본문 바로가기

Security_News/국내보안소식

서울고속버스터미널 또 다시 파밍 app 유포중

728x90

서울고속버스터미널 또 다시 파밍 app 유포중


파일구조



탈취되는 정보 

android.permission.CHANGE_NETWORK_STATE (change network connectivity)
android.permission.VIBRATE (control vibrator)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
android.permission.WRITE_SETTINGS (modify global system settings)
android.permission.READ_PHONE_STATE (read phone state and identity)
android.permission.SEND_SMS (send SMS messages)
android.permission.WRITE_SMS (edit SMS or MMS)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.PROCESS_OUTGOING_CALLS (intercept outgoing calls)
android.permission.WRITE_CALL_LOG (write (but not read) the user's contacts data.)
android.permission.GET_TASKS (retrieve running applications)
android.permission.CALL_PHONE (directly call phone numbers)
android.permission.CHANGE_WIFI_STATE (change Wi-Fi status)
android.permission.RECEIVE_SMS (receive SMS)
android.permission.READ_CONTACTS (read contact data)
android.permission.MOUNT_UNMOUNT_FILESYSTEMS (mount and unmount file systems)
android.permission.INTERNET (full Internet access)
android.permission.READ_SMS (read SMS or MMS)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
android.permission.READ_CALL_LOG (read the user's call log.)

백신탐지정보

https://www.virustotal.com/ko/file/1638c4ebe54bb764e4b30ee877c1d63229a0f6cedc5a41cb7f05c3a3534b61ef/analysis/


C&C 위치 







수상한 app는 설치하지 말아야 하고, 백신을 최신 업데이트 해서 검사를 실시한다.


728x90