Alias/esnot-a-virus:Porn-Dialer.SymbOS.Pornidal.a | ||||||||||||
Detection Availability
| ||||||||||||
Visible Symptoms
| ||||||||||||
Detailed AnalysisThis dialer gives access to porn images located on youth6.net. The billing consists in having the phone automatically call a few distant phone numbers, at user's expense.This application has been classified as a dialer because:
The website hxxp://youth6.net contains sexually explicit material. However, this material is not directly available from this URL. Instead, the end-user must install a Symbian OS application, named iPornPlayer. The application runs on Symbian OS 7 and 8. It installs as any legitimate application. After installation, the application's icon is listed on the end-user's phone. The application drops the following files on the phone:
When the end-user opens the iPornPlayer, the application launches a web browser and contacts URLs such as
The website replies with an encoded stream that the dialer decrypts with the encryption algorithm stored in \system\apps\cipher\cipher.enc. As stated in the Terms and Conditions, the dialer charges the end-user for content he/she views by having the application call phone numbers: "Users get immediate unlimited access to the site youth6.net and are billed each month within the subscription period. The access is billed by calls made to an international destination. The application will try to call destinations which is the most inexpensive for the subscriber (based on the subscriber's country of origin), but are not in any matter obligated to do so. You agree to let the application make these calls to pay for the access fee when due according to these billing terms. Total call duration for unlimited access may vary from ten minutes to four hundred minutes per entry, depending on subscribers country of origin and available international destination. Subscriber's final cost of the calls may vary depending on the mobile operator, international rates may apply."The dialer contains a first set of hard-coded phone numbers it calls. This list is then updated whenever the dialer contacts the web server, with a different set each time (depending on provided parameters - see id and mod URLs above). It must be noted that the dialer actually calls phone numbers (including international numbers). It does not send SMS or MMS messages. | ||||||||||||
Recommended ActionRemove the dialer from the phone's application manager to uninstall. |