{"id":1049,"date":"2015-02-08T18:41:51","date_gmt":"2015-02-08T18:41:51","guid":{"rendered":"http:\/\/blogs.secure-bits.com\/?p=1049"},"modified":"2015-03-01T15:06:49","modified_gmt":"2015-03-01T15:06:49","slug":"the-cost-of-malvertisement","status":"publish","type":"post","link":"https:\/\/blogs.secure-bits.com\/?p=1049","title":{"rendered":"The cost of malvertisement&#8230;"},"content":{"rendered":"<p>In the <a title=\"previous blog\" href=\"http:\/\/blogs.secure-bits.com\/?p=1023\" target=\"_blank\">previous blog<\/a>, we&#8217;ve looked at how malvertisement may affect you and what you can do to protect your system(s) against this threat vector. In today&#8217;s blog, we&#8217;ll look at the actual distribution channels and the cost for displaying malvertisement.<\/p>\n<p>Beyond the advertisement shown in your browser, there&#8217;s a well established business model that isn&#8217;t that much different from any other business models.<\/p>\n<p><a href=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2015\/02\/distribution-channel.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-1051\" src=\"http:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2015\/02\/distribution-channel.jpg\" alt=\"Distribution channel\" width=\"199\" height=\"439\" srcset=\"https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2015\/02\/distribution-channel.jpg 199w, https:\/\/blogs.secure-bits.com\/wp-content\/uploads\/2015\/02\/distribution-channel-136x300.jpg 136w\" sizes=\"(max-width: 199px) 100vw, 199px\" \/><\/a>The picture on the left shows the typical business model. Basically the products are created (including malvertisement), sold to distributers, who in return make them available to consumers.<\/p>\n<p>The difference is how other distribution channels are regulated and the requirements are enforced by various government agencies. You&#8217;d had hard time in the U.S.\u00a0purchasing food at your supermarket, without FDA approval, buy a car\u00a0without NHTSA approval, etc.<\/p>\n<p>Unfortunately, the online advertisements are loosely regulated, with minimal, or no enforcement whatsoever. There&#8217;s no need for approval by the website or the advertisement network. They will pretty much blindly refer your browser to the site, where the actual ad is hosted. The actual site could be hacked\u00a0websites, hosted servers, etc.<\/p>\n<p>Hackers had discovered that they can just bid to display their ads at various sites. Since\u00a0anyone can bid to display their ads, including the maximum price per displaying the ad, this is an easy way to have the malware distributed by reputable websites. The hackers&#8217; malware incorporated in an ad (we call malvertisement), they bid to display their ad at targeted websites, and\u00a0the advertiser network kicks in. When you visit the targeted websites, the ad becomes part of the website&#8217;s content, any script in the ad executed by your browser without you clicking on it. You probably recall a few websites that\u00a0had some music and\/or video already playing just by visiting their home page. This is the type of ad delivery that hackers use to load\u00a0malware\u00a0on to your system.<\/p>\n<p>The process described is automated to the level that the chances are no humans evaluate the actual ad during this process. As such, malware is distributed without any warning. The sole exception might be your system protection that should stop the malware execution.<\/p>\n<p>So, what is the actual cost for the hackers to display their ads? That depends on the website, where the ads are displayed. <a href=\"https:\/\/blog.malwarebytes.org\/exploits-2\/2015\/02\/hanjuan-ek-fires-third-flash-player-0day\/\" target=\"_blank\">Malwarebytes blog<\/a> states $0.927 per displayed ad with current malvertisement at the following websites:<\/p>\n<ul>\n<li>dailymotion.com<\/li>\n<li>theblaze.com<\/li>\n<li>nydailynews.com<\/li>\n<li>tagged.com<\/li>\n<li>webmail.earthlink.net<\/li>\n<li>mail.twc.com<\/li>\n<li>my.juno.com<\/li>\n<\/ul>\n<blockquote>\n<p style=\"padding-left: 30px;\"><span style=\"color: #ff0000;\">Why neither the advertisement network, nor the websites are responsible for delivering malware in the ad, is beyond me. Holding the hackers responsible for the ad, but taking their money nonetheless, should be illegal. <\/span><\/p>\n<\/blockquote>\n<p>Since your system protection should stop the malware, it raises a question. Why don&#8217;t the advertisement companies and websites test the ad for malware, prior to presenting it to the end users? It&#8217;s really not that hard to do:<\/p>\n<ol>\n<li>Advertiser receives the bid for the ad<\/li>\n<li>Client sends the ad to the advertiser<\/li>\n<li>Advertiser scans the ad for malware<\/li>\n<li>Advertiser approves the ad, if no malware found, and hosts it on their server<\/li>\n<li>Websites receive the ad from the advertiser, if they opt into their program<\/li>\n<\/ol>\n<p>It&#8217;s harder to test the ad for malware by the website, but not impossible; real-time scanning for malware had been in existence for decades.\u00a0The chances are that implementing such system would offset some or large part of the financial gains of displaying ads..<\/p>\n<p>If security software on the client side can stop the malware, there should be no reason why advertisers and websites\u00a0cannot scan the ad for malware. Samples of security programs that can stop 0-day malware:<\/p>\n<ul>\n<li><a title=\"Malwarebyte Anti-Malware\" href=\"https:\/\/www.malwarebytes.org\/\" target=\"_blank\">Malwarebyte Anti-malware<\/a><\/li>\n<li><a title=\"Microsoft EMET 5.1\" href=\"http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=43714\" target=\"_blank\">EMET 5.1<\/a><\/li>\n<\/ul>\n<p>There are certainly other security solutions that can stop 0-day malware, but antivirus isn&#8217;t one of them. The samples above are part of the security protection for my systems.<\/p>\n<p>It&#8217;s unlikely that either the regulation or the advertisement\u00a0distribution online\u00a0will change anytime soon. There&#8217;s too much money to be made in the current ad delivery schema. As such, your favored website(s) might be serving up malware to your system that may just gobble\u00a0them up. You should\u00a0protect your system against them and by now, you should know that <a title=\"antivirus will not protect you\" href=\"http:\/\/blogs.secure-bits.com\/?p=781\" target=\"_blank\">antivirus\u00a0will not protect you<\/a>.<\/p>\n<p>Friends, don\u2019t let friends rely on antivirus protection only\u2026<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the previous blog, we&#8217;ve looked at how malvertisement may affect you and what you can do to protect your system(s) against this threat vector. In today&#8217;s blog, we&#8217;ll look at the actual distribution channels and the cost for displaying &hellip; <a href=\"https:\/\/blogs.secure-bits.com\/?p=1049\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[18,24,36],"tags":[],"_links":{"self":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/1049"}],"collection":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1049"}],"version-history":[{"count":19,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/1049\/revisions"}],"predecessor-version":[{"id":1073,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=\/wp\/v2\/posts\/1049\/revisions\/1073"}],"wp:attachment":[{"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.secure-bits.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}