Lazna nagradna igra Mtel Srpska na urlu:
https :// circuitolabs[.]com/index.php?key=iadi3dytif2kyozw76i8&visitor_id=777995855209960197&cost=0.000121&zoneid=6928847&campaignid=7894957&bannerid=20239576&zone_type={zone_type}&os=android&osversion=unspecified_android&country=BA&language=en&isp=telekom%20srpske&user_activity=high#
IP: 95[.]217[.]240[.]250
Quote:Ars Technica was recently used to serve second-stage malware in a campaign that used a never-before-seen attack chain to cleverly cover its tracks, researchers from security firm Mandiant reported Tuesday.
A benign image of a pizza was uploaded to a third-party website and was then linked with a URL pasted into the “about” page of a registered Ars user. Buried in that URL was a string of characters that appeared to be random—but were actually a payload. The campaign also targeted the video-sharing site Vimeo, where a benign video was uploaded and a malicious string was included in the video description.
Izvor: https://arstechnica.com/security/2024/01...fuscation/
Ovo je tema gde možemo slobodno da pišemo o bilo čemu (pazeći da ne kršimo pravila), vodimo diskusije ili postavljamo pitanja.
Hostovi koji su najverovatnije kompromitovani i odatle se vrše napadi.
https://www.virustotal.com/gui/domain/nd.../detection
https://www.scumware.org/
https://www.abuseipdb.com/check/185.119.89.111
