dimanche 22 février 2015

Malware adding code to ga.js opens up random ads/websites?


A friend of mine just handed me his tablet saying that everytime he open a webpage the browser redirects to several advertisement page (or, it "adds" advertisements on the page).


This happens both on Chrome and the stock browser.


I used USB debugging to look at the browser request and I think I found the culprit. When the browser loads http://ift.tt/PkK5TX the actual code is different. See this screenshot (the green line is where ga.js should terminate):


enter image description here


(and the added code goes on...)


I initially thought that some malware changed the hosts file and assigned a different IP to the google-analytics website, but this is not the case since when I visit the above link directly I see the correct JS code.


How can I track which app is doing this?





Aucun commentaire:

Enregistrer un commentaire