{"id":72411,"date":"2011-10-24T13:13:37","date_gmt":"2011-10-24T13:13:37","guid":{"rendered":"https:\/\/localhost\/wordpress\/?p=72411"},"modified":"2011-10-24T13:13:37","modified_gmt":"2011-10-24T13:13:37","slug":"battery-doctor-android-scareware","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/battery-doctor-android-scareware\/","title":{"rendered":"&#8220;Battery Doctor&#8221; Android Scareware"},"content":{"rendered":"<p>A new &#8220;scareware&#8221; targeting mobile devices running Google&#8217;s Android operating system claims that it has the ability to recharge the battery, but in reality it is designed to steal information.<\/p>\n<p>When the program first executes, the overview window shown below appears. As you can see, it shows information about the battery and running applications and the second pie-chart on the right side of the screen shows the available storage space.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/moz-screenshot-101.png\" alt=\"\" width=\"245\" height=\"97\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/moz-screenshot-103.png\" alt=\"\" width=\"243\" height=\"403\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/moz-screenshot-104.png\" alt=\"\" width=\"244\" height=\"183\" \/><\/p>\n<p>The program loads as a service called <strong>NotifAdSDK<\/strong> which checks in (and sends your profile information) every four hours.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/moz-screenshot-95.png\" alt=\"\" width=\"687\" height=\"57\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/moz-screenshot-94.png\" alt=\"\" width=\"750\" height=\"100\" \/><\/p>\n<p><strong>Battery Doctor<\/strong> sends the following information about your device to its home server &#8220;push.m[xxxx]ze.com&#8221;:<br \/>\n-Its screen size<br \/>\n-The version of the browser and OS on the device<br \/>\n-The program which is generating the traffic (com.androidupgrade.battery) and its version<br \/>\n-The name of the campaign<br \/>\n-The device\u2019s manufacturer and model<br \/>\n-The network the device uses<br \/>\n-The phone\u2019s coarse (mobile network) or fine (GPS) location<br \/>\n-The IMEI and phone number<br \/>\n-The app\u2019s API key<br \/>\n-A unique identifier for the device<\/p>\n<p>Thanks Sandip for analyzing the sample. <a href=\"https:\/\/www.quickheal.com\/mobileseclt.asp\">Quick Heal Mobile Security<\/a> detects the file as <strong>Android.Batterydoctor.A<\/strong>.<\/p>\n<p>Users are advised to install applications and games from the trusted Google Play (previously the Android Market) store only.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new &#8220;scareware&#8221; targeting mobile devices running Google&#8217;s Android operating system claims that it has the ability to recharge the battery, but in reality it is designed to steal information. When the program first executes, the overview window shown below appears. As you can see, it shows information about the battery and running applications and [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,24,60],"tags":[56,57,49,59,25,27,61],"class_list":["post-72411","post","type-post","status-publish","format-standard","hentry","category-android","category-malware","category-smartphone","tag-android-security","tag-droid-defense","tag-malware","tag-mobile-devices","tag-phishing","tag-scareware","tag-smartphone-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72411"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=72411"}],"version-history":[{"count":0,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72411\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=72411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=72411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=72411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}