Top websites deliver CryptoWall ransomware via malvertising

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
CryptoWall ransomware with a valid digital signature is being delivered as part of a widespread malvertising campaign, according to Barracuda Labs.

Drive-by downloads were detected as coming from hindustantimes[.]com, bollywoodhungama[.]com, one[.]co[.],il, codingforums[.]com, and mawdoo[.]com, according to a Sunday post, which explains that the ransomware in each instance was delivered via the Zedo ad network.

A specific subchain “is common to every site's sequence of events,” and in that subchain, “ss1[.]zedo[.]com served obfuscated JavaScript that began a series of redirects to malicious content,” according to the post. “The last site, xenon[.]asapparts[.]com, redirected to one of several different exploit kit-backed sites.”

The initial VirusTotal results showed zero detections; however, the program has since been deemed malicious by additional tools, the post indicates.
 

Kent

Level 10
Verified
Well-known
Nov 4, 2013
468
Why do people are reluctant to use adblocker and Malwarebytes Anti-Exploit to avoid it ,even Ghostery blocks Javascripts from the adverts :mad:
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top