Android package file
The Trojan may arrive with one of the following package names:
- com.appengines.fastphone
- com.coolmasterz.flirt
- com.stephbriggs5.batteryimprove
- com.supersocialmob.allfriends
Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
- Access information about networks, including Wifi
- Allow read-only access to phone state
- Cause the phone to vibrate
- Open network sockets
- Send SMS messages
Installation
Once installed, the application will display an icon with one of the following names:
- All Friends
- Battery Improve
- Faster Phone
- Flirt!



Functionality
When the Trojan is executed, it registers an SMS observer to record SMS messages and send them to the following command-and-control (C&C) server:
[http://]android.tetulus.com
The Trojan may delete some SMS messages from the device.
It may also register an SMS receiver to send SMS messages without the user's consent.
The Trojan may send a list of all installed apps on the device to the following remote location:
[http://]fast.app-engines.com
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":