Philippine Yellow Pages Hacked
ID: ce3baf67-9d55-5be5-9572-de634cea18fa
STIX ID: report--ce3baf67-9d55-5be5-9572-de634cea18fa
Feed Name: Zscaler Security Research Blog
Researchers observed a campaign using a single client IP and an open proxy to inject heavily obfuscated JavaScript into thousands of legitimate web pages, adding invisible iframes that load IE6 exploits from a Russian host (e.g., tenthprofit.ru:8080). The injected code varied per site, avoided document.write and used layered obfuscation and eval/exception tricks, but analysts were still able to create signatures and identified the Philippine Yellow Pages (yellowpageph.com) as an infected site; the iframe URL included a path referencing "pagesjaunes" and the malicious domain is currently inaccessible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
