Malicious advertisements served via Yahoo
ID: 8b0177f0-0335-5093-b304-f397604f2195
STIX ID: report--8b0177f0-0335-5093-b304-f397604f2195
Feed Name: Fox-IT blog
Fox-IT's SOC detected a large-scale malvertising campaign on Yahoo that served malicious iframe ads redirecting users to the Magnitude exploit kit (hosted from 193.169.245.78) which exploited Java to install multiple malware families (ZeuS, Andromeda, Dorkbot, Tinba, Necurs, advertisement-clicking malware). The report lists malicious ad domains and IPs (e.g., blistartoncom.org and the 192.133.137.0/24 and 193.169.245.0/24 subnets), estimates ~300k visits/hour with a ~9% infection rate (~27,000 infections/hour), identifies Romania/UK/France as heavily affected, and recommends blocking the cited subnets and monitoring for dropped malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
