ChompSMS flagged as malware by several AV's

Search This thread

Omnius001

Member
Jan 31, 2012
32
10
Hi ppl in the xda hood

I just write to let you know that ChompSMS has now been flagged as malware, both on 2 phone here locally with Avast as scanner, and subsequently by upload to Virustotal, and flagged by some of the major names too.
This concerns both the 5.30 and the update from tonight to v5.31

As Im new, I cannot post urls, but you can dump the apk from both versions, upload for a scan, and have a look at the report yourself from virustotal dot com


XDA must decide if its worth it alarming the community, but better safe than sorry, right?
I guess it could be a false positive, and I do know things should not be rushed about accusations of malware developing, but seeing that several of the major scanners is flagging it both before and after the update, certainly raises my concerns.

I hope those of you who knows your way around decompiling and analyzing code will look into this, so that we can get more eyes on it than "just" the AV companies reports.

Sincerely, Omnius


After a bit of micro-investigating I have so far found these domains in the code, so if you do HAVE to use ChompSMS, (I do) you can ad them to your HOST file, just for the sake of it.
I dont know when or why they will be used but as they are in the code, there is a potential connection lurking in it. Decide for yourself, untill further ppl have a close look than mine.
Im not a dev of any sort, but I do know how to poke around to learn. Therfore please do not just take my words for granted until more competent ppl here have their say.
I do know that a few of these is for "normal" android app ads, and analytics and so on, but these are my finding so far, so filter our what you like it to connect to yourself. If you dont mind ads connections in-app, serve your wish, so to speak.


millennialmedia.com
gateway.textfreek.com
report.bitesms.com
nexage.com
inapp.chompsms.com
adserver.com
greystripe.com
smsgateway.chompsms.com
m.advc.us
cvt.mydas.mobi
rest.starttalking.com
mobileads.google.com
 
Last edited:
  • Like
Reactions: matthenry87

nosit1

Senior Member
May 19, 2010
905
108
Arizona
All of them appear to be valid to the program. Half are ad for ads, the other half are for functionality in ChompSMS.
 

zelendel

Senior Member
Aug 11, 2008
23,360
20,609
OnePlus 6T
OnePlus 9
I would be careful on using go SMS as well.

Antivirus apps will pick up any app that by passes any normal OS use. This always has been and always will be the case.

Anything with ads will always be flagged as it connects to an unknown server.
 
Last edited:

crackers8199

Senior Member
May 11, 2010
697
95
I would be careful on using go SMS as well.

Antivirus apps will pick up any app that by passes any normal OS use. This always has been and always will be the case.

Anything with ads will always be flagged as it connects to an unknown server.

chomp was never flagged before the 5.30 update a few days ago...

really bothers me, i love chomp. i donated to remove the ads. i'm hoping they fixed it with 5.31 and the virus scanners are just still reporting it as a false positive. until it's sorted out though, i uninstalled...
 

BigMatza

Senior Member
Mar 24, 2008
155
36
OnePlus 6T
Lemme tell you...

I noticed the new permissions requested in 5.30 (special access to browser history/bookmarks), and kinda shrugged it off. Dumb move on my part. Immediately upon launching 5.30, I get a notification from ADWLauncher that it cannot fit a new shortcut on my desktop (because the main page was full). So I'm naturally all like WTF... so I flip through my desktop pages to notice that ChompSMS had made itself a shortcut to searchmobileonline.com.

I also heard that it replaces your default browser home page and search method with the same. I use xScope exclusively, so I haven't been able to check that yet.

Delicious, Inc. has really crossed the line with this latest stunt. What were they thinking!? ChompSMS was the best Android messaging app IMHO. Why jeopardize such a great reputation? If it's money they were after, I'd imagine they could've raked in a nice bundle of cash for selling the product to another company.
 

ArdW

Senior Member
Jan 8, 2014
105
3
Does anyone have a copy of this apk that I could take a look at?

I know this is a old thread but better than starting a new one.

I would like to ask if there is any news on this. I love chomp SMS, imo the best messanger for my taste. I have bought the pro version, to stay away from ads and unnecessary internet data. I have chomp on a brand new phone, no sim card, no messages, just activated chomp and my firewall instantly found chomp active on internet. I watched this for some time and really chomp was trying to do something even I did nothing with it.

important note: there is no data mining in any of their terms. Or at least I did not find anything.

So I contacted chomp about the behavior and they said that "they never seen this before" and suggested reinstall. I did, didn't help.

On the second try, they told me that it is connecting because of ads, but I had the pro version (and they knew it). So no luck.

After the third attempt, they said that chomp is sending once a day info that it is installed so they know how many installs they have. :rolleyes:

This sucks a lot. Security concerns appears instantly.

I think it would be worthy to literally sniff a bit around this, since so many people is using chomp.
 

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    Hi ppl in the xda hood

    I just write to let you know that ChompSMS has now been flagged as malware, both on 2 phone here locally with Avast as scanner, and subsequently by upload to Virustotal, and flagged by some of the major names too.
    This concerns both the 5.30 and the update from tonight to v5.31

    As Im new, I cannot post urls, but you can dump the apk from both versions, upload for a scan, and have a look at the report yourself from virustotal dot com


    XDA must decide if its worth it alarming the community, but better safe than sorry, right?
    I guess it could be a false positive, and I do know things should not be rushed about accusations of malware developing, but seeing that several of the major scanners is flagging it both before and after the update, certainly raises my concerns.

    I hope those of you who knows your way around decompiling and analyzing code will look into this, so that we can get more eyes on it than "just" the AV companies reports.

    Sincerely, Omnius


    After a bit of micro-investigating I have so far found these domains in the code, so if you do HAVE to use ChompSMS, (I do) you can ad them to your HOST file, just for the sake of it.
    I dont know when or why they will be used but as they are in the code, there is a potential connection lurking in it. Decide for yourself, untill further ppl have a close look than mine.
    Im not a dev of any sort, but I do know how to poke around to learn. Therfore please do not just take my words for granted until more competent ppl here have their say.
    I do know that a few of these is for "normal" android app ads, and analytics and so on, but these are my finding so far, so filter our what you like it to connect to yourself. If you dont mind ads connections in-app, serve your wish, so to speak.


    millennialmedia.com
    gateway.textfreek.com
    report.bitesms.com
    nexage.com
    inapp.chompsms.com
    adserver.com
    greystripe.com
    smsgateway.chompsms.com
    m.advc.us
    cvt.mydas.mobi
    rest.starttalking.com
    mobileads.google.com