Home / malwarePDF  

Android.Accstealer


First posted on 29 January 2015.
Source: Symantec

Aliases :

There are no other names known for Android.Accstealer.

Explanation :

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.sexywallpapers.wallpaper.sexy
Version: 1.1
Name: SexyWallpapers

Permissions
When the Trojan is being installed, it requests permissions to perform the following actions: Read or write to the system settingsOpen network connectionsAccess information about networksStart once the device has finished bootingMake the phone vibratePrevent processor from sleeping or screen from dimmingAccess list of accounts in the Accounts ServiceCheck the phone's current stateAccess information about the Wi-Fi stateAccess location information, such as GPS informationWrite to external storage devices
Installation
Once installed, the application will display a pink icon with a picture of a woman's face and the text "sexy pictures".



Functionality
The Trojan poses as a wallpaper application for Android devices.


When the Trojan is executed, it gathers account details from the following apps: FacebookTwitterGmail
The Trojan then sends the gathered information to the following remote location: [http://]5.10.71.142/s/s[REMOVED]

Last update 29 January 2015

 

TOP