Monday, January 28, 2008 9:24 PM
sandi
expedia.com hit by malicious banner advertisement?
Expedia.com has been infiltrated by a malicious banner advertisement - a new one that I have not seen before.

| Victim site |
Expedia.com (216.251.114.10) |
| SWF host |
media.expedia.com |
| SWF Source |
|
| Target fraudware domain |
scanner2.malware-scan.com |
| Banned cities, countries and IPs |
199.3.0.0-199.3.255.255 216.251.0.0-216.251.255.255 172.30.0.0-172.30.25.255 (note: expedia.com's IP is banned) IN, IL, UK, AU, FR, IT, CN, JP, DE, ES, MX, AE colorado, washington, california, massachusetts, ontario, texas, hawaii, missouri, illinois |
| Permitted cities, countries and IPS |
|
| SWF URL |
media.expedia.com/ads/FXSound/728x90.swf |
| Special notes |
|
| Incident reported to |
expedia.com |
| Resolution |
|
Let's have a look at the danger path:
| URL |
Referrer |
scanner2.malware-scan.com/18_swp/?tmn=null&aid=&lid=&affid=&ax=&ed=&aid=pygmalioni_ ma18_mb1t&lid=728&affid=&ax=1&ed=2&mt_info= 3958_0_1349prevedmarketing.com/?tmn=mwatmp&aid=mi1eroof&lid=728&ax=1&ed=2 &mt_info=4957_3064_2358 prevedmarketing.com//?tmn=mwatmp&aid=pygmalioni&lid=728&ax=1&ed =2&mt_info=5337_4168_2358blessedads.com/?cmpid=pygmalioni&adid=728quinquecahue.com/statss.php?campaign=pygmalioni&u=1200655836 |
quinquecahue.com/swf/gnida.swf?campaign=pygmalioni&u=1200655836 |
| quinquecahue.com/swf/gnida.swf?campaign=pygmalioni&u=1200655836 |
quinquecahue.com/statsg.php?u=1200655836&campaign=pygmalioni |
| quinquecahue.com/statsa.php?u=1200655836&campaign=pygmalioni |
media.expedia.com/ads/FXSound/728x90.swf |
So, let's take a look at this new name, quinquecahue.com.
Not surprisingly, the malicious domain is hosted by, you guessed it, securehost.com (190.15.64.190):
http://www.robtex.com/dns/quinquecahue.com.html
Who else might we find in that IP range...
http://www.robtex.com/cnet/190.15.64.html
Again, no surprise, we see akamahi.net, newbieadguide.com, vozemiliogaranon.com and a name I have not seen before, familyislands.com.
Check out the domains sharing nameservers with quinquecahue.com - I *know* you're going to recognise many names....
domains sharing nameservers
advancedcleaner.com
akamahi.net
antispywaresuite.com
antiviruspcsuite.com
antiworm2008.com
avsystemcare.com
bestsellerantivirus.com
diskretter.com
elmejorantivirus.com
erreurchasseur.com
exterminadordevirus.com
moncontenuassistant.com
schijfbewaker.com
securepccleaner.com
spyguardpro.com
storageprotector.com
systemdoctor.com
thetechnorati.com
toolsicuro.com
vozemiliogaranon.com
winspycontrol.com
yourprivacyguard.com
subdomains
*.quinquecahue.com
ns1.quinquecahue.com
ns2.quinquecahue.com
ns3.quinquecahue.com
ns4.quinquecahue.com
Filed under: Vulnerabilities, Security, safety and privacy on the Internet, viruses and exploits