Winfixer, real media and valueclick.... the fight continues
I don't know about you, but I feel like I am playing whack-a-mole most of the time.
I was asked to review a discussion through on dslreports today - a report that was complaining about malware incidents on the www.wfaa.com web site - the typical Winfixer via hostile banner advertisements carry on.
Cite: http://www.dslreports.com/forum/r18551684-Another-WinFixer-infiltrationthis-time-on-wwwwfaacom
So, let's go have a look.
I can state, conclusively, that the wfaa.com web site *is* exposing its users to fraudware - and Real Media and ValueCilck are both implicated.
Proof - Fiddler was running during an attempted infestation. - now, there are some bits and pieces stripped.... as much for the readers' convenience as for my privacy, but you get the gist...
The powers that be are welcome to the entire capture... you know who you are...
GET /pages/scanner/index.php?aid=alreadyx&lid=intl&ax=1&ex=1&ed=2 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: en-us
Referer: http://ads.belointeractive.com/RealMedia/ads/Creatives/OasDefault/NtlZappinadsInc001A-rmn/NtlZappinadas728_061907.swf?clickTAG=http://ads.be
Content-Type: application/x-www-form-urlencoded
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: www.errorsafe.com
Proxy-Connection: Keep-Alive
HTTP/1.1 302 Found
Via: 1.1 SERVER
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Transfer-Encoding: chunked
Date: Tue, 26 Jun 2007
Location: http://adfarm.mediaplex.com/ad/ck/52853?aid=alreadyx_rdt&mpt=[CACHEBUSTER]
Content-Type: text/html
Server: Apache
X-Powered-By: PHP/4.4.2
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
Set-Cookie: cnt=**; expires=Thu, 21 Feb 2008 00:13:36 GMT; path=/; domain=.errorsafe.com
Set-Cookie: lng=**; expires=Thu, 21 Feb 2008 00:13:36 GMT; path=/; domain=.errorsafe.com
GET /ad/ck/52853?aid=alreadyx_rdt&mpt=[CACHEBUSTER] HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: en-us
Referer: http://ads.belointeractive.com/RealMedia/ads/Creatives/OasDefault/NtlZappinadsInc001A-rmn/NtlZappinadas728_061907.swf?clickTAG=http://ads.be
Cookie: svid=**
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
Proxy-Connection: Keep-Alive
Host: adfarm.mediaplex.com
HTTP/1.1 302 Moved Temporarily
Via: 1.1 SERVER
Connection: Keep-Alive
Proxy-Connection: Keep-Alive
Content-Length: 0
Date: Tue, 26 Jun 2007 00:13:36 GMT
Location: http://pcturbopro.com/.download_now/index.php?p=18&ax=1&ed=2&ex=1&hv=10&j=1&aid=alreadyx_rdt&mpt=[CACHEBUSTER]
Server: Apache-Coyote/1.1
Cache-Control: no-cache
GET /.download_now/index.php?p=18&ax=1&ed=2&ex=1&hv=10&j=1&aid=alreadyx_rdt&mpt=[CACHEBUSTER] HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: en-us
Referer: http://ads.belointeractive.com/RealMedia/ads/Creatives/OasDefault/NtlZappinadsInc001A-rmn/NtlZappinadas728_061907.swf?clickTAG=http://ads.be
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
Host: pcturbopro.com
Proxy-Connection: Keep-Alive