{"id":88071,"date":"2019-09-09T17:40:30","date_gmt":"2019-09-09T12:10:30","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=88071"},"modified":"2019-09-24T19:26:55","modified_gmt":"2019-09-24T13:56:55","slug":"free-mobile-anti-virus-using-can-fake","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/free-mobile-anti-virus-using-can-fake\/","title":{"rendered":"The Free Mobile Anti-virus you are using can be a Fake!"},"content":{"rendered":"<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">Quick Heal Security Labs recently spotted multiple Fake <\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">Antivirus <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">Apps on Google Play Store. What\u2019s more alarming, is that one of these fake AV Apps has been downloaded <strong>100000+<\/strong> times already. These Apps appear to be genuine Anti-virus\/virus-removal Apps with names like<\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"> Virus Cleaner, Antivirus security,<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"> etc., but do<\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"> no<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">t have any such functionality. As per our analysis, the main purpose of these Apps is to <\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">show advertisements and increase <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">the download count.<\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">These Apps mimic the functionalities of a real Anti-virus App and have functions like <strong>\u201c<\/strong><\/span><\/span><\/span><strong><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><i>Scan Device <\/i><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><i>for Viruses<\/i><\/span><\/span><\/strong><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><strong>\u201d<\/strong>. <\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">As per our analysis, these Apps don\u2019t have any AV engines or scan capabilities except a predefined list of App<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">s<\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"> marked as malicious or clean. This list appears to be static and we haven\u2019t seen it getting updated during our analysis. <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">These Fake AV Apps don\u2019t have any functionalities related to malware scanning or identifying any other security issues. These Apps only show a fake virus detection alert to the user and eventually show advertisements.<\/span><\/span><\/p>\n<h6 style=\"text-align: center\" align=\"justify\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-88077 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/Play_images.png\" alt=\"\" width=\"888\" height=\"405\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Play_images.png 888w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Play_images-300x137.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Play_images-768x350.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Play_images-650x296.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Play_images-789x360.png 789w\" sizes=\"(max-width: 888px) 100vw, 888px\" \/><strong><em><span lang=\"en-IN\">Fig.1 &#8211; <\/span><\/em><\/strong><em><strong>Fake Mobile AV &amp; Virus Removal Apps<\/strong><\/em><\/h6>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>The interesting part of these applications is that they detect themselves as High Risk Applications.<\/b><\/span><\/span><\/span><\/p>\n<h6 style=\"text-align: center\" align=\"justify\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-88074 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/Detects_itself.png\" alt=\"\" width=\"683\" height=\"603\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Detects_itself.png 683w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Detects_itself-300x265.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/Detects_itself-442x390.png 442w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><strong><em>Fig.2<\/em> &#8211; <em><span lang=\"en-IN\">Fake Mobile AV App detecting itself as High Risk Application<\/span><\/em><\/strong><\/h6>\n<p align=\"justify\"><span style=\"font-size: medium\"><strong><span style=\"font-family: Calibri, sans-serif\"><span lang=\"en-IN\">All these Fake AV Apps have common functionalities as mentioned below &#8211;<\/span><\/span><\/strong><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">The Fake AV App contains predefined package lists, like <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>whiteList.json <\/b><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">with few whitelist package names<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>, blackListPackages.json <\/b><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">with few blacklist package names and<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b> blackListActivities.json <\/b><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">with a list of blacklisted activities<\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>. <\/b><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">This list is used for actual scanning and to show final scan results.<\/span><\/span><\/span><\/p>\n<h6 style=\"text-align: center\" align=\"justify\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-88086 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/WL_BL_list.png\" alt=\"\" width=\"684\" height=\"316\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/WL_BL_list.png 1103w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/WL_BL_list-300x139.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/WL_BL_list-768x355.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/WL_BL_list-650x301.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/WL_BL_list-789x365.png 789w\" sizes=\"(max-width: 684px) 100vw, 684px\" \/><strong><span lang=\"en-IN\"><em>Fig. 3 &#8211; Predefined static lists of Whitelisted, Blacklisted Apps and actions<\/em><\/span><\/strong><\/h6>\n<h6 style=\"text-align: left\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">It also contains a list of predefined permissions and uses it to show risks associated with other Apps.<\/span><\/span><\/span><\/h6>\n<h6 style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-88076 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/permissions.png\" alt=\"\" width=\"576\" height=\"328\" \/><strong><span lang=\"en-IN\"><em>Fig. 4 &#8211; Predefined list of permissions\u00a0<\/em><\/span><\/strong><\/h6>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">Following code snippet shows that it checks installed package names against the pre-defined static <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">Whitelists. Interestingly, this is the reason why it detects itself as <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><i>High-Risk Application<\/i><\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"> because its own package name is not present in <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>whitelist.json.<\/b><\/span><\/span><\/span><\/p>\n<h6 style=\"text-align: center\" align=\"justify\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-88073 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/code.png\" alt=\"\" width=\"970\" height=\"377\" \/><span lang=\"en-IN\"><strong><em>Fig. 5 &#8211; Code to parse JSON file<\/em><\/strong><\/span><\/h6>\n<h6 style=\"text-align: left\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">Here is the list of Fake AV Apps reported to Google by Quick Heal Security Labs. Google has removed these Apps from the Play Store now- <\/span><\/span><\/h6>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-88118 aligncenter\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2019\/09\/IOCs_up.png\" alt=\"\" width=\"739\" height=\"431\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/IOCs_up.png 739w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/IOCs_up-300x175.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2019\/09\/IOCs_up-650x379.png 650w\" sizes=\"(max-width: 739px) 100vw, 739px\" \/><\/p>\n<h6 style=\"text-align: center\"><span lang=\"en-IN\"><strong><em>Fig. 6 &#8211; IOCs<br \/>\n<\/em><\/strong><\/span><\/h6>\n<p lang=\"en-IN\" align=\"justify\"><span style=\"color: #000000\"><span style=\"font-family: Calibri, sans-serif\">Above applications disguise as &#8220;<strong>security<\/strong>&#8221; or &#8220;<strong>Antivirus<\/strong>&#8221; in their name and do nothing related to Security. As explained above, they work only on a pre-defined static Blacklist\/Whitelist of Apps and permissions. This might in-turn harm user\u2019s mobile because they don\u2019t have any capabilities to detect real malware and give a false impression of being protected to the end users. This static set of Blacklist\/Whitelist and absence of any update mechanism, confirms that these are Adwares disguised as an Anti-Virus or security related App. <\/span><\/span><span style=\"color: #000000\"><span style=\"font-family: Calibri, sans-serif\">The download count of these applications is alarming. This shows how easy it is for a malware author to entice end users into downloading junk Apps.<\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Times New Roman, serif\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\">Quick Heal Total Security for Mobile successfully detects these applications as &#8211;<\/span><\/span><\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Times New Roman, serif\"> <span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><b>Android.Blacklister.A (PUP)<\/b><\/span><\/span><b> <\/b><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\">and <\/span><\/span><\/span><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><b>Android.FakeAV.E (PUP).<\/b><\/span><\/span><\/span><\/span><\/p>\n<blockquote>\n<p align=\"justify\"><strong><span style=\"color: #7e0021\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><i>While, anything that comes FREE might come across as a temptation for you to buy, remember that FREE can also be FAKE! <\/i><\/span><\/span><\/span><span style=\"color: #7e0021\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><i>So, beware that you don\u2019t fall prey to the <\/i><\/span><\/span><\/span><\/strong><span style=\"color: #7e0021\"><span style=\"font-family: Calibri, sans-serif\"><span style=\"font-size: medium\"><span lang=\"en-IN\"><i><strong>free security software available on Play Store. Go only for trusted brands like Quick Heal when it comes to guaranteed security of your device.<\/strong><\/i><\/span><\/span><\/span><\/span><\/p>\n<\/blockquote>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\"><strong>How to stay safe from fake mobile apps &#8211;<\/strong><br \/>\n<\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\">1. Check an app\u2019s description before you download it.<\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\">2. Check the app developer\u2019s name and their website.If the name sounds strange or odd, you have all the reasons to suspect it.<\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\">3. Go through the reviews and ratings of the app. But, note that these can also be faked.<\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\">4. Avoid downloading apps from third-party app stores.<\/span><\/p>\n<p align=\"justify\"><span style=\"font-family: Calibri, sans-serif\">5. Use a reliable mobile antivirus (like Quick Heal Total Security), that can prevent fake and malicious apps from getting installed on your phone.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Quick Heal Security Labs recently spotted multiple Fake Antivirus Apps on Google Play Store. What\u2019s more alarming, is that one of these fake AV Apps has been downloaded 100000+ times already. These Apps appear to be genuine Anti-virus\/virus-removal Apps with names like Virus Cleaner, Antivirus security, etc., but do not have any such functionality. As [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":88107,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55,1653,24,354,5],"tags":[],"class_list":["post-88071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","category-antivirus","category-malware","category-mobile-security-2","category-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88071"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=88071"}],"version-history":[{"count":20,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88071\/revisions"}],"predecessor-version":[{"id":88169,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/88071\/revisions\/88169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/88107"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=88071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=88071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=88071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}