{"id":186,"date":"2024-04-15T11:17:50","date_gmt":"2024-04-15T16:17:50","guid":{"rendered":"https:\/\/freshphish.info\/?p=186"},"modified":"2024-04-15T11:17:50","modified_gmt":"2024-04-15T16:17:50","slug":"fake-av-toad-ads","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=186","title":{"rendered":"Fake AV TOAD Ads"},"content":{"rendered":"\n<p>This one isn&#8217;t an email I know it is something that has been around awhile. I&#8217;ve seen a lot more of these in the past week or so.<\/p>\n\n\n\n<p>First, a web browser is presented an ad in the middle of a news article that looks like a continue button to read the rest of the story. If the user would scroll down just a bit, they&#8217;d see the rest of their article but they see a &#8220;continue&#8221; button and click it without thinking.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"543\" height=\"343\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/ad.jpg\" alt=\"\" class=\"wp-image-187\" style=\"width:789px;height:auto\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/ad.jpg 543w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/ad-300x190.jpg 300w\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" \/><figcaption class=\"wp-element-caption\">Here is a screenshot of the ad seen.<\/figcaption><\/figure>\n\n\n\n<p>Once clicked, they are initially brought to a Google ad landing page that just presents another Continue button:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"789\" height=\"457\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/firstlink.jpg\" alt=\"\" class=\"wp-image-188\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/firstlink.jpg 789w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/firstlink-300x174.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/firstlink-768x445.jpg 768w\" sizes=\"auto, (max-width: 789px) 100vw, 789px\" \/><\/figure>\n\n\n\n<p>Once they click this Continue button, they&#8217;re brought to the fake ad page, which tries to put the browser into full screen mode, shows malware alerts and has a computer generated voice warning about a malware infection. This is intended to cause a panic in the user so they&#8217;ll call the provided phone number, which would result in a likely fraudulent charge or perhaps a refund scam.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"454\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/toadphish-1024x454.png\" alt=\"\" class=\"wp-image-189\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/toadphish-1024x454.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/toadphish-300x133.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/toadphish-768x341.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2024\/04\/toadphish.png 1273w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Note my virtual environment here shaded the screen and prompted for permission to go full screen. The URL is in the z13.web.core.windows.net subdomain, owned by Microsoft. Doing a search for this subdomain provides a number of discussions about the volume of malicious sites hosted here. I recommend blocking this subdomain for all environments.<\/p>\n\n\n\n<p>-Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This one isn&#8217;t an email I know it is something that has been around awhile. I&#8217;ve seen a lot more<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=186\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Fake AV TOAD Ads<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[53],"tags":[50,52,19,49],"class_list":["post-186","post","type-post","status-publish","format-standard","hentry","category-malvertising","tag-fake-av","tag-malvertising","tag-microsoft","tag-toad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=186"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/186\/revisions"}],"predecessor-version":[{"id":190,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/186\/revisions\/190"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}