NameSilo

domains Attackers take over expired domain to deliver web skimming scripts

Spaceship Spaceship
Watch

Lox

____Top Member
Impact
12,436
The attackers acquired the domain tracker.web-cockpit[.]jp, which belonged to a free web marketing and analytics service that was discontinued in December 2014.

The original JavaScript library was called Cockpit and it was replaced with a malicious web skimming script. Jscrambler researchers told Help Net Security that the attackers made no attempt to make it look like the original script or disguise it in any other way.

The old Cockpit script was loaded by another script placed on e-commerce websites. Depending on the referrer header value, which indentifies the webpage from where it is fetched, the domain would serve either no script, a default skimmer, or a specific skimmer.

The default skimmer would run on the ...

read more
 
3
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
you mean expireddomains.net with an "s" not to be confused with other similar domains.
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back