A malvertizement featuring XE Radio rears its head again

Interestingly, the malvertizement features the same campaign as the MediaMan malvertizement that Kimberley found on isuisse, iquebec, ibelgique and ifrance back on 10 July.

Screenshots of the XM Radio malvertizement:

image

image

image

We see various domains when hit by a malicious redirect, including:

 

stathisranch.net/crossdomain.xml

stathisranch.net/c/index.php?<<removed>>

profitabill.com/?cmpid=asbarrator (this is the same as the MediaMan malvertizement mentioned above)

adnetserver.com/?<<removed>>

adverdaemon.com/?<<removed>>

antispywaremaster.com/data/<<removed>>

sicherheitstool.com/kontroller/?<<removed>>