{"id":88713,"date":"2020-03-20T20:17:55","date_gmt":"2020-03-20T14:47:55","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=88713"},"modified":"2020-03-30T17:51:00","modified_gmt":"2020-03-30T12:21:00","slug":"fake-coronavirus-tracking-app","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/fake-coronavirus-tracking-app\/","title":{"rendered":"Fake Coronavirus\u00a0tracking app exploiting our fear and vulnerable social situation"},"content":{"rendered":"<p><span class=\"TextRun SCXW98564654 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW98564654 BCX0\">As the Coronavirus spreads across countries creating fear across the globe, everybody wants to stay on top of any information related to it wanting to remain safe and away from infected people. Malware authors are also taking advantage of this situation. Previously on the Android\u00a0<\/span><span class=\"SpellingError SCXW98564654 BCX0\">Playstore<\/span><span class=\"NormalTextRun SCXW98564654 BCX0\">, there were\u00a0<\/span><span class=\"ContextualSpellingAndGrammarError SCXW98564654 BCX0\">many\u00a0 applications<\/span><span class=\"NormalTextRun SCXW98564654 BCX0\">\u00a0present which claimed that they could provide Coronavirus tracking information. But Google has set up some rules for these types of applications and have considered these under the \u2018Sensitive events\u2019 category. According to policies from this rule, Google proactively removed many applications from\u00a0<\/span><span class=\"SpellingError SCXW98564654 BCX0\">Playstore<\/span><span class=\"NormalTextRun SCXW98564654 BCX0\">\u00a0to stop malware authors to take advantage of this situation.<\/span><\/span><\/p>\n<p style=\"text-align: left\">\u00a0 \u00a0 \u00a0 \u00a0\u00a0<span class=\"TextRun SCXW194833715 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW194833715 BCX0\">But malware authors have used another way to\u00a0<\/span><span class=\"AdvancedProofingIssue SCXW194833715 BCX0\">enter into<\/span><span class=\"NormalTextRun SCXW194833715 BCX0\">\u00a0the user\u2019s phone. They are using their sites to\u00a0<\/span><span class=\"ContextualSpellingAndGrammarError SCXW194833715 BCX0\">publish\u00a0 malicious<\/span><span class=\"NormalTextRun SCXW194833715 BCX0\">\u00a0apps developed by hackers themselves. There is a website named \u2018<\/span><span class=\"SpellingError SCXW194833715 BCX0\">coronavirusapp<\/span><span class=\"NormalTextRun SCXW194833715 BCX0\">[.]site\u2019 \u2014on this website, an Android application is hosted which claims to get real-time info about Coronavirus patients. The application claims that it will give notification to the user if a Coronavirus patient is present in the vicinity.<\/span><\/span><span class=\"EOP SCXW194833715 BCX0\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-88714\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/site_claim-300x160.png\" alt=\"\" width=\"803\" height=\"428\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/site_claim-300x160.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/site_claim-650x347.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/site_claim.png 724w\" sizes=\"(max-width: 803px) 100vw, 803px\" \/><\/p>\n<p><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">Fig. 1<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u2013<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u00a0Site snapshot<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW13781198\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW13781198\">\u00a0<\/span><\/span><\/p>\n<p><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"AdvancedProofingIssue SCXW187055766 BCX0\">But in reality<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"AdvancedProofingIssue SCXW187055766 BCX0\">,<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"AdvancedProofingIssue SCXW187055766 BCX0\">\u00a0this<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">\u00a0app is\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">ransomware<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">\u2014<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">i<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">t locks\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">the\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">user\u2019s<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">\u00a0android\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">device and asks for\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">a\u00a0<\/span><\/span><span class=\"TextRun SCXW187055766 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW187055766 BCX0\">ransom.<\/span><\/span><\/p>\n<p><strong>Technical Analysis of the App:\u00a0\u00a0<\/strong><\/p>\n<p>After launch, this application asks to ignore battery optimization so it can run in the background.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-88715 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/new1-277x300.png\" alt=\"\" width=\"402\" height=\"435\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new1-277x300.png 277w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new1-768x832.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new1-360x390.png 360w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new1-789x855.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new1.png 1078w\" sizes=\"(max-width: 402px) 100vw, 402px\" \/><\/p>\n<p style=\"text-align: center\"><span class=\"TextRun SCXW241091746 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW241091746 BCX0\">Fig. 2<\/span><\/span><span class=\"TextRun SCXW241091746 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW241091746 BCX0\">\u00a0<\/span><\/span><span class=\"TextRun SCXW241091746 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW241091746 BCX0\">\u2013\u00a0<\/span><\/span><span class=\"TextRun SCXW241091746 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW241091746 BCX0\">Asking for Battery optimization<\/span><\/span><\/p>\n<p><span class=\"TextRun SCXW208400881 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW208400881 BCX0\">\u00a0 \u00a0 \u00a0 \u00a0\u00a0After getting this permission it starts its malicious activity where it asks for accessibility permission \u2014accessibility was introduced in Android to assist physically impaired users. Accessibility service has access to sensitive information such as\u00a0the\u00a0 information\u00a0about running applications on the phone. Attackers can misuse this data. The App\u2019s next step is\u00a0to ask\u00a0for device admin permission. Device administrator enabled app can enforce security policies, password policies being one of\u00a0them. Malware\u00a0authors can use this permission to take control of the device.\u00a0<\/span><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-88716 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/new3-300x218.png\" alt=\"\" width=\"588\" height=\"428\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new3-300x218.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new3-768x559.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new3-536x390.png 536w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new3-789x574.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new3.png 1628w\" sizes=\"(max-width: 588px) 100vw, 588px\" \/><\/p>\n<p style=\"text-align: center\"><span class=\"TextRun SCXW8675407 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW8675407 BCX0\">Fig. 3<\/span><\/span><span class=\"TextRun SCXW8675407 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW8675407 BCX0\">\u00a0<\/span><\/span><span class=\"TextRun SCXW8675407 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"ContextualSpellingAndGrammarError SCXW8675407 BCX0\">\u2013\u00a0\u00a0<\/span><\/span><span class=\"TextRun SCXW8675407 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"ContextualSpellingAndGrammarError SCXW8675407 BCX0\">Activities<\/span><\/span><span class=\"TextRun SCXW8675407 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW8675407 BCX0\">\u00a0asking for device admin permission and accessibility<\/span><\/span><span class=\"EOP SCXW8675407 BCX0\">\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW104946750 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW104946750 BCX0\">\u00a0 \u00a0 \u00a0 \u00a0 After granting permissions, when the user clicks on \u2018scan area for coronavirus\u2019, the\u00a0app\u00a0 calls\u00a0upon the\u00a0onhideapp() method which further checkmarks all required permissions. If all permissions are given by the\u00a0user,\u00a0 it\u00a0hides its icon from the application drawer.\u00a0<\/span><\/span><span class=\"EOP SCXW104946750 BCX0\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88727 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/hideicon-300x137.png\" alt=\"\" width=\"780\" height=\"356\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/hideicon-300x137.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/hideicon-768x352.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/hideicon-650x298.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/hideicon-789x361.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/hideicon.png 981w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/><\/p>\n<p style=\"text-align: center\"><span class=\"TextRun SCXW237541926 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW237541926 BCX0\">Fig. 4\u00a0<\/span><\/span><span class=\"TextRun SCXW237541926 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW237541926 BCX0\">\u2013\u00a0<\/span><\/span><span class=\"TextRun SCXW237541926 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW237541926 BCX0\">Code to hide\u00a0<\/span><\/span><span class=\"TextRun SCXW237541926 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW237541926 BCX0\">the\u00a0<\/span><\/span><span class=\"TextRun SCXW237541926 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW237541926 BCX0\">application icon<\/span><\/span><span class=\"EOP SCXW237541926 BCX0\">\u00a0<\/span><\/p>\n<h4><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">How\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">does this malware\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">lock<\/span><\/span><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">\u00a0the phone<\/span><\/span><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">?<\/span><\/span><span class=\"TextRun BCX0 SCXW134854914\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW134854914\">\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88718 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/nnew-300x235.png\" alt=\"\" width=\"771\" height=\"604\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/nnew-300x235.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/nnew-768x601.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/nnew-499x390.png 499w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/nnew-789x617.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/nnew.png 1174w\" sizes=\"(max-width: 771px) 100vw, 771px\" \/><\/span><\/span><\/h4>\n<p style=\"text-align: center\"><span class=\"TextRun BCX0 SCXW157416372\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW157416372\">Fig. 5\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW157416372\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW157416372\">\u2013 P<\/span><\/span><span class=\"TextRun BCX0 SCXW157416372\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun BCX0 SCXW157416372\">hone locking flow<\/span><\/span><\/p>\n<p>Below are the events which occur to lock User\u2019s device:<\/p>\n<p>A) Due to accessibility permission malware can get all accessibility events. In the above code snippet (block 1) we can see it checks accessibility events type. If this type is TYPE_WINDOW_CONTENT_CHANGED (Constant Value: 2048) Or TYPE_WINDOW_STATE_CHANGED (Constant Value: 32) it calls upon the method\u00a0\u00a0Onblocker().<\/p>\n<p>B) In this method it creates a new thread (code snippet block 2) in which it calls method\u00a0startblockedactivity(), which starts\u00a0BlockedAppactivity. Before calling\u00a0this\u00a0 it\u00a0checks various conditions such as, if the app is hidden from the app drawer (code snippet block 3).<\/p>\n<p>C) Then\u00a0BlockedAppactivity\u00a0is started. In\u00a0oncreate\u00a0it sets\u00a0contentview\u00a0to blocked app which is the ransomware note (code snippet block 4).<\/p>\n<p>Thus,\u00a0whenever\u00a0the\u00a0user tries to open any app this activity\u00a0opens\u00a0not allowing the user\u00a0to use\u00a0the\u00a0intended app.<\/p>\n<p>Below is a snapshot of ransomware note activity. where the malware\u00a0author asks for 250 $ ransom. There is another variant of the app in which ransom amount is 100 $. There is a button \u2018Web\u00a0designius\u2019. \u2014when a user clicks on this button it redirects to\u00a0Pastebin\u00a0page where malware author has given instructions to unlock the phone.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88719 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/new4-300x267.png\" alt=\"\" width=\"530\" height=\"471\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new4-300x267.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new4-438x390.png 438w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/new4.png 654w\" sizes=\"(max-width: 530px) 100vw, 530px\" \/><\/p>\n<p style=\"text-align: center\"><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">Fig.\u00a0<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"ContextualSpellingAndGrammarError SCXW134432054 BCX0\">6\u00a0\u00a0<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"ContextualSpellingAndGrammarError SCXW134432054 BCX0\">\u2013<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">\u00a0<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">a\u00a0<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">variant of coronavirus tracker\u00a0<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">ransomware<\/span><\/span><span class=\"TextRun SCXW134432054 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW134432054 BCX0\">\u00a0with 250 $ ransom note<\/span><\/span><span class=\"EOP SCXW134432054 BCX0\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88720 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/another-169x300.png\" alt=\"\" width=\"274\" height=\"487\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/another-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/another-220x390.png 220w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/another.png 330w\" sizes=\"(max-width: 274px) 100vw, 274px\" \/><\/p>\n<p style=\"text-align: center\"><i>Fig. 7\u00a0<\/i>\u2013\u00a0a\u00a0variant of coronavirus tracker\u00a0ransomware\u00a0with 100\u00a0$ ransom\u00a0note<\/p>\n<p>\u00a0 \u00a0 \u00a0 \u00a0\u00a0<span class=\"TextRun SCXW89470651 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW89470651 BCX0\">Malware author has written pin verification code in the same activity. The\u00a0<\/span><span class=\"SpellingError SCXW89470651 BCX0\">BlockedAppactivity<\/span><span class=\"NormalTextRun SCXW89470651 BCX0\">\u00a0has a function named\u00a0<\/span><span class=\"SpellingError SCXW89470651 BCX0\">verifyPin<\/span><span class=\"NormalTextRun SCXW89470651 BCX0\">() which checks input code to hardcoded key \u20184865083501\u2019. By entering this key user can unlock his phone.<\/span><\/span><span class=\"EOP SCXW89470651 BCX0\">\u00a0<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88721 aligncenter\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2020\/03\/verifypin-300x99.png\" alt=\"\" width=\"630\" height=\"208\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/verifypin-300x99.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/verifypin-650x215.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2020\/03\/verifypin.png 671w\" sizes=\"(max-width: 630px) 100vw, 630px\" \/><\/p>\n<p style=\"text-align: center\"><span class=\"TextRun SCXW118591711 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW118591711 BCX0\">Fig. 8\u00a0<\/span><\/span><span class=\"TextRun SCXW118591711 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW118591711 BCX0\">\u2013\u00a0<\/span><\/span><span class=\"TextRun SCXW118591711 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\"><span class=\"NormalTextRun SCXW118591711 BCX0\">Pin verification code\u00a0<\/span><\/span><span class=\"EOP SCXW118591711 BCX0\">\u00a0<\/span><\/p>\n<p>\u00a0 \u00a0There are many sites which are offering Coronavirus tracking maps and Coronavirus related information, many of these sites ask users to install Android applications to get more info. We have analyzed one of the\u00a0sites which\u00a0claims to give good info\u00a0but in reality, is\u00a0a ransomware app. Users should not fall prey to these types of apps and sites. If they want information for their safety, they can visit the official <a href=\"https:\/\/www.who.int\/\">WHO\u00a0<\/a>website.<\/p>\n<p>&nbsp;<\/p>\n<p>Application\u00a0name :<\/p>\n<p>Coronavirus tracker<\/p>\n<p>Detection:<\/p>\n<p>Quick Heal Mobile Security\u00a0detects\u00a0these apps\u00a0under\u00a0detection\u00a0\u00a0Android.Locker.O<\/p>\n<p>IOC:<\/p>\n<p>69a6b43b5f63030938c578eec05993eb<\/p>\n<p>D1d417235616e4a05096319bb4875f57<\/p>\n<p align=\"justify\"><strong>How to stay safe \u2013<\/strong><\/p>\n<p align=\"justify\">1. Check an app\u2019s description before you download it.<\/p>\n<p align=\"justify\">2. Check the app developer\u2019s name and their website.If the name sounds strange or odd, you have all the reasons to suspect it.<\/p>\n<p align=\"justify\">3. Go through the reviews and ratings of the app. But, note that these can also be faked.<\/p>\n<p align=\"justify\">4. Avoid downloading apps from third-party app stores.<\/p>\n<p align=\"justify\">5. Use a reliable mobile antivirus (like Quick Heal Total Security), that can prevent fake and malicious apps from getting installed on your phone.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the Coronavirus spreads across countries creating fear across the globe, everybody wants to stay on top of any information related to it wanting to remain safe and away from infected people. Malware authors are also taking advantage of this situation. Previously on the Android\u00a0Playstore, there were\u00a0many\u00a0 applications\u00a0present which claimed that they could provide Coronavirus [&hellip;]<\/p>\n","protected":false},"author":61,"featured_media":88730,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,910],"tags":[1721,534,50],"class_list":["post-88713","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-ransomware","tag-coronavirus","tag-cybersecurity","tag-ransomware"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88713"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/61"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=88713"}],"version-history":[{"count":34,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88713\/revisions"}],"predecessor-version":[{"id":88830,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88713\/revisions\/88830"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/88730"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=88713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=88713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=88713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}