Symbian worm Yxes: towards mobile botnets?

被引:0
|
作者
Apvrille, Axelle [1 ]
机构
[1] Fortinet Technol, EMEA AV Team, 120 Rue Albert Caquot, F-06410 Biot, France
关键词
D O I
10.1007/s11416-012-0163-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In 2009, a new Symbian malware named SymbOS/Yxes was detected and quickly hit the headlines as one of the first malware for Symbian OS 9 and above all as the foretaste of a mobile botnet. Yet, detailed analysis of the malware were still missing. This paper addresses this issue and details how the malware silently connects to the Internet, installs new mal ware or spreads to other victims. Each of these points are illustrated with commented assembly code taken from the malware or re-generated Symbian API calls. Besides those implementation aspects, the paper also provides a global overview of Yxes's behaviour. It explains how malicious remote servers participate in the configuration and propagation of the malware, including Yxes's similarities with a botnet. It also tries to shed light on some incomplete or misleading statements in prior press articles. Those statements are corrected, based on the reverse engineering evidence previously. Finally, the paper concludes on Yxes's importance and the lack of security on mobile phones. It also indicates several aspects future work should focus on such as communication decryption, tools to analyze embedded malware or cybercriminals motivations.
引用
收藏
页码:117 / 131
页数:15
相关论文
共 50 条
  • [41] How do mobile phones fail? A failure data analysis of symbian OS smart phones
    Cinque, Marcello
    Cotroneo, Domenico
    Kalbarczyk, Zbigniew
    Iyer, Ravishankar K.
    37TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2007, : 585 - +
  • [42] 决战紫禁之巅 Symbian OS 8.0 VS Windows Mobile 5.0
    潮阳
    数字通信, 2005, (11) : 106 - 108
  • [43] Modeling of a mobile robot with worm-like movement
    Gramescu, B
    Nitu, C
    Alexandrescu, N
    Eurocon 2005: The International Conference on Computer as a Tool, Vol 1 and 2 , Proceedings, 2005, : 1204 - 1207
  • [44] Botnet Triple-Channel Model: Towards Resilient and Efficient Bidirectional Communication Botnets
    Cui Xiang
    Fang Binxing
    Shi Jinqiao
    Liu Chaoge
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2013, 2013, 127 : 53 - +
  • [45] Towards Accurate Node-Based Detection of P2P Botnets
    Yin, Chunyong
    SCIENTIFIC WORLD JOURNAL, 2014,
  • [46] A Worm Containment Approach towards Online Social Networks
    2018 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, ARCHITECTURE AND STORAGE (NAS), 2018,
  • [47] Detecting Social Media Mobile Botnets Using User Activity Correlation and Artificial Immune System
    Al-Dayil, Reham A.
    Dahshan, Mostafa H.
    2016 7TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS (ICICS), 2016, : 109 - 114
  • [48] Towards Generating Benchmark Datasets for Worm Infection Studies
    Asgari, Sara
    Sadeghiyan, Babak
    2020 10TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2020, : 1 - 8
  • [49] Primary Mobile Image Analysis of Human Intestinal Worm Detection
    Appati, Justice Kwame
    Yaokumah, Winfred
    Owusu, Ebenezer
    INTERNATIONAL JOURNAL OF SYSTEM DYNAMICS APPLICATIONS, 2022, 11 (01)
  • [50] Global stability for a SEIQR worm propagation model in mobile internet
    Zhang, Liang
    Liu, Pengyan
    INTERNATIONAL JOURNAL OF NONLINEAR SCIENCES AND NUMERICAL SIMULATION, 2022, 23 (06) : 797 - 812