• We should now be fully online following an overnight outage. Apologies for any inconvenience, we do not expect there to be any further issues.

Security Threat on a page (Ad?)

Status
Not open for further replies.

kevinsbane

Senior member
Jun 16, 2010
694
0
71
Noticed this when I tried to access a page on Anandtech.


AVG Warning
URL:
eus2.admxs.com/index.php?d=9
Name: Blackhole Exploit Kit (type 1397)
virusalert.jpg



The page that was loaded was the CPU forum page, the top page ad is a new one I haven't seen before, soundscience rockus 3D. The bottom left ad is an OCZ power supply ad for the ZX series.
ad1m.jpg
 

postmortemIA

Diamond Member
Jul 11, 2006
7,721
40
91
yep, it is bad, tries to use some java vulnerability. not direct AT fault, that is how badware spreads lately.
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
That's definitely not good...

Do you have any more details on the threat? I'm not finding much on Blackhole Exploit Kit. We've had a problem with false AVG warnings once before, so I'd like to be able to get some confirmation on this before getting too far ahead.
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
Alright, the link is back up and I've been able to parse the JS; it's definitely shady.

For those of you guys getting it, it's the same as tracking down pop-up ads: I need you to get a list of each ad on the page (there are 3; top, left, bottom), and ideally capture the origin URL of each ad. The AnandTech IT guys can't fix this until they know the ad and ad network that's compromised.

Edit: And it's not the Rockus ad; that's a local ad coming right from the AT ad servers and is coming up clean.
 
Last edited:
Status
Not open for further replies.