Home / malware Trojan-Spy:SymbOS/Flexispy.A
First posted on 02 July 2010.
Source: SecurityHomeAliases :
There are no other names known for Trojan-Spy:SymbOS/Flexispy.A.
Explanation :
A trojan that secretly installs spy programs, such as keyloggers.
Additional DetailsTrojan-Spy:SymbOS/Flexispy.A is a spyphone application that allows a user to monitor calls and messages on a targeted phone. The application must be manually installed on the phone in order for the program to operate.
Note: there are newer versions of FlexiSPY than the variant described here. Later versions exhibit different behavior and are not classified as malware.
Installation
Flexispy.A is installed in a standard SIS package and when installed the application uses the name "phones". It does not give any indication as to what is being installed.
After installation the application will immediately go into hiding and locks its files so that the application uninstaller cannot remove it.
The user interface of Flexispy.A is only accessible by entering a special code in the phone number field.
In the user interface, the attacker can control when the spying application reports and what information is recorded.
Recording the Victim's Communication
Flexispy.A records both voice call and SMS information and sends the details to the FlexiSpy server. From there the information can be accessed through a web browser.
Recording Voice Calls
Flexispy.A records the following details from the victim's voice calls:
€ IMEI € Client time € Server time € Direction € Duration € Phone number € Contact name in the victim's phonebook
Recording SMS
Flexispy.A records the following details from the victim's SMS message traffic:
€ IMEI € Client time € Server time € Direction € Duration € Phone number € Contact name in the victim's phonebook € Contents of SMS messages
DetectionF-Secure Anti-Virus detects this malware with the following updates:
[FSAV_Database_Version]
Version = 2006-03-29_02.
F-Secure Mobile Anti-Virus for Symbian detects this malware starting from the update build number 81.Last update 02 July 2010