rhapsody.com hit by malicious banner advertisement
rhapsody.com has been hit by a malicious banner advertisement - rhapsody.com is owned by RealNetworks.
| Victim site | rhapsody.com (207.188.21.32) |
| SWF host | RealOne / Doubleclick
|
| SWF Source | |
| Target fraudware domain | scanner2.malware-scan.com
|
| Banned cities, countries and IPs | 207.188.0.0-207.188.255.255 (note this IP range captures rhapsody.com) newjersey, newyork, california, washington, virginia paris, aarhus, velizycedex, jarrestr, amsterdam, rotterdam, zaanstad, koogaandezaan, seattle
|
| Permitted cities, countries and IPS | US, NL, FR, SE, DK, NO, UA |
| SWF URL | i.realone.com/ads/Rollingstone/1_skyauction_728x90.swf?clickTag=http: // ad.doubleclick.net/click%3Bh=v8/3652/3/0/%2a/x%3B177176445%3B0-0%3B0%3B12874614%3B3454-728/90%3B24358245/24376098/1%3B%3B%7Eaopt%3D2/1/ff/0%3B%7Esscs%3D%3fhttp: // www.skyauction.com/?id=384231 |
| Special notes |
|
| Incident reported to | Doubleclick rhapsody.com
|
| Resolution | |
As always, let's work backwards from the final target site.
| URL | Referrer |
| scanner2.malware-scan.com/9_swp/?tmn=null&aid=&lid=&affid=&ax=&ed=&aid=mi1eroof_ma9_mb1t&lid=728&affid =&ax=1&ed=2&mt_info=3958_0_13496 prevedmarketing.com/?tmn=mwatmp&aid=mi1eroof&lid=728&ax=1&ed=2&mt_info=4957_3064_2358 blessedads.com/?cmpid=mi1eroof&adid=728 newbieadguide.com/statss.php?campaign=mi1eroof&u=23423424 | newbieadguide.com/swf/gnida.swf?campaign=mi1eroof&u=23423424 |
| newbieadguide.com/swf/gnida.swf?campaign=mi1eroof&u=23423424 | newbieadguide.com/statsg.php?u=23423424&campaign=mi1eroof |
| newbieadguide.com/statsa.php?u=23423424&campaign=mi1eroof | i.realone.com/ads/Rollingstone/1_skyauction_728x90.swf?clickTag=http: // ad.doubleclick.net/click%3Bh=v8/3652/3/0/%2a/x%3B177176445%3B0-0%3B0%3B12874614%3B3454-728/90%3B24358245/24376098/1%3B%3B%7Eaopt%3D2/1/ff/0%3B%7Esscs%3D%3fhttp: // www.skyauction.com/?id=384231 |
| i.realone.com/ads/Rollingstone/1_skyauction_728x90.swf?clickTag=http :// ad.doubleclick.net/click%3Bh=v8/3652/3/0/%2a/x%3B177176445%3B0-0%3B0%3B12874614%3B3454-728/90%3B24358245/24376098/1%3B%3B%7Eaopt%3D2/1/ff/0%3B%7Esscs%3D%3fhttp: // www.skyauction.com/?id=384231 | rhapsody.com/-search?query=U2&searchtype=RhapArtist |
Screenshot of malicious SWF - yep, its the infamous Skyauction advertisement - again
