Android package file
The Trojan may arrive as a package with the following name:
APK: com.dreamstep.wFlashPlayer[VERSION]
Name: Flash Player [VERSION]
Note: [VERSION] is variable and subject to change. Examples using this variable include the following:
For APK:
com.dreamstep.wFlashPlayer105
com.dreamstep.wFlashPlayer105New
com.dreamstep.wFlashPlayer12Beta
For Name:
Flash Player 10.5
Flash Player 10.5 New
Flash Player 12 Beta
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Open network connections
- Access information about networks
- Run as a plugin in the webkit
- Register and receive messages
Installation
Once installed, the application may display one of the following icons:
Functionality
When the application is executed, it directs the user to the following website:
1wap.mobi
Note: The user may first be momentarily redirected through additional websites like the following:
- [http://]123moviez.in
- [http://]icymaze.com
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":