The threat is advertised as an application for a Chinese gaming community and may arrive as an application package with the following name:
com.ppxiu
When executed, the Trojan attempts to send premium-rate SMS messages to one or more of the following numbers:
- 8613800755500
- 1065800885566
It then attempts to remove the SMS messages it sends from the device.
The Trojan sends device information, such as IMEI and IMSI numbers, to the following URLs:
- [http://]axy.waplove.cn:8080/Wukong/android/android.[REMOVED]
- [http://]domaindev.51widgets.com/ss/service/actio[REMOVED]
- [http://]domaindev.51widgets.com/ss/service/actio[REMOVED]
The Trojan may also download and install updates.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":