Aggressive in-app advertising in Android – 10 minute mail

Recently, we’ve been noticing ever more dubious advertising libraries in popular apps on Google Play. The monetization methods used in such SDKs can pose a threat to users, yet they pull in more revenue for developers than whitelisted ad modules due to the greater number of views. In this post we will look into a few examples of suspicious-looking ad modules that we discovered in popular apps earlier this year.

One of the applications we researched was a popular app that allows users to ask questions anonymously. Integrated into the code of an earlier version of the app was the module com.haskfm.h5mob. Its task was to show intrusive advertising (in breach of the Google Play rules) when the user unlocked the phone.

Code for displaying ads when the screen is unlocked

In other words, the module can show ads whether the app is running or not. The ad can simply pop up on the main screen all on its own, causing a nuisance for the user. We passed our findings to the app developers, who promptly removed com.haskfm.h5mob. However, this module remains interesting from technical point of view.

In this application to receive advertising offers, the module connects to the C&C servers, whose addresses are encrypted in the app code.

Decrypting the C&C addresses

The C&C response contains the display parameters and the platforms used to receive ads.

The most interesting parameter here is appintset, which specifies the delay before displaying the first ad after installation of the app. In our example, it was set to 43.2 million milliseconds, or 12 hours. This delay makes it much harder for the user to find the culprit for all the ads that suddenly appear on the screen. Also, this technique is frequently used by cybercriminals to trick automatic protection mechanisms, such as sandboxes in app stores. The main parameters are followed by an extensive list of addresses of advertising providers with request parameters for receiving offers.

Earlier we detected a similar ad module in apps without a payload. For example, the code in the app com.android.ggtoolkit_tw_xd, which we detect as not-a-virus:AdWare.AndroidOS.Magic.a, contains the same features and is managed from the same C&C as the com.haskfm.h5mob module. However, this adware app has no graphical interface to speak of, is not displayed in the device’s app menu, and serves only to display intrusive ads as described above. It looks something like this: adware_in-app_video.mp4

While, as previously mentioned, the creators of the application described in the first example, promptly removed the ad module, not all Android developers are so conscientious. For example, the Cut – CutOut & Photo Background Editor app does not hesitate to treat users to a half-screen ad as soon as the smartphone is unlocked, regardless of whether the app is running or not.

Likewise the Fast Cleaner — Speed​Booster & Cleaner app.

In both apps, the library com.vision.lib handles the display of advertising.

Display of advertising

At the time of writing this article, the developers of both apps had not responded to our requests.

Note, however, that adware is not always about greed. Often, app developers are not versed in advertising SDKs and lack the necessary skills to test an integrated advertising library, and therefore may not fully understand what they are adding to their code. The danger for users here is that a dubious library could unexpectedly make its way into an app as part of a rank-and-file update. And it becomes extremely difficult to figure out which of a dozen recently updated apps is the source of intrusive advertising.

IOCs

MD5

1eeda6306a2b12f78902a1bc0b7a7961 – com.android.ggtoolkit_tw_xd
134283b8efedc3d7244ba1b3a52e4a92  – com.xprodev.cutcam
3aba867b8b91c17531e58a9054657e10 – com.powerd.cleaner

С&C

ti.domainforlite[.]com/st/hg
uu.domainforlite[.]com


Temp Mails (https://tempemail.co/) is a new free temporary email addresses service. This service provide you random 10 minutes emails addresses. It is also known by names like: temporary mail, disposable mail, throwaway email, one time mail, anonymous email address… All emails received by Tempmail servers are displayed automatically in your online browser inbox.

Apple’s ‘Bounce’ AirPods Ad Wins ‘Best of Advertising’ Award

Apple’s creative “Bounce” ad designed to highlight the AirPods took top honors in the 99th annual ADC (Art Director’s Club) awards for advertising, earning the “Best of Discipline” award along with two Gold Cube awards in the craft in video and branded content categories.


Released in June 2019, the ad features a bored man who pulls his ‌AirPods‌ off of their wireless charging pad and then pops outside to bounce over street items that are bouncy like a trampoline. The song “I Learnt Some Jazz Today” plays in the background while he bounces throughout town.

The ad was created by Apple’s longtime advertising partner TBWAMedia Arts Lab, and the One Club website where awards are announced has a behind the scenes video that gives some insight into how it was filmed. All of the physical bouncing was done in camera with various props, with a city set built in an airport hangar.


Apple content won other awards too. Apple’s AirPods Pro ads on Apple Stores worldwide earned a Silver Cube award, the opening theme for “The Morning Show” won a Bronze Cube award, and the “Snowbrawl” video won a Bronze Cube award.

Temp Mails (https://tempemail.co/) is a new free temporary email addresses service. This service provide you random 10 minutes emails addresses. It is also known by names like: temporary mail, disposable mail, throwaway email, one time mail, anonymous email address… All emails received by Tempmail servers are displayed automatically in your online browser inbox.

AT&T Might Finally Ditch ‘5GE’ Marketing Following National Advertising Board Recommendation

Following a challenge from T-Mobile, the National Advertising Review Board today announced that it has recommended that AT&T discontinue its “5G Evolution” or “5GE” marketing claims, noting that they may be misleading to consumers.


“5G Evolution” is the branding that AT&T has been using in areas where the latest 4G LTE technologies like three-way carrier aggregation, 4×4 MIMO, and 256-QAM are available. Since the release of iOS 12.2, AT&T has been displaying a “5GE” label in place of “LTE” on iPhones that connect to its network in areas where those technologies are available.

AT&T stated that it “respectfully disagrees” with the decision, but it will comply with the recommendation as a “supporter of the self-regulatory process,” the National Advertising Review Board said. This could mark the end of the “5GE” label on iPhones, although it is unclear how long that may take. We’ve reached out to AT&T for comment.

AT&T has since launched its actual 5G network in select cities in the United States. The first 5G-enabled iPhones are expected to launch later this year.

Temp Mails (https://tempemail.co/) is a new free temporary email addresses service. This service provide you random 10 minutes emails addresses. It is also known by names like: temporary mail, disposable mail, throwaway email, one time mail, anonymous email address… All emails received by Tempmail servers are displayed automatically in your online browser inbox.