{"id":1349,"date":"2023-07-29T06:52:30","date_gmt":"2023-07-29T06:52:30","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1349"},"modified":"2024-04-22T12:50:21","modified_gmt":"2024-04-22T12:50:21","slug":"trojan-android-fakecalls-banker","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/07\/29\/trojan-android-fakecalls-banker\/","title":{"rendered":"Trojan.Android.Fakecalls.Banker"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>Potential Damage<\/strong>: Medium<\/p>\n<p><strong>Prevalence:<\/strong> Medium<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Malware name(s)<\/strong><\/h3>\n<ul>\n<li>Trojan.Android.Fakecalls.Banker<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is a Trojan?<\/h3>\n<p>Trojan is a type of malware that disguises itself as a trusted and legitimate software and behaves totally like a useful and functional software. But once it is executed, it causes a lot of damages to the computer system.<br \/>\nThere are different ways in which trojans could enter the system, some are: Entering through a software downloaded from the Internet, embedding in HTML text, attaching to an email, etc. Unlike viruses and worms, trojans cannot replicate themselves.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Fake call malware family?<\/h3>\n<p>&#8220;fake call&#8221; is a malware family of Trojans. This banking Trojan acts as a banking software. The infecting method of this type of malware is voice phishing (vishing). The process of voice phishing in this malware family is that, the hacker calls the target victims with the fake title of &#8220;banker&#8221; and tries to deceive them. The potential victim is deceived by false and attractive offers of loans with low interest rates. The fake conversation takes place while the phone number belonging to the malware operators is replaced with a real bank number. Therefore, the victim thinks that he had the conversation with a real banker. Once trust is established, the victims are tricked to confirm their credit card information.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>Dangerous permissions request<\/p>\n<p>Request permission to use Accessibility feature<\/p>\n<p>Once the app is installed, despite its successful installation, the app icon is not visible.<\/p>\n<p>The application page is like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1350\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u0639\u06a9\u0634-1.jpg\" alt=\"\" width=\"427\" height=\"727\" \/><\/p>\n<p>First, the user is asked to enable the &#8220;run in background&#8221; option for the application.<br \/>\nThen the user is asked (in Korean) to enable accessibility service in application setting, like this:<br \/>\n(The English equivalent: &#8220;In order to use the app, you must allow to use the normal service&#8221;)<\/p>\n<p>After activating the application, the following page will be displayed.<br \/>\n&#8220;Installation setup is complete&#8221; is written on the green button.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1351\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u0639\u06a9\u0634-2.jpg\" alt=\"\" width=\"397\" height=\"678\" \/><\/p>\n<p>After enabling the accessibility feature of runtime permissions, the user is requested to set the malware as the default calling app.<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>A cursory look at the application code reveals that the important application items,<br \/>\nincluding the names of some methods and strings, have been encoded.<br \/>\nThe m10 method in the sairwpw3.k7ngwog.ra0mef class acts as a decoder, with this method, encoded items are decoded.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1352\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u0639\u06a9\u0633-\u0642\u0628\u0644-\u0627\u0632-\u0645\u0627\u0642\u0628\u0644-\u0622\u062e\u0631.jpg\" alt=\"\" width=\"907\" height=\"244\" \/><\/p>\n<p>By dynamic analysis of this method and observing its inputs and outputs, we reach the following address:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1353\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u0639\u06a9\u0633-\u0645\u0627\u0642\u0628\u0644-\u0622\u062e\u0631.jpg\" alt=\"\" width=\"1247\" height=\"84\" \/><\/p>\n<p>At the above address, there is a file which it&#8217;s name consists of a long string.<br \/>\nThe application generates malware by reading the name of this file and concentrates it with another string and finally with C&amp;C addresses.<\/p>\n<p>SERVER39_sn2c4hg6fprb8.com<br \/>\nSERVER40_sn3isv3hf36ef.com<br \/>\nSERVER41_sn4yitf01o3pk.com<br \/>\nSERVER42_sn5us1iw4h9rv.com<br \/>\nSERVER43_sn1lwm3e04gwf.com<\/p>\n<p>SERVER44_sn6xs1hfa6x2o.com<\/p>\n<p>This malware gets sensitive accesses like list of installed apps, mobile phone operator, serial number, sim card number, contacts, text messages, location, camera, call recordings and call history.<br \/>\nIn addition, by setting itself as the default calling app, it has the ability to answer the call or reject it, delete contacts, text messages and call history. This application makes use of the very sensitive accessibility service to do some of these things.<br \/>\nIn this service, the functionality of dialer application is checked in real time.<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1354\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/\u06a9\u062f-\u06a9\u0627\u0646\u0641\u06cc\u06af-accessibility-service.jpg\" alt=\"\" width=\"1012\" height=\"335\" \/><\/p>\n<h2><\/h2>\n<h3>Malware techniques<\/h3>\n<p>If the application apk file is converted to a zip file, and then unzipped, the application will encounter the next volume required error.<br \/>\nThis means that the malware is manipulated in a way that it is recognized by compression softwares as a multi-part zip file.<br \/>\nOf course, by binary file checks, and making changes in the software signature, the problem of decompressing the software file is solved.<\/p>\n<h2><\/h2>\n<h2>How to deal with and clean the system?<\/h2>\n<p>To ensure that the device is not infected, install Padvish antivirus, keep its database file up-to-date and run an antivirus scan.<\/p>\n<p>&nbsp;<\/p>\n<h3>How to protect your mobile device from infection?<\/h3>\n<ul>\n<li>Make sure you download\/purchase your applications from trusted sources\/app stores and do not download<br \/>\nthem from unknown sources.<\/li>\n<li>When installing mobile applications, pay attention to app permissions.<br \/>\nIf an application asks for irrelevant access permissions, especially the accessibility service permission, be careful in using it.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Potential Damage: Medium Prevalence: Medium &nbsp; Malware name(s) Trojan.Android.Fakecalls.Banker &nbsp; What is a Trojan? Trojan is a type of malware that disguises itself as a trusted and legitimate software and behaves totally like a useful and functional software. But once it is executed, it causes a lot of damages to the computer&hellip;<\/p>\n","protected":false},"author":21,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1349","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1349"}],"version-history":[{"count":10,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1349\/revisions"}],"predecessor-version":[{"id":1548,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1349\/revisions\/1548"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}