Peaches Posted February 25, 2009 Report Share Posted February 25, 2009 Google's DoubleClick spreads malicious ads (again) Lingering threat still not contained By Dan Goodin in San Francisco 24th February 2009 19:43 GMT "Google's DoubleClick ad network has once again been caught distributing malicious banner displays, this time on the home page of eWeek. Unsuspecting end users who browse the Ziff Davis Enterprise Holdings-owned site were presented with malvertisements with invisible iframes that redirect them to attack websites, according to researchers at Websense. The redirects use one of two methods to infect users with malware, including rogue anti-virus software. In one case, a PDF with heavily obscured javascript shunted victims to a subdomain at inside.com. (The PDF in not related to the zero-day vulnerability currently menacing Adobe Reader, Dan Hubbard, vice president of security research at Websense, says). In other scenarios, a generic index.php file did the bidding. Once users were redirected, the site dropped a series of malicious files, including one named winratit.exe, into a user's temporary files folder and then prompted them to be automatically called the next time the machine rebooted. The result was the installation of Anti-Virus-1. It invites users to divulge their payment details and also alters their host file to make it hard to disinfect the machine." The Register for full story: http://www.theregister.co.uk/2009/02/24/do...ibutes_malware/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.