Bangalore Metro Rail Site "bmrc.co.in" Compromised
ID: 336ceec6-8c8e-5ec2-8440-575c1e23dbca
STIX ID: report--336ceec6-8c8e-5ec2-8440-575c1e23dbca
Feed Name: Zscaler Security Research Blog
The Bangalore Metro Rail website (bmrc.co.in) was found to be compromised with obfuscated JavaScript injected into multiple pages; the script set a cookie and injected an iframe that redirected users to a malicious host (ecurie80.hostzi.com/Felenne12/clik.php), behavior attributed to the JS/Exploit-Blacole Trojan. VirusTotal scans and ThreatLabZ notification are cited; the malicious payload is currently offline but the underlying vulnerability and infected pages may still pose a risk, so users are advised to avoid the site until remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
