Android package file
The Trojan may arrive as a package with the following name:
APK: girls.amazing.com
Version: 1.0.1
Name: Amazing Sexy Girls
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about currently or recently running tasks
- Access information about networks
- Access location information, such as Cell-ID, WiFi, or GPS information
- Access the Accounts Service
- Access the flashlight
- Change the background wallpaper
- Check the phone's current state
- Install shortcuts
- Make the phone vibrate
- Open network connections
- Prevent the processor from sleeping or the screen from dimming
- Read and write the browsing history and bookmarks
- Set the wallpaper
- Start once the device has finished booting
- Write to external storage devices
Installation
Once installed, the application will display an icon with the following text:
Amazing Sexy Girls
Functionality
When the Trojan is executed it will collect the following information:
- Google account details
- GPS location
- IMEI
It then sends the information to the following remote location:
[http://]farm.takozkata.com/getur[REMOVED]
The Trojan may also visit the following advertisement websites:
- [http://]api.airpush.com
- [http://]media.admob.com
- [http://]my.mobfox.com
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":