Re: trojan.android.agent.ddovzd outbreak from Chinese fake pokemon game https://forum.avast.com/index.php?topic=155727.0
That thread now contain useless data since the game mentioned has been updated. (If possible, please remove this thread due to the fake data.)
Here is the detection of the new version (type of trojan has been changed), plus a few new game that is malicious. Due to the fact that I saw some of these in Play Store (Hong Kong region), I will show game that are detected by avast as well just to notify others to beware of this.
There is actually more simular apps that is not list here.
PS: Notice how NANO-antivirus give the same detection of “Trojan.Android.Fakengry.dkmmvp” and some other detection remain the same inbetween the different games. May be there is the same thing used by developer that is actually malware and avast need to add a few more “Android:Smsreg-BLC [PUP]”.
Oh boy! This is on google play again!! Does avast detect this??
Sample 1:
URL: htxp://a.4399.cn/game-id-41755.html
Game name: 去吧皮卡丘(全民宝贝) [Not official translation: go pikachu (everbody pokemon)]
Virus type: Trojan.Android.Fakengry.dkmmvp / Android:Smsreg-BLC [PUP]
VT: https://www.virustotal.com/en/file/fdabff2f954b4b269e381232c740ab64ac2697ebe40f18f671f3218588195d07/analysis/
Bad history of the game (older version): https://www.virustotal.com/en/file/793d604b737cebc3dc34c632590450ebd2f7ba198656f8446567dc19eed4330c/analysis/
How many times does it get onto the play market then removed a few week later ???
Unfortunately, I saw the same app in HK region play market using my phone 4 weeks ago from the new hot game section.
There is also a link to the google play market page in the above site
See: https://play.google.com/store/apps/details?id=com.dkgame.gplay.petwarstw
name changed to 寵物戰記 and the company changed from dkgame to guanmodi not long ago!! Some one has already ask how many time do they want to change the name of the game. You can see that they have put the game in a lot of time.
I find some copy of the same game from baidu which, for some unknown reason, is undetected by most antivirus. I don’t know if trojan is added by 4399.cn, 9669.com, and other site when they put the game in, or there is actually trojan from the original game file.
Intentionally seperate this post with the last post
Just not long ago, find one more app that avast does not show detection on virustotal
URL: htxp://www.vipcn.com/shoujiyouxi/celueqipai/192056.html (DO NOT GO TO THIS SITE! THERE IS MALICIOUS ADS REFER TO hxxp://pic.9ht.com/up/2015-2/201521414333.png)
Game name: 哈喽皮卡丘 (Not officially translated: hello pikachu)
virus type: unknown
VT: https://www.virustotal.com/en/file/aa0852eb6a6a461978c42a6159aa1730ebeec114c9c4dfb3e5c4533f550e039d/analysis/1425120282/
Popup by avast: android:lgexin-AJ [PUP] on computer
developer please look at the following, possible bug report
Here shown a glitch in avast mobile security. I find this by scanning known android malware in www.virscan.org
I suspected that the above app is only detected on computer only, not on phone.
When scan apk file in Virustotal, they show result that is from avast mobile security. However in www.virscan.org, they use the computer one regardless the type of the file (They lies that most of the sample is clean when there is a lot of antivirus in VT have a detection).
VT showed avast detected one of my sample (a card game file) as android:lgexin-AJ [PUP] but not this one eventhough avast popup up suggesting that the file may not be detected on phone.
thanks for shared information. I create a detection for one sample which will be released after our tests but can I ask you for some samples? Because unfortunately we are missing these samples in our DB and I am not able to download these samples from original sites.
aa0852eb6a6a461978c42a6159aa1730ebeec114c9c4dfb3e5c4533f550e039d
6169c36f68f96169cd3bcab977883523b253cae00e60e01e55913a12930f9c4e
Good to known that it is detected.
These file may be too large to send via email as this is online game files. Fortunately, there are direct download links for these (2 for each, change “htxp” to “http”):
aa0852eb6a6a461978c42a6159aa1730ebeec114c9c4dfb3e5c4533f550e039d
htxp://d1.vipcn.org/v7/jhd/haloupikaqiu.apk
htxp://d2.vipcn.org/v7/jhd/haloupikaqiu.apk
Well, it has been more than 1 month and I have found more of these “smsreg” app.
These are from htxp://a.4399.cn (I am correct reporting this android app market to avast, there will only be more android mlaware on this site!!)
avast does not detect
Download URL: htxp://sj.img4399.com/game_list/8/com.funnyhux.myguardian.m4399/myguardian.m4399.v70014.apk
game name: GBA口袋妖怪
VirusTotal result: https://www.virustotal.com/en/file/a902b186ff28495901af39130d2efeefc063f234c3aee71a5262e381521bcd25/analysis/1430018873/
All are smsreg detection here too
By the way, when I see the second one, I really laughed at the “GBA” part in the name. They even reference Nintendo’s game console directly as a name of a malicious app. I wonder why Nintendo does not take action on these games yet.