Magecart Strikes Again: Newegg in the Crosshairs
ID: 29e92092-ddeb-5b9b-9abd-d315c314c962
STIX ID: report--29e92092-ddeb-5b9b-9abd-d315c314c962
Feed Name: Volexity Blog
Volexity and RiskIQ investigated a Magecart campaign that injected a small JavaScript skimmer into Newegg's checkout page (secure.newegg.com) to capture customers' payment details and POST them to a malicious domain (neweggstats.com). The domain and SSL certificate were registered on August 13, 2018, attacks were observed starting August 16, and the code was removed on September 18, 2018; the report includes the malicious script behavior and network indicators (neweggstats.com, 217.23.4.11, /GlobalData/).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
