{"id":937,"date":"2021-09-06T11:32:00","date_gmt":"2021-09-06T11:32:00","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=937"},"modified":"2024-01-21T09:54:00","modified_gmt":"2024-01-21T09:54:00","slug":"trojan-android-smspay-caco333","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2021\/09\/06\/trojan-android-smspay-caco333\/","title":{"rendered":"Trojan.Android.SmsPay.Caco333"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: Trojan<\/p>\n<p><strong>Degree of destruction:<\/strong> average<\/p>\n<p><strong>Prevalence:<\/strong> average<\/p>\n<h3>What is a Trojan?<\/h3>\n<p>Trojans are malware types that introduced themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that Trojans are using to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible.<\/p>\n<h3>What is SmsPay.Caco333 malware family?<\/h3>\n<p>There is a bunch of infected applications on authorized android markets such as Caf\u00e9 Bazaar, Myket, ect, in addition to other websites and unauthorized markets, Telegram channels, or SMSs containing infected links that are made to steal users&#8217; financial accounts and phishing. This malware looks like a useful and legal application but in action, not only it represents no positive services but also it steals users&#8217; data using phishing.<\/p>\n<p>A family of this malware has the \u201cCaco333.ca\u201d package name. The procedure of this kind of malware is that they claim to represent multiple services such as accessing official notices, free internet traffic, ect. In return and on a shoestring, it transfers the user to the fake bank gateway. As soon as the user enters financial account information and clicks on the payment button, all user&#8217;s bank card data will be sent to the attacker&#8217;s server along with receiving the demanded price, thus it steals all banking pieces of information of its victims.<\/p>\n<p>These applications are designed both as an internet gateway and as an application.<\/p>\n<ul>\n<li>Internet gateway<\/li>\n<\/ul>\n<p>The procedure of this malware is that it will send a &#8220;To follow up with the official notice you must refer to the link attached in the text of the SMS&#8221; message. As soon as the user clicks on the link, the displayed contents require the user to pay very little money, and for this matter, the user must enter a mobile number and ID number that will direct the user to the fake gateway.<\/p>\n<p>Users must consider that the sent SMSs from the judiciary contain no links, and it&#8217;s just a method that attackers use to transfer the user to their fake gateway.<\/p>\n<p>A sample of real messages from the judiciary:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-938 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/1.png\" alt=\"\" width=\"448\" height=\"79\" \/><\/p>\n<p>The main link of \u201cfollowing up complaints\u201d from the judiciary is:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-939 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/2.png\" alt=\"\" width=\"566\" height=\"285\" \/><\/p>\n<p>The fake link of \u201cfollowing up complaints\u201d is \u201chxxps[:]\/\/eblagh-app[.]gq&#8221;. Then after the user enters information related to mobile and ID number, the malware will send this information to its infected server. There will be no errors even if you enter the wrong mobile number.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-940 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/3.png\" alt=\"\" width=\"562\" height=\"236\" \/><\/p>\n<h2>Sample of application<\/h2>\n<p>Here we will analyze the fake \u201cEdalat-e-Hamrah\u201d application.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-941 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/4.png\" alt=\"\" width=\"565\" height=\"213\" \/><\/p>\n<h2>Technical Explanation<\/h2>\n<p>This application downloads the displayed pages along with receiving the user&#8217;s data through an online connection with its infected server (hxxps[:]\/\/eblagh-app[.]gq). It uses the &#8220;httputils&#8221; library to connect with its server, and in the end, it collects data with the PostString method in the form of a PHP file and sends them to its infected server.<\/p>\n<h3>Caco333.ca.main the main activity<\/h3>\n<p>The application will fetch two url.txt and Lmain.bal files from the application asset path as soon as it is executed.<\/p>\n<p>url.txt: the file contains \u201chxxp[:]\/\/eblagh-iranian[.]cf\/winston\/pay\/mellat\/index.html\u201d link. Application activities are all web-view-based. Immediately, after launching the application, it receives access permissions such as \u201candroid.permission.READ_SMS\u201d, \u201candroid.permission.RECEIVE_SMS\u201d and \u201candroid.permission.WRITE_SMS\u201d. Then, it shows the user a message that the fee for viewing the official notice is twenty thousand IRR, and the user will immediately refer to the fake gateway of Mellat bank \u201chxxp[:]\/\/eblagh-iranian[.]cf\/winston\/pay\/mellat\/payment.mellat\/index.php\u201d by clicking on \u201cview electronic notice\u201d button. Therefore, the page address which displays to the user inside the activity is &#8220;https:\/\/bpm.shaparak.ir\/pgwchannel\/pay.mellat?RefId=66CF529D55E2BFA1&#8221; which is a set image from the malware server to display inside the activity. The attacker opens the URL inside the webview instead of opening it directly in the browser which is hidden from the sight of the user.<\/p>\n<p>If the user enters bank card information, the malware will transfer this data along with a disposable password received from the bank to its infected server. As such, the user will give the total data of the bank account to the attacker along with paying the demanded fee. An attacker with total access to a user&#8217;s data can easily access any messages if the dynamic password is being sent to the user. In this method, the attacker will seduce the user&#8217;s bank account without notice.<\/p>\n<p>Lmain.bal: the information related to layout, and it&#8217;s the method the existing widgets inside the activity are placed. Then, the following services will be executed:<\/p>\n<h3>Caco333.ca.install_caco333 service<\/h3>\n<p>Immediately after uploading the layout related to the activity, the install_caco333 service will run inside the activity to download and display page information. The malware checks if the application is installed correctly to perform the rest of the destruction activities correctly. It goes to the application install path (data\/data\/caco333.ca\/files) and searches for the \u201c29209 dj20d392j3dk0jirjf0i3jf203\u201d file. If this file exists, the application will proceed, else it creates the \u201c29209dj20d392j3dk0jirjf0i3jf203\u201d file inside the installation path (data\/data\/caco333.ca\/files) with the \u201c29209dj20d392j3dk0jirjf0i3jf203\u201d value.<\/p>\n<p>The malware downloads its desired PHP file, and after that (JobDone), it will then use the GetString function and places all sources inside an \u2018install_caco333._vvvvvvvv4\u2019 string variable. Now by having source codes, the malware can easily use the GetElement function on any value with WebViewExtras. First, it will check the &#8220;open&#8221; string value that collects critical data from the user&#8217;s phone, and it will send this data as a string variable to its server using the postString method.<\/p>\n<p>Firebasemessaging service<\/p>\n<p>This service acts as a connection bridge between the malware and the phone. \u00a0The malware receives notifications from Google firebase by the fm_messagearrived() method and executes the following commands:<\/p>\n<p>If \u201ccmd=clipboard\u201d and \u201ctime=text+android_id&#8221; then it will collect all copied contents into a clipboard and send this information along with the exact time of the phone.<\/p>\n<p>If \u201ccmd=vibrate\u201d then it checks how long the phone will be set on vibrate.<\/p>\n<p>If \u201ccmd=hide&#8221;, and &#8220;time=apk+android_id then the malware icon will be hidden and it will run its services in the background. \u00a0Also, it sends the secretion message of the application icon to the malware server along with the &#8220;android_id&#8221; command which is the user&#8217;s phone specifications.<\/p>\n<p>If \u201ctime=phone\u201d and \u201ccmd=mute\u201d then it will silence the phone (without vibration)<\/p>\n<p>If \u201ctime=phone\u201d and \u201ccmd=vibr\u201d then it will silence the phone (with vibration)<\/p>\n<p>If \u201ccmd=app\u201d and \u201ctime=get\u201d then it will collect a complete list of all installed applications on the user\u2019s phone (-versioncode, -versionname, and \u2013packageName) and will send them to its server.<\/p>\n<p>If \u201ccmd=List&#8221; then it collects the model of the phone, the device signature, and the network operator.<\/p>\n<p>&nbsp;<\/p>\n<p>If \u201ccmd=crash\u201d and \u201ctime=app\u201d then automatically exits the application.<\/p>\n<p>If \u201ccmd=sendmessage\u201d then the attacker can send long SMS (SMS_SEND) and receive its delivery report (SMS_DELIVERED) using PNSMS class and send() method. Also, it can check the status of SMSs for when there\u2019s no possibility to send any messages such as when the phone is in \u201cNo Service\u201d status, \u201cNullPDU\u201d when the text of the message is long, or &#8220;Radio off&#8221; when there is no possibility to send any messages. \u00a0The attacker also can send an SMS to a specific phone number. When the malware receives the &#8220;target address&#8221; command for its server, the attacker can send an SMS to a certain number and receive the report to know whether the message was sent.<\/p>\n<p>Sending long messages along with receiving the sending report is the result of the PNSMS function<\/p>\n<p>Sending short or long SMS<\/p>\n<p>Receiving the error message related to SMS delivery (like airplane mode, losing frequency, lack of enough battery charge, ect.)<\/p>\n<p>Receiving the report of SMS delivery status<\/p>\n<p>Receiving all results independently for each stage related to long SMSs<\/p>\n<p>Sending SMS to a specific number and receiving the delivery status:<\/p>\n<p>True: it will send the \u201csuccess=sms send Now Form&amp;&#8221; message along with the user&#8217;s phone model to the malware server if the SMS is sent correctly.<\/p>\n<p>False: it will send the \u201csuccess=sms cannot send From&amp;\u201d message along with the user\u2019s phone model to the malware server if the SMS failed to be sent.<\/p>\n<h3>Caco333.ca.sms_caco333 service<\/h3>\n<p>According to \u201candroid.provider.Telephony.SMS_RECEIVE\u201d which is defined as \u201csms_caco333$sms_caco333_BR\u201d for the receiver, the malware runs its services and collects the following data related to received SMSs as soon as it receives the SMS:<\/p>\n<p>The contents of receiving SMSs are the sender&#8217;s phone number, the user&#8217;s phone model, the network operator, and phone settings.<\/p>\n<p>In the end, the malware runs the Fullsms_caco333 to gain full access to all sent\/received SMSs in the victim&#8217;s phone.<\/p>\n<h3>Fullsms_caco333 service<\/h3>\n<p>According to the \u201candroid.intent.action.BOOT_COMPLETED\u201d action that is defined as &#8220;fullsms_caco333$fullsms_caco333_BR&#8221; for the receiver, the malware runs its service, collects the following information from sent\/received SMSs, and upload them all as a file in its Telegram Bot as soon as the android OS is boot:<\/p>\n<p>According to the value of \u201canywheresoftware.b4a.phone.SmsWrapper\u201d class:<\/p>\n<p>If \u201cpersonID!= 1&#8243;, then it will completely access the text of the user&#8217;s SMSs instead of &#8220;Sent&#8221; and &#8220;Receive&#8221; strings, creating a list of their information (e.g. the type of the message, the text of the message, phone number, the date of send\/receive) and store them inside the file installation path (data\/data\/caco333.ca\/files) along with the same date as a &#8220;txt&#8221; file extension. It uses the \u201cPNUploadFile&#8221; library to update photos and files inside the host with no limits. \u00a0The attacker will upload its desired text file in addition to other complementary information such as the date, time, phone model, and device ID) in its Telegram Bot using the POST method and &#8220;android\u201d specifications.<\/p>\n<p>Telegram API Bot: it has different methods to exchange information such as:<\/p>\n<p>SendDocument: malware uses this method to send files (gif-zip-pdf) to its Telegram bot that has different parameters such as \u2018chatid\u2019 which sets unique specifications of the user or the username of the desired channel.<\/p>\n<p>getUpdate: a method for updating Telegram Bot. It specifies its Telegram Bot address using \u201cToken\u201d, SendDocument\u201d and \u201cChatid&#8221; methods which have already been written inside &#8220;chatid.txt&#8221; and &#8220;token.txt&#8221; files:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1033 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/5-1.png\" alt=\"\" width=\"534\" height=\"121\" \/><\/p>\n<h2>How to deal with this malware and disinfect the system<\/h2>\n<p>Install and update the\u00a0<a href=\"https:\/\/padvish.com\/en-us\/Main\">Padvish Antivirus<\/a>\u00a0database file, and scan your device to assure your device is not infected by malware.<\/p>\n<p><strong>How to prevent the device from infection:<\/strong><\/p>\n<ol>\n<li>Avoid downloading and installing the application from unauthorized sources and stores<\/li>\n<li>Pay attention to the access permissions when installing an application<\/li>\n<li>Continuously back up files and stored data<\/li>\n<li>Do not use unofficial versions of the application. There are many unofficial versions of applications such as Instagram and Telegram that are distributed through telegram channels.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Trojan Degree of destruction: average Prevalence: average What is a Trojan? Trojans are malware types that introduced themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-937","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/937","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=937"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/937\/revisions"}],"predecessor-version":[{"id":1290,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/937\/revisions\/1290"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=937"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=937"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=937"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}