SHA1:
- 21b1fa6b0ca35a2a693dbcfa8ac9b42788968595
- 56cb4fe24eae2311a104f3083f5d174a93f52183
A Trojan for Android mobile devices. It can be distributed by other malicious applications.
Once launched, Android.Backdoor.213.origin attempts to acquire root privileges using a number of tools stored in its program package. If Android.Backdoor.213.origin succeeds in gaining elevated privileges, it removes the su and HTMLViewer applications from the system and plants a malicious modification of HTMLViewer containing Android.Backdoor.114.origin into system/app. Moreover, the Trojan places its own versions of su and busybox into system/xbin.
Main features of Android.Backdoor.213.origin are similar to those of Android.Backdoor.114.origin—in particular, the Trojan can send the command and control server information about the infected system and the contents of /system/build.prop, activate the disabled option to install applications from unreliable sources, and send SMS messages to premium numbers.