1. /
  2. Security Response/
  3. Android.FoncySMS

Android.FoncySMS

Risk Level 1: Very Low

Discovered:
January 15, 2012
Updated:
January 30, 2012 5:55:07 PM
Also Known As:
ANDROIDOS_FONCYSMS.A [Trend]
Type:
Trojan
Infection Length:
17,208,320 bytes
Systems Affected:
Android
Android.FoncySMS is a Trojan horse for Android devices that sends SMS messages to premium-rate phone numbers. It may also connect to an IRC server and execute any received shell commands.

Android package file
The Trojan may arrive as an application package with the following details:

APK: com.android.bot
Version: 1.0
Name: Madden NFL 12

APK: com.android.me
Version: 1.0
Name: Madden NFL 12

Antivirus Protection Dates

  • Initial Rapid Release version January 13, 2012 revision 032
  • Latest Rapid Release version January 13, 2012 revision 038
  • Initial Daily Certified version January 13, 2012 revision 025
  • Latest Daily Certified version January 14, 2012 revision 019
  • Initial Weekly Certified release date January 18, 2012
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low
  • Payload: Sends SMS messages to a premium-rate number.

Distribution

  • Distribution Level: Low
Writeup By: Nino Gutierrez and Masaki Suenaga

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report, Volume 17
Symantec DeepSight Screensaver