Malware Writeup: JS:Trojan:Cryxos.2550
ID: 99f2e3c0-44ab-5509-a7b6-8f32e96332b8
STIX ID: report--99f2e3c0-44ab-5509-a7b6-8f32e96332b8
Feed Name: WatchGuard Secplicity Blog
This report analyzes a January 2020 surge of a Cryxos JavaScript Trojan variant that renders obfuscated, URL-encoded phishing pages via document.write(unescape()), prompting victims for mobile numbers and passwords and POSTing those credentials to an attacker-controlled domain (https://dotcodesoultions.com/bb/result.php). The analysis describes the encoding/decoding technique, PHP routines extracting email components for form pre-fill, includes screenshots of the rendered pages, and identifies the malicious endpoint as an indicator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
