Sunday, March 23, 2008 2:59 PM
sandi
Malicious advertisement detected at www.classmates.com
Thanks to Susan Bradley for the heads up that there is a problem at www.classmates.com
The malicious creative can be seen at this URL:
http://nztv.prod.untd.com/RealMedia/ads/Creatives/ISP/CM_GeminiIntera_FPR_4_10179/300x250.swf?clickTAG=http://cyclops.prod.untd.com/RealMedia/ads/click_lx.ads/www.classmates.com/School_List/L18
/968920812/TopLeft/ISP/CM_GeminiIntera_FPR_4_10179/300x250_GeminiInter_Mar08.html.html/
4f7148557555666c32626f41444a314d?http%3A//www.myjewelrybox.com/%3Fids%3D46ps
Here is a screenshot of the malicious advertisement:
An analysis of the SWF reveals a URL pointing to a known malware domain:
iexplorer-security.org/?id=624400105
----------------
The iexplorer-security.org URL is active, and redirecting victims to xponlinescanner.com as follows:
The URL iexplorer-security.org/?id=624400105 leads us to:
fastwebway.com/soft.php?aid=011807&d=1&product=XPA
The fastwebway.com URL in turn leads us to:
xponlinescanner.com/2008/1/freescan.php?aid=77011807
It should be noted that as part of the hijacking process a cookie is set that expires after just 24 hours.
----------------
The malicious advertisement has been reported to RealMedia although it looks like the advertisement is self-hosted, therefore it may take a little while for the advertisement to be shut down.
----------------
Who are fastwebway.com?
The reverse IP for this domain is traffic-coverter.biz.
Its name servers and mailbox are provided by estdomains.
Its IP address is 72.232.224.154, hosted by LayeredTech (ltdomains.com)
Other sites/services hosted at 72.232.224.154 are:
bestsexworld.info
dvd-disk.net
mail.dvd-disk.net
mail.er-a.net
mail.pornorolikov.net
mail.sexroliki.com
pornorolikov.,net
sexroliki.com

Filed under: Security, safety and privacy on the Internet, Vulnerabilities, viruses and exploits