Detailed Analysis of Android.Qicsomos

Intro: What is Android.Qicsomos?

Android.Qicsomos is a new Android malware that emerged some days ago. It sends SMS messages to premium rated numbers.

Analysis of the Application and Its Structure

The app requests the following permissions:

  • android.permission.READ_LOGS
  • android.permission.SEND_SMS

After the application has been installed successfully, the icon of the app shows up in the dashboard. The name of the application and the UI look like an app for detecting CarrierIQ.

The Malicious Parts:

The malicious part of the app starts, when an user hits the “Déinstaller” button. The app sends four SMS messages to “81168” containing the text “AT37”, “MC49”, “SP99” and “SP93” before it gets deinstalled. (for more information see the following code-snippet)

Sample Information:



Mobile-Sandbox Report

2 Replies to “Detailed Analysis of Android.Qicsomos”

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.