Google AdSense Serving Malware

@revmagdalen Tweeted a warning that her blog was infected and no one should go there.

So I rushed over there to see, naturally.

Her blog appears to have Google Adsense ads, which redirect it as soon as it loads to one of at least three malicious sites.

I loaded it in Firefox with noScript and allowed scripts one by one until I found the malicious one--clicksor, as shown below.

Here are the pages I saw when loading the blog normally in Chrome:

@revmagdalen said she did not put any ads there other than Google Adsense, which means that AdSense itself is handing out malicious ads.

This post from 2012 says you can prevent this by adjusting your Google AdSense settings:

Google AdSense Potential Source of Malware

This discussion from 2013 describes Clicksor from the point of view of bloggers who hope to make money from it:

Clicksor -- Can You Really Make Money With Clicksor?

They certainly look like a legit ad company:

http://www.clicksor.com/

But they have been accused of spreading malware:

https://www.mywot.com/en/forum/7267-clicksor

And from what I see, this accusation is justified.

@revmagdalen removed AdSense and a social sharing widget which I already knew to be clean, and the blog no longer redirects in Chrome:

This seems to prove that Google AdSense is serving up malware, via Clicksor.

I recommended to @revmagdelen that she report this as an AdSense policy violation here:

Reporting a Violation

Packet Capture

If anyone is interested, here is a complete packet capture of loading the blog while it was infected:

revm-infection_052114.pcap

More Previous Reports

Clicksor has been serving the same fake Flash update since at least Feb., 2014:

Clicksor and Amonetize deliver Adobe Flash Player Update

In 2012, they led to the Blackhole kit:

Clicksor Ads on Blogger lead to Blackhole Exploit Kit


Posted 1:10 PM 5-21-14 by Sam Bowne
Violation report link added 1:22 pm
Pcap added 1:31 pm
More links added 1:54 pm