| Description | Visible SymptomsThe following files are created:
- %Program Files%\SmartPhone\Smartphone.exe
- %Program Files%\SmartPhone\OpenNETCF.Net.dll
- %Program Files%\SmartPhone\OpenNETCF.dll
- %Program Files%\SmartPhone\hsmsutil.dll
Detailed AnalysisThis is a "commercial" Spyware tool, allowing for remote monitoring of a mobile device.
It must be noted that proper installation practically requires physical access to the targeted device. Indeed, when run the first time, the user is prompted with the login / password pair generated when buying the tool online (Fig. 1).
Upon successful completion of the login step, the user can click Capture to start the monitoring process, then select Hide to put the Spyware tool in "stealth" mode, making it effectively disappear in the background (Fig 2).
Subsequently, all SMS messages, phone calls information, and visited URLs are recorded and the resulting logs uploaded to the following server:
- http://www.{removed}spy.com
With the proper credentials, a remote user can then access the gathered information over the internet.
 Figure 1: Initial Login |
 Figure 2: Control Interface |
|