ALERT: malvertizement on display at jeuxvideo.com
Hat tip to Malekal
Deja vu – guess what domains are involved in the jeuxvideo.com incident – adclickmate.net and smartadserver.net.
IMPORTANT NOTE: PLEASE DO NOT CONFUSE THE MALICIOUS DOMAIN SMARTADSERVER.NET WITH THE LEGITIMATE SMARTADSERVER.COM.
Adopstools results – positive:
Malicious code is hidden within the SWF creative as dynamic text:
We saw an incident involving adclickmate.net back in January described here. Kimberley also posted a warning about smartadserver.net on 30 January. How unsurprising it is to see that Directi has done nothing to shut down adclickmate. The WHOIS and IP information for adclickmate.net remain unchanged (except for the fact that the IP address 22.214.171.124 is now listed as Turkey, Netdirect-lnwservers.
Registrar: DIRECTI (yet again)
Created 24 March 2008
IP: 126.96.36.199 - Turkey, Netdirekt
WHOIS hidden behind privacy protect (note the nonsense
Domain originally registered via ESTDOMAINS - WHOIS protection temporary removed around late August 2008, which revealed:
Jacob Tua (email@example.com)
Later changing to:
Domain Names copr.
WHOIS was again hidden behind PrivacyProtect on or about 9 January 2009.
Registrar: INTERNET/BS CORP
Created 18 November 2008
IP: 188.8.131.52 - Netherlands, Blue-ace-inc
WHOIS hidden behind the privacy protection service "privatewhois.net". Note the nonsense telephone number +1.23456789
It is interesting note that the web page at smartadserver.net used to display the text “adserver.adtechie.net” (adtechie.net is a DIRECTI registered domain, now suspended). That text has since been changed to “smartadserver.net”.
The domain adtechie.net is interesting in and of itself; it was involved in the malvertizing incident that hit Fox News back in November 2008. You can see my report here. Its IP address has changed from “184.108.40.206” to “220.127.116.11” and now shares IP with the domain mojocounter.biz.
Created 16 January 2009
IP: 18.104.22.168 - Turkey, Netdirect-lnwservers
Andelka Kucinic (firstname.lastname@example.org)
Gosposka ulica 101