Suspect ads targeted at me

Status
Not open for further replies.

JBonz

New Member
Thread author
Aug 27, 2020
11
For a while I have been experiencing online ads that are not legitimate and are targeted at me personaly. Usualy they are ad images that are placed in ad slots but don't appear to be genuine. Recently I have experieced the same thing with youtube video ads. Ads that interupt a long video. I think it's aimed at me, not random. If I'm able to visit sites using Tor it doesn't happen. I would like to know how this is possible? What is the likely method being used? How would someone be able to place a video ad on youtube? I read somwhere that an image can be replaced with a "man in the middle" attack? Is there anything I can do to find out the cause?
 

Attachments

  • FRST.txt
    132.6 KB · Views: 8
  • malwarebytes.txt
    1.4 KB · Views: 10

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Your FRST.TXT log is clean.

What you are possibly dealing with is PUSH notifications.

Follow the instructions on this topic.

Let m know if the problem is solved.
 

JBonz

New Member
Thread author
Aug 27, 2020
11
I don't think I have ever allowed notifications from any site although I may have been tricked into allowing them.

Take a look at this screenshot of an ad funeral-planning-kerrang-crop

I don't think this is genuine. It's in a regular ad slot on a website as if the image that was meant to be there has been replaced. I've read that it's possible to do that. It looks like a genuine ad and if I click on the top right corner I get the usual google message "why this ad". I've seen this ad several times in different places. Usually the images will be in regular ad slots.

Man in the middle attack to replace images: MITM Labs/Bettercap to Replace Images - charlesreid1

There's also the question of how you would show your own video ad to a user on youtube. Correct me if I'm wrong but I don't think it would be easy to do that.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

There are other means to send you ads.

What is phishing?

Or, if the default browser is Synced with other devices.

Syncing issue

If the problem persists and you are Syncing Firefox it with other Devices reset it.

Navigate to this page and Remove it as suggested.


When done restart the computer normally.

If all is well.

Return to your Firefox Account and Click the Connect button.

Reset the sync.

Restart the computer normally.
<<<>>>

Is the problem solved.

p.s.

Right Click on the image, can you get the Link address?
Copy and post it.
 

JBonz

New Member
Thread author
Aug 27, 2020
11
I'm aware of phishing because I was caught out a long time ago when I was on AOL dialup. I gave everything away and AOL kicked me off. The phisher used my email to spam people.

I've never synced firefox with anything.

The link for the image I posted: Funeral Planning

I don't know if that site is legitimate. I contacted them and asked if the image is one of their ads but I've had no reply.

If I right click on the image sometimes I get a link and sometimes nothing.

I had something about a week ago. It was a web search using duckduckgo. I clicked on images and the ad was in the middle. The link was to a USA news site article about Trump. The image and the caption underneath were odd considering the Trump article but it made perfect sense to me and what is happening at the moment. It's not fraud. It's harassment by people who know me. Even if I don't manage to trace it to it's source I would like to know how they are doing it.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

I have not problem rendering the Funeral site.

===

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Check if you have an account that has been compromised in a data breach

Change an address that has been compromised.

===

Pwned Passwords

Change all Pwned passwords.

Use a difference password for each site.

Let me know of any remaining issues.
 

JBonz

New Member
Thread author
Aug 27, 2020
11
One theory that I have about this is that people can buy ads and effectively target them at me if the targeting critera is fine grained enough. I don't understand the ads system so I don't know how hard that would be. I've been told that for google ads the smallest group is 100 people. That might be enough to target them at me.
 

JBonz

New Member
Thread author
Aug 27, 2020
11
This is interesting about youtube video ads
It's possible that it's not malware or even dodgy from a legal point of view?
 

JBonz

New Member
Thread author
Aug 27, 2020
11
nasdaq, you already suggested push notifications.

I think the reason why I'm not getting anywhere with this is because it's either not malware or it's not detectable. If it's not malware then it's probably a network thing like man in the middle or abusing the ads system.
 

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.
 

Attachments

  • fixlist.txt
    1.4 KB · Views: 1

JBonz

New Member
Thread author
Aug 27, 2020
11
It seems to have stopped after I posted some stuff on twitter complaining about it. The people who are doing it will be aware of that twitter account. It might still be happening but in a subtle way so that I can't be sure. The worst ads are pretty obvious so that I can be pretty sure that they're bogus. The obvious stuff had already stopped before I ran FRST with your fixlist.txt so if there's any difference it's barely noticeable.

I've started looking at wireshark so that I might be able to trace it if it starts happening again. I'm also going to take a look at the ads system to find out if it's possible to effectively target an individual.
 

Attachments

  • Fixlog.txt
    7.1 KB · Views: 1

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
This is good news.

I will leave this topic open for 6 days

If you need additional help please ask.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top