CF Admins: More deep linking redirect attacks
I've brought this up before, they disappeared for a while. But this weekend, they're back on.
This happens just sitting viewing the Corvette Forum page. No clicking required. Then a rapid series of uncommanded redirects, which finally sent my browser to a malware site that my router blocked cold.
Again - no clicking required. Just viewing the CF page.
I assume this is also related to a blank/black ad box that may appear either up top or bottom?
I know the advertising team was aware of this issue and was reviewing it the last time.
I've brought this up before, they disappeared for a while. But this weekend, they're back on.
This happens just sitting viewing the Corvette Forum page. No clicking required. Then a rapid series of uncommanded redirects, which finally sent my browser to a malware site that my router blocked cold.
Again - no clicking required. Just viewing the CF page.
Again - I did nothing. I was just reading a post. No clicking, so it comes through an ad re-load. There's so freaking many of them on the CF site, that I'm not sure how to tell what element it was.
They go by so fast but it landed at this URL after several redirects (the usual "virus detected...download this" scam:
WARNING this URL is poison do not click!!!!
Other URL's in the redirect chain:
xttp://your-mac-security-analysis.net.ahrauchd.h5pg5hj9fyamcrwakp091o16mp5sjsne6izdq.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=y-ROUxf_tJrZ4x_Qz0mXCaBogauuVNs-eYfCtpYmdS-ehZemKFETwGKN0zli4hX7qTmy19jfmPtumtRRM_gu3vxgeSfHzURxsyFap-DpR65J9PXaDwpQ4_rfkhfTVKm5ktLp5o4EOxweiQAIlG6LZL9dCrOdECHgy0o6N1LABxgos1UpxaeJfBGklDyPmrVmK8sTb6H-BTPh5kDwTTWp9H5ugH8QCf6yujLNApZTPVYfpV3SBc8vg8VkIbGHc68bMlE__eEnv_a9_nySxrkjQtqMEzbolkuq7negwon7_H8nf6ocBZFcG5MYAPwNnMcg9shiOgQRmQinzYOGL9OFqOqT9iUmyVtTUxUKy3Kws8OaolqXfEJoHxIICP-8dexWzlhPCaMJJaL3Iw5A-hQrzDf-TDYOhXCcjWtCLXLbo-GMu1huhdce3x7TITcdSin1xK-5RF3asdcW6MBvU-tZuPYl1nGwbTMecxMz3nEV7MTto51OdP0_wOTwVD3qefy2n-ttBjibdc4xKkRM49kmF4FUKFasdmjrWmZzZWEUyWqx9vkS2JS7w1LVH_5Yrllv&_=BAoAXXSjUwFddKNTgAGBAcAAIPhDKrP9QjG5-heUhAEtFhN6wtI9psHZFSwKGy343M1MwQAgZPHWsccHmGyCRxQvpCIz1WLFxfV25DEBBAf-pO3Bot3CACDBrYscC8QDvs76dVlH5tBu8QnfpV1oGwVWHoMMKZjN48QAECYBBkaMAIudLLfZFH0P26vFABBZa4IItEn7cGMhHa-AunvrwwAgXAwcYevxT1AMk2M05VXU1_qNUYsu1Ftmg8IhpOPtKJI#b xttp://the.bestoffersonline.stream/?utm_term=6734188736508067961&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbfb28380b086878485a89bd9e9eef3f9bdd1fcfde1e3e3f1e7c6cba1878dc1ecdfd6e3d2d5e6e7e491888e9df9fecefcccc4cbc0f1c7c7c1c5cacbc850 xttp://the.bestoffersonline.stream/?utm_term=6734188745081225418&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbd8283b181868784b79adae8e9f2fabcdefdfee0e4e2f2e6b9caa2868ac0efded9e2d1d4e1e6e790978f9ef8f9cfffcdcbcac3f0c0c6c2c4f5cacbda xttps://0fficial.page/l/Mac/Cleaner/_index.php?lpk=15a367bb92bb58e901&language=en-US&img=sys2&uclick=fta9qdbl xttps://0fficial.page/ll/click.php?key=kf1hssv4d6kqatpev3cz&subid=6734188745081225418&t1=847&t2=847-6d15a6fz&t3=6734188745081225418&t4=US <meta http-equiv="refresh" content="0;URL='https://d5dijku3y67x2.cloudfront.net/?os=mac&x-context=wB0KILCOU4LT9V6P1IMSV908&utm_source=mmfxmrktddl3&utm_campaign=mmfxmrktddl3o&pxl=MMF4072_MMF3976_RUNT&utm_pubid=17521&x-at=f25a69b9-4af8-4553-895a-2041761e8173&override=1'">
Last edited by larrysb; Sep 8, 2019 at 03:16 AM.
Yes, there is a lot of JS. Not all JS is bad. Over the years, websites like CorvetteForum have grown and evolved as technology has changed and how people use and expect of the site has as well. The site is not a static site with text and images. You've got Infinite Scroll and Related Threads enabled, Auto Save Draft, Advanced Image Uploader, etc., that are all features that been developed and take coding (such as JS) to function. Not to mention legacy functions that also require JS (such as the drop-down menus). Turning off JS and browsing popular sites will show just how much JS is used to the point some sites will not load properly.
Again - I did nothing. I was just reading a post. No clicking, so it comes through an ad re-load. There's so freaking many of them on the CF site, that I'm not sure how to tell what element it was.
They go by so fast but it landed at this URL after several redirects (the usual "virus detected...download this" scam:
WARNING this URL is poison do not click!!!!
Other URL's in the redirect chain:
xttp://your-mac-security-analysis.net.ahrauchd.h5pg5hj9fyamcrwakp091o16mp5sjsne6izdq.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=y-ROUxf_tJrZ4x_Qz0mXCaBogauuVNs-eYfCtpYmdS-ehZemKFETwGKN0zli4hX7qTmy19jfmPtumtRRM_gu3vxgeSfHzURxsyFap-DpR65J9PXaDwpQ4_rfkhfTVKm5ktLp5o4EOxweiQAIlG6LZL9dCrOdECHgy0o6N1LABxgos1UpxaeJfBGklDyPmrVmK8sTb6H-BTPh5kDwTTWp9H5ugH8QCf6yujLNApZTPVYfpV3SBc8vg8VkIbGHc68bMlE__eEnv_a9_nySxrkjQtqMEzbolkuq7negwon7_H8nf6ocBZFcG5MYAPwNnMcg9shiOgQRmQinzYOGL9OFqOqT9iUmyVtTUxUKy3Kws8OaolqXfEJoHxIICP-8dexWzlhPCaMJJaL3Iw5A-hQrzDf-TDYOhXCcjWtCLXLbo-GMu1huhdce3x7TITcdSin1xK-5RF3asdcW6MBvU-tZuPYl1nGwbTMecxMz3nEV7MTto51OdP0_wOTwVD3qefy2n-ttBjibdc4xKkRM49kmF4FUKFasdmjrWmZzZWEUyWqx9vkS2JS7w1LVH_5Yrllv&_=BAoAXXSjUwFddKNTgAGBAcAAIPhDKrP9QjG5-heUhAEtFhN6wtI9psHZFSwKGy343M1MwQAgZPHWsccHmGyCRxQvpCIz1WLFxfV25DEBBAf-pO3Bot3CACDBrYscC8QDvs76dVlH5tBu8QnfpV1oGwVWHoMMKZjN48QAECYBBkaMAIudLLfZFH0P26vFABBZa4IItEn7cGMhHa-AunvrwwAgXAwcYevxT1AMk2M05VXU1_qNUYsu1Ftmg8IhpOPtKJI#b xttp://the.bestoffersonline.stream/?utm_term=6734188736508067961&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbfb28380b086878485a89bd9e9eef3f9bdd1fcfde1e3e3f1e7c6cba1878dc1ecdfd6e3d2d5e6e7e491888e9df9fecefcccc4cbc0f1c7c7c1c5cacbc850 xttp://the.bestoffersonline.stream/?utm_term=6734188745081225418&clickverify=1&utm_content=e7cacbe0c0dbc9c1a2a391979e97a49c8f8db888becabcc8b2b381878383b48dbfb988bdbcbf8cbd8283b181868784b79adae8e9f2fabcdefdfee0e4e2f2e6b9caa2868ac0efded9e2d1d4e1e6e790978f9ef8f9cfffcdcbcac3f0c0c6c2c4f5cacbda xttps://0fficial.page/l/Mac/Cleaner/_index.php?lpk=15a367bb92bb58e901&language=en-US&img=sys2&uclick=fta9qdbl xttps://0fficial.page/ll/click.php?key=kf1hssv4d6kqatpev3cz&subid=6734188745081225418&t1=847&t2=847-6d15a6fz&t3=6734188745081225418&t4=US <meta http-equiv="refresh" content="0;URL='https://d5dijku3y67x2.cloudfront.net/?os=mac&x-context=wB0KILCOU4LT9V6P1IMSV908&utm_source=mmfxmrktddl3&utm_campaign=mmfxmrktddl3o&pxl=MMF4072_MMF3976_RUNT&utm_pubid=17521&x-at=f25a69b9-4af8-4553-895a-2041761e8173&override=1'">
Also happens on Rennlist, another Internet Brands site.
I know all about JS, written a fair bit of it myself, but not my speciality. I'm more into embedded C/C++ and python.
The current vector appears to go through c.adsco.re and redirects to MacKeeper and other malware sites.
It's definitely coming through the advertising channel and they're encoding the mal-url in the image data and decoding it with JS.
I changed "http" in the redirect to "xttp" to prevent the hapless from accidentally clicking it.
So the embedded image data, decided by JS, causes a redirect from this rs.eujmj3g.space server, hands it off to adscore (who are providing cover for these kinds of malware redirects).
I'll add this domain to my router blacklist. We'll eventually, hopefully figure out which ad vendor is slipping this crap in. It hits a number of popular web boards, not just corvette forum.
For the users reading along, the scheme is to create a fake "image" file, with the redirect URL embedded as data and a javascript to run on your browser to extract it. They slip this on through adserververs, who kinda scan them looking for this kind of stuff. But they slip through. The ads on the page are active and reload on their own. Sooner or later, the malware redirect comes up on your browser, the fake image data is decoded, then a double-hand-off occurs and you get sent to a "download flash player" or "your mac is infected with three viruses" link.
These people are scum.
I'd love to see more done to stop them. It's BS. It also degrades the business value of ever web provider who gets this garbage slipped in on them.
xttp://rs.eujmj3g.space/zp-redirect?target=https%3A%2F%2Fc.adsco.re%2Fd%23Qj4hAAAAAAAAEy7UL13RqmPdTwDQ5wnEWeWnCCs%2Cdd2df884-574f-4a2c-8f8c-ee9ae7ed62eb_whiskey-bob-H2d0uBT7%2C3%2C%2CAAIe4oCm8tIO9F6MLp_t9rCVO6NgT_LE9ClqeJ90k09s9uOTNky4KpUkl-NqYIGsXcfka20kdzXjcscKks7_zT8kCf8HBVmn32ql5Gc1pyWsQH4JnPZJYzhjZQUDOlF2CeqSw4liYZqt2dHWkKXrkd-262RmSqqXstpc6unRDYigblZGu9-ztAtx7mT7VwM0cdjwt6hLx29EKvKVMchOu-CPS4WGI1fagLF3dZXWa6NvJ1RIhdWYR4F4DVp-Ej3Lz4IJIxgzeCwh5aYyMjxJIlQMs_SSa3xXW4mspx_S9-Bngy5h4VbvZQytXS17x8bMkoD30momCyqYBT4MqhyTIbtye-FQ_d2i3KqPTqHPCWSxOw%3Fbrowser%3DSafari%26trackingdomain%3Drs.eujmj3g.space%26brand%3DDesktop%26model%3DDesktop%26osversion%3DMacOS%252010.14%2520Mojave%26cep%3D%26cep%3D-MEcx42R5Qz8FxVw2wga2BQ-k7wTZzjgwiWGfOfiquBbHj3Lehss49Gpyq_DYTfKTa-stsR6cUnbMIRuKmEYoovk-PCQ6bVsVHAYuoVd5SDUR_JkMbIIq1S4sSWSHvLM50WcYBmCI1OSughEaBXuAX4UcRCQS0gj65SH-Q3_n6-nqt0MAK-TYFu1m6VKmJ-ohQdbULeQZXt-7odpHKAOoVVTvwnG7KZdyfGB8brXV-Wpwwg1Fe9uSMOOsiHCx2NZlPv-8mbsdJTXM19lYzxcStySwqlR-AQNpwUHmDP4k8r31cb5BopqkH-ITteDQM2G6X3lK7HQ5H7Coou47EaCYVW37XVM-386tuKtkF5bJtnaiGokYlNDIgc8IHWhiZ0DxqLSldSwPIRawdsMdDoYq-2_ajROHEsOT9wLwsTvSzNNP1pNgGH01bz1aCvPvC4454XbQOOw23rgF8dGX4A6E_Ny8K_mjFTxmKby9a8f5PCXyKOcublW2hRM4QYXAH4k5F_UlPFpLi3q-lKV29CKxVDmIvlkjiM3IMw-Deunz6G40unCznB1Qvw-_raP86SB7UqL5TL33jFWsWEMh-BgzA%26lptoken%3D15126962368e279f165c&caid=66a39719-c53a-4764-aff0-d410ed5183ba&zpid=332b01ec-df13-11e9-af87-0ad8dd6ea862&cid=&rt=R
End of code
Last edited by larrysb; Sep 24, 2019 at 05:56 PM.
xttp://your-mac-security-analysis.net.gwbpobzrv.semumcgfnqvx8lkkrwtso4jdc4upyxz4.xyz/fx/en/index.php?browser=Safari&fred=1&app=Mac%20Speedup%20Pro&hul=rs.eujmj3g.space&cep=4rGtAf_zZWfdYHnohQ1zM0FMErYW0297RETBBUmZvUls0sl1fGMMDG4xflqD_eG-AQvLwX30FrduXWdz4favn-UHNxJy_MNm3SuCEQyXNxqZumC_HDKZInq9EeEjnEja4wm5pD4BZQnUcA0J5c3q8S6aur2SfjRV_dpdBE0C5N0Id7q2zMIrodV0yYSoaf25-_aLTUc-FxTNPO2lgwXLt9QHgH0oEFKY4rJNQb3KwVuufwa9ln_G1x20nxYeMr1j_NAhzZu6_n6I72Pc9BkEv9LdNlwpt9TIcYdG7nIkySzqx3n39HhCqwS7_y4Fdaom1fjnqr4FsNVjR2gj3qdVcMSSxsMeUza9OBjQXbWFrPWgNXQdE5zK-39gUqLinDir0aU71VT2EhhjSLVVUFhu3mqnxJsA4lPbIdromfjzVQp4CAzqAwcvKY81gpYV6dNJIvHZyWK5PG1gTgrzyyZO2d33wCxXRknB4AO14cffasmgN1C2eb4CqI1mQc0ZZOqrJs35ssImTQlaeMi3L4Fc04acrsV_MtM3owZ_1YTHHmLQcFbk202ri7rgkhJJRv4HSzYv5JipLAG8JRKBvlhwEg&_=BAoAXYqSsAFdipKwgAGBAcAAIOqewL68M-URQBcZYa2GURDXRtGaEoMYCzfRTBW6hjBGwQAg8sef7geIWOpTCTkfHiRWQUW-8Imsv9mF6ixmmJjs2P_CACDOiCWDwyNGQ3r7RXVQA2xw3BwcDeBiIBab56lmlXoTbMQAECYBBkaMAIudnX2gwQ_d0SLFABD-f4oawPYy1TUgi7dmzbqNwwAgBhavMuUnpl62ieHv6IbL7cZzj2cmCGN5aokyxAWKh30
end of code
The Best of Corvette for Corvette Enthusiasts
I have a screen shot of what happens right before the redirect:

I would like to ask you, what do I need to add to my router to block this behavior? You mentioned it above in one of your posts, but could you please tell us exactly what needs to be written to blacklist it?
Thanks again!
That said, the teams were reviewing and discussing this (and other) material regarding this concern on Friday so the teams continue to address these concerns.
You can, at least on MacOSX and Linux systems, edit the 'hosts' file on the system ( in /etc/hosts ).
However, I'm find that for some inexplicable reason, Safari resolves DNS different for HTTP vs HTTPS. It respects /etc/hosts for http, but not https. Who the heck knows why they did that.
I do NOT have an issue with advertisers!!! That' perfectly fine with me. Legitimate advertising is completely OK in my book.
I have a lot hatred for malvertising which is what all these pop-ups and redirects are all about. They're hijacking Internet Brands users to try and trick them into installing malware.
What happens is this:
Internet Brands contracts with ad-insertion providers and get paid for "impressions" and clicks through. There's a rotating banner ad at the top and bottom of the page. If you leave it sit, every few seconds a new banner pops up. These advertisers want to be sure they're not being ripped off with fake views by robots and what not, so they use bot detectors and browser fingerprinting services, like adscore.
The problem comes in when some unscrupulous outfit buys ad impressions and they encode the malware redirects into hidden things, like dummy images. They write little javascripts that decode the blocks, and then they bounce through the robot detection services (who are often on the shady side). The 'bot detection server is supposed to identify real browsers vs. bots and send them the real people a real ad, while sending the robots nothing. The legit purpose is to circumvent click robots.
But - adscore and others, are easily abused (and they don't try real hard not to be abusable) into fingerprinting your browser and redirecting you to a malware vector. That's why Macs get redirected to the "MacKeeper" a-holes, Androids get directed to the "..google user..." scam and Windows users will often get the "your PC is infected...." . All are malvertising and either trying to force-fish you into clicking a link or downloading something harmful to your computer or phone.
Honestly, if I were an exec at Internet Brands, this crap would be way up on my priority list. There is no purpose at all in whoring out your hard-earned users to malware vectors. It's like running a nice restaurant and inviting pick-pockets to wander around and steal what they can from your customers.
I would prefer this thread keep on topic for those who want to report they're seeing the issue, along with a screen capture, and please also provide your regional location if you're reporting the issue. Please keep the discussion of router blocking, software blocking, and management operations (use of ads, etc.,) to PMs or email as it technically doesn't follow our guidelines and it sidetracks this topic from being able to provide the assistance needed for the team to continue tracking the issue.
The team is actively working on this issue and some of the information from this thread and outside of CorvetteForum has given some leads in progress of the recent spam.
Thanks
Thanks for the in depth account of this plague. I seem to get a tsunami of it for a couple of days and then it disappears for a while. Only on my hand held, never on my home computer.
Have you been able to determine yet who the responsible party is?
Greg















