Android package file
The Trojan may arrive as the following APK package:
APK: com.android.XWLauncher
Version: 1.0
Name: Tdhome
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Allow an application to delete packages
- Allow an application to install packages
- Broadcast an SMS receipt notification
- Change the background wallpaper
- Change the wallpaper hints
- Check the phone's current state
- Expand or collapse the status bar
- Get information about the currently or recently running tasks
- Initiate a phone call without using the Phone UI or requiring confirmation from the user
- Make the phone vibrate
- Monitor incoming SMS messages
- Open network connections
- Read or write to the system settings
- Read user's contacts data
- Restart applications
- Send SMS messages
- Start once the device has finished booting
- Tell the AppWidget service which application can access AppWidget's data
- Write to external storage devices
Functionality
When the Trojan is executed, it changes the wallpaper on the device to the following:
Next, the Trojan starts a service with the following name:
MyService
It then downloads and installs one of the following APKs on to the device from download.nnetonline.com:
- android_dipei_1.4.0.apk
- HiMarketPho3.3.2r_5.9_Himarket_Android810.apk
- KSHDToGo-v0.1.48-1.6-20110526_youyoucun3.apk
- QQBrowser2.0(Android)_Build0095_60058.apk
- QQSecure2.0_(Android)_Build289(1).apk
- Renren_Android_3.0.2.7.20110510.apk
- UCBrowser_V7.8.1.96_Android_pf139_bi800_(Build11060915).apk
Next, the Trojan collects certain information from the device, including:
It then sends the stolen information to the following remote location:
www.nnetonline.com
The Trojan may then send SMS messages from the compromised device.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":