Sunday, March 23, 2008 2:59 PM sandi

Malicious advertisement detected at www.classmates.com

Thanks to Susan Bradley for the heads up that there is a problem at www.classmates.com  

The malicious creative can be seen at this URL:

http://nztv.prod.untd.com/RealMedia/ads/Creatives/ISP/CM_GeminiIntera_FPR_4_10179/300x250.swf?clickTAG=http://cyclops.prod.untd.com/RealMedia/ads/click_lx.ads/www.classmates.com/School_List/L18
/968920812/TopLeft/ISP/CM_GeminiIntera_FPR_4_10179/300x250_GeminiInter_Mar08.html.html/
4f7148557555666c32626f41444a314d?http%3A//www.myjewelrybox.com/%3Fids%3D46ps

 

Here is a screenshot of the malicious advertisement:

image 

An analysis of the SWF reveals a URL pointing to a known malware domain:

iexplorer-security.org/?id=624400105

----------------

The iexplorer-security.org URL is active, and redirecting victims to xponlinescanner.com as follows:

The URL iexplorer-security.org/?id=624400105 leads us to:

fastwebway.com/soft.php?aid=011807&d=1&product=XPA

The fastwebway.com URL in turn leads us to:

xponlinescanner.com/2008/1/freescan.php?aid=77011807

It should be noted that as part of the hijacking process a cookie is set that expires after just 24 hours.

----------------

The malicious advertisement has been reported to RealMedia although it looks like the advertisement is self-hosted, therefore it may take a little while for the advertisement to be shut down.

----------------

Who are fastwebway.com?

The reverse IP for this domain is traffic-coverter.biz.

Its name servers and mailbox are provided by estdomains.

Its IP address is 72.232.224.154, hosted by LayeredTech (ltdomains.com)

Other sites/services hosted at 72.232.224.154 are:

bestsexworld.info
dvd-disk.net
mail.dvd-disk.net
mail.er-a.net
mail.pornorolikov.net
mail.sexroliki.com
pornorolikov.,net
sexroliki.com

image

Filed under: ,

# re: Malicious advertisement detected at www.classmates.com

Sunday, March 23, 2008 5:31 PM by Kim

Hi there... The misdirection also appears to be triggered by clicking on Classmates e-mails.  This just happened to me 15 minutes ago.  I had been at Classmates, and sent an e-mail, then logged out.  Got a confirmation of e-mail sent, from Classmates.  Clicked on the e-mail to check the send, and before the entire Classmates page could load, was hijacked and redirected to xpscanneronline.com

There was no time to click on anything at the Classmates site itself.  The Classmates page did NOT fully load before it was hijacked.

Unfortunately, I deleted the e-mail and ran a scan before I thought to look at the source code of the e-mail.

Sorry. :)

Anyway, just a head's up.

# re: Malicious advertisement detected at www.classmates.com

Sunday, March 23, 2008 7:23 PM by Jason Needham

I have a copy of the email if someone wants it.  It worked once normally, then the next time just to check if anyone replied to my posts....POOF!

# re: Malicious advertisement detected at www.classmates.com

Monday, March 24, 2008 12:15 PM by Bozoar

I got hit too. SOB's

This needs to go to Digg.com

# re: Malicious advertisement detected at www.classmates.com

Monday, March 24, 2008 9:15 PM by Boyd Andersen

What can Classmates do about xponlinescanner.com/2008/1/freescan.php?aid=77011807?

# re: Malicious advertisement detected at www.classmates.com

Monday, March 24, 2008 11:35 PM by sandi

@BoydAnderson,

What can classmates.com do?

First, source reliable instructions and advice on how to get rid of xponlinescanner from any reputable anti-spyware advisory forum, and get that information out to their clients.

Second, conduct more comprehensive checks into the background and bona fides of those they accept advertising from - see these linkS for advice:

Avoiding the bad guys - detecting potentially malicious advertising campaigns

msmvps.com/.../1465721.aspx

Winfixer hide 'n' seek: explaining why some people see the ads, and some people don't

msmvps.com/.../1134527.aspx

Third, run advertisements that they receive through services such as www.adopstools.com to check for malicious code.

Sandi &c.

# re: Malicious advertisement detected at www.classmates.com

Friday, March 28, 2008 4:08 AM by lauren Johnson

so, this xpscanner isnt really ..real?

ive been directed to this multiple times on various websites.

or is it real?

# re: Malicious advertisement detected at www.classmates.com

Friday, March 28, 2008 5:52 AM by sandi

Hello Lauren Johnson,

xponlinescanner is NOT a reputable product. It is a con.

Which websites are having a problem with redirects? I will investigate.

Sandi

# re: Malicious advertisement detected at www.classmates.com

Friday, March 28, 2008 10:26 AM by jp

I ran into this on a newspaper website. . .how do I know if my machine was infected? I run Vista SP1

# re: Malicious advertisement detected at www.classmates.com

Friday, March 28, 2008 10:56 PM by sandi

@JP

If you are running Vista (or Vista SP1) ***with UAC turned on*** and Protected Mode for IE running then it is unlikely that your system is infected.

If, on the other hand, you have turned off UAC or use any auto-elevate for UAC because you didn't like the pop-ups (thereby losing Protected Mode in IE as well), and/or you accepted the download/install then yes, you could be infected.

Sandi

# re: Malicious advertisement detected at www.classmates.com

Thursday, April 03, 2008 6:40 PM by Lesley hunter

NERVY! An unwelcome exe file started to download to my computer.  I don't even remember hitting a classmates.com ad. I was just surfing. Glad macs don't autoload!

# re: Malicious advertisement detected at www.classmates.com

Thursday, April 03, 2008 6:45 PM by sandi

@Lesley Hunter,

re "Glad macs don't autoload", I have to point out that nor does IE ever since XP SP2.

These attacks are social engineering attacks as well as drive-by-download.

Sandi

# re: Malicious advertisement detected at www.classmates.com

Monday, April 07, 2008 9:19 PM by Chris

I built my own website from scratch a few years ago and for some reason, I have the xpscanneronline thing popping up when I check my site.  It only started happening a few weeks ago after some updating.  Can anyone tell me how to get rid of it?  What to look for in the code to eliminate it?  I don't want it on my site, any help would be great.

Thanks

Chris

# re: Malicious advertisement detected at www.classmates.com

Friday, April 11, 2008 6:13 PM by Jack

This malware just tried to download to my PC from photobucket.com. I closed IE using the Task Manager.

# re: Malicious advertisement detected at www.classmates.com

Monday, April 14, 2008 10:37 AM by zangtum!

This malware just tried to download to my PC from photobucket.com. too.

# re: Malicious advertisement detected at www.classmates.com

Monday, April 14, 2008 10:50 AM by zangtum!

ROOPS! Hit submit too soon. When I was on Photobucket, moving through  pages looking for something specific, suddenly Google desktop sent the following warning [a first for me from GD] about this malware, which I didn't even notice - I assume it was a result of the same ad mentioned by Jack:

Warning - visiting this web site may harm your computer! - the page you are about to visit may be a web forgery!

You can learn more about malware and how to protect yourself at StopBadware.org. This page is very likely to have been designed to trick users into sharing personal or financial information. Entering any personal information on this page may result in identity theft or other fraud.

You can read more about phishing here antiphishing.org.

Or you can continue to fastwebway.com/soft.php at your own risk.

You can also turn off safe browsing warnings by going to Google Desktop preferences.

Would you like to help make the web safer by always sending information to Google about sites with suspicious links?

# re: Malicious advertisement detected at www.classmates.com

Wednesday, April 23, 2008 6:37 PM by n3tfury

ran across this at mininova.org.  thankfully i'm on ubuntu (linux) so this means nothing to me, but just thought i'd share.

# re: Malicious advertisement detected at www.classmates.com

Thursday, April 24, 2008 12:12 AM by warrior

same thing for me on mini nova with Ubuntu :). Googled it to see what it was and came up on this thread and was pleased to read that some one else is using Ubuntu.

# re: Malicious advertisement detected at www.classmates.com

Thursday, May 01, 2008 1:47 AM by steve

i was on photobucket.com when it did it to me. i almost did the xponlinescanner thing but followed my gut and googled it first which brought me here. sheww

# re: Malicious advertisement detected at www.classmates.com

Monday, May 05, 2008 7:03 PM by MuddBuddha

Ubuntu here as well! :)  Also ran across it on mininova.

# re: Malicious advertisement detected at www.classmates.com

Saturday, May 17, 2008 8:42 PM by Rob

f1.racing-live.com/.../index.shtml appears to be serving this malicious adware up in the past week or so :-(

# re: Malicious advertisement detected at www.classmates.com

Wednesday, May 21, 2008 8:35 PM by Brian

I've been getting it on juno.com, which is another United Online company like classmates.com.

Thanks,

Brian

# re: Malicious advertisement detected at www.classmates.com

Monday, May 26, 2008 3:30 PM by annh_909

i've been getting the same popup on my pc when browsing through deviantart.com..

Leave a Comment

(required) 
(required) 
(optional)
(required)