Poor Websites Infected with Malicious JavaScript Code
ID: b8d52f9d-4c78-5ddb-9234-7d32e7f1a2b1
STIX ID: report--b8d52f9d-4c78-5ddb-9234-7d32e7f1a2b1
Feed Name: Zscaler Security Research Blog
Zscaler researchers discovered that the BSNL Bangalore telecom website was compromised: attackers injected six different obfuscated JavaScript snippets into the site's search.js which, when the site search was used, redirected users to the Gumblar botnet domain gumblar.cn. The post includes decoded examples, explains the infection vector, notes other Indian sites previously affected, and states that Zscaler blocked the infected page and the malicious domain has since been taken down.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
