Mr.Trunk · @mrtrunk
9 followers · 15877 posts · Server dromedary.seedoubleyou.me

SecurityOnline: EKFiddle v1.1.9 released: A framework to study Exploit Kits securityonline.info/ekfiddle-f

#malwareanalysis #ekfiddle

Last updated 1 year ago

Jérôme Segura · @malwareinfosec
737 followers · 133 posts · Server infosec.exchange

Added detection rules for new skimmer.

entrydelt[.]sbs/check[.]js
entrydelt[.]sbs/loader[.]min[.]js
flagmob[.]quest/id[.]min[.]js
flowit[.]pics/logg[.]min[.]js
prijetech[.]shop/ww[.]min[.]js
sanpatech[.]shop/techs[.]min[.]js
vitalmob[.]pics/pre-loader[.]js

github.com/malwareinfosec/EKFi

#ekfiddle #magecart

Last updated 1 year ago

Jérôme Segura · @malwareinfosec
429 followers · 44 posts · Server infosec.exchange

Some updates to (Fiddler extension)

- Set your own custom (fake) referer
- New upstream proxy UI (change external IP address)

github.com/malwareinfosec/EKFi

#ekfiddle

Last updated 2 years ago

Jérôme Segura · @malwareinfosec
413 followers · 42 posts · Server infosec.exchange

Lots of changes with recently.

There are some new URI patterns (no more report?r=).

Updated regexes for Fiddler's extension can be found here: github.com/malwareinfosec/EKFi

#SocGholish #ekfiddle

Last updated 2 years ago

Jérôme Segura · @malwareinfosec
140 followers · 14 posts · Server infosec.exchange

Nice blog by Ben from :
blog.sucuri.net/2022/11/massiv

Hacked sites are redirecting to bogus Q&A pages.

They also abuse a Google open redirect.

Rules for updated to detect this campaign: github.com/malwareinfosec/EKFi

#Sucuri #ekfiddle

Last updated 2 years ago