Banner adware not detected? Website cramped with 3rd party ad-tracking...

Website is vulnerable to recent Drupal exploit: Outdated Drupal Found Security Announcements Drupal under 8.1.3/7.44

See where it is flagged by Fortinet’s: http://urlquery.net/report.php?id=1498322472756
The third party tracking cookie status:
Related matches for “wXw.medaille.edu/sites/default/files/webform/mbchd_2.html”
-http://www.day.kiev.ua/sites/default/files/subs.png 3rd-party 0 Persistent 0 Session 0 Score ?
-http://www.oleroninsel.de/sites/default/files/push.jpg 3rd-party 0 Persistent 0 Session 0 Score ?
-http://www.progettodedalus.it/sites/default/files/news_menu.png 3rd-party 0 Persistent 0 Session 0 Score ?
-http://www.mcrconference.it/ecm/sites/default/files/verde.png 3rd-party 0 Persistent 0 Session 0 Score ?
-http://www.uspto.gov/sites/default/files/js/js_dc50b9c82f.js Status Connection error ( error)
-http://www.ecocentral.si/sites/default/files/solar-power.jpeg 3rd-party 0 Persistent 0 Session 0 Score ?
-http://www.aufundab.eu/sites/default/files/piwik/piwik.js?o68jgr= Status Connection error ( error)
-http://www.ncu.edu/sites/all/modules/webform/js/webform.js?o2g06e= Status Connection error ( error)
-http://www.dallenogare.it/sites/default/files/js/gmap_markers.js Status Connection error ( error)
-http://www.aufundab.eu/sites/default/files/piwik/piwik.js?o2dron= Status Connection error ( error)
-http://www.voxmail.it/sites/default/files/voxmail-main-logo.png Status Sub-resource URL
-http://www.voxmail.it/sites/default/files/002_editor_new.png Status Sub-resource URL
-http://www.voxmail.it/sites/default/files/logoembmedium.png Status Sub-resource URL
-http://www.joyofbingo.com/sites/default/files/menu_icon.png Status Sub-resource URL
-http://www.joyofbingo.com/sites/default/files/Places_2.png Status Sub-resource URL
-http://www.joyofbingo.com/sites/default/files/CTA_HP.PNG Status Sub-resource URL
-http://www.joyofbingo.com/sites/default/files/Pnk_BTN.png Status Sub-resource URL
-http://www.idojaras.hu/sites/default/files/hirdet/mamegu.jpg Status Sub-resource URL
-http://www.pubpress.com/sites/default/files/pubpress-logo.png Status Sub-resource URL
-http://www.eluniversal.com.mx/sites/default/files/2017/04/10/sbk.jpg Status Sub-resource URL
-http://unicen.edu.ar/sites/default/files/imagenes/iconos/webmail.png Status Sub-resource URL
-http://www.prysmiangroup.com/sites/default/files/logo_2.png Status Sub-resource URL
-http://unicen.edu.ar/sites/default/files/imagenes/iconos/webmail-ho… Status Sub-resource URL
-http://www.elgrafico.mx/sites/default/files/consultorio_sexual.jpg Status Sub-resource URL
-http://www.iprima.cz/sites/default/files/prima-style-cerny.png Status Sub-resource URL

Not detected: https://www.virustotal.com/pl/url/d29b11df31cb112d951114d8688b02618ef674abd8c70f669f0242ec33ea6931/analysis/1498332873/

SRI Report F-status: https://sritest.io/#report/dacdf612-684a-4b08-9dac-ecd431ed9dcb

Retirable jQuery libraries: http://retire.insecurity.today/#!/scan/311f9aa159e573d235ea1708b8b05683ea1567f7dfe3114ffa748eb3836d979b

F-status and recommendations: https://observatory.mozilla.org/analyze.html?host=www.medaille.edu

Why the site should be blocked and alerted by Google Safebrowsing: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=www.medaille.edu%2Fsites%2Fdefault%2Ffiles%2Fwebform%2Fmbchd_2.html&ref_sel=GSP2&ua_sel=ff&fs=1

Sucuri flags: /undergraduate-programs
Severity: Potentially Suspicious
Reason: Detected hidden potentially suspicious instructions
Details: Detected hidden CSS declaration
Offset: 153792
Threat dump: re: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.medaille.edu%2Fundergraduate-programs
Threat dump MD5: 5793A1FECADA97A1A6BA5F06C1E35176
File size[byte]: 163062
File type: HTML
Page/File MD5: 4C7652FEBA22F33C890BC5F228B5BE08
Scan duration[sec]: 1.379000

polonus (volunteer website security analyst and website error-hunter)

And they call themselves “Medaille College is a private liberal arts college”
Makes you wonder what they see as arts.

Hi Eddy,

Quite agree with you there, question is why Google Safebrowsing not alerts this. Redleg’s fileviewer is quite certain about that redirect,
it is not kosher or rather hallal in this case:

Suspicious URLs found in: -http://www.medaille.edu/sites/default/files/webform/mbchd_2.html

1: hxxp://p216219·clksite·com/adServe/banners?tid=216219_404440_0&tagid=2

Also this tracking counter code: -http://server.easycounter.com/track.yuhuads.com

polonus