
We have found around 1,845 applications which are flagged by one or more AV vendors as including adware. This is a big number. Most of the applications were flagged by AV vendors due to their excessive inclusion of ads and deceptive practices for delivering them, including altering device settings. For example, many AV vendors flag the Airpush API as adware. Despite this fact, there are many apps within the Google Play store that include this API. This illustrates the conflicting interests that Google and the AV vendors have. It is in the best interests of Google to appease advertising companies. Google wants to encourage developers to expand offerings in their app store and developers often profit from free apps through advertising. Paid apps may also include advertising, in which case, Google takes a direct cut from from the app proceeds. Therefore, Google has plenty of incentive to allow apps with aggressive advertising practices. AV vendors on the other hand have no such incentive but are instead under pressure to show that they are adding value by identifying malicious/suspicious/unwanted content. As such, there is a big gap between Google and AV vendors when it comes to adware. Ultimately, end users are stuck in the middle as they are left to decide if they will keep or delete the apps being flagged. Other adware commonly flagged by AV vendors includes leadbolt, airmob, plankton etc.

This above chart shows adware percentage in each app store category

- Device UDID
- Device IMEI(GSM)/MEID or ESN(CDMA) number
- Device geo-location
- Personal identification information leakage
- Reads contact info.
- SMS activity
- Call activity
- Writes to external storage
- Startapp
- Zestadz
- Admob
- Inmobi
- Airpush
- Mdotm
- Jumptap
- Adwhirl
- Millennialmedia
- http://api.airpush.com/api.php
- http://api.airpush.com/model/user/getappinfo.php?packageName=
- http://api.airpush.com/redirect.php?market=
- http://api.airpush.com/testicon.php
- http://api.airpush.com/testmsg2.php
- http://api.airpush.com/v2/api.php
- http://api.airpush.com/v2/api.php?apikey=
- http://cus.adwhirl.com/custom.php?appid=%s&nid=%s&uuid=%s&country_code=%s%s&appver=%d&client=2
- http://met.adwhirl.com/exclick.php?appid=%s&nid=%s&type=%d&uuid=%s&country_code=%s&appver=%d&client=2
- http://met.adwhirl.com/exmet.php?appid=%s&nid=%s&type=%d&uuid=%s&country_code=%s&appver=%d&client=2
- http://cus.adwhirl.com/custom.php?appid=%s&nid=%s&uuid=%s&country_code=%s%s&appver=%d&client=2
http://www.virustotal.com/file/61ac5c6e1d65c83a24f0cbd04522cf191dd482f4e4880e834e4eb98857355f15/analysis/
http://www.virustotal.com/file/35f4710cb074545fe17ce6b2b210c7159384eaec4ee4b77a6f084b28d18d6973/analysis/
http://www.virustotal.com/file/cf1bc23afbdd5b451c883c9e2f728dcf4afc4e110945b45627b04101b9d41552/analysis/
http://www.virustotal.com/file/bae10ad31a6a9d9e5131848e1f85d3ad5abc44b9bc0bafad1cbbb958bf65b265/analysis/
http://www.virustotal.com/file/97bbc480ba361fa483fa4954a52acbcc8c937bd0152d09058fcd7a31a014c69c/analysis/
http://www.virustotal.com/file/aa968157319a85b2c7ee9fe9a405184c5dd1ce0ab5971e13e33422b83bf0cd2e/analysis/
http://www.virustotal.com/file/885a97cdae23b1c0989cf8b29c01640620504c199e7c1724dcb3b2aaf2ff4344/analysis/
http://www.virustotal.com/file/6233cb4641c1042a1d8880e4843f1b848fcba567c47a6649cb1d51db04c460ee/analysis/
http://www.virustotal.com/file/5fe938ccc2fe4668795f3ea527a0c16b5a9fc7d78d70ee3bd43d18b344bd96db/analysis/
http://www.virustotal.com/file/f39cb97d259b2e4c9fde915f3792e34a700a74c97b3125c4772984a62e592794/analysis/
http://www.virustotal.com/file/360efd96e5db9ac8683930eb445ac76435b39ac38ef8ed13320207822766f7e5/analysis/
http://www.virustotal.com/file/2e941c7ff48409c8e139aec0a3db3af84676a2fc6beea7877689eb43cee56363/analysis/
http://www.virustotal.com/file/d6675e3b833c8f4805f99198dc7ba85810d34041e08ceb72314b5b8b3ba32c12/analysis/
http://www.virustotal.com/file/4a939c5a1f23ead3cd7a4bda7aebc7ca750fdc50484b110c34bb53f72306c892/analysis/
http://www.virustotal.com/file/16f7e29768665a7f66c666f035ce855bcf1e4f2640375cc63b96ddba71fde49b/analysis/
http://www.virustotal.com/file/d2196932ad4c343574cf2ef0dd51410a0052638e864c5e7caf1d12ed36f3e775/analysis/
http://www.virustotal.com/file/fc6cad34884e56a44ffa0de4acfd627113aa47fac80130e4c726486427c54010/analysis/
http://www.virustotal.com/file/4ffc0d56ae32d36839b97e5bf4420bfe50b1968104f82f31bcbf3f27e9275c7d/analysis/
http://www.virustotal.com/file/d5d75fd12bc7aae28603f883eb39eacf784a616e16f1395696701581de014638/analysis/
http://www.virustotal.com/file/6a4bebaa2bb21634aab5082362e22ba022eeaa143610aa3d3184dda996eb59ae/analysis/
http://www.virustotal.com/file/936978dce7a042efb7b1aebc6f8ed3b699457ccb6eb161020aae537cbfb836ce/analysis/
http://www.virustotal.com/file/9603b8b2b74b84292e7275eee5311bbb6c959898bec26d438e73dfc9405d6784/analysis/
http://www.virustotal.com/file/5220608a893ddead034fb8f219ec763dfe9406c52487d13b288e4e81eac67078/analysis
http://www.virustotal.com/file/f4e9ba663b5a9b2e95e22925799479c36b9fd55b57ce848ea1b79c6392ea91e5/analysis/
- Harvests excessive personally identifiable information
- Performs unexpected actions in response to ad clicks without appropriate user consent (appropriate user consent entails providing a clear alert in the application that the user canaccept or decline before any behavior takes place)
- Collects IMEI numbers, UDIDs or MAC addresses
- Initiating phone calls and SMS messages
- Changing wallpaper and ringtones
- Leaks location information
- Leaks email addresses
- Leaks personal information such as contacts, birthdays, calendar appointments, etc