Trojan:Android/NandroBox.A

Classification

Malware

Trojan

Android

Trojan:Android/NandroBox.A

Summary

NandroBox.A sends out SMS messages to a specific number, and then intercept incoming messages from that number to cover its track.

Removal

Automatic action

Once the scan is complete, the F-Secure security product will ask if you want to uninstall the file, move it to the quarantine or keep it installed on your device.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

When launched, NandroBox.A displays a page that notifies the user of a list of terms and conditions. Once the user has clicked 'Confirm,' it sends out the device's IMEI number and other information to a remote site in XML format.

Screenshots of NandroBox.A

Next, it sends an SMS message to 1065800815747, with content that follows this format: XXX, game_id, version, 0, channel. To cover its track, the malware will intercept all messages from the aforementioned number.

Details for SMS messages that NandroBox.A is instructed to send

Date Created: -

Date Last Modified: -