Android package file
The Trojan may arrive as a package with one of the following names:
Package name:
- goldenhammer.bmsnowfullzxl
- Mag3DLite.SF3DxX
- com.panda.slay
- com.aceviral.teamwdfy
- com.strikermanager.android.strikersossft
- com.zhuqzu
- com.AndPhone.game.GoldRacings
- com.rovio.angrybirdsspace.premiumszs
- com.creativemobile.DragRacingaxbwx
- com.iava.kofns9er
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Write to external storage devices.
- Access information about the WiFi state.
- Access information about networks.
- Open network connections.
- Check the phone's current state.
- Access information about currently or recently running tasks.
- Mount and unmount file systems for removable storage.
- Allows applications to write the apn settings.
- Change network connectivity state.
- Change Wi-Fi connectivity state.
- Write to external storage devices.
- Make the phone vibrate.
- Prevent processor from sleeping or screen from dimming.
Installation
Once installed, the application will display an icon depending on the application that was downloaded.
Functionality
When the Trojan is executed, it connects to the following URL in order to download an encrypted zip file, which includes the main malicious script:
[http://]an.yu61.com:5222/kspp/d[REMOVED]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":