Alias/esAlbum.A (NetQin) | ||||||||||||
Detection Availability
| ||||||||||||
Visible SymptomsAbnormally high bill | ||||||||||||
Detailed AnalysisSymbOS/Album.A!tr is a malware affecting mobile phones running Symbian OS 9 or greater.This malware silently:
This malware targets users located in China, who may experience heavy bills due to intensive SMS/Internet traffic. The malware does not fully work elsewhere in the world, so end-users located in other countries should only suffer small expenses (due to the initialization SMS and Internet traffic, occuring in any case). Technical DetailsThis malware poses as an MMS Album software managment. Its package, usually named PF_V100_Express_Signed.sis, actually contains 2 other sub-packages: an extended command parser package (ExtendCmdParser) and the alleged MMS Album package. The malware installs the following files on the mobile phone:
The malware silently sends SMS to the following numbers:
The malware ensures those SMS messages are silently sent, i.e no popup asks for end-user's approval and they are not written to the phone's "Sent" message box. The malware also visits a Chinese WAP website, from where end-users may download several ringtones, videos or games (see figure below). ![]() Figure 1. Typical WAP site the malware visits. The malware has the capability to identify incoming commands in SMS messages from the malicious service provider, and act depending on those commands, typically get phone information, download and install software or update. The installation of new software is done silently, without user's approval. This malware has been signed by Symbian Express Signed program. The malware's certificate has been revoked. Enable OCSP checking on your mobile phones to check for revoked certificates. | ||||||||||||
Recommended Action
|