1. /
  2. Security Response/
  3. Android.Phimdropper


Risk Level 1: Very Low

February 7, 2014
February 10, 2014 11:31:31 AM
Infection Length:
Systems Affected:
Android.Phimdropper is a Trojan horse for Android devices that sends and intercepts incoming SMS messages.

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.vn.thegioididong.phim18
APK: com.vn.thegioididong.phim18_1.0.1.apk
Version: 1.0.1
Name: Phim 18

Once installed, the application will display an icon with an image of a black haired girl with pink lingerie.

Antivirus Protection Dates

  • Initial Rapid Release version February 7, 2014 revision 007
  • Latest Rapid Release version February 7, 2014 revision 007
  • Initial Daily Certified version February 7, 2014 revision 018
  • Latest Daily Certified version February 7, 2014 revision 018
  • Initial Weekly Certified release date February 12, 2014
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy


  • Damage Level: Medium
  • Payload: Sends and intercepts SMS messages.


  • Distribution Level: Low
Note: On May 14, 2015, modifications will be made to the threat write-ups to streamline the content. The Threat Assessment section will no longer be published as this section is no longer relevant to today's threat landscape. The Risk Level will continue to be the main threat risk assessment indicator.
Writeup By: Tommy Dong

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report