Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa

Kambani yeDoctor Web inowanikwa mukatalogu yepamutemo Android-Mapurogiramu ekudzvanya eTrojan anogona kunyorera vashandisi otomatiki kumasevhisi anobhadharwa. Vanoongorora mavhairasi vakaona shanduko dzakasiyana dzeiyi malware, inonzi Android.Click.322.mavambo, Android.Click.323.mavambo ΠΈ Android.Click.324.mavambo. Kuvanza chinangwa chavo chechokwadi uye zvakare kuderedza mukana wekuonekwa kweTrojan, vanorwisa vakashandisa nzira dzakawanda.

Kutanga, vakagadzira maclickers muzvishandiso zvisina mhosva-makamera uye kuunganidzwa kwemifananidzo-akaita mabasa avakada. Nekuda kweizvozvo, pakanga pasina chikonzero chakajeka chekuti vashandisi nevashandi vekuchengetedza ruzivo vazvione sekutyisidzira.

Chechipiri, ese malware akadzivirirwa neiyo yekutengesa Jiagu package, iyo inoomesa kuona neantivirus uye inoomesa kodhi kuongororwa. Nenzira iyi, iyo Trojan yaive nemukana uri nani wekudzivirira kuoneswa neyakavakwa-mukati chengetedzo yeGoogle Play dhairekitori.

Chechitatu, vanyori vehutachiona vakaedza kuvanza iyo Trojan sezviziviso zvinozivikanwa zvekushambadzira uye zvinyorwa zvekuongorora. Kana yangowedzerwa kumapurogiramu ekutakura, yakavakirwa mumaSDK aripo kubva kuFacebook uye Gadzirisa, ichihwanda pakati pezvikamu zvadzo.

Uye zvakare, iyo clicker yakarwisa vashandisi nekusarudza: haina kuita chero hutsinye kana angave akabatwa anga asiri mugari weimwe yenyika dzinofarira kune vanorwisa.

Pazasi pane mienzaniso yekushandisa ine Trojan yakamisikidzwa mairi:

Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa

Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa

Mushure mekuisa uye kuvhura iyo clicker (pano, shanduko yayo ichashandiswa semuenzaniso Android.Click.322.mavambo) kuedza kuwana zviziviso zvesystem yekushandisa nekuratidza chikumbiro chinotevera:

Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa

Kana mushandisi akabvuma kumupa mvumo inodiwa, iyo Trojan ichakwanisa kuvanza zvese zviziviso nezve inouya SMS uye kubata meseji zvinyorwa.

Tevere, iyo inodzvanya inotamisa data yehunyanzvi nezve mudziyo une hutachiona kune yekudzora server uye inotarisa serial nhamba yeSIM kadhi yemunhu akabatwa. Kana ichienderana neimwe yenyika dzakatariswa, Android.Click.322.mavambo inotumira kune sevha ruzivo nezve nhamba yefoni yakabatana nayo. Panguva imwecheteyo, anodzvanya anoratidza vashandisi kubva kune dzimwe nyika hwindo rekubira pavanenge vavakumbira kuti vaise nhamba kana kupinda muakaundi yavo yeGoogle:

Android- iyo clicker inonyorera vashandisi kune masevhisi anobhadharwa

Kana SIM kadhi yemunhu akabatwa isiri yenyika inofarira kune vanorwisa, iyo Trojan haitore chiito uye inomisa kuita kwayo kwakashata. Iko kutsvagirwa kugadziridzwa kweiyo clicker kurwisa vagari venyika dzinotevera:

  • Austria
  • Italy
  • France
  • Π’Π°ΠΈΠ»Π°Π½Π΄
  • Малайзия
  • Germany
  • Qatar
  • Poland
  • Greece
  • Ireland

Mushure mekutumira ruzivo rwenhamba Android.Click.322.mavambo inomirira mirairo kubva kune manejimendi server. Inotumira mabasa kuTrojan, iyo ine kero dzemawebhusaiti yekurodha uye kodhi muJavaScript fomati. Iyi kodhi inoshandiswa kudzora kudzvanya kuburikidza neJavascriptInterface, kuratidza pop-up mameseji pachishandiso, kudzvanya pamapeji ewebhu, uye zvimwe zviito.

Mushure mekugamuchira kero yesaiti, Android.Click.322.mavambo inoivhura muWebView isingaonekwe, uko iyo yaimbogamuchirwa JavaScript ine paramita yekudzvanya inoiswa zvakare. Mushure mekuvhura webhusaiti ine premium sevhisi, iyo Trojan inongodzvanya pane inodiwa mabhatani uye mabhatani. Tevere, anogamuchira macode ekusimbisa kubva kuSMS uye anozvimiririra anosimbisa kunyoreswa.

Kunyangwe iyo iyo yekudzvanya haina basa rekushanda neSMS uye kuwana mameseji, inodarika ichi chinogumira. Zvinofamba sezvizvi. Iyo Trojan sevhisi inotarisisa zviziviso kubva pachishandiso, iyo nekusarudzika inopihwa kushanda neSMS. Kana meseji yasvika, sevhisi inovanza inoenderana system chiziviso. Inobva yabvisa ruzivo nezve yakagamuchirwa SMS kubva kwairi uye yoendesa kune iyo Trojan nhepfenyuro inogamuchira. Nekuda kweizvozvo, mushandisi haaone chero zviziviso nezve inouya SMS uye haazive zviri kuitika. Anodzidza nezve kunyoresa kushumiro chete kana mari ikatanga kunyangarika kubva kuaccount yake, kana paanoenda kune meseji menyu uye anoona SMS ine chekuita neyekutanga sevhisi.

ПослС обращСния спСциалистов Β«Π”ΠΎΠΊΡ‚ΠΎΡ€ Π’Π΅Π±Β» Π² ΠΊΠΎΡ€ΠΏΠΎΡ€Π°Ρ†ΠΈΡŽ Google ΠΎΠ±Π½Π°Ρ€ΡƒΠΆΠ΅Π½Π½Ρ‹Π΅ врСдоносныС прилоТСния Π±Ρ‹Π»ΠΈ ΡƒΠ΄Π°Π»Π΅Π½Ρ‹ ΠΈΠ· Google Play. ВсС извСстныС ΠΌΠΎΠ΄ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ этого ΠΊΠ»ΠΈΠΊΠ΅Ρ€Π° ΡƒΡΠΏΠ΅ΡˆΠ½ΠΎ Π΄Π΅Ρ‚Π΅ΠΊΡ‚ΠΈΡ€ΡƒΡŽΡ‚ΡΡ ΠΈ ΡƒΠ΄Π°Π»ΡΡŽΡ‚ΡΡ антивирусными ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Π°ΠΌΠΈ Dr.Web для Android ΠΈ ΠΏΠΎΡ‚ΠΎΠΌΡƒ Π½Π΅ ΠΏΡ€Π΅Π΄ΡΡ‚Π°Π²Π»ΡΡŽΡ‚ ΡƒΠ³Ρ€ΠΎΠ·Ρƒ для Π½Π°ΡˆΠΈΡ… ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ.

ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ ΠΎΠ± Android.Click.322.mavambo

Source: www.habr.com

Tenga inovimbika yekutambira kwemasaiti ane DDoS dziviriro, VPS VDS maseva πŸ”₯ Tenga webhusaiti yakavimbika ine dziviriro yeDDoS, maseva eVPS VDS | ProHoster