Top websites deliver CryptoWall ransomware via malvertising

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,357
20,489
6,278
Somewhere In nowhere
CryptoWall ransomware with a valid digital signature is being delivered as part of a widespread malvertising campaign, according to Barracuda Labs.

Drive-by downloads were detected as coming from hindustantimes[.]com, bollywoodhungama[.]com, one[.]co[.],il, codingforums[.]com, and mawdoo[.]com, according to a Sunday post, which explains that the ransomware in each instance was delivered via the Zedo ad network.

A specific subchain “is common to every site's sequence of events,” and in that subchain, “ss1[.]zedo[.]com served obfuscated JavaScript that began a series of redirects to malicious content,” according to the post. “The last site, xenon[.]asapparts[.]com, redirected to one of several different exploit kit-backed sites.”

The initial VirusTotal results showed zero detections; however, the program has since been deemed malicious by additional tools, the post indicates.
 
Why do people are reluctant to use adblocker and Malwarebytes Anti-Exploit to avoid it ,even Ghostery blocks Javascripts from the adverts :mad:
 
Status
Not open for further replies.