Large Number of Adult Sites Distribute Malware Via AdXpansion Malvertising

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
While malvertising activity on adult sites has been ‘relatively’ quiet for some time, we started picking up dozens of attacks on moderately popular XXX portals, where moderate still means millions of daily visitors.

The modus operandi is quite straightforward and facilitated by a compromised Flash advert directly hosted and served by AdXpansion, an adult ad network, which triggers a hidden Flash exploit loaded from a seemingly innocent XML file. This technique has been used before in other self-sufficient Flash ad/exploit attacks.

This malvertising campaign has been running since at least Nov 21 and is affecting hundreds of adults sites. As soon as the rogue Flash advert is displayed in the browser (no click on it is required) it will attempt to load the exploit code.

Notable sites that were affected include:

  • drtuber.com (55.3 M)
  • nuvid.com (41.9 M)
  • eroprofile.com (14M)
  • iceporn.com (6.9M)
  • xbabe.com (4.2M)
Monthly traffic in millions, according to SimilarWeb.

The malicious advert:



Read more: Large Number of Adult Sites Distribute Malware Via AdXpansion Malvertising
 

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
Interesting, since it is about ads could Adguard provide first layer of protection first before others (e.g. MBAE)?
Just curious to know.
 
  • Like
Reactions: Online_Sword

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Would be nice to see if HMP alert, Dr.Web new Katana can protect from this exploit....
 

Anupam

Level 21
Verified
Well-known
Jul 7, 2014
1,017
Well I use these three protection as of now

1. I use Ad Block Plus
2. Search unknown or "such" :p sites in Incognito
3. While surfing unknown site I run my browser in Sandbox.

Right now I have 360 Total security on my system. Will such malware still affect me?
 
  • Like
Reactions: Andrew999

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
Well I use these three protection as of now

1. I use Ad Block Plus
2. Search unknown or "such" :p sites in Incognito
3. While surfing unknown site I run my browser in Sandbox.

Right now I have 360 Total security on my system. Will such malware still affect me?

I mean if you don't go to adult site, then that malware couldn't affect you I guess. :)
 
  • Like
Reactions: Andrew999

Anupam

Level 21
Verified
Well-known
Jul 7, 2014
1,017
I mean if you don't go to adult site, then that malware couldn't affect you I guess. :)

Hey malware can be in any site. Just because Adult Site has it does not mean it won't be there in other sites too.
 

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
Hey malware can be in any site. Just because Adult Site has it does not mean it won't be there in other sites too.

I mean in the particular context posted, though I agree with your point. Otherwise I wouldn't "overkill" myself with anti-malwares. ;)
 

OC-Rat11

Level 1
Nov 16, 2015
11
Hey malware can be in any site. Just because Adult Site has it does not mean it won't be there in other sites too.

Definitely. My last two memorable infections were by clicking on popular images from Google searches.

Whenever I go surfing these days, I always sandbox firefox with no script and ublock extensions on. With no script, I only temporarily allow those scripts that deal with the core content of the site. The rest of the scripts are blocked. Sounds like a little much, but I've had absolutely no infections or problems since. Happy surfing!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top