Movement in the malvertisement world
There has been a lot going on over the past few weeks, and it's time to bring everybody up to speed on recent discoveries. First, a malicious advertisement has been discovered at ADECN again, the URL being: cds.adecn.com/resource/ads/875_9159_1202999742.swf As you will see, visually the advertisement is identical to the malicious advertisement that appeared on diepresse and washingtonpost.com From acedn we are redirected to station-appraisals.com/crossdomain.xml, and to: station-appraisals.com/c/index.php?id=WjM0VnExOHBjeDMza0dEUDdnUGRoPTEyMDI4MjE3MjYmcG56Y252dGE9dnFyYWd2c2xmYgYNkiDgNmYNkiDgNm We then hit blessedads.com/?cmpid=identifyso, and prevedmarketing.com/?tmn=mwatmp&aid=identifyso&lid=&ax=1&ed=2&mt_info=5586_5581_2358, before we finally hit: scanner2.malware-scan.com/9_swp/?tmn=null&aid=identifyso_ma9s_mb1t&lid=&affid=&ax=1&ed=2&mt_info=5586_5581_2358:3958_0_15362 (via)
March 12th, 2008
