SHA1:
- 5430a8a02e4810ce9624500454c648efe9cedce4
Malware for Android mobile devices. Its primary purpose is to show ads whenever the screen of the affected device is on.
Android.HiddenAds.752 disguises itself as a system application. It may be installed by the Trojan Android.DownLoader.828.origin after downloading from the server https://cdn.***rr.us.
After the first launch, Android.HiddenAds.752 displays an application startup window for a few seconds, then closes the window and removes its icon from the apps list on the home screen. To ensure its autorun, the Trojan monitores the following system events:
- android.net.conn.CONNECTIVITY_CHANGE — Internet connection or disconnection.
- android.intent.action.BOOT_COMPLETED — operating system loading.
After the successful launch, Android.HiddenAds.752 registers a broadcast receiver to receive the android.intent.action.SCREEN_ON system event and thus monitor when the device screen powers up. Every time the screen of the infected smartphone or tablet is active, the Trojan downloads and displays ads using the com.google.android.gms.ads.InterstitialAd class.