Triada.aw trojan in brand new Ulefone S8 Pro [MT6737]

Search This thread

Diomorgan

Senior Member
Jul 11, 2011
617
84
Rome
Just search software info->software update in settings.I'm on 304 (will post screenshoot if I can) I've been asked to upgrade to 305, but I was able to root the phone (and maybe it's even a bootloader check, since there is no custom recovery, if only magisk would hide the root to the updater, but it's not in the list).On 19 I have another update with final 305, and I was pretty bothered not to be able to update even if I have the stock recovery, but somehow the update app found I'm rooted.I'm pretty sure it was 305, since I'm on 304, but now it says I'm rooted and has last update...(maybe they removed the 305 due to bugs?)
picture.php
the circle says "sistem is up to date", and under the firmware version: etcetcetcetc... 3.04.
Maybe I was drunk (I'm joking I don't drink alchool at all...) but for a few days and the 19th that I wrote the post the update says there were a 3.05 but after download it says "phone roted can't upgrade"...
By the way is really sad we have not a working TWRP for this phone (all the article refer to S9Plus then they post other versione, or version that bootloop...), otherwise we can make flashable .zip and do TWRP backup.
For me is a nice ultra-inexpensive phone with 4 batteries bought, 2 sims and micro SD all separated.Nice for summer (not for picture:( ) as backup phone and a nice hotspot, cheaper then the big branded ones.
 
Last edited:

wasp09

New member
Jun 7, 2018
3
0
Is there an app on google play that can pinpoint this trojan. I received my new S8 Pro from Geekbuying this week. I tried a couple of malware/antivirus scanners, but did not find anything.
Baseband version is still dated 2017/07/13. Build version is still V3.03. Security patch is dated January 5, 2018 and kernel version is dated Jan 23 2018. Is it still in danger?
Regards,
 

bouyhy01

Senior Member
May 4, 2016
441
70
bourges
ASUS ROG Phone 5
Hello i own a brand new ulefone s8 pro bricked after ota update failure i donwloaded the rom from ulefone site and managed to flash it but still bootlooping for about 10 minute and then turning off , i did a donwload only + firmware upgrade and even a format all + download but still bootlooping , i tried to flash twrp but it wont and then tried unlocking bootloader but it failed im really desperate is it a really a software issue or it may be a hard one? Plz help me im begging you
 

IronRoo

Senior Member
Aug 4, 2014
1,403
454
Is there an app on google play that can pinpoint this trojan. I received my new S8 Pro from Geekbuying this week. I tried a couple of malware/antivirus scanners, but did not find anything.
Baseband version is still dated 2017/07/13. Build version is still V3.03. Security patch is dated January 5, 2018 and kernel version is dated Jan 23 2018. Is it still in danger?
Regards,

I don't have this phone but think they may update system apps silently in the background, so you may have new version which passes AV check.

You can use the following app to check against multiple AV engines via virustotal and submit the new file for analysis if it has not already been submitted.

https://play.google.com/store/apps/details?id=com.funnycat.virustotal

(it's NOT a realtime antivirus app, so does not run in the background like a normal anti virus, it is manual activated each time)
 
Last edited:

wasp09

New member
Jun 7, 2018
3
0
... it's NOT a realtime antivirus app...

Ah, it's not a realtime check. It looks like it is pulling reports from a database somewhere. There are no reports on the sound recorder. However it shows reports on many apps including google. Yes, google is definitely spying on us. :)

Not sure who to believe anymore. Thanks anyway.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 2
    Workaround

    Hello, I have the same problem and I have sent several emails to the company to eliminate the Trojan of the sound recorder ... but they still do not answer.
    I'll keep sending more emails, but ... if some developer does twrp for our phone, we can root it and delete it.

    Yes, Ulefone just doesn't care. You can try ADB, then uninstall that app. The apk stays on the phone but inactive. That's what I have done.
    2
    freeze it

    The problem of the Trojan of my ULEFONE S8 PRO is the sound recorder, and it is installed in the system part, so if I do not root or install TWRP I can not delete it. If any developer can help us and give us some solution ... I sent several emails to ULEFONE and they do not answer. The Trojan was detected by ESET NOD 32 MOBILE.
    Thank you:(

    Yes, with TWRP or CWM we could root it and delete the apk, but with ADB you can uninstall it. Then just the apk package sits in the priv-apps folder, without harming the OS.
    2
    fixed trojan in ULEFONE

    Do you mind giving details about how you did without root? I tried the following

    Code:
    adb shell pm uninstall com.android.soundrecorder

    and got the following error: Failure [DELETE_FAILED_INTERNAL_ERROR]

    Never mind, found it:
    Code:
    pm uninstall -k --user 0 com.android.soundrecorder

    Hello, follow the instructions in this tutorial, and you can remove the Trojan from your ULEFONE :good:
    https://www.xda-developers.com/uninstall-carrier-oem-bloatware-without-root-access/
    1
    Hello.
    I just bought a brand new Ulefone S8 Pro from Gearbest.
    While connecting to my company's wifi an alarm from their security service (Esentire) picked up a trojan signature hash: Triada.aw
    Anyone had this problem before?
    How can I root this phone and which ROM should I flash?
    Thank you.

    Don't know about your phone specifically but you should be able to find a way to disable that app (others too maybe) their are many tutorials on web eg
    https://www.xda-developers.com/uninstall-carrier-oem-bloatware-without-root-access/

    Or maybe apps like Package Disabler or Debloater etc will work for you. But if you can find a root method & custom ROM, that may be better (best to use a well known one from a trusted dev here on XDA)
    1
    The problem of the Trojan of my ULEFONE S8 PRO is the sound recorder, and it is installed in the system part, so if I do not root or install TWRP I can not delete it. If any developer can help us and give us some solution ... I sent several emails to ULEFONE and they do not answer. The Trojan was detected by ESET NOD 32 MOBILE.
    Thank you:(

    They will not remove it it's what they built into system & it is working exactly as it was designed to work, I believe. It's just that most people would probably class it as a Trojan due to it's behavior.

    you should freeze it like @r1kkman.