Malware Analysis CashU.com site compromised ?

Andrew3000

Level 11
Verified
Top Poster
Malware Hunter
Well-known
Feb 8, 2016
537
Brave is not properly signed in Eset, you need to check the ssl settings in Eset.
Thats mostly the problem with rather new browsers.

Check advanced settings - Web and email :

View attachment 216669

It is already included in the list, but after selecting from automatic to control seems to block the script (only two warnings, but after scan no other malicious files found). Thanks for the tips :)

216671

216672
 

Divine_Barakah

Level 33
Thread author
Verified
Top Poster
Well-known
May 10, 2019
2,289
Any update? Avast still blocks the site i wrote the support on the begin of this thread. no response until now.

CashU support has not responded to me yet. I tweeted @CashU about the issue but my tweet has disappeared somehow :unsure:

Edit: What concerns me the most is that this site is online banking and one should not see such warnings on such sites. Carelessness -_-
 

Divine_Barakah

Level 33
Thread author
Verified
Top Poster
Well-known
May 10, 2019
2,289
Sorry I don't have it installed atm. It may or may not detect it as it doesn't do HTTPS scanning.

Either way I wouldn't trust that site as it is currently.

Thank you @Raiden Have you uninstalled SHP for the sake of change or have you encountered any specific issues that steered you away from it? Anyway, yes this site should be avoided in its current state until sth is done by developers.
 
F

ForgottenSeer 72227

Thank you @Raiden Have you uninstalled SHP for the sake of change or have you encountered any specific issues that steered you away from it? Anyway, yes this site should be avoided in its current state until sth is done by developers.

Mostly to try out different programs. I do like SHP a lot, it's improved, but still needs a bit of work. For me the biggest annoyance is it does impact the boot-up/login time into Windows. There's a definite lag there, especially when I compare it to WD and Eset in that regard. I still keep a close eye on it and I will for sure participating in the beta once it's released.
 

Divine_Barakah

Level 33
Thread author
Verified
Top Poster
Well-known
May 10, 2019
2,289
Mostly to try out different programs. I do like SHP a lot, it's improved, but still needs a bit of work. For me the biggest annoyance is it does impact the boot-up/login time into Windows. There's a definite lag there, especially when I compare it to WD and Eset in that regard. I still keep a close eye on it and I will for sure participating in the beta once it's released.
Yes the new version shows great improvement especially when it comes to performance. I like SHP too but will wait to the next version which, I hope, it will address all the issue and refine the product.
 

lThinkFreel

Level 2
Jun 24, 2019
66
After asking them yesterday, got a response:
"Hello Dear,

Thank you for contacting CASHU.


We apologize for the inconvenience caused, would you please provide us with a screenshot with the details of the virus that you are facing.


Should you need further assistance, please do not hesitate to contact us again.

Thank you and best regards,"


attached the warnings from this post and sended them. (Avast still blocks the site)
 

SeriousHoax

Level 49
Verified
Top Poster
Well-known
Mar 16, 2019
3,862
On my Firefox with uBO & uMatrix installed I get no popup from Eset. The websites loads fast but every script except googletagmanager is allowed so not sure what uMatrix is blocking here that's making those malicious script not to load. While on Microsoft Edge(EdgeHTML) with only Adguard extension enabled, the website takes a lot of time to load and 20+ Eset popup show up. I also have Privacy Possum installed on Firefox which is blocking 58 referrer headers, not sure if it's related.
 
4

436880927

I was doing some de-obfuscation last night and it looked to me that the JavaScript doesn't support calling home like it would in Magecart attacks via HTTP requests. Furthermore, the service's SSL certificate seems to be fine.

I'm letting them do their jobs - I was requested by them to provide them the details and I have done so. They should be able to fix this soon.
 
Last edited by a moderator:
4

436880927

It might not be malware but I can understand why it's being flagged by numerous AVs. It's strange. It's not usual to add obfuscated JavaScript code to the end of scripts from official libraries like jQuery and Owl Carousel - especially with anti-debugging checks. Microsoft, Rising, GData and some others have started flagging it as well now, so the detection's are only just increasing instead of decreasing.

CASHU told me to send them full details this morning so they could resolve the problem. I did so. The fix hasn't been pushed out yet.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top