Android package file
The Trojan may arrive as a package with the following characteristics:
Package name: com.stech.stopphishing
APK:
- com.stech.stopphishing.apk
- com.stech.spamguard.apk
- com.stech.stopphishing.apk
Version: 2.1.9
Name: Stop Phishing!
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about networks
- Check the phone's current state
- Monitor incoming SMS and MMS messages
- Open network connections
- Prevent processor from sleeping or screen from dimming
- Start once the device has finished booting
- Write to external storage devices
Installation
Once installed, the application will display an icon with a red and white "No Phishing" sign with the text "Stop Phishing!" below it.
Functionality
The threat poses as a security application that claims to stop phishing and spam messages.
Once executed, the Trojan sends the following information to a remote location:
- Carrier information
- Device's phone number
- SMS messages
The Trojan may connect to the following IP address on ports 4869 and 2501:
54.243.187.[REMOVED]
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":