Blog

New Adware Uses Interesting Technique To Avoid Detection

By baypointetech • August 22, 2019

Being more of a nuisance than anything, adware doesn't see as many innovations as other forms of malware. Once in a while, an adware developer surprises the security researchers.


That happened recently when two researchers working for enSilo discovered an innovation in an adware strain, known as DealPly.


As Adi Zeligson and Rotem Kerner indicated in a recent blog post, DealPly has some interesting features bolted on, which make it much more adept than most other forms of adware at avoiding detection by antivirus programs.


The adware is typically installed on a target's machine by being bundled with a legitimate app. Once it's installed, it will add itself to the Windows Task Scheduler and run every hour. Each time it runs, it will contact its command and control server and request instructions.


Here's where things get interesting. DealPly was designed modularly and makes use of Virtual Machine Detection and Machine Fingerprinting techniques.


Microsoft SmartScreen is one of two major systems used to verify the risk of files and web addresses. It's updated regularly with newly blacklisted sites. Naturally, malware authors find this to be a problem because it only gives them a limited window of time before their code and malicious URLs wind up on the list.



DealPlay, however, contains code that seems to be based on a reverse-engineering of Microsoft SmartScreen. When it contacts its command and control server, it requests a list of hashes and URLs to query using the SmartScreen reputation server. Once it has its list of queries to make, it will send a JSON request to the SmartScreen API to see if the server will respond with any of the following:


  • UNKN Unknown URL/File
  • MLWR Malware related URL/File
  • PHSH Phishing related URL/File


Essentially, this query allows DealPly to know whether it has been blacklisted. If so, the software enters an idled state until it can be updated. This allows DealPly's developers a something close to real-time mechanism to know when they need to update their code, allowing them to stay ahead of the curve. Very clever. Very clever indeed, and troubling to IT staff everywhere. We can expect this technique to be copied by other malware developers, worldwide.


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • October 7, 2026
Learn what secure remote IT support requires, from trusted help requests and controlled access to device standards, session records, and onsite escalation.
By BayPointe Technology • September 30, 2026
Find out whether your business backups can support recovery. Plan restore tests, measure results, and address gaps before an outage disrupts work.
By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256