Summary
BeanBot.A forwards device's data to a remote server and sends out premium-rate SMS messages from the infected device.
Disinfection & Removal
F-Secure's Mobile Security product blocks installation of this program with default settings.
Technical Details
Upon launching, BeanBot.A prompts an 'update' option that would connect to a command and control (C&C) server when clicked on. It then forwards the following information to the server:
- International Mobile Equipment Identity (IMEI) number
- International Mobile Subscriber Identity (IMSI) number
- Phone number
Additionally, BeanBot.A also sends out premium-rate SMS messages from the infected device, leaving the user with a hefty bill charged to his or her account.
BeanBot.A listed as 'BlowUp,' and the permissions it requested upon installation
Submit a sample
Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)
Give And Get Advice
Give advice. Get advice. Share the knowledge on our free discussion forum.
Keep your mobile device protected

F-Secure Mobile Security will keep your mobile device protected on the go and enable you to find it in case you lose it