Android package file
The Trojan arrives on the device as part of repackaged versions of legitimate applications. It may arrive as a package with the following characteristics:
Package names:
- air.com.huale.StarWar
- air.com.huale.SummerFishing
- com.letang.game124.cn.free
- com.letang.game126.en
- com.letang.game128.cn
- com.letanginc.marinedefender
- com.mobappbox.glasstower
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about networks (including Wi-Fi)
- Access to the list of accounts in the Accounts Service
- Allow read-only access to the phone state
- Cause the phone to vibrate
- Install packages
- Monitor incoming SMS messages, to record or perform processing on them
- Mount and unmount file systems for removable storage
- Open network sockets
- Open windows using the TYPE_SYSTEM_ALERT command, which is shown on top of all other applications
- Receive the ACTION_BOOT_COMPLETED message that is broadcast after the system finishes booting
- Send SMS messages
- Use PowerManager WakeLocks to keep the processor from sleeping or the screen from dimming
- Write to (but not read) the owner's data
- Write to external storage devices
Installation
The Trojan arrives on the device as part of repackaged versions of legitimate applications. Once installed, the application will display an icon for the legitimate application.




Functionality
The Trojan executes whenever it receives one of the following commands:
- android.intent.action.PACKAGE_ADDED
- android.intent.action.PACKAGE_INSTALL
- android.intent.action.PACKAGE_REMOVED
- android.intent.action.SCREEN_ON
- android.net.conn.CONNECTIVITY_CHANGE
- android.provider.Telephony.SMS_RECEIVED
When the Trojan executes, it steals information from the device, including:
- Country code
- IMEI
- IMSI
- Screen size
It sends the stolen information to the following remote location:
[http://]data.cnappbox.com/andro[REMOVED]
Next, the Trojan may download an advertisement APK on to the compromised device. The advertisement APK may have one of the following common file extensions:
- .cfg
- .mid
- .mp3
- .m4a
- .oog
- .so
- .swf
- .wav
- .xml
The Trojan then displays a message on the device.
The Trojan then opens a back door on the compromised device and connects to the following locations:
- server0.jsjz.iego.net/pluginPHP/pluginapk.php
- server0.jsjz.iego.net/pluginPHP/addata.php
The Trojan may then issue the following commands:
- killServiceName
- shieldAdIDs
- shieldChannelIDs
- noticeHead
- noticeTitle
- noticeContent
- url
- iconId
- pushApkName
- downloadProbability
- pictureUrl
- shieldCountry
- shieldIMEI
- shieldIMSI
- shieldLanguage
- shieldPackageName
- shieldIpInfo
- specifiedCountry
- specifiedIMEI
- specifiedIMSI
- specifiedLanguage
- specifiedPackageName
- specifiedIpInfo

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":