facebook message.zi...
 
Notifications
Clear all

facebook message.zip

8 Posts
5 Users
0 Reactions
572 Views
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

hi all, I have checked with UFED physical analyzer an iphone and found 2 viruses on it
facebook message.zip
worm.generic.247786

cv-20100120-112.zip
trojan.generic.5085202

checked on google but couldn't find any mention regarding iphones, I do know that they are viruses to infect windows based systems.

does any one know if these are able to infect Iphones????

thanks in advance.


   
Quote
(@badgerau)
Trusted Member
Joined: 12 years ago
Posts: 96
 

Hi,

Can you confirm that you used the malware scanner within UFED Physical?

Have you been able to determine where the infected file were in the file system? What model iPhone is this and which version OS is it running?

I am very interested in this as I have yet to find any malware on an iOS device.


   
ReplyQuote
Adam10541
(@adam10541)
Honorable Member
Joined: 13 years ago
Posts: 550
 

I'd also be very interested as well to know the location.

It may be possible the malware is 'dormant' so to speak somewhere, unable to actively infect iOS but still present until such time as a malware scanner can remove them.


   
ReplyQuote
(@dcs1094)
Estimable Member
Joined: 12 years ago
Posts: 146
 

Can you give more details on the iOS device. Is the iPhone jailbroken?


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

Hi,

Can you confirm that you used the malware scanner within UFED Physical?

Have you been able to determine where the infected file were in the file system? What model iPhone is this and which version OS is it running?

I am very interested in this as I have yet to find any malware on an iOS device.

hi, yes it has been scanned via UFED physical analyzer, the iphone is iphone 4 OS 7.

The infected files were in the \Documents\Inbox


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

Can you give more details on the iOS device. Is the iPhone jailbroken?

it's Iphone 4 , OS 7, and no it is not jailbroken.

the files were recived by e-mail and opened on the iphone.

the funny thing is that when trying to analyze these files on different sites which check for viruses got this message
High security alert!!!
You are not permitted to upload the file "CV-20100120-112.zip" because it is infected with the virus "W32/Injector.fam!tr".
URL = http//eureka.cyber-ta.org/cgi-bin/upload.new.cgi
File quarantined as .
http//www.fortinet.com/ve?vn=W32%2FInjector.fam%21tr


   
ReplyQuote
(@rampage)
Reputable Member
Joined: 17 years ago
Posts: 354
 

my first bet is that these malwares are there just because they were email attachments, and they aren't targeting iOS.

to be sure the only thing you can do is check the files and see which formats they are.

if inside the zip file you find a PE executable they are not targeting iOS for sure.


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
Topic starter  

my first bet is that these malwares are there just because they were email attachments, and they aren't targeting iOS.

to be sure the only thing you can do is check the files and see which formats they are.

if inside the zip file you find a PE executable they are not targeting iOS for sure.

no, there was no pe file in there, thanks.


   
ReplyQuote
Share: