[Method] Adsense Blackhat In deep analyze

meannn

Elite Member
Joined
Apr 22, 2009
Messages
1,908
Reaction score
2,771
The scenario here is that traffic to some popular adult websites will get redirected via malicious advertising to one of several fake blogs with topics ranging anywhere from wedding tips, pest control, or appliances.

The redirection chain includes the mandatory passage through what we call a gate whose objective is typically to inspect incoming traffic and take actions.

Within one of those gates, we noticed interesting bits of code that was meant to “fingerprinting” visitors to collect their IP address, User-Agent, and screen resolution via a POST request, upon the initial redirection from malvertising.



Figure 1: Fingerprinting code at the gate (click to enlarge)

This information is typically harvested by most websites for stats and optimization purposes, but given the explicit use of an appropriately named getfingerprint.php file, we can assume that the fraudsters were trying to identify real users versus crawlers or repeated visits of the same page.



Figure 2: Web traffic from malvertising to gate (click to enlarge)

A façade: adult gallery hides fake blog
Content is one of those things that is very important to search engines and other crawlers as it ultimately gives more value to a website. A long time ago, blackhat SEO criminals used a technique known as keyword stuffing which aimed at getting the site ranked high in the search engine result pages (SERP), but it is easy to detect nowadays.

Plagiarism is still very effective, and copy and paste has never been easier. It’s a cheap way to get some decent content with little effort. In this particular campaign, we witnessed several websites that had been created recently and filled with new blog entries.

It didn’t take long to find out where the write-ups were stolen from: mainly sites like Ezine or Pinterest. The thieves didn’t even bother changing any of the wording, they simply did a copy/paste to populate each of their fraudulent website with dozens of entries.



Figure 3: A fake blog about weddings with stolen content (click to enlarge)



Figure 4: Original content used by fake blog found on Ezine (click to enlarge)

If you visited one of those sites directly, you would see what seems to be a site giving advice for weddings accompanied by a few adverts powered by Google’s DoubleClick, which is quite typical for any website that needs to pay for its operating costs. However, only crawlers most likely visited those websites directly as the motives for setting them up was very clear: to defraud advertisers via hijacked traffic.

A layer containing adult images is superimposed such that both content is displayed in the browser, but only the top layer (adult material) is visible to the eye.

adult_content.png


Figure 5: The wedding blog turned into an adult portal thanks to an overlay (click to enlarge)

This is important because the crooks want to load the underlying blog and its content which includes paid adverts so that they can monetize on ad impressions, while at the same time tricking visitors into thinking they are still accessing their adult videos.



Figure 6: Diagram of ad impression fraud via adult page overlay (click to enlarge)



Figure 7: Web traffic from gate to fake blog, to advert (click to enlarge)

Stealing (real) users’ clicks
The first stage of this ad fraud campaign consisted of showing a thumbnail of adult videos while displaying hidden adverts, but that is not all. Users are conned into clicking to actually view any particular video, which takes us to the second part, that involves Pay Per Click (PPC) fraud.

The user is presented with a single adult video page but there is no actual video to be played, as it is just a screenshot designed to mimic a video player with the play button and timeline bar.

The goal is to get users to click on a hidden advert, but only after some validation checks that ensure the clicks are from genuine humans. This is somewhat ironic for fraudsters to check against bots.



Figure 8: Diagram of fake video page which tricks the user into clicking play button (click to enlarge)

hidden_ad.png


Figure 9: The hidden advert revealed with its placement over the video’s play button (click to enlarge)

One can actually show the hidden advert (as seen in Figure 9) simply by clicking in the browser’s address bar which results in the banner coming at the forefront. Similarly, giving focus back to the page by clicking anywhere in it will put the banner back in hidden mode again.

The crooks use JavaScript code to check for user activity, in particular mouse movements and clicks. Indeed, bots often do very programmatic and predictable actions that can be detected as patterns of non real human activity. The detector.js script from the fake blog will attempt to detect those emulated actions and immediately redirect the browser to Google’s homepage if it identifies any.

antibot_code.png


Figure 10: Checking for mouse activity to ensure clicks are legitimate (click to enlarge)

For instance, if a click is detected but the mouse hasn’t moved at all, this is a suspicious behaviour. Same goes for the mouse moving to specific onscreen coordinates at particular time frames. Malware that tries to emulate user activity will typically do some scrolls on screen or clicks, but those are usually not very random or unique enough and they get repeated from one infected machine to another.

Online criminals make money by exploiting weaknesses in systems and people which make them very aware of certain pitfalls that they need to avoid. We have seen in the past malware closing the security hole that allowed it to get in, or even remove a previous infection. Similarly, when it comes to ad fraud the bad guys know very well how to ensure they are getting paid and have less chances of getting caught.

It also clears the browser back button URL history such that the user cannot revisit the same page again:



Figure 11: Changing the ‘back URL’ based on mouse activity (click to enlarge)

If a real human clicked to view the non-existing video, they actually clicked on the hidden ad, thereby generating money for the crooks. Whoever got duped will soon realize that this was just a waste of time and that no video actually loaded. Users are less likely to report on this fraud due to the nature of the content they were trying to view.

In the meantime, the fraudsters behind this operation are making money for each view and click. Given that they only have to pay for cheap incoming traffic versus the more expensive Google Ads, this is a profitable business model.



Figure 12: Web traffic from fake blog to click fraud (click to enlarge)

Link with previous campaign
In January of 2016, we wrote about a clickjacking attack taking advantage of the new European law on browser cookies. Similarly, users were tricked into clicking on ‘I accept cookies’ which actually clicked on an ad banner and defrauded legitimate advertisers.

The domain names used then and now have a similar pattern with the word ‘webhosting‘ in it, which could be a coincidence of course, but is noteworthy since both campaigns use clickjacking to abuse Google AdSense.



Figure 13: Traffic capture from the European cookie clickjacking campaign

Another interesting aspect is the use of filters (i.e. filter.php, process.php) to weed out bots or machines that are already blacklisted. This was not something we had covered in our original blog post but by comparing with past captures, we can see the idea is very similar, although not as sophisticated.

Closing thoughts
There aren’t many industries that generate as many heated debates as the ad industry does. One argument that you will often hear is that ad agencies, networks and publishers still make money whether an ad is malicious or never was actually viewed by anyone. There is also a direct correlation between digital ad spend and ad fraud over the past few years.

This does not mean that the involved parties are desensitized to malware or fraud (they invest a lot of resources to combat that problem). In fact, treating them as ‘they’ is a poor choice since it assumes everyone is on the same level. We know that there are some networks/publishers that turn a blind eye – or worse – are directly affiliated with criminal gangs, while others are actually taking an active stance to fight malware and fraud.

The problem remains that there is an ever growing concern from both users (adopting ad blockers at a fast pace) and advertisers, getting less and less bang for their buck. Just like with malvertising, as long as there is an economic gain, criminals will keep on pursuing their abuse to exploit advertising as a unique and profitable fraud and infection vector.

We have notified Google and passed along the necessary information about this abuse of their ad platform.

Further reading:
IOCs:
Gates:

stockwebhosting[.]com
doctorwebhosting[.]com
triwebhosting[.]com
webhostingfashion[.]com

Fake blogs:

justhappymarriage[.]com
myamericansofa[.]com
instaautohire[.]com
bugcurb[.]com
bestautotariff[.]com
pestdomination[.]com
pleasedwedding[.]com
nicewashing[.]com
theusaappliance[.]com
topcaraccidentals[.]com
perfectpurification[.]com
 
nice , you suggest to use owr own adsence with this method or fake? to be sure that we don't get banned
 
I saw the "same" article about this google adsense blackhat thing maybe 2-3 years ago, but in a foreign language blog, we always know the black hatters will never give up and always come up with ideas to spam/abuse whatever they can, but I will never do such thing even I have the knowledge to do.

No doubt they can make a lot of money, but often this like a mouse catching game only very very few people earn enough from pure black hat spam, those who failed are countless and wasted their time.
 
I saw the "same" article about this google adsense blackhat thing maybe 2-3 years ago, but in a foreign language blog, we always know the black hatters will never give up and always come up with ideas to spam/abuse whatever they can, but I will never do such thing even I have the knowledge to do.

No doubt they can make a lot of money, but often this like a mouse catching game only very very few people earn enough from pure black hat spam, those who failed are countless and wasted their time.

If you dont make huge numbers, its always ok. Just dont abuse it too much and they will not catch you. Those who lost their adsense always tried hard with it, just make it look natural, dont send too much traffic suddenly, step by step and not soo much.
 
According to the report; Ad Fraud in U.S. alone is $31 Billion per year. which is huge market :smirk:

If you dont make huge numbers, its always ok. Just dont abuse it too much and they will not catch you. Those who lost their adsense always tried hard with it, just make it look natural, dont send too much traffic suddenly, step by step and not soo much.
I think the people who discover working blackhat methods with adsense have multiple accounts and scale the hell out of it.
 
@meannn

Thx for this great write-up!

Just for my understanding, how are these guys are making money? As I understand it, they are ranking with their Fake-Blogs high in the SERPs, but instead of showing the article they show porn and make money with the adsense ad, right?
 
This remind of world cup, you know a lot countries now a days increase the
fee to watch WC due to licsences fee , etc etc

next depend how much sponsors willing to pay for the broadcast , some countries only
start show the Q final stage to final never show the inital stages matches in groups stages

So what happen? you will bound to see lots of streaming site pop out
show live WC matches, I have to admit I have no choice also search around for it

also in forum people showing the link to stream

you can see how much traffic they can get during WC one month just one month
provided their streaming site is very popular for those soccer fans

even WC finish also can earn , Uefa cup, Champions leagues etc matches , and usual EPL games , etc
leagues games

and yes they will force you click the ad than you close in order can watch.
 
I saw the "same" article about this google adsense blackhat thing maybe 2-3 years ago, but in a foreign language blog, we always know the black hatters will never give up and always come up with ideas to spam/abuse whatever they can, but I will never do such thing even I have the knowledge to do.

No doubt they can make a lot of money, but often this like a mouse catching game only very very few people earn enough from pure black hat spam, those who failed are countless and wasted their time.


the worst night mare, is ironic google ban you yet you never do anything funny all thanks to these black sheeps zzzzzz
but keep fingers cross will not happen

I feel more piss off is we do CLEAN way to earn but don't know why get ban this is the most piss off part

for them , these frauster they already know is short term , is like " gamble " if never get caught for months even years they already profit big enough
even on day got caught they also don't mind with it
 
actually I wonder how google counter Ad blocker .

It does indeed affect adsense earnings , of course if you have lots of traffic few hundred k u don't bother
but still it does rob some of your earnings.

Those buy google ad also know about ab blocker beside google

Of course Google got so many ways to get big revenue but neverthless

well....
 
People using these same tactics from years using FB and still, they are doing. They are using a play button xxx picture and when click it retired to some blogs with ads and there are no nude pics or videos.
 
actually I wonder how google counter Ad blocker .

It does indeed affect adsense earnings , of course if you have lots of traffic few hundred k u don't bother
but still it does rob some of your earnings.

Those buy google ad also know about ab blocker beside google

Of course Google got so many ways to get big revenue but neverthless

well....

new google chrome could break ad blocker scripts
since they dominate the browser market revenues will increase for them and for us
 
i have done this shit but that is next level, it was posted on a adfraud blog 2 years ago
biggest ad fraud i have ever seen with my eyes was an alex top 1k site doing clickjacking, funny thing they used distil to separate bots from human lol
 
Just like Virus and anti-Virus, you jump, I jump.
 
side note is google adsnese having problem?

can't display the earming keep loading I even use smartphone check same results too
update now can .
 
Last edited:
i came across similar project in 2015 mid in some spanish forum overlay with x video website overlay. it ended badly and always google use to take whole money due to invalid traffic no matter we use to get human organic visits.
and in 2019 may god help all.
i wont say its totally waste but it needs more tune to make it work properly.
 
Back
Top