When the Trojan executes, it checks the current date on the device. Depending on the date, the Trojan may modify the wallpaper to different images.
If the date is May 21st, 2011, the Trojan may then send one of following SMS messages to all contacts in the address book:
- Cannot talk right now, the world is about to end
- Es el fin del mundo
- Its the Raptures,praise Jebus
- Jebus is way over due for a come back
- Just saw the four horsemen of the apocalypse and man did they have the worst case of road rage
- Prepare to meet thy maker,make sure to hedge your bet just in case the Muslims\u2019 were right
If the date is May 22nd, 2011, it sends the following SMS message to all contacts in the address book:
Looks like Jebus is a no show, maybe Judaism was on to something
If the date is neither May 21st or 22nd, the Trojan contacts the following location using SOAP:
[http://]biofaction.no-ip.biz/talkto[REMOVED]
The Trojan may then receive commands to perform further operations on the device.
It may send the following SMS message to all contacts in the address book:
You have to download this and thank me later
[URL]
Where [URL] is one of following locations:
- [http://]turbobit.net/3qijra41[REMOVED]
- [http://]turbobit.net/9c19sk0t[REMOVED]
- [http://]turbobit.net/9fzlltk2[REMOVED]
If the compromised device receives the following SMS message, it deletes all SMS messages in the phone from that sender:
health
The Trojan may also send the following SMS messages from the device:
- Cannot talk right now, the world is about to end
- Es el fin del mundo
- I am infected and alive ver 1.00
- Its the Raptures,praise Jebus
- Jebus is way over due for a come back
- Just saw the four horsemen of the apocalypse and man did they have the worst case of road rage
- Prepare to meet thy maker, make sure to hedge your bet just in case the Muslims were right
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":