Blog | G5 Cyber Security

Massive Admedia/Adverting iFrame Infection

The malware only infects first time visitors, it sets the ad-cookie cookie (er2vdr5gdc3ds) that expires in 24 hours. It injects an invisible iframe URL Admedia or advertizing in the path part of the URLs (so we called this malware admedia iframe injection ) The same structure of URL parameter, including ad_id which is always the same Twiue123.polnue123. The use of the third level domains is typical for adding malicious subdomains on legitimate. domains.”]

Source: https://blog.sucuri.net/2016/02/massive-admedia-iframe-javascript-infection.html

Exit mobile version