Mastodon Feed: Post

Mastodon Feed

kevinevans@hachyderm.io ("Kevin") wrote:

I think the #Blitzortung forum is compromised. It's got this fake (but real-looking) captcha that'll sometimes appear, which tries to get me to run a malicious script. And upon further inspection, they're loading a very sus obfuscated script on every page load (that seems to call out to an external server and evals the response).

Malicious script: https://forum.blitzortung.org/jscripts/general.js?ver=1827 (the very last line)

#security #malware

sussy looking fake captcha that tries to get someone to run a malicious script in their Run dialog in Windows
sussy looking obfuscated code in their scripts
network log and callstack of some third party requests that were invoked by general.js