Rewterz
Rewterz Threat Alert – New ELECTRICFISH Tool by HIDDEN COBRA
May 10, 2019
Rewterz
Middle East Expected to See a Series of Cyber Attacks Disrupting Industrial Processes
May 13, 2019

Rewterz Threat Alert – Malicious Domain Injecting JS Scripts to Steal Credit Card Data

Severity

Medium

Analysis Summary


A malicious domain magento-analytics[.]com was tracked for months and was found to have been used to inject malicious JS script to various online shopping sites to steal the credit card owner / card number / expiration time / CVV information. The types of goods sold by the victim websites cover a wide range including but not limited to high-end bags, mountain bikes, baby products, wine, electronic products, etc., which shows that the campaign focuses on stealing credit card information only.

Impact

Theft of Credit Card Information

Indicators of Compromise

IP(s) / Hostname(s)

93[.]187[.]129[.]249

URLs

  • hxxp[:]//magento-analytics[.]com:443/5c0c3e8455ebc[.]js
  • hxxp[:]//magento-analytics[.]com/
  • hxxp[:]//magento-analytics[.]com/gate[.]php
  • hxxps[:]//magento-analytics[.]com/5c330014a67ac[.]js
  • hxxps[:]//magento-analytics[.]com/5c8ba95b0a705[.]js
  • hxxps[:]//magento-analytics[.]com/gate[.]php
  • magento-analytics[.]com

Following are the compromised websites/impacted domains which have this JS injected:

  • adirectholdings[.]com
  • adm[.]sieger-trophaen[.]de
  • adventureequipment[.]com[.]au
  • alkoholeswiata[.]com
  • alphathermalsystems[.]com
  • ameta-anson[.]com
  • ametagroup[.]com
  • ametawest[.]com
  • appliancespareparts[.]com[.]au
  • armenianbread[.]com
  • autosportcompany[.]nl
  • bagboycompany[.]com
  • boardbookalbum[.]biz
  • boardbookalbum[.]com
  • boardbookalbum[.]net
  • boardbookalbums[.]biz
  • boardbookalbums[.]net
  • burmabibas[.]com
  • businesstravellerbags[.]com
  • clotures-electriques[.]fr
  • cltradingfl[.]com
  • colorsecretspro[.]com
  • connfab[.]com
  • cupidonlingerie[.]fr
  • devantsporttowels[.]com
  • diamondbladedealer[.]com
  • digital-2000[.]com
  • emersonstreetclothing[.]com
  • equalli[.]com
  • equalli[.]co[.]uk
  • equalli[.]de
  • eu[.]twoajewelry[.]com
  • eyeongate[.]net
  • fitnessmusic[.]com
  • fluttereyewear[.]com
  • freemypaws[.]info
  • gabelshop[.]ch
  • gosuworld[.]com
  • hotelcathedrale[.]be
  • huntsmanproducts[.]com[.]au
  • iconicpineapple[.]com
  • ilybean[.]com
  • imitsosa[.]com
  • jasonandpartners[.]com[.]au
  • jekoshop[.]com
  • jekoshop[.]de
  • junglefeveramerica[.]com
  • kermanigbakery[.]com
  • kermanigfoods[.]com
  • kings2[.]com
  • koalabi[.]com
  • lamajune[.]com
  • libertyboutique[.]com[.]au
  • lighteningcornhole[.]com
  • lighting-direct[.]com[.]au
  • lightingwill[.]com
  • liquorishonline[.]com
  • lojacristinacairo[.]com[.]br
  • magformers[.]com
  • maxqsupport[.]com
  • mdcpublishers[.]com
  • meizitangireland[.]com
  • mockberg[.]com
  • monsieurplus[.]com
  • mont[.]com[.]au
  • mtbsale[.]com
  • noirnyc[.]com
  • nyassabathandbody[.]com
  • pgmetalshop[.]com
  • pinkorchard[.]com
  • pizzaholic[.]net
  • powermusic[.]com
  • prestigeandfancy[.]com
  • prestigebag[.]com
  • prestigefancy[.]com
  • prestigepakinc[.]com
  • prettysalonusa[.]com
  • promusica[.]ie
  • qspproducts[.]com
  • qspproducts[.]nl
  • qspracewear[.]nl
  • rightwayhp[.]com
  • safarijewelry[.]com
  • schogini[.]biz
  • shopatsimba[.]com
  • spalventilator[.]nl
  • spieltraum-shop[.]de
  • storageshedsoutlet[.]com
  • stylishfashionusa[.]com
  • suitpack[.]co[.]uk
  • svpmobilesystems[.]com
  • task-tools[.]com
  • tiroler-kraeuterhof[.]at
  • tiroler-kraeuterhof[.]com
  • tiroler-kraeuterhof-naturkosmetik[.]com
  • ucc-bd[.]com
  • ussi-md[.]com
  • utvcover[.]com
  • vezabands[.]com
  • vitibox[.]co[.]uk
  • waltertool[.]info
  • waltertool[.]org
  • waltertools[.]com
  • workoutmusic[.]com

Remediation

Block the threat indicators at their respective controls.