Stopping Affiliate Hijackers
Extracting Affiliate Details from Hijacked Ads
marcode automatically analyses hijacked ads daily to extract affiliate details sometimes you'll want to run a manual analysis for more recent ads or to gather additional evidence this guide shows you how watch the 2 minute interactive demo when to use manual analysis you'll need this when automated analysis hasn't run yet on recent ads you're gathering further evidence for enforcement action you need up to the minute analysis results step 1 open the ad details from the hijacking advertisers tab click on an example ad for the advertiser you're investigating this loads all ads we've captured from that advertiser step 2 check for existing analyses at the top of the ad list, you'll see if any ads have already been analysed if analyses exist click the filter to view only analysed ads review the existing results before running new analyses if no analyses exist you'll need to run a manual analysis (continue to step 3) screenshot placeholder top of ad list showing analysis count step 3 run a manual analysis to analyse an ad find an ad you want to investigate click the "run analysis" button next to it wait a few minutes for the analysis to complete what happens during analysis marcode's system clicks on the ad bypasses any cloaking techniques follows the entire url redirect chain extracts all affiliate parameters found this typically takes 2 5 minutes screenshot placeholder "run analysis" button highlighted on an ad row step 4 review the analysis results once complete, you'll see an overview showing affiliate parameters found (ids, click refs, sub ids, etc ) final destination url redirect chain summary what you're looking for affiliate id or click reference sub publisher ids any tracking parameters that identify the fraudster screenshot placeholder analysis results overview with affiliate parameters highlighted understanding the url chain click "ad click url chain" to see the complete redirect path this shows you every url in the redirect sequence where affiliate parameters were added how the cloaking works the final destination why this matters understanding the redirect chain helps you identify the cloaking method used spot patterns across multiple hijackers gather evidence for enforcement explain the fraud to networks or legal teams screenshot placeholder url chain view showing multiple redirects with affiliate parameters viewing historical analyses to see past analyses, click the microscope button in the report two types of analyses automated system generated analyses run automatically on detected ads updated regularly manual analyses you or your team have run on demand investigations timestamped with user details switch between tabs to see each type click any individual analysis to view its full details screenshot placeholder historical analyses view showing automated and manual tabs what if analysis fails? sometimes analysis can't extract details because the ad is no longer active cloaking detects our system and shows different content the redirect chain is broken the advertiser removed their affiliate parameters what to do try analysing a different ad from the same advertiser try at a different time (some hijackers use time based cloaking) check if the hijacking has stopped (they may have been removed) contact support if you consistently can't extract details tips for better results analyse multiple ads from the same advertiser to see patterns and confirm the affiliate details are consistent try different times some hijackers only bid at certain hours, and cloaking may behave differently look for recent ads older ads may have expired links that no longer work save your findings export the analysis or screenshot it for your evidence file what if no affiliate details are found? there's normally one of four reasons analysis has not yet run run a manual analysis advertiser warming up accounts they're not using affiliate ids yet whilst they get their account approved you should report to google see here docid\ djy v6o 6p xnttzqj09h extractor needs updating if there are ids in the url path, but the system isn't recognising them we need to update the extractor this often occurs when you have a specific format for affiliate parameters that aren't commonly used contact us and we can get it updated cloaking beating marcode this shouldn't happen, but if you do consistently see ads going via redirects with no affiliate details found, contact us to take a closer look what to do next once you've extracted the affiliate details document the evidence save the analysis results identify the affiliate match the id to your publisher list decide your action warn or ban? use communication templates contact the affiliate or network common questions "how often does automated analysis run?" daily for active hijackers manual analysis is instant on demand "can i analyse the same ad multiple times?" yes useful if cloaking changes or you want to verify results "what if the affiliate parameters are encrypted?" marcode's analysis decodes most encoding methods contact support for unusual cases "how long are analysis results stored?" all analyses are stored permanently in your account 💡 pro tip if you find a hijacker using sophisticated cloaking, analyse several of their ads at different times patterns in their redirect chains can reveal their entire operation, including other domains they control