More Than 200K Expired Domains Spreading Malicious Ads
The expert investigation began with the client to contact technical support. The customer complained that the ads displayed “XWINNER COM” on its website and asked to look into the incident and clear the site from malware. An analysis of HTTP traffic revealed that the client site loads images from the site “www.twomediaxthemes.com”. The impression was that the hackers somehow managed to introduce a reference to the image in the website templates:- However, these injections are not inherent to the burglary site, but, the most detailed analysis showed that the links have been added to the template image by a developer....