FYI...
Malware on ad networks at Google, MS...
DoubleClick ADShufffle drive-by download malvertising
-
http://www.pcworld.c...th_malware.html12.10.2010 10:00 pm - "...
cybercriminals managed to infect Google's and Microsoft's online ad networks with malicious advertisements that attacked users' PCs, according to security consultancy Armorize*. The attacks started around Dec. 5 and lasted a few days, sending victims who clicked on the ads to malicious Web pages..."
*
http://blog.armorize...ad-through.html12.10.2010 - "... Over the past few days, we saw the quick spread of
HDD Plus** - a malware that (somehow) gets installed on victim computers, and holds the computer hostage by displaying threatening message (that the system is failing), asking you to purchase a license so
HDD Plus will fix the problems... one of the means for HDD Plus to spread, was via drive-by download malvertising through (at least) DoubleClick and rad.msn .com, which are both the world's largest ad serving platforms...
Known sites affected: Sites that incorporate DoubleClick or rad.msn .com banners, including for example Scout .com (using DoubleClick), realestate.msn .com, msnbc .com (using both), and mail.live .com. We'd like to note here
it's very possible that multiple exchanges, besides those listed here, have been serving the fake ADShufffle's ads...
Malware installed: Over the past week, ADShufffle kept on changing the malware. Besides HDD Plus, other types of malware, such as backdoors, have been served...
Exploit packs used: Primarily a modified version of
Eleonore.
Neosploit was also used.
With neosploit, malicious binaries are obfuscated on-the-fly before being served..."
(More detail and flow chart available at the blog.armorize.com URL above.)**
http://www.bleepingc...remove-hdd-plus___
Q3'10... Web-Based Malware
-
http://blog.dasient....01_archive.htmlNovember 22, 2010Q1'10... Web-Based Malware
-
http://blog.dasient....01_archive.htmlMay 10, 2010-
http://news.cnet.com...000898-245.htmlMarch 22, 2010-
http://blog.avast.co...–-jsprontexi/February 18, 2010-
http://blog.avast.co...ntexi_chart.png
Edited by AplusWebMaster, 11 December 2010 - 03:15 PM.