The Album by Google Photos Ad Clicker | xxxThe Album by Google Photos Ad Clicker – xxx
菜单

The Album by Google Photos Ad Clicker

十月 14, 2018 - BleepingComputer

A malicious app called “Album by Google Photos” was found in the Microsoft Store today that pretends to be from Google. This app pretends to be part of Google Photos, but is actually an ad clicker that repeatedly opens hidden advertisements in Windows 10.

This free Album by Google Photos app claims to be created by Google LLC and has a description of “Finally, a photos app that’s as smart as you.”.  You can see an image of its Microsoft Store page below.

The Album by Google Photos Ad Clicker
Microsoft Store Page

As this is an ad clicker, the reviews for the app are not very good. One review calls it a “Fake App” and another is titled “Fake, do not install”. 

The Album by Google Photos Ad Clicker
Reviews

Below we will dig down and explain how the ad clicker works and the types of advertisements that are displayed.

The Album by Google Photos Ad Clicker

The Album by Google Photos app is a PWA app (progressive web app) that acts as a front end to Google Photos, but with a bundled ad clicker. While the app is running, this ad clicker will repeatedly connect to remote hosts and display advertisements in the background in order to generate revenue for the developers.

The ad clicker component consists of three files located in the app’s folder called Block Craft 3D.dll, Block Craft 3D.exe, and Block Craft 3D.xr. You can see these files in the image of the folder below.

The Album by Google Photos Ad Clicker
Album by Google Photos Folder

When a user starts the Album by Google Photos app they will be greeted by a screen asking them to login to Google Photos. This is a legitimate login screen from Google and though I did not see any indications that your logins are being stolen, I would still not advise logging into Google Photos with this app.

The Album by Google Photos Ad Clicker
Google Photos Login Page

In the background, the app will then connect to http://11k.online/Ad/constants/9n0wkj6hpz86.json and download a configuration file. This configuration file, shown below, contains settings on how often ads should be displayed, the URLs to the advertisement pages, and more. The configuration file also indicates that ads may be displayed directly in the app, but BleepingComputer did not see any when testing the app.

The Album by Google Photos Ad Clicker
Part of the Configuration File

After the app reads the configuration file, it will connect to the various “AdBanner” URLs and display them in the background. You can see in the Fiddler traffic below the app connecting to each of the ad URLs.

The Album by Google Photos Ad Clicker
Fiddler Traffic

When displaying an advertisement, it will do so in the background and not display it to the user. So if the advertisement has audio, like a tech support scam, the user will hear it but not be able to see where it is coming from. This can be eerie when your computer starts telling you that it is infected because of a tech support scam ad, but you see no indication what application is generating the warning.

When testing the ad URLs from the configuration file, the advertisements that were displayed were very similar to what we would see from adware. These ads included tech support scams, tons of pages pushing unwanted Chrome extensions, fake Java and Flash installers, blogs who are buying traffic, and other low quality sites.

For example, below you can see a tech support scam opened by the app that is pushing an unwanted system optimizer program by stating Windows is vulnerable.

The Album by Google Photos Ad Clicker
Example of a hidden ad

It is not known how an app like this could have passed the review process by Microsoft considering it pretends to be from Google. Furthermore, as the reviews state that this is malware or malicious, you would think it would have triggered an alert to review it further.

BleepingComputer has contacted Microsoft with questions regarding the review process, but had not heard back from Microsoft by the time of this publication. This article will be updated with Microsoft’s statement if we hear back from them.

H/T: GeekLatest.com

Related Articles:

Windows 10 Photos App Gets New Image Editing UI in Fast Ring

You May Soon Be Able to Log Into Windows 10 Using a Google Account

Windows 10 Audio Not Working After Installing Latest Windows Updates

Google Accidentally Pushed Internal November 2018 Security Update to Pixel User

HP PCs Getting WDF_VIOLATION BSOD After Installing Windows 10 Updates

Forum Rules and Posting Guidelines

Bleeping Computer® is a community of individuals of all ages who are here to learn new information, to help each other, and to help their fellow peers. With that in mind, we ask that all members please follow these simple rules in order to create an atmosphere where everyone feels comfortable.

The rules are as follows:

Violation of any of these rules can lead to a banning of the user from our Web Site and a deletion of their account. The consequences will be determined by the Staff on a case by case basis.

When posting you agree that the administrators and the moderators of this forum have the right to modify, delete, edit or close any topic, signature, account, or profile data at any time that they see fit. If you have any questions concerning this, please do not start a new thread, but rather private message to an administrator or moderator.

contact us


Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51