Nayatel website is hacked/Malware filled

Joker99

Intermediate
May 30, 2009
219
0
21
RAWALPINDI
@murtaza12

Okay, so I just visited Nayatel website some minutes ago and got hit with "Update Chrome" screen. I did end up clicking the Download - just to see what happens, nothing happened except a JS file downloading from a Dropbox link I believe. Anyhow, I think I am safe? :confused: Since it did not actually run the JS?

The HTML from Update page (Mods, feel free to remove the code if its not safe?):
CODE REMOVED by OP.

The javascript file that download was named: Chrome_76.19.js and its just jumbled up text, on purpose, encrypted or whatever.

Putting up some screenshots.






More about the injection method:

https://blog.malwarebytes.com/threa...ampaign-leverages-multiple-website-platforms/


Sucuri Report:

https://sitecheck.sucuri.net/results/nayatel.com
 
Last edited:

Joker99

Intermediate
May 30, 2009
219
0
21
RAWALPINDI
24 hours, of informing them, later, the JS code is still up on their site... Seems to be quite "intelligent" Malware-ing attempt, only shows on your first fresh visit. Won't replicate on repeated visits unless you try from a different browser for example. Firefox threw up "Update Firefox" fake page.
 
General chit-chat
Help Users
We have disabled traderscore and are working on a fix. There was a bug with the plugin | Click for Discord
  • No one is chatting at the moment.
    NaNoW NaNoW: ....