{"id":87225,"date":"2018-12-21T12:46:46","date_gmt":"2018-12-21T07:16:46","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=87225"},"modified":"2023-09-25T18:09:14","modified_gmt":"2023-09-25T12:39:14","slug":"fakeapp-discovered-google-play-store-increases-download-count-rating-applications","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/fakeapp-discovered-google-play-store-increases-download-count-rating-applications\/","title":{"rendered":"FakeApp discovered on Google Play Store which increases download count and rating of other applications."},"content":{"rendered":"<p><span style=\"font-size: large;\">Quick Heal Security Lab has spotted few FakeApps with more than 50,000+ installations on Google Play Store. These applications appear to be genuine as a PDF reader, PDF Downloader, PDF Scanner etc., but don&#8217;t have such functionality. The main purpose of these apps is to increase the download count of other applications and improve their ratings.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-87227 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/12\/icon.png\" alt=\"\" width=\"594\" height=\"182\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/icon.png 594w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/icon-300x92.png 300w\" sizes=\"(max-width: 594px) 100vw, 594px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: large;\">Fig 1. List of applications present on Google Play Store.<\/span><\/p>\n<p><span style=\"font-size: large;\">These applications prompt users to download and rate 5 stars to sponsor apps in order to unlock this application. After <a href=\"https:\/\/blogs.quickheal.com\/update-security-certificate-to-install-quick-heal-product-successfully\/\">installation<\/a> of other applications and ratings, the user will be able to use the PDF reader after 24 hours. But after 24 hours, the same loop starts. It asks users to log in with some created password and asks them to download the same application to unlock the application.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-87228 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/12\/Screenshot_20181220-122242.png\" alt=\"\" width=\"315\" height=\"560\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/Screenshot_20181220-122242.png 720w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/Screenshot_20181220-122242-169x300.png 169w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/Screenshot_20181220-122242-219x390.png 219w\" sizes=\"(max-width: 315px) 100vw, 315px\" \/><\/p>\n<p style=\"text-align: center;\"><span style=\"font-size: large;\">Fig 3. PDF converter with 50k+ downloads count<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-87234 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/12\/logdown.png\" alt=\"\" width=\"618\" height=\"535\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/logdown.png 618w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/logdown-300x260.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/logdown-451x390.png 451w\" sizes=\"(max-width: 618px) 100vw, 618px\" \/><\/p>\n<p style=\"text-align: center;\">Fig 3. <span style=\"font-size: large;\">Login page and sponsored app download applications.<\/span><\/p>\n<p><span style=\"font-size: large;\">The application just loads a URL &#8220;https:\/\/shar*********.blogspot.com\/p\/index.html&#8221; and displays the above webpage. It does not have any permissions in the manifest related to a PDF reader or converter.<\/span><\/p>\n<p><span style=\"font-size: large;\">The basic intention of this application is to increase the download count and good rating of sponsored apps. The sponsored application also does the same thing. In order to use other applications, first user should rate and download sponsored app. This is the trick of the author to increase the download count to earn revenue in the easiest way.<\/span><\/p>\n<p><a name=\"_GoBack\"><\/a> <span style=\"font-size: large;\">Users should be careful while downloading such fake applications. User can easily recognize it by going through review. We have reported these applications to Google.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-87236 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2018\/12\/usercomments.png\" alt=\"\" width=\"698\" height=\"370\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/usercomments.png 698w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/usercomments-300x159.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2018\/12\/usercomments-650x345.png 650w\" sizes=\"(max-width: 698px) 100vw, 698px\" \/><\/p>\n<p style=\"text-align: center;\">Fig 4. <span style=\"font-size: large;\">Users review.<\/span><\/p>\n<p><span style=\"font-size: large;\">Here is the list of package name with MD5 :<br \/>\n<\/span><\/p>\n<table width=\"660\" cellspacing=\"0\" cellpadding=\"4\">\n<colgroup>\n<col width=\"327\" \/>\n<col width=\"315\" \/> <\/colgroup>\n<tbody>\n<tr valign=\"top\">\n<td width=\"327\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">Package Name<\/span><\/p>\n<\/td>\n<td width=\"315\"><span style=\"font-size: large;\">MD5<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td width=\"327\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">com.frenzy.live<\/span><\/p>\n<\/td>\n<td width=\"315\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">8d9bb39840bcf8c751418cb691eb8893<\/span><\/p>\n<\/td>\n<\/tr>\n<tr valign=\"top\">\n<td width=\"327\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">com.shartel.pdfebookconverter<\/span><\/p>\n<\/td>\n<td width=\"315\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">46d45604a170a22a113d8f645ebca62c<\/span><\/p>\n<\/td>\n<\/tr>\n<tr valign=\"top\">\n<td width=\"327\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">com.shartel.pdfebookreader<\/span><\/p>\n<\/td>\n<td width=\"315\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">71b392ffa80e96d63dfd08410cbd5b3d<\/span><\/p>\n<\/td>\n<\/tr>\n<tr valign=\"top\">\n<td width=\"327\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">com.shartel.pdfebookdownloader<\/span><\/p>\n<\/td>\n<td width=\"315\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">b1e787f0ad43a1ccead89071d8532725<\/span><\/p>\n<\/td>\n<\/tr>\n<tr valign=\"top\">\n<td width=\"327\" height=\"25\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">com.shartel.pdfscannerocr<\/span><\/p>\n<\/td>\n<td width=\"315\">\n<p style=\"text-align: left;\"><span style=\"font-size: large;\">dd519b9901cd544e0016331ccf666670<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-size: large;\"><b>Quick Heal Detection<\/b><\/span><\/p>\n<p><span style=\"font-size: large;\">Quick Heal detects this application as :<br \/>\n<\/span><\/p>\n<table width=\"660\" cellspacing=\"0\" cellpadding=\"4\">\n<colgroup>\n<col width=\"327\" \/>\n<col width=\"315\" \/> <\/colgroup>\n<tbody>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\"><span style=\"font-size: large;\">Package Name<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Detection Name<br \/>\n<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\"><span style=\"font-size: large;\">com.frenzy.live<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Android.Fakeapp.A3f8f<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\"><span style=\"font-size: large;\">com.shartel.pdfebookconverter<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Android.Fakeapp.A3f93<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\"><span style=\"font-size: large;\">com.shartel.pdfebookreader<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Android.Fakeapp.A3f90<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\"><span style=\"font-size: large;\">com.shartel.pdfebookdownloader<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Android.Fakeapp.A3f91<\/span><\/td>\n<\/tr>\n<tr valign=\"top\">\n<td style=\"text-align: left;\" width=\"327\" height=\"25\"><span style=\"font-size: large;\">com.shartel.pdfscannerocr<\/span><\/td>\n<td style=\"text-align: left;\" width=\"315\"><span style=\"font-size: large;\">Android.Fakeapp.A3f92 <\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><span style=\"font-size: large;\">How to stay safe from fake mobile apps<\/span><\/strong><\/p>\n<p><span style=\"font-size: large;\">1. Check an app\u2019s description before you download it.<\/span><\/p>\n<p><span style=\"font-size: large;\">2. Check the app developer\u2019s name and their website. If the name sounds strange or odd, you have reasons to suspect it.<\/span><\/p>\n<p><span style=\"font-size: large;\">3. Go through the reviews and ratings of the app. But, note that these can be faked too.<\/span><\/p>\n<p><span style=\"font-size: large;\">4. Avoid downloading apps from third-party app stores.<\/span><\/p>\n<p><span style=\"font-size: large;\">5. Use a reliable mobile antivirus that can prevent fake and malicious apps from getting installed on your phone.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quick Heal Security Lab has spotted few FakeApps with more than 50,000+ installations on Google Play Store. These applications appear to be genuine as a PDF reader, PDF Downloader, PDF Scanner etc., but don&#8217;t have such functionality. The main purpose of these apps is to increase the download count of other applications and improve their [&hellip;]<\/p>\n","protected":false},"author":48,"featured_media":85666,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,24],"tags":[380,1566],"class_list":["post-87225","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-malware","tag-android-malware","tag-fakeapp"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/87225"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/48"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=87225"}],"version-history":[{"count":12,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/87225\/revisions"}],"predecessor-version":[{"id":92098,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/87225\/revisions\/92098"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/85666"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=87225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=87225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=87225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}