Alias/esTrojan.WinCE.Terdial.a (KAV) | ||||||||||||
Detection Availability
| ||||||||||||
Visible SymptomsAbnormally high bill due to calling international phone numbers. | ||||||||||||
Detailed AnalysisThis malware affects Windows Mobile 6 Professional devices.It poses as an online game, named Antiterrorist 3D, but silently places calls to international phone numbers (at the victim's expense). Technical DetailsThis Trojan is typically contained in a CAB file named antiterrorist3d.cab. At first, the malware installs an executable named smart32.exe, in the Windows directory, on the Windows Mobile device. Then, it schedules to run that executable in approximately 3 days (+/- 6 hours). Approximately 3 days later, the smart32.exe executable runs and places 6 calls to international phone numbers, waiting for 50 seconds between each sending. Those phone numbers are located in various countries around the world, and some of them are valid in several countries. Cost depends on the victim's operator, but turn out to be quite substantial. The malware then re-schedules to be run in one month (at that time, it will, again, send 6 SMS messages). | ||||||||||||
Recommended Action
|