Rodrigo,
Is that the same telemetry data that the Windows Defender/Anti-Malware teams can provide, since I mentioned to Greg, the originator of this thread that he should suggest you contact them?
They're obviously able to identify at least the incidents which invoke the Trojan identified in this thread, so I'd think that this might aid in narrowing those particular events down, though that also depends upon whether they can be traced back to the
page which originally invoked the redirect.
I would assume that these ads are not only being targeted at particular types of users, but also that the advertisers involved are using the same techniques that were identified by the Confiant security group in this article about the Ziconium group in January.
This allows them not only to filter for their targets, but also to avoid triggering the ads for security researchers and others trying to find them like your group.
Uncovering 2017’s Largest Malvertising Operation – Confiant
As a side note, I eventually realized that in my own case it's my relatively extreme privacy and other settings that allow me to avoid these completely. Since I have the Advertising ID turned off and also normally use Internet Explorer with both tracking
cookies blocked and IE Tracking protection enabled with the EasyPrivacy list, I'm an unlikely target for this type of attack. My settings have less to do with malvertising than my own aversion to the noise that ads create, but apparently has the side effect
of suppressing these type of targeted attacks as well.
Rob