Where is the click on the adserver? I don't see that.
Where is the click on the adserver? I don't see that.
If you want to see the scheme in action go to the new domains set up by the scammer:
http://www.kidsbeanbags1.com/index2.php
http://www.kingsizemattress1.com/index2.php
http://www.neckpillow1.com/index2.php
http://www.pillowtopmattress1.com/index2.php
http://www.pillowcovers1.com/index2.php
http://www.tempurpillow1.com/index2.php
http://www.contourpillow1.com/index2.php
If you want to observe the full click behavior: Chrome->Tools->DeveloperTools->Network
Let me know what you see. Curious to see if the scammer changed the behavior.
I still don't understand.
Where is the money? Is this CPC or CPM fraud?
It couldn't be CPC because there is no landing page served.
It couldn't be CPM because there is no ad served.
I got the explanation: All the targeted sites (e.g., Mevio or Current.TV) now have filters in place. So you will not be able to see the actual landing pages. The landing page will be a blank page as the ad click will not work.
Btw for the record: It is mainly CPC fraud, sending (invisible) traffic to sites like Mevio and Current.TV which serve mainly CPM ads.
If there is a click on an adserver, where is it in this bunch of redirects?
Note that he was not always clicking on the links, to maintain a reasonable low clickthrough rate for the ads.
You run a video site or a search engine that serves CPM ads. If you can buy PPC cheap enough, you can arbitrage and make money.
PPC from Google is expensive, but there are companies that sell cheap clicks. Some publishers on these ad networks run porn sites with hidden iframes that generate the clickthrough.
However, iframes generate a http referer, and this gives away the rather dubious traffic sources. The series of redirected clicks are used to subvert click fraud analysis.