4 ms·
Hmm, that sounds strange. If you were only able to reproduce it on a Nexus 5, I don't think analysis with ScriptObservatory will be easy. I'd still suggest sub
by andy112 11y ago
Hmm, that sounds strange.
If you were only able to reproduce it on a Nexus 5, I don't think analysis with ScriptObservatory will be easy. I'd still suggest submitting the URLs to be scanned by the robo-browser and then looking to see if what gets reported looks similar to what you saw before.
Also, if you write a Yara rule that matches on some of the unique features in the JS/iframes you saw, you could run a search through what's been seen. You can use that to also be alerted when new matches are reported. If something similar has been seen elsewhere, you might be able to tie it to a specific ad network.
- voltagex_ 11y agoThe only reason I haven't run it again in a VM on a desktop is that the desktop version of these ads is a lot more malicious - exe downloads of antivirus scam software
- voltagex_ 11y agoLooking at Yara rules - I won't have time today but a unique-ish string in the script was adsbyText:"ADS BY "+ including quotes.
- andy112 11y agoYep that looks like a good string to key off of. The results for the site you mentioned are here - https://scriptobservatory.org/webpage/543677125f1bea8226ba7c0578e4836332c97f48f56d23894c63b61725965959 https://scriptobservatory.org/webpage/543677125f1bea8226ba7c... - but I don't see anything that looks like a clear match.