Teardown: A Mobile Install Report for SDK Spoofing and Click Injection
Objective: Given a synthetic-realistic mobile install and post-install event report, distinguish genuine app install fraud (SDK spoofing, click injection) from normal attribution variance.
PolicyBazaar's app install campaign shows a strong install number this month, but the insurance-quote team says lead quality from app users has cratered.
Review the install-to-event report, identify which installs show fraud signatures, and recommend which ad network to pause.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free, sufficient for a sampled report of this size
Paid upgrades (optional, faster/deeper)
Turns this one-time teardown into an ongoing weekly fraud-monitoring view
No access? A saved Google Sheets pivot table refreshed weekly
The process
Specimens to review
Compare Network C to the Network A control group in this report. What does the combination of post-install silence and click-to-install timing tell you?
PolicyBazaar app install report, Network C, 500 installs sampled Metric Value Installs attributed to Network C 500 Installs with any post-install event 41 (8.2%) Installs with a quote-form start 6 (1.2%) Average click-to-install time 1.4 seconds Installs attributed to Network A (control) 500 Network A: installs with post-install event 412 (82.4%) Network A: average click-to-install time 41 minutes
Specimen: synthetic, realistic
This is the same Network C from a different report view. What two additional red flags does this geo and timing breakdown add to the case for pausing this network?
PolicyBazaar Network C, weekly click summary by geo Geo Clicks Target Geo? India-Tier1 2,100 Yes India-Tier2 3,400 Yes Unknown/VPN 8,900 No, campaign targets India only Click timing distribution: 61% of all Network C clicks landed between 2:00-2:15 AM IST
Specimen: synthetic, realistic
Final deliverable
A written case for pausing Network C, citing the post-install silence rate, click-to-install timing, geo mismatch, and click timing clustering as combined evidence.
See a reference example
Nubank app install fraud review (excerpt) Network D: 91% post-install silence, 2.1 sec average click-to-install time, 58% clicks from unlisted geo Recommendation: Pause Network D immediately, request MMP raw log export for the last 30 days before any refund negotiation
Success criteria
You're done when you can:
- Correctly identifies post-install silence rate as an SDK spoofing signal
- Correctly identifies sub-second click-to-install timing as a click injection signal
- Cites the geo mismatch and click timing cluster as corroborating, not standalone, evidence