مسدود کننده تبلیغات مخرب AllBlock تبلیغات جدید را به مرورگر تزریق می کند

Experts from Imperva discovered the malicious ad blocker AllBlock, a browser extension, which fulfills its task, also but injects hidden affiliate links into the browser.

The extension is still available in the Chrome Web Store and is positioned as a tool for blocking ads on YouTube and Facebook, including to combat pop-ups and speed up browsing.

Researchers say AllBlock indeed fights advertising, but only to implement its own. مثلا, AllBlock forces legitimate URLs to redirect users to affiliate links controlled by the extension’s developers.

This allows fraudsters to make money from advertising themselves or to redirect people to affiliate sites to earn royalties from affiliates.the researchers say.

Specialists discovered the strange AllBlock activity back in August 2021, when they identified a number of previously unknown malicious domains distributing a script to inject ads. The script sent legitimate URLs to the remote server and received a list of domains to redirect in response. If a user clicked on a link modified in this way, he was redirected to another page (usually an affiliate link).

AllBlock activity

علاوه بر این, the script can evade detection, مثلا, stays out of sight of large search engines, clears the debug console every 100 ms and actively detects Firebug variables.

After examining the AllBlock blocker in more detail, را Imperva team discovered this script (bg.js), which injects the code into each new tab opened in the browser. To inject a malicious script, the extension connects to a URL on allblock.net, which returns the script in base64, after which it will be decoded and embedded into the page. همزمان, the developers of the extension even added several harmless objects and variables to the malicious code fragment, trying to hide its malicious functions.

How AllBlock is advertised and distributed is not yet clear, but Imperva experts believe that scammers may use other extensions in this campaign. مثلا, they managed to find some evidence that the same IP addresses and domains link this extension to the malicious Pbot campaign, which has been active since at least 2018.

بگذارید این را به شما یادآوری کنم Strange malware prevents victims from visiting pirate sites.

هلگا اسمیت

من همیشه به علوم کامپیوتر علاقه داشتم, به خصوص امنیت داده ها و موضوع, که امروزه نامیده می شود "علم داده", از اوایل نوجوانی من. قبل از ورود به تیم حذف ویروس به عنوان سردبیر, من به عنوان کارشناس امنیت سایبری در چندین شرکت کار کردم, از جمله یکی از پیمانکاران آمازون. یک تجربه دیگر: من در دانشگاه های آردن و ریدینگ تدریس می کنم.

پاسخ دهید

این سایت از Akismet برای کاهش هرزنامه استفاده می کند. با نحوه پردازش داده های نظر خود آشنا شوید.

دکمه بازگشت به بالا