Offensive Security. Continuous Protection.
Subscribe to get Free Cyber Threat Intellegence by Forenzy to safeguard your Digital assets.
©2024 Forenzy Networks Private Limited. All rights reserved.
We use strictly necessary cookies to run forenzy.net. With your consent we also use analytics (Google Analytics) and marketing cookies to understand traffic and follow up on business enquiries. See our Cookie Policy and Privacy Policy.
Helps us measure pages visited and traffic sources. No advertising profiles.
Relates site visits to campaigns and business enquiries.
SonicSpy Spyware
Android malware SonicSpy has been spotted in wild on the Official Google Play Store. Researchers reported 1000+ apps being hosted by the same Iraqi Developer. It has been aggressively deployed on Play Store since Feb 2017.
Forenzy's Android Incident Response Team has done detailed analysis on "SonicSpy" Android Spyware. The facts and analysis are as per following:
1. Analysis of package “sys.arshad.sys” (One of the App with “SonicSpy” Spyware)
Permissions required by Malicious App “sys.arshad.sys”
2.The developer signature and C&C (Command and Control) URL was observed to arshad93.ddns[dot]net. The port used to spawn the shell was observed to 2222. The attacker seems to be using Dynamic DNS services to constantly change IP of C&C server.
Following analysis shows use of Dynamic DNS services to load C&C instructions
Forenzy Security Team
The Forenzy Security Team publishes research on penetration testing, threat intelligence, CVE analysis, and enterprise cybersecurity best practices.
Recent Posts
Categories
Archives