Inside a Malicious Push Network: What 57M Logs Taught Us
ID: 612e7cc0-53d0-546e-aee6-4eba7dc71d63
STIX ID: report--612e7cc0-53d0-546e-aee6-4eba7dc71d63
Feed Name: Infoblox Threat Intel Blog
Threat Score
Researchers exploited lame DNS delegations to claim abandoned domains used by a global push-notification affiliate ad network, passively collecting ~57M events and 60GB of JSON over ~15 days; analysis exposed large-scale deceptive/sCAM push notifications in 60+ languages, detailed subscriber metadata, the actor’s fraud mitigation and pricing practices, low effective CTRs and modest revenue, and confirmed that no malware payloads were delivered via the sampled network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
