{"id":111,"date":"2020-11-18T10:29:48","date_gmt":"2020-11-18T10:29:48","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=111"},"modified":"2023-02-07T07:20:55","modified_gmt":"2023-02-07T07:20:55","slug":"pua-android-adware-ghanon","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/pua-android-adware-ghanon\/","title":{"rendered":"PUA.Android.Adware.Ghanon"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type:<\/strong> PUA (potential unwanted Application)<\/p>\n<p><strong>Degree of destruction:<\/strong> average<\/p>\n<p><strong>Prevalence:<\/strong> average<\/p>\n<h3>What is PUA?<\/h3>\n<p><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">These are malware that often includes adware or install toolbars or such aims but is not like other malicious malware. This category of malware maybe perform some actions which are not approved or expected by the user and are malicious but some users believe that the advantages of using these kinds of applications are more than their defects and consider the arbitrary use of them has no problem.<\/span><\/p>\n<h2>Technical Explanation<\/h2>\n<p>The name of this application is \u201claw in simple words\u201d and uses an advertising service named \u201cPushe\u201d to show notifications and advertising links. Pushe is a Push notification sender service and belongs to an Iranian company name Ronash (Ronash. co and pushe. co). This service is for mobile and web developers to show their notifications in their applications so they can send some notifications for their applications based on the set rules in the company.<\/p>\n<p>Application developers send notifications to their customers through the user panel that the company provides them, but these notifications without notifying and approval by the users can be annoying or malicious, especially without necessary reviews under what title and with what content they are presented.<\/p>\n<p>Inside the application, there is a button named \u201cmedical channel\u201d to advertise this channel and lead the user to a telegram channel (https[:]\/\/t.me\/anatome), but the name and the contents of this channel are about law and does not relate to medical contents. Since it is not obvious what contents and under what titles are provided to users, it will be dangerous in turn.<\/p>\n<p>Also, in this application the advertising links of a filtered site are obvious. Here you can see the advertising links of this application:<\/p>\n<p>http[:]\/\/gamejoo.com\/tabligh.html<br \/>\nhttp[:]\/\/gamejoo.com\/tabligh.html?bazaar<\/p>\n<p>Both links are related to the \u201cJoApp\u201d application builder whose job, as they call it, is to build different applications, showing notifications and etc. which now are filtered.<\/p>\n<p>Also, in this application, for advertising, important information will be fetched from users; actually, by using methods called from TelephonyManager class, the app will access the following information:<\/p>\n<p>getNetworkType: accessing network information<\/p>\n<p>getSimOperatorName: accessing SIM card operator information<\/p>\n<p>getDeviceID: accessing to user\u2019s phone&#8217;s unique signature<\/p>\n<p>And also by using the getLastKnownLocation method, it can access to user\u2019s local place and geographical situation.<\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p>To make sure that the system is safe, install<a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\"> Padvish antivirus<\/a> and keep its database file and scan it.<\/p>\n<p><strong>Methods of preventing phone infection <\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Avoid downloading and installing any application from unauthorized resources\/markets.<\/li>\n<li style=\"min-height: 1.5em\">Note the requested permissions, when installing the mobile application.<\/li>\n<li style=\"min-height: 1.5em\">Continuously back up your saved data and files.<\/li>\n<li style=\"min-height: 1.5em\">Do not use an unofficial version of applications. Applications such as Telegram, and Instagram have many unofficial versions and most of them release through Telegram channels.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: PUA (potential unwanted Application) Degree of destruction: average Prevalence: average What is PUA? These are malware that often includes adware or install toolbars or such aims but is not like other malicious malware. This category of malware maybe perform some actions which are not approved or expected by the user and are&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,8],"tags":[],"class_list":["post-111","post","type-post","status-publish","format-standard","hentry","category-adware","category-pua"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=111"}],"version-history":[{"count":5,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/111\/revisions"}],"predecessor-version":[{"id":1235,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/111\/revisions\/1235"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}