V
V
VerstovAS2012-02-29 21:30:56
Malware
VerstovAS, 2012-02-29 21:30:56

Mobile viruses, who sorted it out?

Just a couple of minutes ago, I received an SMS with the following content:
“Subscriber Katya left you a message. Open: 2sms.ru/lov027 »
From the number +7 (968) 711-33-01 Follow

the jar link, who can parse it, please in the comment, which is extremely interesting what it should have done, since I myself did not parse such viruses. If the file is not available - write me, I saved a copy for myself, I'll post it on some file sharing service.

I also want to know if Chot had experience in dealing with such things, if so, share your experience, since the Habr community does not deal with such things, but only analyzes such viruses for fun, but I want to protect the rest.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
A
Alexey, 2012-02-29
@Sterhel

I do not want to seem like a snob (although, xs), but still.
a) It would be very cool to read the help. It can be read even with negative karma.
b) Who can then publish a post!
From the same help you can find out what the ban is for. So, do not count on the queue of people who want to publish a post.
c) Phrases like "Hey, people, I'm new, I can't read the previous questions and use the search, check out the button accordion, I can't post myself - there is no karma" will inevitably lead to a drop in karma.
Threat
And it was really good and useful advice.

E
egorinsk, 2012-03-01
@egorinsk

Author, you are a double. Here's what you can do in a minute:
1) download the archive from the link
2) press Ctrl + PgDn with the total commander (to unpack the zip archive, which jar is).
3) see the following files right at the root:
link.txt:
The message has been deleted by the sender.
sms.txt:
[item number="3652" prefix="8230011"/]
icon.png with iPhone-style MMS icon
text.txt:
To view MMS-Photos, press the "Continue"
button wait.txt:
(contains BOM only in utf-8)
There are several compiled Java classes in the core folder, in c.class we see the lines:
Ljavax/wireless/messaging/Message
javax/wireless/messaging/MessageConnection
javax/wireless/messaging/TextMessage
sms://
Do you still have doubts about what the applet does?

V
Veliant, 2012-02-29
@Veliant

Standard SMS Sender. Sends a short message number

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question