Rewterz Threat Alert – New ELECTRICFISH Tool by HIDDEN COBRA
May 10, 2019Middle East Expected to See a Series of Cyber Attacks Disrupting Industrial Processes
May 13, 2019Rewterz Threat Alert – New ELECTRICFISH Tool by HIDDEN COBRA
May 10, 2019Middle East Expected to See a Series of Cyber Attacks Disrupting Industrial Processes
May 13, 2019Severity
Medium
Analysis Summary
A malicious domain magento-analytics[.]com was tracked for months and was found to have been used to inject malicious JS script to various online shopping sites to steal the credit card owner / card number / expiration time / CVV information. The types of goods sold by the victim websites cover a wide range including but not limited to high-end bags, mountain bikes, baby products, wine, electronic products, etc., which shows that the campaign focuses on stealing credit card information only.
Impact
Theft of Credit Card Information
Indicators of Compromise
IP(s) / Hostname(s)
93[.]187[.]129[.]249
URLs
- hxxp[:]//magento-analytics[.]com:443/5c0c3e8455ebc[.]js
- hxxp[:]//magento-analytics[.]com/
- hxxp[:]//magento-analytics[.]com/gate[.]php
- hxxps[:]//magento-analytics[.]com/5c330014a67ac[.]js
- hxxps[:]//magento-analytics[.]com/5c8ba95b0a705[.]js
- hxxps[:]//magento-analytics[.]com/gate[.]php
- magento-analytics[.]com
Following are the compromised websites/impacted domains which have this JS injected:
- adirectholdings[.]com
- adm[.]sieger-trophaen[.]de
- adventureequipment[.]com[.]au
- alkoholeswiata[.]com
- alphathermalsystems[.]com
- ameta-anson[.]com
- ametagroup[.]com
- ametawest[.]com
- appliancespareparts[.]com[.]au
- armenianbread[.]com
- autosportcompany[.]nl
- bagboycompany[.]com
- boardbookalbum[.]biz
- boardbookalbum[.]com
- boardbookalbum[.]net
- boardbookalbums[.]biz
- boardbookalbums[.]net
- burmabibas[.]com
- businesstravellerbags[.]com
- clotures-electriques[.]fr
- cltradingfl[.]com
- colorsecretspro[.]com
- connfab[.]com
- cupidonlingerie[.]fr
- devantsporttowels[.]com
- diamondbladedealer[.]com
- digital-2000[.]com
- emersonstreetclothing[.]com
- equalli[.]com
- equalli[.]co[.]uk
- equalli[.]de
- eu[.]twoajewelry[.]com
- eyeongate[.]net
- fitnessmusic[.]com
- fluttereyewear[.]com
- freemypaws[.]info
- gabelshop[.]ch
- gosuworld[.]com
- hotelcathedrale[.]be
- huntsmanproducts[.]com[.]au
- iconicpineapple[.]com
- ilybean[.]com
- imitsosa[.]com
- jasonandpartners[.]com[.]au
- jekoshop[.]com
- jekoshop[.]de
- junglefeveramerica[.]com
- kermanigbakery[.]com
- kermanigfoods[.]com
- kings2[.]com
- koalabi[.]com
- lamajune[.]com
- libertyboutique[.]com[.]au
- lighteningcornhole[.]com
- lighting-direct[.]com[.]au
- lightingwill[.]com
- liquorishonline[.]com
- lojacristinacairo[.]com[.]br
- magformers[.]com
- maxqsupport[.]com
- mdcpublishers[.]com
- meizitangireland[.]com
- mockberg[.]com
- monsieurplus[.]com
- mont[.]com[.]au
- mtbsale[.]com
- noirnyc[.]com
- nyassabathandbody[.]com
- pgmetalshop[.]com
- pinkorchard[.]com
- pizzaholic[.]net
- powermusic[.]com
- prestigeandfancy[.]com
- prestigebag[.]com
- prestigefancy[.]com
- prestigepakinc[.]com
- prettysalonusa[.]com
- promusica[.]ie
- qspproducts[.]com
- qspproducts[.]nl
- qspracewear[.]nl
- rightwayhp[.]com
- safarijewelry[.]com
- schogini[.]biz
- shopatsimba[.]com
- spalventilator[.]nl
- spieltraum-shop[.]de
- storageshedsoutlet[.]com
- stylishfashionusa[.]com
- suitpack[.]co[.]uk
- svpmobilesystems[.]com
- task-tools[.]com
- tiroler-kraeuterhof[.]at
- tiroler-kraeuterhof[.]com
- tiroler-kraeuterhof-naturkosmetik[.]com
- ucc-bd[.]com
- ussi-md[.]com
- utvcover[.]com
- vezabands[.]com
- vitibox[.]co[.]uk
- waltertool[.]info
- waltertool[.]org
- waltertools[.]com
- workoutmusic[.]com
Remediation
Block the threat indicators at their respective controls.