Dissection Of Android Malware MouaBad.P
ID: f29403a2-c50e-5081-b876-7e2ef440875d
STIX ID: report--f29403a2-c50e-5081-b876-7e2ef440875d
Feed Name: Zscaler Security Research Blog
This report analyzes an Android malware sample (package com.android.service, version 1.00.11) that silently installs without a launcher icon, harvests device identifiers (IMEI and SIM information), monitors screen/keyguard state, and abuses telephony permissions to send premium-rate SMS and initiate calls to attacker-controlled numbers (hardcoded list in China) to generate fraudulent revenue; the static findings include permissions, services, receivers, and evidence of possible C2 URL assembly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
