These advertisement banners were stored on
a remote domain with the URL hxxps://browser-defence.com and hxxps://broxu.com.
Without requiring any user interaction, the
initial script reports information about the victim’s machine to the attacker’s
remote server. Based on server-side logic, the target is then served either a
clean image or its almost imperceptibly modified malicious evil twin.
The malicious version of the graphic has a
script encoded in its alpha
channel, which defines the transparency of each pixel. Since the
modification is minor, the final picture's color tone is only slightly
different to that of the clean version.