Android package file
The Trojan may arrive as a package with the following name:
APK: getContact.apk
Version: 1.0
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Read user's contacts data.
- Open network connections.
- Check the phone's current state.
Installation
Once installed, the application will display an icon with the text "Android".
Functionality
When the Trojan is executed, it connects to the following URL:
[http://]122.202.100.231/GetContacts/demoPa[REMOVED]
The Trojan collects the following information:
- Information stored in Contacts
- Phone number of the device
It then sends the information to the following remote location:
[http://]122.202.100.231/GetContacts/getIn[REMOVED]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":