Malicious skyauction banner ad at blick.ch
Blick is an extremely popular German language website, and it has been infiltrated by a malicious Skyauction banner advertisement. My husband was redirected by the malicious banner advertisement, and phoned me at work in a less than happy state of mind.
So, let's have a look at the guilty parties this time, working backwards from the final fraudware destination.
-----
scanner2.malware-scan.com/3_swp/?tmn=null&aid=&lid=&affid=&ax=&ed=&aid=orlapidary_ma3_mb1&lid=728&affid=&ax=1&ed=2&mt_info=3958_0_11471
Referrer:
akamahi.net/swf/gnida.swf?campaign=orlapidary&u=1197898069
-----
prevedmarketing.com/?tmn=mwatmp&aid=orlapidary&lid=728&ax=1&ed=2&mt_info=5130_3563_2358
Referrer:
akamahi.net/swf/gnida.swf?campaign=orlapidary&u=1197898069
-----
blessedads.com/?cmpid=orlapidary&adid=728
Referrer:
akamahi.net/swf/gnida.swf?campaign=orlapidary&u=1197898069
-----
akamahi.net/swf/gnida.swf?campaign=orlapidary&u=1197898069
Referrer:
akamahi.net/statsg.php?u=1197898069&campaign=orlapidary
-----
akamahi.net/statsg.php?u=1197898069&campaign=orlapidary
Referrer:
ch.p-digital-server.com/RealMedia/ads/Creatives/web2com/blick-skyauction-5207//728x90.swf
-----
ch.p-digital-server.com/RealMedia/ads/Creatives/web2com/blick-skyauction-5207//728x90.swf
Referrer:
blick.ch/news/schweiz/toedlicher-sesselllift-unfall-im-berner-oberland-79762
-----
So, once again it is time to get in touch with the victim networks, including Blick, and Real Media, and probably MediaConnect (ch.p-digital-server.com) as well. As always, a network capture is available for review by the appropriate parties. I haven't been able to track down contact information for Akamahi.
This game of whack-a-mole with the bad guys is never ending.
Screenshot of malicious advertisement in situ below - my apologies for the blurring, the screenshot was captured mid-change:
