Cleartrip.com Infected with Blackhole Exploit Kit
ID: aceba290-f3d5-56a9-a7a3-620612ae0d4e
STIX ID: report--aceba290-f3d5-56a9-a7a3-620612ae0d4e
Feed Name: Zscaler Security Research Blog
Threat Score
A Cleartrip.com page contained obfuscated JavaScript that injected a hidden iframe pointing to trafficgoodster.info, which served the Blackhole Exploit Kit; the analyst de-obfuscated the code, captured the malicious iframe URL and WHOIS details for the newly registered .info domain, and noted that Zscaler notified Cleartrip and that Google has blocked the malicious URL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
