Malware on a vendor website

  • Thread starter Thread starter aqua_code
  • Start date Start date
  • Tagged users Tagged users None
Status
Not open for further replies.
I will not, if you would like to start your own thread with the information please do so. I just based this on speculation. I sent you a message of the site and where the code is.

that’s the issue. speculating and assuming can be very damaging. i’m just saying, either call out @AquaSD by name or do some more investigating before you post about it, to ensure you’re not making false statements. that’s all.
 
that’s the issue. speculating and assuming can be very damaging. i’m just saying, either call out @AquaSD by name or do some more investigating before you post about it, to ensure you’re not making false statements. that’s all.
That's the thing, revhtree is trying to deal with it before outing a vendor. Let the mods do their thing.
 
There are more false positives (and threats you don't even know exist yet) floating around than there are actual compromised sites / threats.

I hope a disclosure has been provided to the vendor - if there has been and they are ignoring it - expose them. If they are cooperative and working on it - give them the space to do so.

And remember - you're data has been compromised - if you think you haven't been - you simply don't know it yet.
 
That's the thing, revhtree is trying to deal with it before outing a vendor. Let the mods do their thing.

i agree. if there wasn’t sufficient evidence to begin with, no need to make anything public. otherwise it’s obvious tons of people will want to know the vendor. which is exactly what happened. reverse logic here.
 
The OP was just trying to protect the community, I respect that. He saw it and said something without trying to "out" the site , like was discussed. I confirmed his suspicion privately and now the mods are dealing with it at this point I'm sure. That being said , be thankful somebody cared enough to warn you . Its been happening a REALLY long time, I cant believe NOBODY but the OP and myself even knew ..... c'mon thats pathetic , to all the people who were wondering what antivirus to use , I would strongly suggest ESET NOD 32, as was mentioned. It is the end users responsibility to protect their electronic communication , period. Dont let your nuts drag out there folks. An ounce of prevention is worth a pound of cure , correct.
 
The script appears to to search for and copy data from your local hard drive and send it to a remote location. Just briefly looking at the attack matrix below, it doesn't look good even if it is a false positive. I wouldn't want a script utilizing process injection, security software discovery, and remote file copy processes when I was browsing for corals.
1583198078822.png

It looks to me like the javascript utilizes a remote domain sending json through a "/optout/set/lt" URL. A similar type of malware appears in wordpress sites and appears in this stackoverflow:

https://stackoverflow.com/questions...ece-of-code-automatically-added-to-my-content
My guess is they are using an old or outdated shopify theme or plugin and it was compromised somehow like earlier posters were saying. I do not think the vendor is aware of the issue, or how to properly fix it. It's not my intention to bash any vendor and I do my research before posting anything, especially web development related.
 
Last edited:
If the mods want to take over this thread and post the site I am happy to step away from it. If you would like to know privately please PM me and I will respond pretty quickly.
Maybe that is a good idea. I have had numerous 'false alarms' with antivirus programs - or my misinterpretation of them - if you dont want to post the vendor - thats fine - but - you've done what you needed to do let the site people determine the next step (in my humble opinion)
 
aqua_code,

Can you please email me the site? I would like to see if my existing Bitdefender will flag the trouble.

You're a gentleman...
 
aqua_code,

Can you please email me the site? I would like to see if my existing Bitdefender will flag the trouble.

You're a gentleman...
Bitdefender will flag the trouble if its a updated version. Mine did every time I opened their pages during sale.
 
aqua_code,

Can you please email me the site? I would like to see if my existing Bitdefender will flag the trouble.

You're a gentleman...
Can someone PM me the details. I had an unauthorized used of my card last night after shopping around on a few sites.. Not sure if related
Please PM me too, OP!
Please PM me also .
The vendor has been identified in a previous post.
 
The vendor has been identified in a previous post.
Instead of digging through 60 posts, can you identify? They shouldn’t be a sponsored vendor if they’re infecting members pc’s/computers, and should be called out
 
Listening to the OP I can tell that he knows what he is talking about. Now that the name is posted I hope nobody is thinking of going there to check if their AV software is going to go off LOL :p.
I use ESET and it is not cheap, but they update the signature DB at least once per day if not more.
Five years and it's caught everything. I check my running Processes from time to time and so far all the files check out.
 
Status
Not open for further replies.

TOP 10 Trending Threads

ARE YOU READY TO CONFESS TO CRAZIEST, DUMBEST, FUNNIEST THING YOU’VE EVER DONE IN REEFING?

  • Yeah, I'll confess! (Share your story in the comments!)

    Votes: 62 55.4%
  • Nah, I'll keep mine a secret...(Don't be like that, share with the class!)

    Votes: 50 44.6%

New Posts

Back
Top
Home
Post thread…
Market
What's new