1. /
  2. Security Response/
  3. Android.Fakebok

Android.Fakebok

Risk Level 1: Very Low

Discovered:
February 11, 2014
Updated:
February 11, 2014 4:38:05 PM
Type:
Trojan
Infection Length:
258,476 bytes
Systems Affected:
Android
Android.Fakebok is a Trojan horse for Android devices that sends SMS messages to premium phone numbers.



Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.facebook
APK: facebookx.apk
Version: 1.0


Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
  • Open network connections
  • Send SMS messages
  • Check the phone's current state
  • Access information about networks
  • Write to external storage device

Installation
Once installed, the application will display a blue icon with a white letter "f", mimicking the appearance of the legitimate Facebook icon.


Antivirus Protection Dates

  • Initial Rapid Release version February 11, 2014 revision 009
  • Latest Rapid Release version February 11, 2014 revision 009
  • Initial Daily Certified version February 11, 2014 revision 020
  • Latest Daily Certified version February 11, 2014 revision 020
  • Initial Weekly Certified release date February 12, 2014
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Payload: Sends SMS messages to premium numbers.

Distribution

  • Distribution Level: Low
Writeup By: Mark Anthony Balanza

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver