PG in Laxmi Nagar
PG in Gurgaon
PG for girls in Gurgaon
PG in Indiranagar
PG in sector 15 Noida
Get the best of african music @ wownaija
Deletemp3 music download
fakaza.com
AFRO HOUSE MUSIC
Get the best of african music @ wownaija
HIP HOP
NAIJA MUSIC MIX
SOUTH AFRICA MUSIC
NIGERIA HIT MUSIC
MUSIC
ZAMUSIC
FAKAZA
SONG
https://www.mp3juices.cc/
DeleteFAKAZA MUSIC MP3
ZAMUSIC
SOUTH AFRICAN MUSIC MP3 DOWNLOAD
Amapiano songs download
AFRO HOUSE MUSIC
mp3 music download app
King Monada Di Number ft Dj Tira & Mack Eaze
MP3 DOWNLOAD
ALBUM: DJ Tira – Ikhenani - AFRO HOUSE MUSIC
TNS – S’yatholana Ft. Masandi mp3 download
DJ Stylagang – Uthando Ft. Leezy, G-Snap &
Red Button mp3 song download
download amabhotela uzongithola ematshwaleni mp3
song download
MP3 DOWNLOAD
Kaba De Small & DJ Maphorisa – Nangu Sika
Bopha
Download Tsebe Boy and Tebza Ngwana – R1000
mp3 download
south african pop music
MP3 SONG DOWNLOAD
TNS – Shake It Ft. Mampintsha mp3 download
mp3 music download pro
Download GQOM MIX 05 September 2019- DJ
Twiist umlilo wodwa Vol. 12
OCTOBER 2019 MP3 DOWNLOAD
youtube to mp3 converter download
mp3 songs free download
mp3 music download hunter
mp3 music download free
WOWNAIJA
DeleteGet the best of african music @ wownaija
25th south african music awards
mp3 song download
mp3 music downloader
south african music 2019
Dj Sunco – Koko Matswale mp3 download
SUNCOVISION – KO KO MATSWALE
south africa house music 2019
mp3 songs free download
mp3 music download youtube
Kaba De Small & DJ Maphorisa – Nangu Sika Bopha
AMAPIANO
AFRO HOUSE MUSIC
mp3 music download hunter
mp3 music
MP3 DOWNLOAD
https://www.youtube.com/
download Amabhotela – Uzongithola mp3 song
Ematshwaleni
mp3 music download sites
Really great article, Glad to read the article. It is very informative for us. Thanks for posting.Norton™
ReplyDeleteprovides industry-leading antivirus and security software
for your PC, Mca, and mobile devices Visit @: - McAfee.com/activate | norton.com/setup
Really great article, Glad to read the article. It is very informative for us. Thanks for posting.Norton™
ReplyDeleteprovides industry-leading antivirus and security software
for your PC, Mca, and mobile devices Visit @: - McAfee.com/activate | norton.com/setup
Great Article
ReplyDeleteNetwork Security Projects for CSE
JavaScript Training in Chennai
Project Centers in Chennai
JavaScript Training in Chennai
Gemini Support Number, We have 24 hour client support teams to be had solving your problems against crypto exchange, Blockchain, BTC Support, Binance support. We have a tendency to solve your problems.
ReplyDeleteIt's a very nice article, thanking for sharing this helpful article with us.
ReplyDeletemcafee.com/activate | norton.com/setup
http://www.deluxedubaiescorts.com/
ReplyDeletehttp://www.pakistani-escorts.com/
http://www.pakistaniescorts.biz/
http://www.escortsdubai.club/
Thank you for posting this article, it was really helpfull. Great Article.
ReplyDeletehttp://bit.ly/2MaLzHA
The ultimate goal of online sociology research paper writing services is to provide Sociology Assignment Writing Services and sociology essay writing services since most sociology term paper writing service students lack time to complete their custom sociology coursework writing services.
ReplyDeleteGreat article! We will be linking to this great article on our website. Keep up the good writing.
ReplyDeleteدانلود سریال قورباغه دانلود سریال قورباغه دانلود سریال قورباغه دانلود سریال قورباغه
Wales publications are well-known publishing solution providers in various disciplines in the UK, Wales Publications serving to scientific organizations worldwide. Contact us for further information and know our best services and deals to achieve your goal.The fast submission process includes rapid publication research in UK that includes unique rapid process, inhouse peer review and 100% acceptance guarantee.
ReplyDeleteThank you for sharing, I think you can check out some new songs at:
ReplyDeletehttps://openuserjs.org/users/Binlade95