Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Android.Spy.4498

Added to the Dr.Web virus database: 2022-01-17

Virus description added:

  • SHA1: a8d8bb0dc846612be7998175bec6d5e893a7cbf6

Description

Android.Spy.4498 is a trojan app for Android-powered devices. Its main functionality is stealing other apps’ notifications contents. It also downloads and asks users to install other apps and can display various dialog boxes.

Known versions of the Android.Spy.4498 are built into some unofficial modifications (mods) of WhatsApp messenger, like GBWhatsApp, OBWhatsApp, WhatsApp Plus, and others. Attackers usually spread these trojanized mods through malicious websites.

#drweb#drweb

#drweb

Operating routine

During its operation, the Android.Spy.4498 requests access to manage notifications and read their contents. This particular version of the trojan is targeting notifications from the following apps:

  • com.sec.android.app.samsungapps—Samsung Galaxy Store (Galaxy Apps);
  • com.android.vending—Google Play Store.

Additionally, this trojan can remotely log the contents of notifications from apps that are on a set list. To do so, it uses various statistics services, like Flurry. With that, the usage of a particular service depends on the malware modification. However, the known Android.Spy.4498 versions do not have such a list.

What’s more, when the host app is used, the trojan covertly downloads an apk file, using an URL received from malicious actors. It then asks the user to install it under the guise of a new version of the app, for which it shows the corresponding dialog box. At the same time, during its launch, Android.Spy.4498 displays another update-related dialog box, where the apk files’ downloading progress is shown.

Moreover, this trojan can display random dialog boxes. The contents in these boxes are also received from the attackers. When the user taps the “Ok” button on this dialog box, a targeted website is loaded in the browser.

Requests to access notifications, functionality to display dialog boxes with custom contents, as well as apk file downloading routine are executed from the modified com.whatsapp.HomeActivity activity of the original WhatsApp application.

Recommandations pour le traitement


Android

  1. Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile le produit antivirus gratuit Dr.Web для Android Light. Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
  2. Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur une violation grave de la loi ou une demande de rançon s’affichent sur l'écran de l'appareil mobile), procédez comme suit :
    • démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
    • puis téléchargez et installez sur votre appareil contaminé le produit antivirus gratuit Dr.Web для Android Light et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
    • Débranchez votre appareil et rebranchez-le.

En savoir plus sur Dr.Web pour Android