Android package fileThis Trojan disguises itself on certain marketplaces as game software, but it comes bundled with a Trojan.
InstallationThe Trojan then creates a service with the following name:
zjService
System monitoringWhen an SMS is received, the Trojan records the following information in a file named zjsms.txt:
- Date and time
- Message body
- Sender's address
When a phone call is made, it stores the following information in a file named zjphonecall.txt:
- Date and time
- Phone number
When a phone call is received, the Trojan stores the following information in a file named zjphonecall.txt:
- Ending date and time
- Phone number
- Starting date and time
The Trojan also steals the following information and sends it to the remote attacker:
- Device ID
- SIM serial number
- Subscriber ID
The Trojan may then upload the files containing the stolen information to the following location:
http://lebar.gicp.net/zj/upload/UploadFiles.aspx
Remote accessNext, the Trojan may download commands from the following location:
[http://]lebar.gicp.net/zj/allotWork[REMOVED]
It may then perform the following actions on the compromised device:
- Install and execute a new package
- Make arbitrary phone calls
- Send arbitrary SMS messages
- Uninstall a package
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":