Showing posts with label Infected Ads. Show all posts
Showing posts with label Infected Ads. Show all posts

Saturday, 14 November 2015

Video Ads On Popular Sites Spread Malware

Caption: Process flow for video-borne malware infection

The use of advertising to spread malware takes place for some time, but cyber criminals also convert video advertisements. Recently appeared on 3000 websites, including many in the Alexa Top 100 most visited websites, a malicious video ad, reports Media Trust.

The ad showed a pop-up in which a rogue security was offered, for example, Apple Safari. When users clicked on the pop-up was actually downloaded malware. The incident took place on 29 October and the infected ads were distributed 12 hours.According to Media Trust is the use of video ads attractive to cyber criminals because they are much harder to control. The use of such advertisements would therefore be on the increase.

Friday, 23 October 2015

Infected Ads With T-Online And eBay Germany


On the website of the German ISP T-Online and eBay Germany are infected ads appeared which attempted to infect visitors with malware. Also received several other German sites to do with the infected ads but eBay.de and T-Online.de are respectively 131 million and 79 million monthly visitors by far the biggest websites were affected.

Through the ads were visitors silently redirected to pages with the Angler- and Neutrino-exploit kits. This exploit kits do include using known vulnerabilities in Internet Explorer and Adobe Flash Player. These are known vulnerabilities. Users whose software was up-to-date therefore were not at risk.

What malware was installed on the attack late anti-malware company Malwarebytes not know. The ad network which spread the infected ads would meanwhile have intervened, but analyst Jerome Segura does not rule out that the attack campaign through other ad networks will continue.

Tuesday, 29 September 2015

Infected Ads On YouPorn And Pornhub


After xHamster are also on the popular porn site Pornhub and YouPorn contaminated ads have appeared that tried to infect visitors with malware, says anti-malware company Malwarebytes. The websites get together 800 million visitors per month.

Pornhub is according to Alexa on the 64th spot of most visited websites on the internet. YouPorn is at the 161st place back. The ads came from the ExoClick ad network. The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed.

After Geek Mind, publisher Pornhub and YouPorn, discovered the ad network ads were off the infected ads. The company also states that all third-party advertising on "continuous basis" audit to malvertising, as mentioned infected ads preventable. Recently, it was also for the third time in a year hit by xHamster. This website receives nearly half a billion visitors monthly.

Saturday, 12 September 2015

Google Receives Complaints About 300.000 Injected Ads


Since the beginning of this year, Google has received more than 300,000 complaints of Chrome users on injected ads. It is the largest source of annoyance for Chrome users. The injected ads come from so-called "ad injectors".

This relates to adware or browser extensions that inject additional ads on random websites or replace existing ads. According to Google ad injectors are a problem for advertisers and websites. Advertisers do not know that their ads be injected and so have no idea where their ads are displayed. Websites are not, however, paid for these ads because they are injected locally on the users' computers. The content sometimes dubious, it may involve malware, making the injected ads are a risk to visitors. This is negative for the image of the website, which can do nothing to the injected ads.

Filter

To have to tackle Google ad injectors for several measures taken. Since July, the Internet giant has also begun to filter injected ads of its own advertising platform DoubleClick. Google allows advertisers DoubleClick Bid Manager, which can be bid on ad space. To prevent injected advertisers buy ad space, there is now an automatic filter active.

This new system will detect injected ads and proactively establishes a blacklist that prevents advertisers to bid on ad space injected. Google expects that this measure will not immediately solve the problem, but it hopes that other parties in the advertising industry will take action against ad injectors. "Progress can be achieved only if we work together," said Vegard Johnsen, product manager of Google Ads.

Saturday, 15 August 2015

Infected Ads Hide Behind SSL



The criminals who first infected ads on the websites of Yahoo demonstrated have now found a new ad network and use SSL to complicate the detection of malicious traffic. That leaves anti-virus company Malwarebytes know. The ad network in question is AdSpirit.de whose ads drudgereport.com and wunderground.com shown.

These websites get together more than 110 million visitors per month. The infected ads contain a redirect via SSL to an Azure-site, making it difficult to detect the malicious traffic at the network layer, reports analyst Jerome Segura. The ads users a website with the Angler-exploitkit charge. This exploitkit uses known vulnerabilities include Adobe Flash Player that users are not patched. What malware is installed on a successful attack Segura do not know.

Wednesday, 29 July 2015

Internet Again Exposed To Contaminated Ads


In recent weeks several popular websites appeared infected ads, making the potential for at least 10 million Internet users have run risk of infection. The actual number of people that the received ads to see infected and as a consequence thereof became infected is not known. The ads pointed to a copy of the Angler Exploitkit.

This exploitkit tries users silently through vulnerabilities in popular software such as Adobe Flash Player to infect with malware. It regularly happens that the ads or exploits are displayed only to visitors from certain countries. In case the infected advert appears the attack can only succeed if the visitor uses the attacked software or browser plug-in instance is not up to date.

The sites where the ads would appear according to statistics from security Cyphort SimilarWeb and get at least 10 million visitors per month. The most popular websites showing the infected ads were found in Vietnam, Greece, Indonesia and Thailand. Earlier this month, the ads were also found on the Japanese edition of the Huffington Post. Earlier this year warned Cyphort even for infected ads on popular websites. Even when it came to the Huffington Post.

Monday, 13 July 2015

Ads Malware Via Flash Player Flaw


Vulnerability in Adobe Flash Player last Wednesday by Adobe was patched is now attacked by infected ads. It is the first flaw in Flash Player that were found in the stolen data of the Italian Hacking Team.

According to anti-virus firm Malwarebytes there since the discovery of this vulnerability an increase in attacks on Internet users through so-called drive-by downloads. In this case, Internet users become infected through unpatched software, which only visiting a malicious or hacked website or see getting an infected ad is sufficient. One reason for the increase in the number of attacks is that many users their Flash Player version have not yet patched, said analyst Jerome Segura.

Ads

Meanwhile, the leak will also be attacked by infected ads. The way this is done is remarkable, says Segura. This primarily concerns a Flash ad that loads another Flash file containing the exploit for the Flash Player leak. The use of contaminated advertentes is much more common, but in most cases advertisements pointing to another website that the user attempts to attack.

The infected ad came from the DirectRev ad network and offered directly from the ad network server. In case the attack is successful, the Kovter malware is installed. Kovter can use computers to commit fraud ad (click fraud) or install ransomware.The malware was recently still in the news because the vulnerable versions of Flash Player on infected computers patches, to keep other malware on the computer outdoors.