Click to jump to signature section
Source: https://tozoma.poletofuti.com/b.js | Avira URL Cloud: Label: malware |
Source: https://file-connection-all-ez.com/dive-into-the-intuitive-interface-of-folder-size-shell-3-2/?utm_term=vegas+pro+16+free+template&utm_content=19fo3tg69fejs&utm_medium=link&utm_source=0pHUd050003810000000008066419&referer=https%3A%2F%2Fb.figozow.com%2F | Avira URL Cloud: Label: malware |
Source: https://tozoma.poletofuti.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=92eb1f0e4df29ac0 | Avira URL Cloud: Label: malware |
Source: https://tozoma.poletofuti.com/48727331318472313528826811?wufulufugufojugenupakosotojaxunekibugepiguj | Avira URL Cloud: Label: malware |
Source: 1.6..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: blob:https://tozoma.poletofuti.com/e9a0388e-4f07-4... This script demonstrates high-risk behavior by using the `eval()` function to execute dynamic code received from an untrusted source. The use of `eval()` allows for the execution of arbitrary JavaScript, which poses a significant security risk. Additionally, the lack of origin verification and the absence of a message source indicate that this script is vulnerable to cross-origin attacks and could be used to execute malicious code on the client-side. |
Source: 0.0..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://tozoma.poletofuti.com/48727331318472313528... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and the use of obfuscated code/URLs. It appears to be a malicious script designed to collect sensitive user data and potentially execute remote code. The script interacts with an untrusted domain, further increasing the risk. While the specific intent is unclear, the overall behavior is highly suspicious and poses a significant security threat. |
Source: https://yfyfx.sparefastads.top/shared-js/assets/static-pl.js?v=6 | HTTP Parser: (function(_0x28c6e7,_0x3b1176){const _0x32e133=_0x20a9,_0x15f93f=_0x28c6e7();while(!![]){try{const _ |
Source: https://www.mcafee.com/en-us/ipz/feyncart/2web/payment-va.html?tm_global_sitesection_level3=enus_uiux_vara_q4_24&adobe_mc_sdid=SDID%3D58AC915C83B7F96B-37FA06D4E98EB84A%7CMCORGID%3DA729776A5245B1590A490D44%40AdobeOrg%7CTS%3D1744381301&adobe_mc_ref=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fidentity-theft%2Fprotection.html&moguid=17ba14ab-1071-4c77-a974-b61ad29a145c&culture=en-us&affid=0&pkgCode=663&pt=1yp&fp=80.99&curCode=USD&btnSec=hero&cctype=&ccstype=&cseg=default&cexp=&ccta=663%3A1yp%3A80.99%3Ausd%3Ahero&ccpubn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault%40663%3A1yp%3A80.99%3Ausd%3Ahero&ccpun=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault&ccpn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection&csrc=&csrcl2=&cls=0&cupf=0&cafcat=&ccoe=&ccoel2=&ak_culture=&ipst=&ipcon=&tm_local_lp_ab_test_variant=&origin=macrometa | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: https://tozoma.poletofuti.com/48727331318472313528826811?wufulufugufojugenupakosotojaxunekibugepigujawafevubopoderazizinar=wekodidijanewoxelejemevefawedogufajapibisukokopamafulopofomonerizewamanobanavanurinireboxaniwijinejijibodaritasuwugewajumukilemubodezasatulebemojareripuxirolupipipokaridoviposuboxikakexuxowepupomaniroxizupedu&utm_term=vegas+pro+16+free+template&ranobejawozerawivaguzujuvewuponumokalanudujexijujunozakapoxelixukufagok=poburakuzamogujifatogixumejexexajokumaxefabixoniwejixesosalapidebofikoxukojidominotatuwosolepagolorilesinelu | HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" fill="none"><path fill="#B20F03" d="M16 3a13 13 0 1 0 13 13A13.015 13.015 0 0 0 16 3m0 24a11 11 0 1 1 11-11 11.01 11.01 0 0 1-11 11"/><path fill="#B20F03" d="M17.038 18.615H14.87L14.563 9.5h2.... |
Source: https://www.mcafee.com/ | HTTP Parser: Iframe src: https://mcafeeinc.demdex.net/dest5.html?d_nsid=0#https%3A%2F%2Fwww.mcafee.com |
Source: https://www.mcafee.com/ | HTTP Parser: Iframe src: https://mcafeeinc.demdex.net/dest5.html?d_nsid=0#https%3A%2F%2Fwww.mcafee.com |
Source: https://www.mcafee.com/ | HTTP Parser: Iframe src: https://id.mcafee.com/authorize?client_id=Rrg3qpQF8HCcr81hJ2dbBHuVyJXLXYpJ&scope=openid+profile+email&prompt=none&response_type=code&response_mode=web_message&state=MnVHRG5DWVBTZEVuV0plM0EyVFZsMTNqalp2V2tHcExKcmtkTFVjVGZRTw%3D%3D&nonce=cDA2bHU5WnY4cWFPdlJjTGVLN3RwMF9rYTRoZ3luNjQ2Z0xlZzZRbl9RZw%3D%3D&redirect_uri=https%3A%2F%2Fwww.mcafee.com&code_challenge=qKy9wPXyWjiEQL1Y18GcMvKtZnw-WVCfW-FltQ_G9-o&code_challenge_method=S256&auth0Client=eyJuYW1lIjoiYXV0aDAtc3BhLWpzIiwidmVyc2lvbiI6IjIuMC44In0%3D |
Source: https://www.mcafee.com/ | HTTP Parser: Iframe src: https://mcafeeinc.demdex.net/dest5.html?d_nsid=0#https%3A%2F%2Fwww.mcafee.com |
Source: https://www.mcafee.com/ | HTTP Parser: Iframe src: https://mcafeeinc.demdex.net/dest5.html?d_nsid=0#https%3A%2F%2Fwww.mcafee.com |
Source: https://www.mcafee.com/en-us/ipz/feyncart/2web/payment-va.html?tm_global_sitesection_level3=enus_uiux_vara_q4_24&adobe_mc_sdid=SDID%3D58AC915C83B7F96B-37FA06D4E98EB84A%7CMCORGID%3DA729776A5245B1590A490D44%40AdobeOrg%7CTS%3D1744381301&adobe_mc_ref=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fidentity-theft%2Fprotection.html&moguid=17ba14ab-1071-4c77-a974-b61ad29a145c&culture=en-us&affid=0&pkgCode=663&pt=1yp&fp=80.99&curCode=USD&btnSec=hero&cctype=&ccstype=&cseg=default&cexp=&ccta=663%3A1yp%3A80.99%3Ausd%3Ahero&ccpubn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault%40663%3A1yp%3A80.99%3Ausd%3Ahero&ccpun=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault&ccpn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection&csrc=&csrcl2=&cls=0&cupf=0&cafcat=&ccoe=&ccoel2=&ak_culture=&ipst=&ipcon=&tm_local_lp_ab_test_variant=&origin=macrometa | HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/740246542?random=1744381307711&cv=11&fst=1744381307711&fmt=3&bg=ffffff&guid=ON&async=1>m=45be5490v883266441za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=102509682~102788824~102803279~102813109~102887800~102926062~103021830~103027016~103047562~103050889~103051953&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fipz%2Ffeyncart%2F2web%2Fpayment-va.html%3Ftm_global_sitesection_level3%3Denus_uiux_vara_q4_24%26adobe_mc_sdid%3DSDID%253D58AC915C83B7F96B-37FA06D4E98EB84A%257CMCORGID%253DA729776A5245B1590A490D44%2540AdobeOrg%257CTS%253D1744381301%26adobe_mc_ref%3Dhttps%253A%252F%252Fwww.mcafee.com%252Fen-us%252Fidentity-theft%252Fprotection.html%26moguid%3D17ba14ab-1071-4c77-a974-b61ad29a145c%26culture%3Den-us%26affid%3D0%26pkgCode%3D663%26pt%3D1yp%26fp%3D80.99%26curCode%3DUSD%26btnSec%3Dhero%26cctype%3D%26ccstype%3D%26cseg%3Ddefault%26cexp%3D%26ccta%3D663%253A1yp%253A80.99%253Ausd%253Ahero%26ccp&ref=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fipz%2Ffeyncart%2F2web%2Fpayment.html%3Fmoguid%3D17ba14ab-1071-4c77-a974-b61ad29a145c%26culture%3Den-us%26affid%3D0%26pkgCode%3D663%26pt%3D1yp%26fp%3D80.99%26curCode%3DUSD%26btnSec%3Dhero%26cctype%3D%26ccstype%3D%26cseg%3Ddefault%26cexp%3D%26ccta%3D663%253A1yp%253A80.99%253Ausd%253Ahero%26ccpubn%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%2540%253Adefault%2540663%253A1yp%253A80.99%253Ausd%253Ahero%26ccpun%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%2540%253Adefault%26ccpn%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%26csrc%3D%26csrcl2%3D%26cls%3D0%26cupf%3D0%26cafcat%3D%26ccoe%3D%26ccoel2%3D%26ak_culture%3D%26ipst%3D%26ipcon%3D%26tm_local_lp_ab_test_variant%3D%26origin%3Dmacrometa&hn=www.googleadservices.com&frm=0&tiba=Antivirus%20Software%20and%20Internet%20Security%20For%20Your%20PC%20or%20Mac%20%7C%20McAfee&npa=0&pscdl=noapi&auid=2104169992.1744381308&uaa=x86&uab=64&uafvl=Chromium%3B134.0.6998.36%7CNot%253AA-Brand%3B24.0.0.0%7CGoogle%2520Chrome%3B134.0.6998.36&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config |
Source: https://www.mcafee.com/en-us/ipz/feyncart/2web/payment-va.html?tm_global_sitesection_level3=enus_uiux_vara_q4_24&adobe_mc_sdid=SDID%3D58AC915C83B7F96B-37FA06D4E98EB84A%7CMCORGID%3DA729776A5245B1590A490D44%40AdobeOrg%7CTS%3D1744381301&adobe_mc_ref=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fidentity-theft%2Fprotection.html&moguid=17ba14ab-1071-4c77-a974-b61ad29a145c&culture=en-us&affid=0&pkgCode=663&pt=1yp&fp=80.99&curCode=USD&btnSec=hero&cctype=&ccstype=&cseg=default&cexp=&ccta=663%3A1yp%3A80.99%3Ausd%3Ahero&ccpubn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault%40663%3A1yp%3A80.99%3Ausd%3Ahero&ccpun=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection%40%3Adefault&ccpn=en-us%3Astore%3Apdp%3Amcafee-identity-theft-protection%3Aprotection&csrc=&csrcl2=&cls=0&cupf=0&cafcat=&ccoe=&ccoel2=&ak_culture=&ipst=&ipcon=&tm_local_lp_ab_test_variant=&origin=macrometa | HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/740246542?random=1744381307821&cv=11&fst=1744381307821&fmt=3&bg=ffffff&guid=ON&async=1&gcl_ctr=1>m=45be5490v883266441za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=102509682~102788824~102803279~102813109~102887800~102926062~103021830~103027016~103047562~103050889~103051953&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fipz%2Ffeyncart%2F2web%2Fpayment-va.html%3Ftm_global_sitesection_level3%3Denus_uiux_vara_q4_24%26adobe_mc_sdid%3DSDID%253D58AC915C83B7F96B-37FA06D4E98EB84A%257CMCORGID%253DA729776A5245B1590A490D44%2540AdobeOrg%257CTS%253D1744381301%26adobe_mc_ref%3Dhttps%253A%252F%252Fwww.mcafee.com%252Fen-us%252Fidentity-theft%252Fprotection.html%26moguid%3D17ba14ab-1071-4c77-a974-b61ad29a145c%26culture%3Den-us%26affid%3D0%26pkgCode%3D663%26pt%3D1yp%26fp%3D80.99%26curCode%3DUSD%26btnSec%3Dhero%26cctype%3D%26ccstype%3D%26cseg%3Ddefault%26cexp%3D%26ccta%3D663%253A1yp%253A80.99%253Ausd%253Ahero%26ccp&ref=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fipz%2Ffeyncart%2F2web%2Fpayment.html%3Fmoguid%3D17ba14ab-1071-4c77-a974-b61ad29a145c%26culture%3Den-us%26affid%3D0%26pkgCode%3D663%26pt%3D1yp%26fp%3D80.99%26curCode%3DUSD%26btnSec%3Dhero%26cctype%3D%26ccstype%3D%26cseg%3Ddefault%26cexp%3D%26ccta%3D663%253A1yp%253A80.99%253Ausd%253Ahero%26ccpubn%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%2540%253Adefault%2540663%253A1yp%253A80.99%253Ausd%253Ahero%26ccpun%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%2540%253Adefault%26ccpn%3Den-us%253Astore%253Apdp%253Amcafee-identity-theft-protection%253Aprotection%26csrc%3D%26csrcl2%3D%26cls%3D0%26cupf%3D0%26cafcat%3D%26ccoe%3D%26ccoel2%3D%26ak_culture%3D%26ipst%3D%26ipcon%3D%26tm_local_lp_ab_test_variant%3D%26origin%3Dmacrometa&top=https%3A%2F%2Fwww.mcafee.com%2Fen-us%2Fipz%2Ffeyncart%2F2web%2Fpayment-va.html%3Ftm_global_sitesection_level3%3Denus_uiux_vara_q4_24%26adobe_mc_sdid%3DSDID%253D58AC915C83B7F96B-37FA06D4E98EB84A%257CMCORGID%253DA729776A5245B1590A490D44%2540AdobeOrg%257CTS%253D1744381301%26adobe_mc_ref%3Dhttps%253A%252F%252Fwww.mcafee.com%252Fen-us%252Fidentity-theft%252Fprotection.html%26moguid%3D17ba14ab-1071-4c77-a974-b61ad29a145c%26culture%3Den-us%26affid%3D0%26pkgCode%3D663%26pt%3D1yp%26fp%3D80.99%26curCode%3DUSD%26btnSec%3Dhero%26cctype%3D%26ccstype%3D%26cseg%3Ddefault%26cexp%3D%26ccta%3D663%253A1yp%253A80.99%253Ausd%253Ahero%26ccp&hn=www.googleadservices.com&frm=0&tiba=Antivi |