KVGBANK Affected With Malicious JavaScript
ID: f8e8a9c9-2195-5a04-9548-0af54f09e1f5
STIX ID: report--f8e8a9c9-2195-5a04-9548-0af54f09e1f5
Feed Name: Zscaler Security Research Blog
Threat Score
The kvgbank.com site was infected with multilevel-obfuscated JavaScript that, once de-obfuscated, performed browser-version checks and redirected users (via a popup) to a malicious domain (currently parked). The injection indicates a site compromise possibly exploiting an unpatched vulnerability; VirusTotal flags the site (23/43 detections) and the bank has been informed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
