{"id":113,"date":"2020-11-18T10:40:56","date_gmt":"2020-11-18T10:40:56","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=113"},"modified":"2023-02-07T07:25:08","modified_gmt":"2023-02-07T07:25:08","slug":"pua-android-notifyer-adware","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/pua-android-notifyer-adware\/","title":{"rendered":"PUA.Android.Notifyer.Adware"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: PUA (Potential Unwanted Application)<\/p>\n<p><strong>Degree of destruction<\/strong>: average<\/p>\n<p><strong>Prevalence rate: <\/strong>average<\/p>\n<h3>What is PUA?<\/h3>\n<p>These are malware that often includes adware or install toolbars or such aims but is not like other malicious malware. This category of malware maybe perform some actions which are not approved or expected by the user and are malicious but some users believe that the advantages of using these kinds of applications are more than their defects and consider the arbitrary use of them has no problem.<\/p>\n<h3>What is the Notifier malware family?<\/h3>\n<p>Notifier malware families send ads notification to users by using notification services. If a user clicks on each of the notifications on the phone, the advertising page will open in the browser.<\/p>\n<h2>Technical Explanation<\/h2>\n<p>The name of this application is Maddahi- e-Ashura and uses advertising services named Pushe to show its notifications and advertising links. Pushe is a push notification service related to an Iranian company named Ronash (Ronash. co and pushe. co)<\/p>\n<p>This service is embedded for mobile and web developers to show their notifications so they can send them to their users according to rules set in the company. Application developers will send notifications to their subscribers by user panel which this company provides them, but these notifications can be annoying and destructive, without user permission and acceptance and especially without necessary checking based on what title and content they have.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-115\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/adware.png\" alt=\"\" width=\"753\" height=\"439\" \/><\/p>\n<p>After running the program, the different sections of the application will be run by recalling some files that are in the application assets folder of the program. For different sections of this application, it needs to connect to the specified address to be executed. For instance, it sends a message to the user that to play the videos, the user should download the player file from \u201cHTTPS [:]\/\/myket.ir\/app\/ com.Devi.MXplayer \/? Lang =fa\u201d (right now there no other application in this address). By Telegram channel https[:]\/\/t.me\/ myappforyou\u201d you can connect with the developers and if the user does not have the Telegram app on the phone, the user will encounter this message: \u201cthere is no Telegram on your phone\u201d.<\/p>\n<p>Regarding static checking of the application, according to manifest.xml, about permissions and application and then after checking application code, it is easy to see this application using notification sending services. Also, the type that it uses to send its notifications is \u201cJSON\u201d which means sending desired content in the form of JSON to the application. According to the notification sending service of the Pushe to the user\u2019s phone, sending content (title, text, icon, image, etc.) to the user is possible.<\/p>\n<p>Also, the application uses the user\u2019s location to send purposeful notifications (advertising). The use Token of this application in Pushe is as follows:<\/p>\n<p><code>&lt;meta-data android:name=\"co.ronash.pushe.token\" android:value=\"PUSHE_48483076454\"\/&gt;<\/code><\/p>\n<p><code>&lt;uses-permission android:name=\"android.permission.ACCESS_COARSE_LOCATION\u201d\/ &gt;<\/code><\/p>\n<ul>\n<li>Sending\/receiving data as JSON:<\/li>\n<\/ul>\n<p><code>&lt;service android:name=\".pushejsonservice\"\/&gt;<\/code><\/p>\n<p><code>&lt;receiver android:name=\".pushejsonservice$pushejsonservice_BR\" android:permission=\"com.google.android.c2dm.permission.SEND\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"android.intent.action.BOOT_COMPLETED\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"com.google.android.c2dm.intent.RECEIVE\"\/&gt;<\/code><\/p>\n<p><code>&lt;category android:name=\"moharam.madahi.mv\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"com.google.android.c2dm.intent.REGISTRATION\"\/&gt;<\/code><\/p>\n<p><code>&lt;category android:name=\"moharam.madahi.mv\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/receiver&gt;<\/code><\/p>\n<ul>\n<li>Receiving system boot permission for automatic re-activation of application after boot and also restarting the Pushe service when restarting the system:<\/li>\n<\/ul>\n<p><code>&lt;uses-permission android:name=\"android.permission.RECEIVE_BOOT_COMPLETED\"\/&gt;<\/code><\/p>\n<p><code>&lt;receiver android:name=\".pushejsonservice$pushejsonservice_BR\" android:permission=\"com.google.android.c2dm.permission.SEND\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"android.intent.action.BOOT_COMPLETED\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"com.google.android.c2dm.intent.RECEIVE\"\/&gt;<\/code><\/p>\n<p><code>&lt;category android:name=\"moharam.madahi.mv\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"com.google.android.c2dm.intent.REGISTRATION\"\/&gt;<\/code><\/p>\n<p><code>&lt;category android:name=\"moharam.madahi.mv\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/receiver&gt;<\/code><\/p>\n<ul>\n<li>The ability to receive application updates by Pushe service; the developer can update the application, add more feasibilities and also easily replace the previous application with the new application by using this service.<\/li>\n<\/ul>\n<p><code>&lt;receiver android:name=\"co.ronash.pushe.receiver.UpdateReceiver\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;action android:name=\"android.intent.action.PACKAGE_REPLACED\"\/&gt;<\/code><\/p>\n<p><code>&lt;data android:path=\"moharam.madahi.mv\" android:scheme=\"package\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/receiver&gt;<\/code><\/p>\n<ul>\n<li>One can run JSON code on the victim device and extract some data from the user\u2019s phone by using the Pushe service, for example, the information about IP, city, operator, and other user\u2019s data.<\/li>\n<\/ul>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/4.ifcfg.me\/json&#8221;, &#8220;ip&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/ifcfg.me\/json&#8221;, &#8220;ip&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/ipinfo.io\/json&#8221;, &#8220;ip&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/ip-api.com\/json\/?callback=yourfunction&#8221;, &#8220;query&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;https:\/\/api.ipify.org?format=json&#8221;, &#8220;ip&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/icanhazip.com\/&#8221;, &#8220;&#8221;));<\/p>\n<p>add(new AbstractMap.SimpleEntry(&#8220;http:\/\/ip.ronash.co\/geoip&#8221;, &#8220;ip&#8221;));<\/p>\n<ul>\n<li>Other possibilities of the application which will be accessible due to using Pushe service:<\/li>\n<li>Attain the most important data from the user\u2019s phone such as UUID, DeviceID, and unique specification for each number of phone active SIM card.<\/li>\n<li>Attain information about the user\u2019s phone network and check that it is active.<\/li>\n<\/ul>\n<p>android.net.ConnectivityManager.getActiveNetworkInfo<br \/>\nandroid.net.NetworkInfo.isConnectedOrConnecting<br \/>\nandroid.net.wifi.WifiManager.getConnectionInfo<br \/>\nandroid.net.ConnectivityManager.getNetworkInfo<br \/>\nandroid.net.NetworkInfo.isConnected<br \/>\nandroid.net.NetworkInfo.getState<\/p>\n<ul>\n<li>Also, in this application, the ready library \u201cArabLib\u201d has been used. The general job of this section is:<\/li>\n<li>AriaCustomShareList: by using this section, a developer can add this application to the list of applications in the user\u2019s phone that can share text or files. So, as soon as the user desire to share a text or file, this application will be open as the phone&#8217;s main chosen application and the user choose an application to share with.<\/li>\n<li>AriaMarkets\n<ul>\n<li>Opening the application page in Caf\u00e9 Bazar, Iran apps, Myket, and Pars hub.<\/li>\n<li>Opening commenting page to application in Caf\u00e9 Bazar, Iran apps, Myket, and Pars hub.<\/li>\n<li>Opening application developer page in Caf\u00e9 Bazar, Iran apps, Myket, and Pars hub.<\/li>\n<\/ul>\n<\/li>\n<li>AriaMultipleSharing: by using this class you can share any number of tiles simultaneously. These files can be chosen from any format. For instance, sharing 5 or 10 or any number of photos simultaneously to applications that are supporting this possibility such as Telegram, Line, Zapya, etc.<\/li>\n<li>Also, attaining the user\u2019s phone information by B4a (B4a is a powerful tool in mobile programming, which programmers can use in their apps).<\/li>\n<li>Attain information such as: following the list from the user\u2019s phone by using the phone.CallLogWrapper\n<ol>\n<li>getAllCalls: attain a complete list of users\u2019 phone calls based on their specifications (number, ID, Call time duration, name, day, etc.)<\/li>\n<li>GetEmails: returns the contact\u2019s email address as the key and all types of emails as their values.<\/li>\n<li>GetPhones: returns all contact\u2019s phone numbers as a key and all types of the stored phone for them will be their values.<\/li>\n<li>GetPhoto: if there is any attached image for each contact will bring them back and if there is no image of the contract, will return Null.<\/li>\n<li>GetAllContacts: returns the user\u2019s phone contact list.<\/li>\n<li>FindByMail: checks receiving and sending an email of the user that their sender\/ receiver is harmonized with the phone contact list<\/li>\n<li>GetLine1Number: returns the first phone number related to each person and stored in a SIM card.<\/li>\n<\/ol>\n<\/li>\n<\/ul>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p>To make sure that the system is safe, install <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> and keep its database file and scan it.<\/p>\n<p><strong>Methods of preventing phone infection <\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Avoid downloading and installing any application from unauthorized resources\/markets.<\/li>\n<li style=\"min-height: 1.5em\">Note the requested permissions, when installing the mobile application.<\/li>\n<li style=\"min-height: 1.5em\">Continuously back up your saved data and files.<\/li>\n<li style=\"min-height: 1.5em\">Do not use an unofficial version of applications. Applications such as Telegram, and Instagram have many unofficial versions and most of them release through Telegram channels.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: PUA (Potential Unwanted Application) Degree of destruction: average Prevalence rate: average What is PUA? These are malware that often includes adware or install toolbars or such aims but is not like other malicious malware. This category of malware maybe perform some actions which are not approved or expected by the user and&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,8],"tags":[24],"class_list":["post-113","post","type-post","status-publish","format-standard","hentry","category-adware","category-pua","tag-android"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=113"}],"version-history":[{"count":12,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/113\/revisions"}],"predecessor-version":[{"id":1236,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/113\/revisions\/1236"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}