Malware Analysis CashU.com site compromised ?

L0ckJaw

Level 19
Verified
Content Creator
Well-known
Feb 17, 2018
870
Yup Eset also the same, 23 notifications !

216663
 

Attachments

  • Eset warnings.txt
    9.7 KB · Views: 375

Andrew3000

Level 11
Verified
Top Poster
Malware Hunter
Well-known
Feb 8, 2016
537
Maybe Brave Shields blocked the bad parts of the site?

Maybe but I don't know, Because if a scan is made, Eset finds the malicious code in cache files.
C:\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina

216668
 

L0ckJaw

Level 19
Verified
Content Creator
Well-known
Feb 17, 2018
870
Maybe but I don't know, Because if a scan is made, Eset finds the malicious code in cache files.
C:\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676d JS/Agent.OCJ trojan horse Elimina
C:\ProgramData\Microsoft\Windows\Containers\BaseImages\29d8b5d7-1735-4b27-9ca1-9ea12269b252\BaseLayer\Files\Documents and Settings\andre\Impostazioni locali\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_00676e JS/Agent.OCJ trojan horse Elimina

View attachment 216668
Brave is not properly signed in Eset, you need to check the ssl settings in Eset.
Thats mostly the problem with rather new browsers.

Check advanced settings - Web and email :

216669
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top