본문 바로가기

Security_News/국내보안소식

투**로 사이트 모바일 뱅킹 탈취용 악성코드 유포중 주의 당부

728x90

현재 모**로 여행사이트에서 모바일 뱅킹 탈취 목적 악성코드가 유포중에 있습니다.

설치하시지 않게 주의를 당부드립니다.

Risk summary
 The studied DEX file makes use of API reflection
 The studied DEX file loads a shared library
 The studied DEX file makes use of cryptographic functions
 The APK package studied contains shared ELF libraries
 The APK package studied contains other APK packages
 Permissions that allow the application to manipulate SMS
 Permissions that allow the application to perform payments
 Permissions that allow the application to access Internet
 Permissions that allow the application to access private information
 Other permissions that could be considered as dangerous in certain scenarios
Required permissions
android.permission.INTERNET (full Internet access)
android.permission.WRITE_CONTACTS (write contact data)
android.permission.SEND_SMS (send SMS messages)
android.permission.UPDATE_APP_OPS_STATS (Unknown permission from android reference)
android.permission.WRITE_SMS (edit SMS or MMS)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.WRITE_CALL_LOG (write (but not read) the user's contacts data.)
android.permission.GET_TASKS (retrieve running applications)
android.permission.READ_CALL_LOG (read the user's call log.)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
android.permission.CALL_PHONE (directly call phone numbers)
android.permission.WRITE_SETTINGS (modify global system settings)
android.permission.READ_PHONE_STATE (read phone state and identity)
android.permission.READ_SMS (read SMS or MMS)
android.permission.VIBRATE (control vibrator)
android.permission.SYSTEM_ALERT_WINDOW (display system-level alerts)
android.permission.KILL_BACKGROUND_PROCESSES (kill background processes)
android.permission.ACCESS_WIFI_STATE (view Wi-Fi status)
android.permission.WAKE_LOCK (prevent phone from sleeping)
android.permission.RECEIVE_SMS (receive SMS)
android.permission.READ_CONTACTS (read contact data)
Main Activity
com.qwe.MainAct
 Activities
com.qwe.MainAct
com.qwe.Bridg
com.qwe.Act
com.qwe.C_LLLP
com.qwe.SB_CCC
com.qwe.Secu
com.qwe.TakePhot
com.qwe.F
Services
com.qwe.service.AutBan
com.qwe.service.SMM
com.qwe.service.Inte
com.qwe.service.InLitt
com.qwe.service.UploadServ
com.qwe.service.Hear
 Receivers
com.a.MyAdminReceiver
com.a.Boo
com.a.A114

주요백신 탐지정보 


다운받아서 분석을 해보니 구글 플레이 스토어 사칭을 합니다.






절대 출처가 불문명한 apk는 설치하지 마세요 


728x90