Content

SymbOS/Mobispy

Type
Program
SubType
Spyware
Discovery Date
04/10/2006
Length
Minimum DAT
4737 (04/10/2006)
Updated DAT
5066 (07/03/2007)
Minimum Engine
5.1.00
Description Added
04/10/2006
Description Modified
12/04/2006 4:42 PM (PT)
Risk Assessment
Corporate User
N/A
Home User
N/A

Tab Navigation

Characteristics

SymbOS/Mobispy.A is a spyware application. This malware monitors incoming and outgoing phone numbers and SMS messages.

SymbOS/Mobispy.A steals the following informstion:

  • Both incoming and outgoing phone numbers are recorded
  • Incoming and outgoing SMS messages are recorded.

The stolen information is sent to a central server for later retrieval.

SymbOS/Mobispy.A is a commercial application used for monitoring phone calls and text messages. It is distributed in a sis file named "FSL_[PHONE Model]_SIS", where [PHONE Model]is the phone model for which the software is customized

The malware installs under the name "Phones".

A user who purchases SymbOS/Mobispy.A also receives an account on a central server run by the software's publisher. The account number is also used to access the Settings screen.

The Settings screen is accessed by entering the user's Account Number

Fig 1 - The Settings screen is accessed by entering the user's Account Number.

Connection method and reporting frequency are adjustable

Fig 2 - Connection method and reporting frequency are adjustable.

SymbOS/Mobispy.A uses the phone's GPRS internet connection to transmit its logs. The traffic logs are viewable only on the software publisher's site. The user that installs the software can adjust how often reports are sent to the central server.

Event logging selection screen

Fig 3 - Event logging selection screen.

The user may also choose whether to log SMS messages, Phone numbers or both. The content and destination of SMS messages is logged. For phone calls, only incoming and outgoing phone numbers are logged.

The publisher claims that SymbOS/Mobispy.A is completely invisible on the phone. This is not true, as the program's files are all visible on disk when viewed with a 3rd party file manager.

Symptoms

Method of Infection

Removal

Variants

Variants

    N/A

All Information

Overview -

Characteristics

Characteristics -

SymbOS/Mobispy.A is a spyware application. This malware monitors incoming and outgoing phone numbers and SMS messages.

SymbOS/Mobispy.A steals the following informstion:

  • Both incoming and outgoing phone numbers are recorded
  • Incoming and outgoing SMS messages are recorded.

The stolen information is sent to a central server for later retrieval.

SymbOS/Mobispy.A is a commercial application used for monitoring phone calls and text messages. It is distributed in a sis file named "FSL_[PHONE Model]_SIS", where [PHONE Model]is the phone model for which the software is customized

The malware installs under the name "Phones".

A user who purchases SymbOS/Mobispy.A also receives an account on a central server run by the software's publisher. The account number is also used to access the Settings screen.

The Settings screen is accessed by entering the user's Account Number

Fig 1 - The Settings screen is accessed by entering the user's Account Number.

Connection method and reporting frequency are adjustable

Fig 2 - Connection method and reporting frequency are adjustable.

SymbOS/Mobispy.A uses the phone's GPRS internet connection to transmit its logs. The traffic logs are viewable only on the software publisher's site. The user that installs the software can adjust how often reports are sent to the central server.

Event logging selection screen

Fig 3 - Event logging selection screen.

The user may also choose whether to log SMS messages, Phone numbers or both. The content and destination of SMS messages is logged. For phone calls, only incoming and outgoing phone numbers are logged.

The publisher claims that SymbOS/Mobispy.A is completely invisible on the phone. This is not true, as the program's files are all visible on disk when viewed with a 3rd party file manager.

Symptoms

Symptoms -

Method of Infection

Method of Infection -

Removal -

Removal -

Variants

Variants -

    N/A