Showing posts with label Alexa. Show all posts
Showing posts with label Alexa. Show all posts

Saturday, 14 November 2015

Video Ads On Popular Sites Spread Malware

Caption: Process flow for video-borne malware infection

The use of advertising to spread malware takes place for some time, but cyber criminals also convert video advertisements. Recently appeared on 3000 websites, including many in the Alexa Top 100 most visited websites, a malicious video ad, reports Media Trust.

The ad showed a pop-up in which a rogue security was offered, for example, Apple Safari. When users clicked on the pop-up was actually downloaded malware. The incident took place on 29 October and the infected ads were distributed 12 hours.According to Media Trust is the use of video ads attractive to cyber criminals because they are much harder to control. The use of such advertisements would therefore be on the increase.

Monday, 12 October 2015

Weather Infected Ads On KickassTorrents


On the very popular torrent KickassTorrents again infected ads have appeared that tried to infect visitors with malware. The ads were spotted by the Safe Browsing service provided by Google, which then in users of Chrome and Firefox website blocked.

What kind of vulnerability, there was used to spread malware and to not know what is exactly the malware lets Google. Across TorrentFreak explains the team Kickass Torrents that the responsible advertiser has been removed. At the time of writing, the Web site, however, is still blocked. In July KickassTorrents was already by Google blocked. The torrent is according to Alexa on the 75th spot of most visited websites in the world.

Saturday, 26 September 2015

Porn XHamster Spread Malware Weather


For the third time in a year there are again infected ads on the most popular porn xHamster published that attempted to infect visitors with malware. XHamster receives nearly half a billion monthly visitors and is on the 71st place of most visited websites on the internet.

The infected ads first carried out various checks. Thus, it ensures that the visitor Internet Explorer and certain security tools such as Wireshark and Fiddler active, said anti-malware company Malwarebytes. In case it IE users without said security tools went unnoticed was a page loaded with the Nuclear-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer users have not patched.

In the case the attack was successful was ransomware and other malware installed. After being informed removed the ad network TrafficHaus infected ads. A few days later appeared again malicious ads on xHamster. This time the browser was based Brow lock ransomware spread. This ransomware is not on the computer, but locks the browser via a special JavaScript and states that the user must pay to get access again.

Again TrafficHaus was informed. Malwarebytes but does not know if the second round with malicious ads has been removed. In January and April also appeared already contaminated ads on xHamster.

Saturday, 2 May 2015

Malware Lets Computers See Pro-Russian Videos



Cyber criminals turn into infected computers in order to artificially inflate the number of views of pro-Russian videos on the website Dailymotion, which increases the visibility of the videos in real website visitors. It is more common before infected computers used to visit websites and example to commit or advertising click fraud or to increase the number of views of a video.

Researchers Trustwave first thought that this is also in the now discovered malware campaign was the case, until the contents of the traffic information has been viewed. This was in fact intended for various pro-Russian videos on DailyMotion. The website is according to Alexa on the 84th spot of most visited websites on the internet. The researchers believe that political considerations should play a role.

Users of infected computers were shown the pro-Russian films do not, as they were loaded on a "hidden desktop". The videos, each of which had about 320,000 views, were thus more visible to real visitors from Dailymotion. According to researchers from Trustwave is the first time that this technique is used for a probable political agenda.

Wednesday, 29 April 2015

Weather Infected Ads On Porn xHamster


On the popular porn xHamster again infected ads have appeared that attempt to infect visitors with malware. In late January it was even hit on the porn site, which according to Alexa is on the 68th place of most visited sites on the Internet and gets 514 million visitors monthly.

The ads direct visitors unnoticed to another page where the Angler Exploitkit runs. This page checks to see if the visitor uses the virus from Kaspersky Lab or Norton. If this is not the case, then it is decided to attack the user further. The Angler Exploitkit makes abuse of vulnerabilities in Internet Explorer, Java, Silverlight and Adobe Flash Player. Anti-virus firm Malwarebytes suggests that only an old vulnerability in Internet Explorer is used in the attack.

Is the attack successful, is the Bedep malware installed. The same malware that also the end of January on the website was spread via infected ads. Bedep making computers part of a botnet and can then install additional malware. Once active Bedep used infected computers to commit fraud advertisement. Additionally silently loads the Magnitude Exploitkit, which also makes abuse of vulnerabilities, provide users with additional malware can become infected.

Thursday, 19 February 2015

Popular Porn RedTube Spread Malware


On the popular porn RedTube researchers have found malicious code that tried to infect visitors with malware. That leaves anti-virus company Malwarebytes know today. Unlike several other porn sites that for "drive-by downloads" were used, there were no infectious ads used in this case. The attackers had direct access to the code of the website.

The malicious code was executed inside an iframe and pointed to the Angler Exploitkit on another page. This exploitkit uses a recently patched vulnerability in Adobe Flash Player. In case users do not use the latest version of Flash Player, they can become infected with a Trojan horse. This malware steals personal information and installs browser helper objects showing ads. Some of these ads pointing again to other operating pages can infect your computer with malware so on.

RedTube leaves in front Malwarebytes know that last Sunday was attacked and the problem was resolved within a few hours.Meanwhile RedTube the malicious code would be removed . The porn is according to measurement agency Alexa on the 128th place of most visited websites on the internet. Earlier today, the anti-virus company warned that the website of chef Jamie Oliver malware spread . Also, this problem has now been resolved.

Hash:
1e0134d9b5b51d9ad233b0a2ecb7cf83

Thursday, 29 January 2015

Infected Ads on xHamster Spread Malware


Researchers have discovered the popular porn site xHamster infected ads that try to infect visitors through a recently patched flaw in Flash Player. According to anti-virus company Malwarebytes is the number of infections from xHamster recent days has increased by 1500%.

The porn is according to measurement agency Alexa on the 64th spot of most visited websites on the internet. In case the attack is successful the Bedep malware is installed. Bedep making computers part of a botnet and can then install additional malware. Meanwhile, there is an update to the attacked Flash Player leak released, but may still not be installed anywhere.

"Although malvertising on xHamster is nothing new, this particular campaign is very active. Given that this porn site generates a lot of traffic, the number of infections are gigantic," says Malwarebytes. Previously had security FireEye already know that had infected ads on porn sites found , including a porn site in the Alexa Top 1000. However, it seems to go a different attack. As was pointed infected computers installed Reveton-ransomware.