Update 08/14: The campaign has moved to another advertiser (AOL) and new Azure domain: Malvertising URL: imp.bid.ace.advertising.com/{redacted}pmcpmprice=0.545/{redacted}dref=http://www.ebay.com/sch/i.html?_nkw=jazzy+wheelchair+battery&_pgn=3&_skc=100&rt=nc First redirection (Azure website)…
Tag: website
Of Counterfeit Sites and Denali Jackets
At hpHosts, Malwarebytes’s trusted blacklist of malicious sites, we also receive tip-offs or reports from users about one or two dodgy URLs…
Unusual Exploit Kit Targets Chinese Users (Part 1)
We are very accustomed to seeing the same exploit kits over and over. Angler EK, Nuclear EK or Fiesta EK all…
‘Payload tested’ browser popup via AOL’s ad network causes a scare
Today, we are looking at a strange case and a potential malvertising issue that appeared on popular news website salon.com but probably…
Booby-trapped Hugo Boss Advert Spreads Cryptowall Ransomware
Malicious advertising attacks (malvertising) have been plaguing mainstream sites and their visitors a lot these past few years. While some are…
A history lesson brought to you by the Nuclear exploit kit
During our malware investigations, we are often learning about new techniques or ways the bad guys try to bypass us. But sometimes,…
Jamieoliver[dot]com still compromised, now drops digitally signed malware
Almost one month ago we blogged about popular Chef Jamie Oliver having his website hacked and serving malware. The issue was…
Association of Internet Researchers Website Compromised
The Association of Internet Researchers is an “Academic association dedicated to the advancement of…Internet studies” – [Wikipedia]. They’ve held conferences since…
Philippine .Gov Compromised by Anti-ISIS Defacement, Phishing
There’s a ph(dot)gov website located at canaman(dot)gov(dot)ph which serves the region of Canaman in the Philippines. The homepage as it currently stands:…
Major malvertising campaign spreads Kovter Ad Fraud malware
Last year was a busy year for malvertising with top rank ad networks such as Google’s DoubleClick caught in large scale attacks, and…