Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a21c24e80d7db23b

Jump to content

Brain Test

From Wikipedia, the free encyclopedia

Brain Test was a piece of malware masquerading as an Android app that tested the user's IQ.[1][2] Brain Test was discovered by security firm Check Point and was available in the Google Play app store until 15 September 2015.[1] Check Point described Brain Test as "A new level of sophistication in malware".[1]

Brain Test was uploaded on two occasions (com.zmhitlte.brain and com.mile.brain), starting in August 2015, both times Google's Bouncer antivirus failed to detect the malware. After the first removal on 24 August 2015 the software was reintroduced using an obfuscation technique. Tim Erin of Tripwire said the "Bypassing the vetting processes of Apple and Google is the keystone in a mobile malware campaign."

The malware turned out to include a rootkit, the revelation being described as "more cunning than first thought".[3]

The malware is thought to have been written by a Chinese threat actor, according to Shaulov of Check Point, based on the use of a packing/obfuscation tool from Baidu. Eleven Paths, a Telefonica-owned company, found links to may other pieces of malware, based on the id used to access Umeng, Internet domains accessed by the apps and shared jpg and png images.[4]

It appears the app was first detected on a Nexus 5 using Check Point's Mobile Threat Prevention System. The fact that the system was unable to remove the malware alerted the software company's researchers that it was an unusual threat.

According to Check Point, it may be necessary to re-flash the ROM on a device if Brain Test has successfully installed a reinstaller in the system directory.

Features

[edit]

The malware was uploaded in two forms. The packing feature was only present in the second.

  • Evades detection by Google Bouncer by avoiding malicious behavior on Google servers with IP addresses 209.85.128.0–209.85.255.255, 216.58.192.0–216.58.223.255, 173.194.0.0–173.194.255.255, or 74.125.0.0–74.125.255.255, or domain names "google", "android" or "1e100".
  • Root exploits. Four exploits to gain root access to the system were included, to account for variations in the kernel and drivers of different manufacturers and Android versions,[5] which provide alternative paths to root.
  • External payloads - via command and control system. The system used up to five external servers to provide variable payload, believed to be primarily advertising related.
  • Packing and time delay. The main downloaded malware portion sits in a sound file, and the bootstrap code unpacks this after a time delay.
  • Dual install and re-install. Two copies of the malware are installed. If one is removed the other re-installs it.

See also

[edit]

References

[edit]
  1. 1 2 3 Polkovnichenko, Andrey; Boxiner, Alon (21 September 2015). "BrainTest – A New Level of Sophistication in Mobile Malware". Archived from the original on 25 November 2015. Retrieved 27 November 2015.
  2. Graham Cluley (23 September 2015). "Malware hits the Google Play Android app store again (and again)".
  3. Cett, Hans (2 November 2015). "Brain Test malware more cunning than 1st thought". GoMo News. Archived from the original on 26 November 2015. Retrieved 27 November 2015.
  4. "Detailed coverage at Forbes Chinese Cybercriminals Breached Google Play To Infect 'Up To 1 Million' Androids". Retrieved 25 August 2017.
  5. Kerner, Sean Michael (21 September 2015). "Malicious Brain Test App Thwarts Google Play Android Security". eweek.com. Retrieved 27 November 2015.[permanent dead link]
[edit]