When a user opens the Trojan file, the phone installer displays the following prompt:
Install
Sexy Girls?
If the user clicks yes, then the installer will display the following message:
Name: Sexy Girls
Version: 1.05
Supplier: Play Boy
The Trojan then displays the following valid Symbian Signed certificate:
Subject: XiaMen Jinlonghuatian Technology Co. Ltd.
Valid from: 14/10/2008
Valid until: 15/10/2018
Serial number: 59D90001002343FE87A1C26833F0
Once the user chooses to continue installing the application, the following files are installed on to the mobile device memory:
- c:\sys\bin\BootHelper.exe
- c:\private\101f875a\import\[20017741].rsc
The Trojan starts automatically after the the mobile device is restarted.
It attempts to end the following process control or file control utilities
The Trojan collects the following data from the mobile device and then attempts to connect to a remote location to download configuration information:
- IMEI
- IMSI
- Phone Number
- Phone type
- Version
It creates the following sis file:
c:\Download.sisx
It also creates the following log file:
c:\logs\bh.log
The Trojan may also creates the following text files:
It then attempts to send numerous SMS messages to a list of predetermined numbers.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":