Android package file
The Trojan may arrive as a package with the following name:
APK: zombie.mainmenus
Version: 1.0.2
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Start once the device has finished booting
- Open network sockets
- Write to external storage
- Access information about networks
- Read access to phone state
- Get information about the currently or recently running tasks
- Check the phone's current state
- Change the phone state, such as powering it on and off
Installation
Once installed, the application will display the following icon:
The Trojan generally arrives within a repackaged .apk file from a legitimate application.
Downloading
The Trojan downloads a list of URLs from the following locations:
- [http://]www.00android.com/InstallApk/Install[REMOVED]
- [http://]g.00android.com/install/apke[REMOVED]
The Trojan may then download different .apk files from the following locations:
- [http://]installapk7.googlecode.com/files/daha[REMOVED]
- [http://]installapk7.googlecode.com/files/daha[REMOVED]
- [http://]oouutt.googlecode.com/files/hdaha[REMOVED]
- [http://]installapk7.googlecode.com/files/oupen[REMOVED]
- [http://]installapk7.googlecode.com/files/oupen[REMOVED]
- [http://]installapk7.googlecode.com/files/zhengq[REMOVED]
Note: The Trojan displays a fake system update notification to entice the user to manually install downloaded .apk files.
Functionality
The Trojan creates a service with the following name so that it executes every time the device restarts:
com.google.process.gapp.A
The Trojan also looks for a SD Card for the device and starts the following service:
com.google.process.gapp.GoogleServicesFrameworkService
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":