ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื›ืžืขื˜ ื›ื•ืœื ื• ืžืฉืชืžืฉื™ื ื‘ืฉื™ืจื•ืชื™ ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช, ืžื” ืฉืื•ืžืจ ืฉื‘ืžื•ืงื“ื ืื• ื‘ืžืื•ื—ืจ ืื ื• ืžืกืชื›ื ื™ื ืœื”ืคื•ืš ืœืงื•ืจื‘ืŸ ืฉืœ ืกื ืคื™ืจื™ JavaScript - ืงื•ื“ ืžื™ื•ื—ื“ ืฉืชื•ืงืคื™ื ืžื™ื™ืฉืžื™ื ื‘ืืชืจ ื›ื“ื™ ืœื’ื ื•ื‘ ื ืชื•ื ื™ ื›ืจื˜ื™ืกื™ ื‘ื ืง, ื›ืชื•ื‘ื•ืช, ื›ื ื™ืกื•ืช ื•ืกื™ืกืžืื•ืช ืฉืœ ืžืฉืชืžืฉื™ื .

ื›ืžืขื˜ 400 ืžืฉืชืžืฉื™ื ื‘ืืชืจ ื•ื‘ืืคืœื™ืงืฆื™ื™ืช ื”ืกืœื•ืœืจ ืฉืœ ื‘ืจื™ื˜ื™ืฉ ืื™ื™ืจื•ื•ื™ื™ืก ื›ื‘ืจ ื”ื•ืฉืคืขื• ืžืจื—ืคื ื™ื, ื›ืžื• ื’ื ืžื‘ืงืจื™ื ื‘ืืชืจ ื”ื‘ืจื™ื˜ื™ ืฉืœ ืขื ืงื™ืช ื”ืกืคื•ืจื˜ FILA ื•ืžืคื™ืฅ ื”ื›ืจื˜ื™ืกื™ื ื”ืืžืจื™ืงืื™ Ticketmaster. PayPal, Chase Paymenttech, USAePay, Moneris - ืžืขืจื›ื•ืช ืชืฉืœื•ื ืืœื” ื•ืขื•ื“ ืจื‘ื•ืช ืื—ืจื•ืช ื ื“ื‘ืงื•.

ืื ืœื™ืกื˜ ืฉืœ Threat Intelligence Group-IB ื•ื™ืงื˜ื•ืจ ืื•ืงื•ืจื•ืงื•ื‘ ืžื“ื‘ืจ ืขืœ ื”ืื•ืคืŸ ืฉื‘ื• ืžืจื—ืจื—ื™ื ื—ื•ื“ืจื™ื ืœืงื•ื“ ืืชืจ ื•ื’ื•ื ื‘ื™ื ืžื™ื“ืข ืขืœ ืชืฉืœื•ื, ื›ืžื• ื’ื ืขืœ ืื™ืœื• CRMs ื”ื ืชื•ืงืคื™ื.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

"ืื™ื•ื ื ืกืชืจ"

ื›ืš ืงืจื” ืฉื‘ืžืฉืš ื–ืžืŸ ืจื‘ ื ื•ืชืจื• ืžืจื—ืจื— JS ืžื—ื•ืฅ ืœื˜ื•ื•ื— ืจืื™ื™ืชื ืฉืœ ืื ืœื™ืกื˜ื™ื ืฉืœ ืื ื˜ื™-ื•ื™ืจื•ืก, ื•ื‘ื ืงื™ื ื•ืžืขืจื›ื•ืช ืชืฉืœื•ื ืœื ืจืื• ื‘ื”ื ืื™ื•ื ืจืฆื™ื ื™. ื•ืœืฉื•ื•ื ืœื’ืžืจื™. ืžื•ืžื—ื™ Group-IB ืžึฐื ื•ึผืชึธื— 2440 ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช ื ื’ื•ืขื•ืช, ืฉื”ืžื‘ืงืจื™ื ื‘ื”ืŸ - ื‘ืกืš ื”ื›ืœ ื›-1,5 ืžื™ืœื™ื•ืŸ ืื™ืฉ ื‘ื™ื•ื - ื”ื™ื• ื‘ืกื™ื›ื•ืŸ ืœืคืฉืจื”. ื‘ื™ืŸ ื”ื ืคื’ืขื™ื ืœื ืจืง ืžืฉืชืžืฉื™ื, ืืœื ื’ื ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช, ืžืขืจื›ื•ืช ืชืฉืœื•ื ื•ื‘ื ืงื™ื ืฉื”ื ืคื™ืงื• ื›ืจื˜ื™ืกื™ื ืฉื ืคื’ืขื•.

ื“ื•ื•ื— Group-IB ื”ืคืš ืœืžื—ืงืจ ื”ืจืืฉื•ืŸ ืขืœ ืฉื•ืง ื”-Darknet ืœ-Sniffers, ื”ืชืฉืชื™ืช ืฉืœื”ื ื•ืฉื™ื˜ื•ืช ื”ืžื•ื ื˜ื™ื–ืฆื™ื”, ืžื” ืฉืžื›ื ื™ืก ืœื™ื•ืฆืจื™ื”ื ืžื™ืœื™ื•ื ื™ ื“ื•ืœืจื™ื. ื–ื™ื”ื™ื ื• 38 ืžืฉืคื—ื•ืช ืฉืœ ืžืจื—ืจื—ื™ื, ืžืชื•ื›ืŸ ืจืง 12 ื”ื™ื• ืžื•ื›ืจื•ืช ื‘ืขื‘ืจ ืœื—ื•ืงืจื™ื.

ื”ื‘ื” ื ืชืขื›ื‘ ื‘ืคื™ืจื•ื˜ ืขืœ ืืจื‘ืข ืžืฉืคื—ื•ืช ื”ืžืจื—ืจื—ื™ื ืฉื ื—ืงืจื• ื‘ืžื”ืœืš ื”ืžื—ืงืจ.

ReactGet Family

ืกื ื™ืคืจื™ื ืžืžืฉืคื—ืช ReactGet ืžืฉืžืฉื™ื ืœื’ื ื™ื‘ืช ื ืชื•ื ื™ ื›ืจื˜ื™ืกื™ ื‘ื ืง ื‘ืืชืจื™ ืงื ื™ื•ืช ืžืงื•ื•ื ื™ื. ื”ืกื ื™ืคืจ ื™ื›ื•ืœ ืœืขื‘ื•ื“ ืขื ืžืกืคืจ ืจื‘ ืฉืœ ืžืขืจื›ื•ืช ืชืฉืœื•ื ืฉื•ื ื•ืช ื”ืžืฉืžืฉื•ืช ื‘ืืชืจ: ืขืจืš ืคืจืžื˜ืจ ืื—ื“ ืžืชืื™ื ืœืžืขืจื›ืช ืชืฉืœื•ื ืื—ืช, ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื’ืจืกืื•ืช ื‘ื•ื“ื“ื•ืช ืฉื–ื•ื”ื• ืฉืœ ื”ืกื ื™ืคืจ ืœื’ื ื™ื‘ืช ืื™ืฉื•ืจื™ื, ื›ืžื• ื’ื ืœื’ื ื™ื‘ืช ื ืชื•ื ื™ ื›ืจื˜ื™ืก ื‘ื ืง ืžืชืฉืœื•ื ืฆื•ืจื•ืช ืฉืœ ื›ืžื” ืžืขืจื›ื•ืช ืชืฉืœื•ื ื‘ื•-ื–ืžื ื™ืช, ื›ืžื• ืžื” ืฉื ืงืจื ืกื ื™ืคืจ ืื•ื ื™ื‘ืจืกืœื™. ื ืžืฆื ืฉื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื ืชื•ืงืคื™ื ืžื‘ืฆืขื™ื ื”ืชืงืคื•ืช ืคื™ืฉื™ื ื’ ืขืœ ืžื ื”ืœื™ ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช ืขืœ ืžื ืช ืœืงื‘ืœ ื’ื™ืฉื” ืœืคืื ืœ ื”ื ื™ื”ื•ืœื™ ืฉืœ ื”ืืชืจ.

ืžืกืข ืคืจืกื•ื ืฉืžืฉืชืžืฉ ื‘ืžืฉืคื—ืช ื”ืกื ื™ืคืจื™ื ื”ื–ื• ื”ื—ืœ ื‘ืžืื™ 2017; ืืชืจื™ื ื”ืžืจื™ืฆื™ื CMS ื•ืคืœื˜ืคื•ืจืžื•ืช Magento, Bigcommerce ื•-Shopify ื”ื•ืชืงืคื•.

ืื™ืš ReactGet ืžื™ื•ืฉืžืช ื‘ืงื•ื“ ืฉืœ ื—ื ื•ืช ืžืงื•ื•ื ืช

ื‘ื ื•ืกืฃ ืœื”ื˜ืžืขื” ื”"ืงืœืืกื™ืช" ืฉืœ ืกืงืจื™ืคื˜ ื‘ืืžืฆืขื•ืช ืงื™ืฉื•ืจ, ื”ืžืคืขื™ืœื™ื ืฉืœ ืžืฉืคื—ืช ื”ืกื ื™ืคืจื™ื ReactGet ืžืฉืชืžืฉื™ื ื‘ื˜ื›ื ื™ืงื” ืžื™ื•ื—ื“ืช: ื‘ืืžืฆืขื•ืช ืงื•ื“ JavaScript, ื”ื ื‘ื•ื“ืงื™ื ื”ืื ื”ื›ืชื•ื‘ืช ื”ื ื•ื›ื—ื™ืช ืฉื‘ื” ื ืžืฆื ื”ืžืฉืชืžืฉ ืขื•ืžื“ืช ื‘ืงืจื™ื˜ืจื™ื•ื ื™ื ืžืกื•ื™ืžื™ื. ื”ืงื•ื“ ื”ื–ื“ื•ื ื™ ื™ื‘ื•ืฆืข ืจืง ืื ื”ืžื—ืจื•ื–ืช ื”ืžืฉื ื” ืงื™ื™ืžืช ื‘ื›ืชื•ื‘ืช ื”ืืชืจ ื”ื ื•ื›ื—ื™ืช ืœืชืฉืœื•ื ืื• ืชืฉืœื•ื ืฆืขื“ ืื—ื“, ืขืžื•ื“ ืื—ื“/, out/onepag, ืงื•ืคื”/ืื—ื“, ckout/one. ืœืคื™ื›ืš, ืงื•ื“ ื”ืกื ื™ืคืจ ื™ืชื‘ืฆืข ื‘ื“ื™ื•ืง ื‘ืจื’ืข ื‘ื• ื”ืžืฉืชืžืฉ ื™ืžืฉื™ืš ืœืฉืœื ืขื‘ื•ืจ ืจื›ื™ืฉื•ืช ื•ื™ื–ื™ืŸ ืคืจื˜ื™ ืชืฉืœื•ื ื‘ื˜ื•ืคืก ื‘ืืชืจ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื”ืžืจื—ืจื— ื”ื–ื” ืžืฉืชืžืฉ ื‘ื˜ื›ื ื™ืงื” ืœื ืกื˜ื ื“ืจื˜ื™ืช. ื”ืชืฉืœื•ื ื•ื”ื ืชื•ื ื™ื ื”ืื™ืฉื™ื™ื ืฉืœ ื”ืงื•ืจื‘ืŸ ื ืืกืคื™ื ื™ื—ื“ ื•ืžืงื•ื“ื“ื™ื ื‘ืืžืฆืขื•ืช base64, ื•ืœืื—ืจ ืžื›ืŸ ื”ืžื—ืจื•ื–ืช ื”ืžืชืงื‘ืœืช ืžืฉืžืฉืช ื›ืคืจืžื˜ืจ ืœืฉืœื™ื—ืช ื‘ืงืฉื” ืœืืชืจ ื”ืชื•ืงืคื™ื. ืœืจื•ื‘, ื”ื ืชื™ื‘ ืœืฉืขืจ ืžื—ืงื” ืงื•ื‘ืฅ JavaScript, ืœืžืฉืœ resp.js, data.js ื•ื›ืŸ ื”ืœืื”, ืื‘ืœ ืžืฉืชืžืฉื™ื ื’ื ื‘ืงื™ืฉื•ืจื™ื ืœืงื‘ืฆื™ ืชืžื•ื ื”, GIF ะธ JPG. ื”ืžื•ื–ืจื•ืช ื”ื™ื ืฉื”ืจื—ืจื— ื™ื•ืฆืจ ืื•ื‘ื™ื™ืงื˜ ืชืžื•ื ื” ื‘ื’ื•ื“ืœ 1 ืขืœ ืคื™ืงืกืœ ืื—ื“ ื•ืžืฉืชืžืฉ ื‘ืงื™ืฉื•ืจ ืฉื”ืชืงื‘ืœ ืงื•ื“ื ืœื›ืŸ ื›ืคืจืžื˜ืจ src ืชืžื•ื ื•ืช. ื›ืœื•ืžืจ, ืขื‘ื•ืจ ื”ืžืฉืชืžืฉ ื‘ืงืฉื” ื›ื–ื• ื‘ืชื ื•ืขื” ืชื™ืจืื” ื›ืžื• ื‘ืงืฉื” ืœืชืžื•ื ื” ืจื’ื™ืœื”. ื˜ื›ื ื™ืงื” ื“ื•ืžื” ืฉื™ืžืฉื” ื‘ืžืฉืคื—ืช ื”ืžืจื—ื—ื™ื ImageID. ื‘ื ื•ืกืฃ, ื”ื˜ื›ื ื™ืงื” ืฉืœ ืฉื™ืžื•ืฉ ื‘ืชืžื•ื ื” ืฉืœ 1 ืขืœ 1 ืคื™ืงืกืœ ืžืฉืžืฉืช ื‘ื”ืจื‘ื” ืกืงืจื™ืคื˜ื™ื ืœื’ื™ื˜ื™ืžื™ื™ื ืœื ื™ืชื•ื— ืžืงื•ื•ืŸ, ืฉืขืœื•ืœื™ื ื’ื ืœื”ื˜ืขื•ืช ืืช ื”ืžืฉืชืžืฉ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื ื™ืชื•ื— ื’ืจืกืื•ืช

ื ื™ืชื•ื— ืฉืœ ื”ื“ื•ืžื™ื™ื ื™ื ื”ืคืขื™ืœื™ื ื”ืžืฉืžืฉื™ื ืืช ืžืคืขื™ืœื™ ื”ืกื ื™ืคืจื™ื ืฉืœ ReactGet ื’ื™ืœื” ื’ืจืกืื•ืช ืจื‘ื•ืช ื•ืฉื•ื ื•ืช ืฉืœ ืžืฉืคื—ืช ื”ืกื ื™ืคืจื™ื ื”ื–ื•. ื’ืจืกืื•ืช ืฉื•ื ื•ืช ื‘ื ื•ื›ื—ื•ืช ืื• ื”ื™ืขื“ืจ ืขืจืคื•ืœ, ื•ื‘ื ื•ืกืฃ, ื›ืœ ืกื ื™ืคืจ ืžื™ื•ืขื“ ืœืžืขืจื›ืช ืชืฉืœื•ืžื™ื ืกืคืฆื™ืคื™ืช ื”ืžืขื‘ื“ืช ืชืฉืœื•ืžื™ื ื‘ื›ืจื˜ื™ืกื™ ื‘ื ืง ืขื‘ื•ืจ ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช. ืœืื—ืจ ืฉืกื™ื™ื ื• ืืช ืขืจืš ื”ืคืจืžื˜ืจ ื”ืžืชืื™ื ืœืžืกืคืจ ื”ื’ืจืกื”, ืžื•ืžื—ื™ Group-IB ืงื™ื‘ืœื• ืจืฉื™ืžื” ืžืœืื” ืฉืœ ื•ืจื™ืืฆื™ื•ืช ื”ืกื ื™ืคืจ ื”ื–ืžื™ื ื•ืช, ื•ืœืคื™ ืฉืžื•ืช ืฉื“ื•ืช ื”ื˜ื•ืคืก ืฉื›ืœ ืกื ืคื™ืจ ืžื—ืคืฉ ื‘ืงื•ื“ ื”ืขืžื•ื“, ื”ื ื–ื™ื”ื• ืืช ืžืขืจื›ื•ืช ื”ืชืฉืœื•ื ืฉื”ืจื—ืจื— ืžื›ื•ื•ืŸ ืืœื™ื•.

ืจืฉื™ืžืช ื”ืกื ื™ืคืจื™ื ื•ืžืขืจื›ื•ืช ื”ืชืฉืœื•ื ื”ืžืชืื™ืžื•ืช ืœื”ื

ื›ืชื•ื‘ืช ืืชืจ ืฉืœ Sniffer ืžืขืจื›ืช ืชืฉืœื•ื
reactjsapi.com/react.js Authorize.Net
ajaxstatic.com/api.js?v=2.1.1 ืฉืžื™ืจืช ื›ืจื˜ื™ืกื™ื
ajaxstatic.com/api.js?v=2.1.2 Authorize.Net
ajaxstatic.com/api.js?v=2.1.3 Authorize.Net
ajaxstatic.com/api.js?v=2.1.4 eWAY ืžื”ื™ืจ
ajaxstatic.com/api.js?v=2.1.5 Authorize.Net
ajaxstatic.com/api.js?v=2.1.6 ืื“ื™ืŸ
ajaxstatic.com/api.js?v=2.1.7 USAePay
ajaxstatic.com/api.js?v=2.1.9 Authorize.Net
apitstatus.com/api.js?v=2.1.1 USAePay
apitstatus.com/api.js?v=2.1.2 Authorize.Net
apitstatus.com/api.js?v=2.1.3 ืžื•ื ืจื™ืก
apitstatus.com/api.js?v=2.1.5 USAePay
apitstatus.com/api.js?v=2.1.6 PayPal
apitstatus.com/api.js?v=2.1.7 ืกื™ื™ื’ ืฉืœื
apitstatus.com/api.js?v=2.1.8 Verisign
apitstatus.com/api.js?v=2.1.9 PayPal
apitstatus.com/api.js?v=2.3.0 ืคึผึทืก
apitstatus.com/api.js?v=3.0.2 ืจื™ืืœืงืก
apitstatus.com/api.js?v=3.0.3 PayPal
apitstatus.com/api.js?v=3.0.4 LinkPoint
apitstatus.com/api.js?v=3.0.5 PayPal
apitstatus.com/api.js?v=3.0.7 PayPal
apitstatus.com/api.js?v=3.0.8 DataCash
apitstatus.com/api.js?v=3.0.9 PayPal
asianfoodgracer.com/footer.js Authorize.Net
billgetstatus.com/api.js?v=1.2 Authorize.Net
billgetstatus.com/api.js?v=1.3 Authorize.Net
billgetstatus.com/api.js?v=1.4 Authorize.Net
billgetstatus.com/api.js?v=1.5 Verisign
billgetstatus.com/api.js?v=1.6 Authorize.Net
billgetstatus.com/api.js?v=1.7 ืžื•ื ืจื™ืก
billgetstatus.com/api.js?v=1.8 ืกื™ื™ื’ ืฉืœื
billgetstatus.com/api.js?v=2.0 USAePay
billgetstatus.com/react.js Authorize.Net
cloudodesc.com/gtm.js?v=1.2 Authorize.Net
cloudodesc.com/gtm.js?v=1.3 ANZ eGate
cloudodesc.com/gtm.js?v=2.3 Authorize.Net
cloudodesc.com/gtm.js?v=2.4 ืžื•ื ืจื™ืก
cloudodesc.com/gtm.js?v=2.6 ืกื™ื™ื’ ืฉืœื
cloudodesc.com/gtm.js?v=2.7 ืกื™ื™ื’ ืฉืœื
cloudodesc.com/gtm.js?v=2.8 ืฆ'ื™ื™ืก ืคื™ื™ืžื ื˜ืฉ
cloudodesc.com/gtm.js?v=2.9 Authorize.Net
cloudodesc.com/gtm.js?v=2.91 ืื“ื™ืŸ
cloudodesc.com/gtm.js?v=2.92 PsiGate
cloudodesc.com/gtm.js?v=2.93 ืžืงื•ืจ ืกื™ื™ื‘ืจ
cloudodesc.com/gtm.js?v=2.95 ANZ eGate
cloudodesc.com/gtm.js?v=2.97 ืจื™ืืœืงืก
geisseie.com/gs.js USAePay
gtmproc.com/age.js Authorize.Net
gtmproc.com/gtm.js?v=1.2 Authorize.Net
gtmproc.com/gtm.js?v=1.3 ANZ eGate
gtmproc.com/gtm.js?v=1.5 PayPal
gtmproc.com/gtm.js?v=1.6 PayPal
gtmproc.com/gtm.js?v=1.7 ืจื™ืืœืงืก
livecheckpay.com/api.js?v=2.0 ืกื™ื™ื’ ืฉืœื
livecheckpay.com/api.js?v=2.1 PayPal
livecheckpay.com/api.js?v=2.2 Verisign
livecheckpay.com/api.js?v=2.3 Authorize.Net
livecheckpay.com/api.js?v=2.4 Verisign
livecheckpay.com/react.js Authorize.Net
livegetpay.com/pay.js?v=2.1.2 ANZ eGate
livegetpay.com/pay.js?v=2.1.3 PayPal
livegetpay.com/pay.js?v=2.1.5 ืžืงื•ืจ ืกื™ื™ื‘ืจ
livegetpay.com/pay.js?v=2.1.7 Authorize.Net
livegetpay.com/pay.js?v=2.1.8 ืกื™ื™ื’ ืฉืœื
livegetpay.com/pay.js?v=2.1.9 ืจื™ืืœืงืก
livegetpay.com/pay.js?v=2.2.0 ืžืงื•ืจ ืกื™ื™ื‘ืจ
livegetpay.com/pay.js?v=2.2.1 PayPal
livegetpay.com/pay.js?v=2.2.2 PayPal
livegetpay.com/pay.js?v=2.2.3 PayPal
livegetpay.com/pay.js?v=2.2.4 Verisign
livegetpay.com/pay.js?v=2.2.5 eWAY ืžื”ื™ืจ
livegetpay.com/pay.js?v=2.2.7 ืกื™ื™ื’ ืฉืœื
livegetpay.com/pay.js?v=2.2.8 ืกื™ื™ื’ ืฉืœื
livegetpay.com/pay.js?v=2.2.9 Verisign
livegetpay.com/pay.js?v=2.3.0 Authorize.Net
livegetpay.com/pay.js?v=2.3.1 Authorize.Net
livegetpay.com/pay.js?v=2.3.2 First Data Global Gateway
livegetpay.com/pay.js?v=2.3.3 Authorize.Net
livegetpay.com/pay.js?v=2.3.4 Authorize.Net
livegetpay.com/pay.js?v=2.3.5 ืžื•ื ืจื™ืก
livegetpay.com/pay.js?v=2.3.6 Authorize.Net
livegetpay.com/pay.js?v=2.3.8 PayPal
livegetpay.com/pay.js?v=2.4.0 Verisign
maxstatics.com/site.js USAePay
mediapack.info/track.js?d=funlove.com USAePay
mediapack.info/track.js?d=qbedding.com Authorize.Net
mediapack.info/track.js?d=vseyewear.com Verisign
mxcounter.com/c.js?v=1.2 PayPal
mxcounter.com/c.js?v=1.3 Authorize.Net
mxcounter.com/c.js?v=1.4 ืคึผึทืก
mxcounter.com/c.js?v=1.6 Authorize.Net
mxcounter.com/c.js?v=1.7 eWAY ืžื”ื™ืจ
mxcounter.com/c.js?v=1.8 ืกื™ื™ื’ ืฉืœื
mxcounter.com/c.js?v=2.0 Authorize.Net
mxcounter.com/c.js?v=2.1 ื‘ืจื™ื™ื ื˜ืจื™
mxcounter.com/c.js?v=2.10 ื‘ืจื™ื™ื ื˜ืจื™
mxcounter.com/c.js?v=2.2 PayPal
mxcounter.com/c.js?v=2.3 ืกื™ื™ื’ ืฉืœื
mxcounter.com/c.js?v=2.31 ืกื™ื™ื’ ืฉืœื
mxcounter.com/c.js?v=2.32 Authorize.Net
mxcounter.com/c.js?v=2.33 PayPal
mxcounter.com/c.js?v=2.34 Authorize.Net
mxcounter.com/c.js?v=2.35 Verisign
mxcounter.com/click.js?v=1.2 PayPal
mxcounter.com/click.js?v=1.3 Authorize.Net
mxcounter.com/click.js?v=1.4 ืคึผึทืก
mxcounter.com/click.js?v=1.6 Authorize.Net
mxcounter.com/click.js?v=1.7 eWAY ืžื”ื™ืจ
mxcounter.com/click.js?v=1.8 ืกื™ื™ื’ ืฉืœื
mxcounter.com/click.js?v=2.0 Authorize.Net
mxcounter.com/click.js?v=2.1 ื‘ืจื™ื™ื ื˜ืจื™
mxcounter.com/click.js?v=2.2 PayPal
mxcounter.com/click.js?v=2.3 ืกื™ื™ื’ ืฉืœื
mxcounter.com/click.js?v=2.31 ืกื™ื™ื’ ืฉืœื
mxcounter.com/click.js?v=2.32 Authorize.Net
mxcounter.com/click.js?v=2.33 PayPal
mxcounter.com/click.js?v=2.34 Authorize.Net
mxcounter.com/click.js?v=2.35 Verisign
mxcounter.com/cnt.js Authorize.Net
mxcounter.com/j.js Authorize.Net
newrelicnet.com/api.js?v=1.2 Authorize.Net
newrelicnet.com/api.js?v=1.4 Authorize.Net
newrelicnet.com/api.js?v=1.8 ืกื™ื™ื’ ืฉืœื
newrelicnet.com/api.js?v=4.5 ืกื™ื™ื’ ืฉืœื
newrelicnet.com/api.js?v=4.6 Westpac PayWay
nr-public.com/api.js?v=2.0 PayFort
nr-public.com/api.js?v=2.1 PayPal
nr-public.com/api.js?v=2.2 Authorize.Net
nr-public.com/api.js?v=2.3 ืคึผึทืก
nr-public.com/api.js?v=2.4 First Data Global Gateway
nr-public.com/api.js?v=2.5 PsiGate
nr-public.com/api.js?v=2.6 Authorize.Net
nr-public.com/api.js?v=2.7 Authorize.Net
nr-public.com/api.js?v=2.8 ืžื•ื ืจื™ืก
nr-public.com/api.js?v=2.9 Authorize.Net
nr-public.com/api.js?v=3.1 ืกื™ื™ื’ ืฉืœื
nr-public.com/api.js?v=3.2 Verisign
nr-public.com/api.js?v=3.3 ืžื•ื ืจื™ืก
nr-public.com/api.js?v=3.5 PayPal
nr-public.com/api.js?v=3.6 LinkPoint
nr-public.com/api.js?v=3.7 Westpac PayWay
nr-public.com/api.js?v=3.8 Authorize.Net
nr-public.com/api.js?v=4.0 ืžื•ื ืจื™ืก
nr-public.com/api.js?v=4.0.2 PayPal
nr-public.com/api.js?v=4.0.3 ืื“ื™ืŸ
nr-public.com/api.js?v=4.0.4 PayPal
nr-public.com/api.js?v=4.0.5 Authorize.Net
nr-public.com/api.js?v=4.0.6 USAePay
nr-public.com/api.js?v=4.0.7 EBizCharge
nr-public.com/api.js?v=4.0.8 Authorize.Net
nr-public.com/api.js?v=4.0.9 Verisign
nr-public.com/api.js?v=4.1.2 Verisign
ordercheckpays.com/api.js?v=2.11 Authorize.Net
ordercheckpays.com/api.js?v=2.12 PayPal
ordercheckpays.com/api.js?v=2.13 ืžื•ื ืจื™ืก
ordercheckpays.com/api.js?v=2.14 Authorize.Net
ordercheckpays.com/api.js?v=2.15 PayPal
ordercheckpays.com/api.js?v=2.16 PayPal
ordercheckpays.com/api.js?v=2.17 Westpac PayWay
ordercheckpays.com/api.js?v=2.18 Authorize.Net
ordercheckpays.com/api.js?v=2.19 Authorize.Net
ordercheckpays.com/api.js?v=2.21 ืกื™ื™ื’ ืฉืœื
ordercheckpays.com/api.js?v=2.22 Verisign
ordercheckpays.com/api.js?v=2.23 Authorize.Net
ordercheckpays.com/api.js?v=2.24 PayPal
ordercheckpays.com/api.js?v=2.25 PayFort
ordercheckpays.com/api.js?v=2.29 ืžืงื•ืจ ืกื™ื™ื‘ืจ
ordercheckpays.com/api.js?v=2.4 PayPal Payflow Pro
ordercheckpays.com/api.js?v=2.7 Authorize.Net
ordercheckpays.com/api.js?v=2.8 Authorize.Net
ordercheckpays.com/api.js?v=2.9 Verisign
ordercheckpays.com/api.js?v=3.1 Authorize.Net
ordercheckpays.com/api.js?v=3.2 Authorize.Net
ordercheckpays.com/api.js?v=3.3 ืกื™ื™ื’ ืฉืœื
ordercheckpays.com/api.js?v=3.4 Authorize.Net
ordercheckpays.com/api.js?v=3.5 ืคึผึทืก
ordercheckpays.com/api.js?v=3.6 Authorize.Net
ordercheckpays.com/api.js?v=3.7 Authorize.Net
ordercheckpays.com/api.js?v=3.8 Verisign
ordercheckpays.com/api.js?v=3.9 PayPal
ordercheckpays.com/api.js?v=4.0 Authorize.Net
ordercheckpays.com/api.js?v=4.1 Authorize.Net
ordercheckpays.com/api.js?v=4.2 ืกื™ื™ื’ ืฉืœื
ordercheckpays.com/api.js?v=4.3 Authorize.Net
reactjsapi.com/api.js?v=0.1.0 Authorize.Net
reactjsapi.com/api.js?v=0.1.1 PayPal
reactjsapi.com/api.js?v=4.1.2 ืฆื•ืจ
reactjsapi.com/api.js?v=4.1.4 PayPal
reactjsapi.com/api.js?v=4.1.5 ืกื™ื™ื’ ืฉืœื
reactjsapi.com/api.js?v=4.1.51 Verisign
reactjsapi.com/api.js?v=4.1.6 Authorize.Net
reactjsapi.com/api.js?v=4.1.7 Authorize.Net
reactjsapi.com/api.js?v=4.1.8 ืคึผึทืก
reactjsapi.com/api.js?v=4.1.9 ื–ื‘ืจื” ืฉืžื ื”
reactjsapi.com/api.js?v=4.2.0 ืกื™ื™ื’ ืฉืœื
reactjsapi.com/api.js?v=4.2.1 Authorize.Net
reactjsapi.com/api.js?v=4.2.2 First Data Global Gateway
reactjsapi.com/api.js?v=4.2.3 Authorize.Net
reactjsapi.com/api.js?v=4.2.4 eWAY ืžื”ื™ืจ
reactjsapi.com/api.js?v=4.2.5 ืื“ื™ืŸ
reactjsapi.com/api.js?v=4.2.7 PayPal
reactjsapi.com/api.js?v=4.2.8 ืฉื™ืจื•ืชื™ ืกื•ื—ืจื™ื QuickBooks
reactjsapi.com/api.js?v=4.2.9 Verisign
reactjsapi.com/api.js?v=4.2.91 ืกื™ื™ื’ ืฉืœื
reactjsapi.com/api.js?v=4.2.92 Verisign
reactjsapi.com/api.js?v=4.2.94 Authorize.Net
reactjsapi.com/api.js?v=4.3.97 Authorize.Net
reactjsapi.com/api.js?v=4.5 ืกื™ื™ื’ ืฉืœื
reactjsapi.com/react.js Authorize.Net
sydneysalonsupplies.com/gtm.js eWAY ืžื”ื™ืจ
tagsmediaget.com/react.js Authorize.Net
tagstracking.com/tag.js?v=2.1.2 ANZ eGate
tagstracking.com/tag.js?v=2.1.3 PayPal
tagstracking.com/tag.js?v=2.1.5 ืžืงื•ืจ ืกื™ื™ื‘ืจ
tagstracking.com/tag.js?v=2.1.7 Authorize.Net
tagstracking.com/tag.js?v=2.1.8 ืกื™ื™ื’ ืฉืœื
tagstracking.com/tag.js?v=2.1.9 ืจื™ืืœืงืก
tagstracking.com/tag.js?v=2.2.0 ืžืงื•ืจ ืกื™ื™ื‘ืจ
tagstracking.com/tag.js?v=2.2.1 PayPal
tagstracking.com/tag.js?v=2.2.2 PayPal
tagstracking.com/tag.js?v=2.2.3 PayPal
tagstracking.com/tag.js?v=2.2.4 Verisign
tagstracking.com/tag.js?v=2.2.5 eWAY ืžื”ื™ืจ
tagstracking.com/tag.js?v=2.2.7 ืกื™ื™ื’ ืฉืœื
tagstracking.com/tag.js?v=2.2.8 ืกื™ื™ื’ ืฉืœื
tagstracking.com/tag.js?v=2.2.9 Verisign
tagstracking.com/tag.js?v=2.3.0 Authorize.Net
tagstracking.com/tag.js?v=2.3.1 Authorize.Net
tagstracking.com/tag.js?v=2.3.2 First Data Global Gateway
tagstracking.com/tag.js?v=2.3.3 Authorize.Net
tagstracking.com/tag.js?v=2.3.4 Authorize.Net
tagstracking.com/tag.js?v=2.3.5 ืžื•ื ืจื™ืก
tagstracking.com/tag.js?v=2.3.6 Authorize.Net
tagstracking.com/tag.js?v=2.3.8 PayPal

ืžืจื—ืจื— ืกื™ืกืžืื•ืช

ืื—ื“ ื”ื™ืชืจื•ื ื•ืช ืฉืœ ืกื ืคื™ืจื™ JavaScript ื”ืคื•ืขืœื™ื ื‘ืฆื“ ื”ืœืงื•ื— ืฉืœ ืืชืจ ืื™ื ื˜ืจื ื˜ ื”ื•ื ื”ืจื‘ื’ื•ื ื™ื•ืช ืฉืœื”ื: ืงื•ื“ ื–ื“ื•ื ื™ ื”ืžื•ื˜ืžืข ื‘ืืชืจ ื™ื›ื•ืœ ืœื’ื ื•ื‘ ื›ืœ ืกื•ื’ ืฉืœ ื ืชื•ื ื™ื, ื‘ื™ืŸ ืื ื–ื” ื ืชื•ื ื™ ืชืฉืœื•ื ืื• ืคืจื˜ื™ ื›ื ื™ืกื” ื•ืกื™ืกืžื” ืฉืœ ื—ืฉื‘ื•ืŸ ืžืฉืชืžืฉ. ืžื•ืžื—ื™ Group-IB ื’ื™ืœื• ื“ื•ื’ืžื” ืฉืœ ืจื—ืจื— ื”ืฉื™ื™ืš ืœืžืฉืคื—ืช ReactGet, ืฉื ื•ืขื“ ืœื’ื ื•ื‘ ื›ืชื•ื‘ื•ืช ืื™ืžื™ื™ืœ ื•ืกื™ืกืžืื•ืช ืฉืœ ืžืฉืชืžืฉื™ ื”ืืชืจ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ืฆื•ืžืช ืขื ImageID sniffer

ื‘ืžื”ืœืš ื”ื ื™ืชื•ื— ืฉืœ ืื—ืช ื”ื—ื ื•ื™ื•ืช ื”ื ื’ื•ืขื•ืช, ื ืžืฆื ืฉื”ืืชืจ ืฉืœื” ื ื’ื•ืข ืคืขืžื™ื™ื: ื‘ื ื•ืกืฃ ืœืงื•ื“ ื”ื–ื“ื•ื ื™ ืฉืœ ื”ืกื ื™ืคืจ ื”ืžืฉืคื—ืชื™ ืฉืœ ReactGet, ื–ื•ื”ื” ืงื•ื“ ืฉืœ ื”ืกื ื™ืคืจ ื”ืžืฉืคื—ืชื™ ืฉืœ ImageID. ื—ืคื™ืคื” ื–ื• ื™ื›ื•ืœื” ืœื”ื•ื•ืช ืขื“ื•ืช ืœื›ืš ืฉื”ืžืคืขื™ืœื™ื ืฉืžืื—ื•ืจื™ ืฉื ื™ ื”ืžืจื—ืจื—ื™ื ืžืฉืชืžืฉื™ื ื‘ื˜ื›ื ื™ืงื•ืช ื“ื•ืžื•ืช ื›ื“ื™ ืœื”ื—ื“ื™ืจ ืงื•ื“ ื–ื“ื•ื ื™.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ืจื—ืจื— ืื•ื ื™ื‘ืจืกืœื™

ื ื™ืชื•ื— ืฉืœ ืื—ื“ ืžืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ื”ืžืฉื•ื™ื›ื™ื ืœืชืฉืชื™ืช ื”ืกื ื™ืคืจ ืฉืœ ReactGet ื”ืขืœื” ืฉืื•ืชื• ืžืฉืชืžืฉ ืจืฉื ืฉืœื•ืฉื” ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ื ื•ืกืคื™ื. ืฉืœื•ืฉืช ื”ื“ื•ืžื™ื™ื ื™ื ื”ืœืœื• ื—ื™ืงื• ืืช ื”ื“ื•ืžื™ื™ื ื™ื ืฉืœ ืืชืจื™ื ืžื”ื—ื™ื™ื ื”ืืžื™ืชื™ื™ื ื•ืฉื™ืžืฉื• ื‘ืขื‘ืจ ืœืื™ืจื•ื— ืกื ื™ืคืจื™ื. ื‘ืขืช ื ื™ืชื•ื— ื”ืงื•ื“ ืฉืœ ืฉืœื•ืฉื” ืืชืจื™ื ืœื’ื™ื˜ื™ืžื™ื™ื, ื–ื•ื”ื” ืกื ื™ืคืจ ืœื ื™ื“ื•ืข, ื•ื ื™ืชื•ื— ื ื•ืกืฃ ื”ืจืื” ื›ื™ ืžื“ื•ื‘ืจ ื‘ื’ืจืกื” ืžืฉื•ืคืจืช ืฉืœ ืกื ื™ืคืจ ReactGet. ื›ืœ ื”ื’ืจืกืื•ืช ื”ืžื ื•ื˜ืจื•ืช ื‘ืขื‘ืจ ืฉืœ ืžืฉืคื—ืช ื”ืกื ื™ืคืจื™ื ื”ื–ื• ื›ื•ื•ื ื• ืœืžืขืจื›ืช ืชืฉืœื•ื ืื—ืช, ื›ืœื•ืžืจ, ื›ืœ ืžืขืจื›ืช ืชืฉืœื•ื ื“ืจืฉื” ื’ืจืกื” ืžื™ื•ื—ื“ืช ืฉืœ ื”ืกื ื™ืคืจ. ืขื ื–ืืช, ื‘ืžืงืจื” ื–ื”, ื”ืชื’ืœืชื” ื’ืจืกื” ืื•ื ื™ื‘ืจืกืœื™ืช ืฉืœ ื”ืกื ื™ืคืจ ืฉืžืกื•ื’ืœืช ืœื’ื ื•ื‘ ืžื™ื“ืข ืžื˜ืคืกื™ื ื”ืงืฉื•ืจื™ื ืœ-15 ืžืขืจื›ื•ืช ืชืฉืœื•ื ืฉื•ื ื•ืช ื•ืžื•ื“ื•ืœื™ื ืฉืœ ืืชืจื™ ืžืกื—ืจ ืืœืงื˜ืจื•ื ื™ ืœื‘ื™ืฆื•ืข ืชืฉืœื•ืžื™ื ืžืงื•ื•ื ื™ื.

ืื–, ื‘ืชื—ื™ืœืช ื”ืขื‘ื•ื“ื”, ื”ืžืจื—ืจื— ื—ื™ืคืฉ ืฉื“ื•ืช ื˜ืคืกื™ื ื‘ืกื™ืกื™ื™ื ื”ืžื›ื™ืœื™ื ืืช ื”ืžื™ื“ืข ื”ืื™ืฉื™ ืฉืœ ื”ืงื•ืจื‘ืŸ: ืฉื ืžืœื, ื›ืชื•ื‘ืช ืคื™ื–ื™ืช, ืžืกืคืจ ื˜ืœืคื•ืŸ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืœืื—ืจ ืžื›ืŸ ื—ื™ืคืฉ ื”ืžืจื—ืจื— ืžืขืœ 15 ืงื™ื“ื•ืžื•ืช ืฉื•ื ื•ืช ื”ืžืชืื™ืžื•ืช ืœืžืขืจื›ื•ืช ืชืฉืœื•ื ืฉื•ื ื•ืช ื•ืœืžื•ื“ื•ืœื™ ืชืฉืœื•ื ืžืงื•ื•ื ื™ื.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืœืื—ืจ ืžื›ืŸ, ื”ื ืชื•ื ื™ื ื”ืื™ืฉื™ื™ื ื•ืคืจื˜ื™ ื”ืชืฉืœื•ื ืฉืœ ื”ืงื•ืจื‘ืŸ ื ืืกืคื• ื™ื—ื“ ื•ื ืฉืœื—ื• ืœืืชืจ ืฉื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ: ื‘ืžืงืจื” ื”ืกืคืฆื™ืคื™ ื”ื–ื”, ื”ืชื’ืœื• ืฉืชื™ ื’ืจืกืื•ืช ืฉืœ ื”ืจื—ืคืŸ ื”ืื•ื ื™ื‘ืจืกืœื™ ืฉืœ ReactGet, ื”ืžืžื•ืงืžื•ืช ื‘ืฉื ื™ ืืชืจื™ื ืฉื•ื ื™ื ืฉื ืคืจืฆื•. ืขื ื–ืืช, ืฉืชื™ ื”ื’ืจืกืื•ืช ืฉืœื—ื• ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื ืœืื•ืชื• ืืชืจ ืคืจื•ืฅ zoobashop.com.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื ื™ืชื•ื— ื”ืงื™ื“ื•ืžื•ืช ืฉื‘ื”ืŸ ื”ืฉืชืžืฉ ื”ืžืจื—ืจื— ืœื—ื™ืคื•ืฉ ืฉื“ื•ืช ื”ืžื›ื™ืœื™ื ืืช ืคืจื˜ื™ ื”ืชืฉืœื•ื ืฉืœ ื”ืงื•ืจื‘ืŸ ืืคืฉืจื• ืœื ื• ืœืงื‘ื•ืข ืฉื“ื’ื™ืžืช ื”ืžืจื—ืจื— ื”ื–ื• ื›ื•ื•ื ื” ืœืžืขืจื›ื•ืช ื”ืชืฉืœื•ืžื™ื ื”ื‘ืื•ืช:

  • Authorize.Net
  • Verisign
  • ื ืชื•ื ื™ื ื”ืจืืฉื•ื ื™ื
  • USAePay
  • ืคึผึทืก
  • PayPal
  • ANZ eGate
  • ื‘ืจื™ื™ื ื˜ืจื™
  • DataCash (ืžืืกื˜ืจืงืืจื“)
  • Realex Payments
  • PsiGate
  • Heartland Payment Systems

ื‘ืื™ืœื• ื›ืœื™ื ืžืฉืชืžืฉื™ื ื›ื“ื™ ืœื’ื ื•ื‘ ืคืจื˜ื™ ืชืฉืœื•ื?

ื”ื›ืœื™ ื”ืจืืฉื•ืŸ, ืฉื”ืชื’ืœื” ื‘ืžื”ืœืš ื ื™ืชื•ื— ื”ืชืฉืชื™ืช ืฉืœ ื”ืชื•ืงืคื™ื, ืžืฉืžืฉ ืœื˜ืฉื˜ืฉ ืกืงืจื™ืคื˜ื™ื ื–ื“ื•ื ื™ื™ื ื”ืื—ืจืื™ื ืœื’ื ื™ื‘ืช ื›ืจื˜ื™ืกื™ ื‘ื ืง. ื‘ืื—ื“ ื”ืžืืจื—ื™ื ืฉืœ ื”ืชื•ืงืฃ ื”ืชื’ืœื” ืชืกืจื™ื˜ bash ืฉืžืฉืชืžืฉ ื‘-CLI ืฉืœ ื”ืคืจื•ื™ืงื˜ javascript-obfuscator ื›ื“ื™ ืœื”ืคื•ืš ืขืจืคื•ืœ ืฉืœ ืงื•ื“ ื”ืžืจื—ืฃ ืœืื•ื˜ื•ืžื˜ื™.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื”ื›ืœื™ ื”ืฉื ื™ ืฉื”ืชื’ืœื” ื ื•ืขื“ ืœื™ืฆื•ืจ ืงื•ื“ ืฉืื—ืจืื™ ืœื˜ืขื™ื ืช ื”ืกื ื™ืคืจ ื”ืจืืฉื™. ื›ืœื™ ื–ื” ื™ื•ืฆืจ ืงื•ื“ JavaScript ืฉื‘ื•ื“ืง ืื ื”ืžืฉืชืžืฉ ื ืžืฆื ื‘ื“ืฃ ื”ืชืฉืœื•ื ืขืœ ื™ื“ื™ ื—ื™ืคื•ืฉ ืžื—ืจื•ื–ื•ืช ื‘ื›ืชื•ื‘ืช ื”ื ื•ื›ื—ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ ืœืชืฉืœื•ื, ืขื’ืœื” ื•ื›ืŸ ื”ืœืื”, ื•ืื ื”ืชื•ืฆืื” ื—ื™ื•ื‘ื™ืช, ืื– ื”ืงื•ื“ ื˜ื•ืขืŸ ืืช ื”ืกื ื™ืคืจ ื”ืจืืฉื™ ืžื”ืฉืจืช ืฉืœ ื”ืชื•ืงืคื™ื. ื›ื“ื™ ืœื”ืกืชื™ืจ ืคืขื™ืœื•ืช ื–ื“ื•ื ื™ืช, ื›ืœ ื”ืฉื•ืจื•ืช, ืœืจื‘ื•ืช ืฉื•ืจื•ืช ื‘ื“ื™ืงื” ืœืงื‘ื™ืขืช ื“ืฃ ื”ืชืฉืœื•ื, ื•ื›ืŸ ืงื™ืฉื•ืจ ืœ-sniffer, ืžืงื•ื“ื“ื•ืช ื‘ืืžืฆืขื•ืช base64.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื”ืชืงืคื•ืช ื“ื™ื•ื’

ื ื™ืชื•ื— ืฉืœ ืชืฉืชื™ืช ื”ืจืฉืช ืฉืœ ื”ืชื•ืงืคื™ื ื”ืขืœื” ื›ื™ ื”ืงื‘ื•ืฆื” ื”ืคื•ืฉืขืช ืžืฉืชืžืฉืช ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ื“ื™ื•ื’ ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืœืคืื ืœ ื”ื ื™ื”ื•ืœื™ ืฉืœ ื—ื ื•ืช ื”ื™ืขื“ ื”ืžืงื•ื•ื ืช. ืชื•ืงืคื™ื ืจื•ืฉืžื™ื ื“ื•ืžื™ื™ืŸ ืฉื“ื•ืžื” ืžื‘ื—ื™ื ื” ื•ื™ื–ื•ืืœื™ืช ืœื“ื•ืžื™ื™ืŸ ืฉืœ ื—ื ื•ืช, ื•ืื– ืคื•ืจืกื™ื ื‘ื• ื˜ื•ืคืก ื”ืชื—ื‘ืจื•ืช ืžื–ื•ื™ืฃ ืœืคืื ืœ ื ื™ื”ื•ืœ Magento. ืื ื™ืฆืœื™ื—, ื”ืชื•ืงืคื™ื ื™ืงื‘ืœื• ื’ื™ืฉื” ืœืคืื ืœ ื”ืื“ืžื™ื ื™ืกื˜ืจื˜ื™ื‘ื™ ืฉืœ Magento CMS, ืžื” ืฉื ื•ืชืŸ ืœื”ื ื”ื–ื“ืžื ื•ืช ืœืขืจื•ืš ืืช ืจื›ื™ื‘ื™ ื”ืืชืจ ื•ืœื™ื™ืฉื ืกื ื™ืคืจ ื›ื“ื™ ืœื’ื ื•ื‘ ื ืชื•ื ื™ ื›ืจื˜ื™ืกื™ ืืฉืจืื™.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืชืฉืชื™ืช

ะ”ะพะผะตะฝ ืชืืจื™ืš ื’ื™ืœื•ื™/ื”ื•ืคืขื”
mediapack.info 04.05.2017
adsgetapi.com 15.06.2017
simcounter.com 14.08.2017
mageanalytics.com 22.12.2017
maxstatics.com 16.01.2018
reactjsapi.com 19.01.2018
mxcounter.com 02.02.2018
apitstatus.com 01.03.2018
orderracker.com 20.04.2018
tagstracking.com 25.06.2018
adsapigate.com 12.07.2018
trust-tracker.com 15.07.2018
fbstatspartner.com 02.10.2018
billgetstatus.com 12.10.2018
www.aldenmlilhouse.com 20.10.2018
balletbeautlful.com 20.10.2018
bargalnjunkie.com 20.10.2018
payselector.com 21.10.2018
tagsmediaget.com 02.11.2018
hs-payments.com 16.11.2018
ordercheckpays.com 19.11.2018
geisseie.com 24.11.2018
gtmproc.com 29.11.2018
livegetpay.com 18.12.2018
sydneysalonsupplies.com 18.12.2018
newrelicnet.com 19.12.2018
nr-public.com 03.01.2019
cloudodesc.com 04.01.2019
ajaxstatic.com 11.01.2019
livecheckpay.com 21.01.2019
asianfoodgracer.com 25.01.2019

ืžืฉืคื—ืช G-Analytics

ืžืฉืคื—ืช ื”ืžืจื—ืจื—ื™ื ื”ื–ื• ืžืฉืžืฉืช ืœื’ื ื™ื‘ืช ื›ืจื˜ื™ืกื™ ืœืงื•ื—ื•ืช ืžื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช. ืฉื ื”ื“ื•ืžื™ื™ืŸ ื”ืจืืฉื•ืŸ ื‘ืฉื™ืžื•ืฉ ื”ืงื‘ื•ืฆื” ื ืจืฉื ื‘ืืคืจื™ืœ 2016, ืžื” ืฉืขืฉื•ื™ ืœื”ืขื™ื“ ืขืœ ื›ืš ืฉื”ืงื‘ื•ืฆื” ื”ื—ืœื” ื‘ืคืขื™ืœื•ืช ื‘ืืžืฆืข 2016.

ื‘ืงืžืคื™ื™ืŸ ื”ื ื•ื›ื—ื™, ื”ืงื‘ื•ืฆื” ืžืฉืชืžืฉืช ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื”ืžื—ืงื™ื ืฉื™ืจื•ืชื™ื ืžื”ื—ื™ื™ื ื”ืืžื™ืชื™ื™ื, ื›ืžื• ื’ื•ื’ืœ ืื ืœื™ื˜ื™ืงืก ื•-jQuery, ื”ืžืกื•ื•ื” ืืช ืคืขื™ืœื•ืช ื”ืกื ื™ืคืจื™ื ืขื ืกืงืจื™ืคื˜ื™ื ืœื’ื™ื˜ื™ืžื™ื™ื ื•ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื“ื•ืžื™ื ืœืืœื” ืœื’ื™ื˜ื™ืžื™ื™ื. ืืชืจื™ื ื”ืžืจื™ืฆื™ื ืืช Magento CMS ื”ื•ืชืงืคื•.

ื›ื™ืฆื“ ืžื™ื•ืฉืžืช G-Analytics ื‘ืงื•ื“ ืฉืœ ื—ื ื•ืช ืžืงื•ื•ื ืช

ืžืืคื™ื™ืŸ ื™ื™ื—ื•ื“ื™ ืฉืœ ืžืฉืคื—ื” ื–ื• ื”ื•ื ื”ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ื•ืช ืฉื•ื ื•ืช ืœื’ื ื™ื‘ืช ืคืจื˜ื™ ืชืฉืœื•ื ืฉืœ ืžืฉืชืžืฉื™ื. ื‘ื ื•ืกืฃ ืœื”ื–ืจืงื” ื”ืงืœืืกื™ืช ืฉืœ ืงื•ื“ JavaScript ืœืฆื“ ื”ืœืงื•ื— ืฉืœ ื”ืืชืจ, ื”ืงื‘ื•ืฆื” ื”ืคื•ืฉืขืช ื”ืฉืชืžืฉื” ื’ื ื‘ื˜ื›ื ื™ืงื•ืช ืฉืœ ื”ื–ืจืงืช ืงื•ื“ ืœืฆื“ ื”ืฉืจืช ืฉืœ ื”ืืชืจ, ื›ืœื•ืžืจ ืกืงืจื™ืคื˜ื™ื ืฉืœ PHP ื”ืžืขื‘ื“ื™ื ื ืชื•ื ื™ื ืฉื”ื•ื–ื ื• ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ. ื˜ื›ื ื™ืงื” ื–ื• ืžืกื•ื›ื ืช ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ืžืงืฉื” ืขืœ ื—ื•ืงืจื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืœื–ื”ื•ืช ืงื•ื“ ื–ื“ื•ื ื™. ืžื•ืžื—ื™ Group-IB ื’ื™ืœื• ื’ืจืกื” ืฉืœ ื”ืกื ื™ืคืจ ื”ืžื•ื˜ืžืขืช ื‘ืงื•ื“ PHP ืฉืœ ื”ืืชืจ, ืชื•ืš ืฉื™ืžื•ืฉ ื‘ื“ื•ืžื™ื™ืŸ ื›ืฉืขืจ dittm.org.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื”ืชื’ืœืชื” ื’ื ื’ืจืกื” ืžื•ืงื“ืžืช ืฉืœ ืกื ื™ืคืจ ืฉืžืฉืชืžืฉืช ื‘ืื•ืชื• ืชื—ื•ื ื›ื“ื™ ืœืืกื•ืฃ ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื dittm.org, ืืš ื’ืจืกื” ื–ื• ืžื™ื•ืขื“ืช ืœื”ืชืงื ื” ื‘ืฆื“ ื”ืœืงื•ื— ืฉืœ ื—ื ื•ืช ืžืงื•ื•ื ืช.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืžืื•ื—ืจ ื™ื•ืชืจ ื”ืงื‘ื•ืฆื” ืฉื™ื ืชื” ืืช ื”ื˜ืงื˜ื™ืงื” ืฉืœื” ื•ื”ื—ืœื” ืœื”ืชืžืงื“ ื™ื•ืชืจ ื‘ื”ืกืชืจืช ืคืขื™ืœื•ืช ื–ื“ื•ื ื™ืช ื•ื”ืกื•ื•ืื”.

ื‘ืชื—ื™ืœืช 2017 ื”ื—ืœื” ื”ืงื‘ื•ืฆื” ืœื”ืฉืชืžืฉ ื‘ื“ื•ืžื™ื™ืŸ jquery-js.com, ืžืชื—ื–ื” ืœ-CDN ืขื‘ื•ืจ jQuery: ื›ืืฉืจ ืขื•ื‘ืจื™ื ืœืืชืจ ื”ืชื•ืงืคื™ื, ื”ืžืฉืชืžืฉ ืžื•ืคื ื” ืœืืชืจ ืœื’ื™ื˜ื™ืžื™ jquery.com.

ื•ื‘ืืžืฆืข 2018, ื”ืงื‘ื•ืฆื” ืื™ืžืฆื” ืืช ืฉื ื”ื“ื•ืžื™ื™ืŸ g-analytics.com ื•ื”ื—ืœ ืœื”ืกื•ื•ืช ืืช ืคืขื™ืœื•ืชื• ืฉืœ ื”ืžืจื—ืจื— ื›ืฉื™ืจื•ืช ืœื’ื™ื˜ื™ืžื™ ืฉืœ ื’ื•ื’ืœ ืื ืœื™ื˜ื™ืงืก.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื ื™ืชื•ื— ื’ืจืกืื•ืช

ื‘ืžื”ืœืš ื ื™ืชื•ื— ื”ื“ื•ืžื™ื™ื ื™ื ื”ืžืฉืžืฉื™ื ืœืื—ืกื•ืŸ ืงื•ื“ ื”ืกื ื™ืคืจ, ื ืžืฆื ื›ื™ ื”ืืชืจ ืžื›ื™ืœ ืžืกืคืจ ืจื‘ ืฉืœ ื’ืจืกืื•ืช, ื”ื ื‘ื“ืœื•ืช ื‘ื ื•ื›ื—ื•ืช ืขืจืคื•ืœ, ื•ื›ืŸ ื‘ื ื•ื›ื—ื•ืช ืื• ื”ื™ืขื“ืจ ืงื•ื“ ื‘ืœืชื™ ื ื™ืชืŸ ืœื”ืฉื’ื” ืฉื ื•ืกืฃ ืœืงื•ื‘ืฅ ื›ื“ื™ ืœื”ืกื™ื— ืืช ืชืฉื•ืžืช ื”ืœื‘ ื•ืœื”ืกืชื™ืจ ืงื•ื“ ื–ื“ื•ื ื™.

ืกื”"ื› ื‘ืืชืจ jquery-js.com ื–ื•ื”ื• ืฉืฉ ื’ืจืกืื•ืช ืฉืœ ืžืจื—ืจื—ื™ื. ื”ืžืจื—ืจื—ื™ื ื”ืืœื” ืฉื•ืœื—ื™ื ืืช ื”ื ืชื•ื ื™ื ื”ื’ื ื•ื‘ื™ื ืœื›ืชื•ื‘ืช ื”ืžืžื•ืงืžืช ื‘ืื•ืชื• ืืชืจ ื›ืžื• ื”ืžืจื—ืจื— ืขืฆืžื•: hxxps://jquery-js[.]com/latest/jquery.min.js:

  • hxxps://jquery-js[.]com/jquery.min.js
  • hxxps://jquery-js[.]com/jquery.2.2.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.8.3.min.js
  • hxxps://jquery-js[.]com/jquery.1.6.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.4.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.12.4.min.js

ืชื—ื•ื ืžืื•ื—ืจ ื™ื•ืชืจ g-analytics.com, ื”ืžืฉืžืฉ ืืช ื”ืงื‘ื•ืฆื” ื‘ื”ืชืงืคื•ืช ืžืื– ืืžืฆืข 2018, ืžืฉืžืฉ ื›ืžืื’ืจ ืœืจื—ืคื ื™ื ื ื•ืกืคื™ื. ื‘ืกืš ื”ื›ืœ ื”ืชื’ืœื• 16 ื’ืจืกืื•ืช ืฉื•ื ื•ืช ืฉืœ ื”ืžืจื—ืจื—. ื‘ืžืงืจื” ื–ื”, ื”ืฉืขืจ ืœืฉืœื™ื—ืช ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื ื”ื•ืกื•ื•ื” ื›ืงื™ืฉื•ืจ ืœืคื•ืจืžื˜ ืชืžื•ื ื” GIF: hxxp://g-analytics[.]com/__utm.gif?v=1&_v=j68&a=98811130&t=pageview&_s=1&sd=24-bit&sr=2560ร—1440&vp=2145ร—371&je=0&_u=AACAAEAB~&jid=1841704724&gjid=877686936&cid
= 1283183910.1527732071
:

  • hxxps://g-analytics[.]com/libs/1.0.1/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.10/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.11/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.12/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.13/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.14/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.15/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.16/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.3/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.4/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.5/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.6/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.7/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.8/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.9/analytics.js
  • hxxps://g-analytics[.]com/libs/analytics.js

ืžื•ื ื˜ื™ื–ืฆื™ื” ืฉืœ ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื

ื”ืงื‘ื•ืฆื” ื”ืคื•ืฉืขืช ืžื™ื™ืฆืจืช ืจื•ื•ื—ื™ื ืžื”ื ืชื•ื ื™ื ื”ื’ื ื•ื‘ื™ื ืขืœ ื™ื“ื™ ืžื›ื™ืจืช ื›ืจื˜ื™ืกื™ื ื“ืจืš ื—ื ื•ืช ืžื—ืชืจืชื™ืช ืฉื ื•ืฆืจื” ื‘ืžื™ื•ื—ื“ ื”ืžืกืคืงืช ืฉื™ืจื•ืชื™ื ืœืงืœืคื™ื. ื ื™ืชื•ื— ืฉืœ ื”ื“ื•ืžื™ื™ื ื™ื ืฉื‘ื”ื ื”ืฉืชืžืฉื• ื”ืชื•ืงืคื™ื ืืคืฉืจื• ืœื ื• ืœืงื‘ื•ืข ื–ืืช google-analytics.cm ื ืจืฉื ืขืœ ื™ื“ื™ ืื•ืชื• ืžืฉืชืžืฉ ื›ืžื• ื”ื“ื•ืžื™ื™ืŸ cardz.vc. ืชึฐื—ื•ึผื cardz.vc ื”ื›ื•ื•ื ื” ืœื—ื ื•ืช ืฉืžื•ื›ืจืช ื›ืจื˜ื™ืกื™ื ื‘ื ืงืื™ื™ื ื’ื ื•ื‘ื™ื Cardsurfs (Flysurfs), ืฉื–ื›ืชื” ืœืคื•ืคื•ืœืจื™ื•ืช ืขื•ื“ ื‘ื™ืžื™ ืคืขื™ืœื•ืชื” ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”ืžืกื—ืจ ื”ืžื—ืชืจืชื™ืช AlphaBay ื›ื—ื ื•ืช ืœืžืžื›ืจ ื›ืจื˜ื™ืกื™ื ื‘ื ืงืื™ื™ื ืฉื ื’ื ื‘ื• ื‘ืืžืฆืขื•ืช ืกื ื™ืคืจ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื ื™ืชื•ื— ื”ืชื—ื•ื analytical.is, ื”ืžืžื•ืงื ื‘ืื•ืชื• ืฉืจืช ื›ืžื• ื”ื“ื•ืžื™ื™ื ื™ื ื”ืžืฉืžืฉื™ื ืืช ื”ืกื ื™ืคืจื™ื ืœืื™ืกื•ืฃ ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื, ืžื•ืžื—ื™ Group-IB ื’ื™ืœื• ืงื•ื‘ืฅ ื”ืžื›ื™ืœ ื™ื•ืžื ื™ ื’ื ื™ื‘ืช ืขื•ื’ื™ื•ืช, ืฉื ืจืื” ื›ืื™ืœื• ื ื˜ืฉ ืžืื•ื—ืจ ื™ื•ืชืจ ืขืœ ื™ื“ื™ ื”ืžืคืชื—. ืื—ื“ ื”ืขืจื›ื™ื ื‘ื™ื•ืžืŸ ื”ื›ื™ืœ ื“ื•ืžื™ื™ืŸ iozoz.com, ืฉืฉื™ืžืฉ ื‘ืขื‘ืจ ื‘ืื—ื“ ืžื”ืกื ื™ืคืจื™ื ื”ืคืขื™ืœื™ื ื‘-2016. ื›ื›ืœ ื”ื ืจืื”, ื“ื•ืžื™ื™ืŸ ื–ื” ืฉื™ืžืฉ ื‘ืขื‘ืจ ืขืœ ื™ื“ื™ ืชื•ืงืฃ ืœืื™ืกื•ืฃ ื›ืจื˜ื™ืกื™ื ืฉื ื’ื ื‘ื• ื‘ืืžืฆืขื•ืช ืกื ื™ืคืจ. ื“ื•ืžื™ื™ืŸ ื–ื” ื ืจืฉื ืœื›ืชื•ื‘ืช ื“ื•ื"ืœ [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ], ืฉืฉื™ืžืฉ ื’ื ืœืจื™ืฉื•ื ื“ื•ืžื™ื™ื ื™ื cardz.su ะธ cardz.vc, ืงืฉื•ืจ ืœื—ื ื•ืช ื”ืงืœืคื™ื Cardsurfs.

ืขืœ ืกืžืš ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื•, ื ื™ืชืŸ ืœืฉืขืจ ื›ื™ ืžืฉืคื—ืช ื”ืžืจื—ื—ื™ื G-Analytics ื•ื”ื—ื ื•ืช ื”ืžื—ืชืจืชื™ืช ืœืžืžื›ืจ ื›ืจื˜ื™ืกื™ื ื‘ื ืงืื™ื™ื Cardsurf ืžื ื•ื”ืœื™ื ืขืœ ื™ื“ื™ ืื•ืชื ืื ืฉื™ื, ื•ื”ื—ื ื•ืช ืžืฉืžืฉืช ืœืžื›ื™ืจืช ื›ืจื˜ื™ืกื™ ื‘ื ืง ืฉื ื’ื ื‘ื• ื‘ืืžืฆืขื•ืช ื”ืกื ื™ืคืจ.

ืชืฉืชื™ืช

ะ”ะพะผะตะฝ ืชืืจื™ืš ื’ื™ืœื•ื™/ื”ื•ืคืขื”
iozoz.com 08.04.2016
dittm.org 10.09.2016
jquery-js.com 02.01.2017
g-analytics.com 31.05.2018
google-analytics.is 21.11.2018
ืื ืœื™ื˜ื™.ืœ 04.12.2018
google-analytics.to 06.12.2018
google-analytics.cm 28.12.2018
analytical.is 28.12.2018
google-analytics.cm 17.01.2019

ืžืฉืคื—ืช ืื™ืœื•ื

Illum ื”ื™ื ืžืฉืคื—ื” ืฉืœ ืจื—ืคื ื™ื ื”ืžืฉืžืฉืช ืœืชืงื•ืฃ ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช ื”ืžืจืฆื•ืช ืืช Magento CMS. ื‘ื ื•ืกืฃ ืœื”ื›ื ืกืช ืงื•ื“ ื–ื“ื•ื ื™, ืžืคืขื™ืœื™ ื”ืžืจื—ืจื— ื”ื–ื” ืžืฉืชืžืฉื™ื ื’ื ื‘ื”ื—ื“ืจืช ื˜ืคืกื™ ืชืฉืœื•ื ืžื–ื•ื™ืคื™ื ืžืœืื™ื ื”ืฉื•ืœื—ื™ื ื ืชื•ื ื™ื ืœืฉืขืจื™ื ืฉื ืฉืœื˜ื™ื ืขืœ ื™ื“ื™ ืชื•ืงืคื™ื.

ื‘ืขืช ื ื™ืชื•ื— ืชืฉืชื™ืช ื”ืจืฉืช ื”ืžืฉืžืฉืช ืืช ืžืคืขื™ืœื™ ื”ืžืจื—ืจื— ื”ื–ื”, ืฆื•ื™ืŸ ืžืกืคืจ ืจื‘ ืฉืœ ืกืงืจื™ืคื˜ื™ื ื–ื“ื•ื ื™ื™ื, ื ื™ืฆื•ืœื™ื, ื˜ืคืกื™ ืชืฉืœื•ื ืžื–ื•ื™ืคื™ื, ื›ืžื• ื’ื ืื•ืกืฃ ืฉืœ ื“ื•ื’ืžืื•ืช ืขื ืกื ื™ืคืจื™ื ื–ื“ื•ื ื™ื™ื ืฉืœ ืžืชื—ืจื™ื. ืขืœ ืกืžืš ืžื™ื“ืข ืขืœ ืชืืจื™ื›ื™ ื”ื•ืคืขืชื ืฉืœ ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ื‘ื”ื ื”ืฉืชืžืฉื” ื”ืงื‘ื•ืฆื”, ื ื™ืชืŸ ืœืฉืขืจ ื›ื™ ื”ืงืžืคื™ื™ืŸ ื”ื—ืœ ื‘ืกื•ืฃ ืฉื ืช 2016.

ืื™ืš Illum ืžื™ื•ืฉืžืช ื‘ืงื•ื“ ืฉืœ ื—ื ื•ืช ืžืงื•ื•ื ืช

ื”ื’ืจืกืื•ืช ื”ืจืืฉื•ื ื•ืช ืฉืœ ื”ืกื ื™ืคืจ ืฉื”ืชื’ืœื• ื”ื•ื˜ืžืขื• ื™ืฉื™ืจื•ืช ื‘ืงื•ื“ ืฉืœ ื”ืืชืจ ืฉื ืคืจืฅ. ื”ื ืชื•ื ื™ื ื”ื’ื ื•ื‘ื™ื ื ืฉืœื—ื• ืืœ cdn.illum[.]pw/records.php, ื”ืฉืขืจ ืงื•ื“ื“ ื‘ืืžืฆืขื•ืช base64.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืžืื•ื—ืจ ื™ื•ืชืจ, ื”ืชื’ืœืชื” ื’ืจืกื” ืืจื•ื–ื” ืฉืœ ื”ืžืจื—ืจื— ืฉืžืฉืชืžืฉืช ื‘ืฉืขืจ ืื—ืจ - records.nstatistics[.]com/records.php.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืขืœ ืคื™ ืœื”ื’ื™ืฉ ืชืœื•ื ื” ื•ื™ืœื ื“ื” ื’ืจื•ื˜, ืื•ืชื• ืžืืจื— ืฉื™ืžืฉ ื‘ืกื ื™ืคืจ, ืฉื™ื•ืฉื ืขืœ ืืชืจ ื”ื—ื ื•ืช, ื‘ื‘ืขืœื•ืช ื”ืžืคืœื’ื” ื”ื’ืจืžื ื™ืช CSU.

ื ื™ืชื•ื— ืืชืจ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ืชื•ืงืคื™ื

ืžื•ืžื—ื™ Group-IB ื’ื™ืœื• ื•ื ื™ืชื—ื• ืืชืจ ืื™ื ื˜ืจื ื˜ ื”ืžืฉืžืฉ ืืช ื”ืงื‘ื•ืฆื” ื”ืคื•ืฉืขืช ื”ื–ื• ืœืื—ืกื•ืŸ ื›ืœื™ื ื•ืœืื™ืกื•ืฃ ืžื™ื“ืข ื’ื ื•ื‘.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื‘ื™ืŸ ื”ื›ืœื™ื ืฉื ืžืฆืื• ื‘ืฉืจืช ื”ืชื•ืงืคื™ื ื”ื™ื• ืกืงืจื™ืคื˜ื™ื ื•ื ื™ืฆื•ืœื™ื ืœื”ืกืœืžื” ืฉืœ ื”ืจืฉืื•ืช ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” Linux: ืœืžืฉืœ, Linux Privilege Escalation Check Script ืฉืคื•ืชื— ืขืœ ื™ื“ื™ Mike Czumak, ื›ืžื• ื’ื ื ื™ืฆื•ืœ ืขื‘ื•ืจ CVE-2009-1185.

ื”ืชื•ืงืคื™ื ื”ืฉืชืžืฉื• ื‘ืฉื ื™ ืžืขืœืœื™ื ื™ืฉื™ืจื•ืช ื›ื“ื™ ืœืชืงื•ืฃ ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช: ะฟะตั€ะฒั‹ะน ืžืกื•ื’ืœ ืœื”ื—ื“ื™ืจ ืœืชื•ื›ื• ืงื•ื“ ื–ื“ื•ื ื™ core_config_data ืขืœ ื™ื“ื™ ื ื™ืฆื•ืœ CVE-2016-4010, ืฉื ื™ ืžื ืฆืœ ืคื’ื™ืขื•ืช RCE ื‘ืชื•ืกืคื™ื ืขื‘ื•ืจ CMS Magento, ื•ืžืืคืฉืจ ืœื”ืคืขื™ืœ ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืฉืจืช ืื™ื ื˜ืจื ื˜ ืคื’ื™ืข.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื›ืžื• ื›ืŸ, ื‘ืžื”ืœืš ื ื™ืชื•ื— ื”ืฉืจืช ื”ืชื’ืœื• ื“ื•ื’ืžืื•ืช ืฉื•ื ื•ืช ืฉืœ ืกื ื™ืคืจื™ื ื•ื˜ืคืกื™ ืชืฉืœื•ื ืžื–ื•ื™ืคื™ื, ื”ืžืฉืžืฉื™ื ืชื•ืงืคื™ื ืœืื™ืกื•ืฃ ืคืจื˜ื™ ืชืฉืœื•ื ืžืืชืจื™ื ืคืจื•ืฆื™ื. ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช ืžื”ืจืฉื™ืžื” ืœืžื˜ื”, ื›ืžื” ืกืงืจื™ืคื˜ื™ื ื ื•ืฆืจื• ื‘ื ืคืจื“ ืขื‘ื•ืจ ื›ืœ ืืชืจ ืฉื ืคืจืฅ, ื‘ืขื•ื“ ืฉืคืชืจื•ืŸ ืื•ื ื™ื‘ืจืกืœื™ ืฉื™ืžืฉ ืขื‘ื•ืจ CMS ื•ืฉืขืจื™ื ืžืกื•ื™ืžื™ื ืœืชืฉืœื•ื. ืœืžืฉืœ, ืชืกืจื™ื˜ื™ื segapay_standart.js ะธ segapay_onpage.js ืžื™ื•ืขื“ื™ื ืœื™ื™ืฉื•ื ื‘ืืชืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืฉืขืจ ื”ืชืฉืœื•ื ืฉืœ Sage Pay.

ืจืฉื™ืžืช ืกืงืจื™ืคื˜ื™ื ืœืฉืขืจื™ ืชืฉืœื•ื ืฉื•ื ื™ื

ืชึทืกืจึดื™ื˜ ืฉืขืจ ืชืฉืœื•ื
sr.illum[.]pw/mjs_special/visiondirect.co.uk.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/topdierenshop.nl.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/tiendalenovo.es.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/pro-bolt.com.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/plae.co.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/ottolenghi.co.uk.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/oldtimecandy.com.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/mylook.ee.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs_special/luluandsky.com.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/julep.com.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs_special/gymcompany.es.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/grotekadoshop.nl.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/fushi.co.uk.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/fareastflora.com.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/compuindia.com.js //request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs/segapay_standart.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/segapay_onpage.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/replace_standart.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs/all_inputs.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/add_inputs_standart.js //request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/magento/payment_standart.js //cdn.illum[.]pw/records.php
sr.illum[.]pw/magento/payment_redirect.js //payrightnow[.]cf/?payment=
sr.illum[.]pw/magento/payment_redcrypt.js //payrightnow[.]cf/?payment=
sr.illum[.]pw/magento/payment_forminsite.js //paymentnow[.]tk/?payment=

ืžืืจื— paynow[.]tk, ืžืฉืžืฉ ื›ืฉืขืจ ื‘ืชืกืจื™ื˜ payment_forminsite.js, ื”ืชื’ืœื” ื› subjectAltName ื‘ืžืกืคืจ ืื™ืฉื•ืจื™ื ื”ืงืฉื•ืจื™ื ืœืฉื™ืจื•ืช CloudFlare. ื‘ื ื•ืกืฃ, ื”ืžืืจื— ื”ื›ื™ืœ ืชืกืจื™ื˜ evil.js. ืื ืœืฉืคื•ื˜ ืœืคื™ ืฉื ื”ืกืงืจื™ืคื˜, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื—ืœืง ืžื ื™ืฆื•ืœ ื”-CVE-2016-4010, ืฉื‘ื–ื›ื•ืชื• ื ื™ืชืŸ ืœื”ื—ื“ื™ืจ ืงื•ื“ ื–ื“ื•ื ื™ ืœื›ื•ืชืจืช ื”ืชื—ืชื•ื ื” ืฉืœ ืืชืจ ื”ืžืจื™ืฅ ืืช CMS Magento. ื”ืžืืจื— ื”ืฉืชืžืฉ ื‘ืกืงืจื™ืคื˜ ื–ื” ื›ืฉืขืจ request.requestnet[.]tkื‘ืืžืฆืขื•ืช ืื•ืชื• ืื™ืฉื•ืจ ื›ืžื• ื”ืžืืจื— paynow[.]tk.

ื˜ืคืกื™ ืชืฉืœื•ื ืžื–ื•ื™ืคื™ื

ื”ืื™ื•ืจ ืฉืœื”ืœืŸ ืžืฆื™ื’ ื“ื•ื’ืžื” ืœื˜ื•ืคืก ืœื”ื–ื ืช ื ืชื•ื ื™ ื›ืจื˜ื™ืก. ื˜ื•ืคืก ื–ื” ืฉื™ืžืฉ ื›ื“ื™ ืœื—ื“ื•ืจ ืœื—ื ื•ืช ืžืงื•ื•ื ืช ื•ืœื’ื ื™ื‘ืช ื ืชื•ื ื™ ื›ืจื˜ื™ืกื™ื.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื”ืื™ื•ืจ ื”ื‘ื ืžืฆื™ื’ ื“ื•ื’ืžื” ืœื˜ื•ืคืก ืชืฉืœื•ื ืžื–ื•ื™ืฃ ืฉืœ PayPal ืฉืฉื™ืžืฉ ืืช ื”ืชื•ืงืคื™ื ื›ื“ื™ ืœื—ื“ื•ืจ ืœืืชืจื™ื ืขื ืืžืฆืขื™ ืชืฉืœื•ื ื–ื”.
ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืชืฉืชื™ืช

ะ”ะพะผะตะฝ ืชืืจื™ืš ื’ื™ืœื•ื™/ื”ื•ืคืขื”
cdn.illum.pw 27/11/2016
records.nstatistics.com 06/09/2018
request.payrightnow.cf 25/05/2018
paymentnow.tk 16/07/2017
pay-line.tk 01/03/2018
paypal.cf 04/09/2017
requestnet.tk 28/06/2017

ืžืฉืคื—ืช CoffeeMokko

ืžืฉืคื—ืช ื”ืžืจื—ื—ื™ื CoffeMokko, ืฉื ื•ืขื“ื” ืœื’ื ื•ื‘ ื›ืจื˜ื™ืกื™ ื‘ื ืง ืžืžืฉืชืžืฉื™ ื—ื ื•ืช ืžืงื•ื•ื ืช, ื ืžืฆืืช ื‘ืฉื™ืžื•ืฉ ืœืคื—ื•ืช ืžืื– ืžืื™ 2017. ื™ืฉ ืœื”ื ื™ื— ืฉื”ืžืคืขื™ืœื™ื ืฉืœ ืžืฉืคื—ืช ื”ืžืจื—ืจื—ื™ื ื”ื–ื• ื”ื ืงื‘ื•ืฆืช ื”ืคืฉืข Group 1, ืฉืชื•ืืจื” ืขืœ ื™ื“ื™ ืžื•ืžื—ื™ RiskIQ ื‘-2016. ืืชืจื™ื ื”ืžืจื™ืฆื™ื ืžืขืจื›ื•ืช CMS ื›ืžื• Magento, OpenCart, WordPress, osCommerce ื•-Shopify ื”ื•ืชืงืคื•.

ื›ื™ืฆื“ CoffeMokko ืžื™ื•ืฉื ื‘ืงื•ื“ ืฉืœ ื—ื ื•ืช ืžืงื•ื•ื ืช

ืžืคืขื™ืœื™ ืžืฉืคื—ื” ื–ื• ื™ื•ืฆืจื™ื ืกื ื™ืคืจื™ื ื™ื™ื—ื•ื“ื™ื™ื ืขื‘ื•ืจ ื›ืœ ื–ื™ื”ื•ื: ืงื•ื‘ืฅ ื”ืกื ื™ืคืจ ืžืžื•ืงื ื‘ืกืคืจื™ื™ื” src ืื• js ื‘ืฉืจืช ืฉืœ ื”ืชื•ืงืคื™ื. ื”ืฉื™ืœื•ื‘ ื‘ืงื•ื“ ื”ืืชืจ ืžืชื‘ืฆืข ื‘ืืžืฆืขื•ืช ืงื™ืฉื•ืจ ื™ืฉื™ืจ ืœ-sniffer.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืงื•ื“ ื”ืกื ื™ืคืจ ืžืงื•ื“ื“ ื‘ืฆื•ืจื” ืงืฉื™ื—ื” ืืช ืฉืžื•ืช ืฉื“ื•ืช ื”ื˜ื•ืคืก ืฉืžื”ื ืฆืจื™ืš ืœื’ื ื•ื‘ ื ืชื•ื ื™ื. ื”ืžืจื—ืจื— ื’ื ื‘ื•ื“ืง ื”ืื ื”ืžืฉืชืžืฉ ื ืžืฆื ื‘ื“ืฃ ื”ืชืฉืœื•ื ืขืœ ื™ื“ื™ ื‘ื“ื™ืงืช ืจืฉื™ืžืช ืžื™ืœื•ืช ื”ืžืคืชื— ืขื ื”ื›ืชื•ื‘ืช ื”ื ื•ื›ื—ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื›ืžื” ื’ืจืกืื•ืช ืฉื”ืชื’ืœื• ืฉืœ ื”ืžืจื—ืจื— ื”ื™ื• ืžืขื•ืจืคืœื•ืช ื•ื”ื›ื™ืœื• ืžื—ืจื•ื–ืช ืžื•ืฆืคื ืช ืฉื‘ื” ืžืื•ื—ืกืŸ ืžืขืจืš ื”ืžืฉืื‘ื™ื ื”ืขื™ืงืจื™: ื”ื™ื ื”ื›ื™ืœื” ืืช ืฉืžื•ืช ืฉื“ื•ืช ื”ื˜ืคืกื™ื ืขื‘ื•ืจ ืžืขืจื›ื•ืช ืชืฉืœื•ื ืฉื•ื ื•ืช, ื•ื›ืŸ ืืช ื›ืชื•ื‘ืช ื”ืฉืขืจ ืฉืืœื™ื” ื™ืฉ ืœืฉืœื•ื— ืืช ื”ื ืชื•ื ื™ื ื”ื’ื ื•ื‘ื™ื.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืคืจื˜ื™ ื”ืชืฉืœื•ื ื”ื’ื ื•ื‘ื™ื ื ืฉืœื—ื• ืœืกืงืจื™ืคื˜ ื‘ืฉืจืช ื”ืชื•ืงืคื™ื ืœืื•ืจืš ื”ื“ืจืš /savePayment/index.php ืื• /tr/index.php. ื›ื›ืœ ื”ื ืจืื”, ื”ืกืงืจื™ืคื˜ ื”ื–ื” ืžืฉืžืฉ ืœืฉืœื™ื—ืช ื ืชื•ื ื™ื ืžื”ืฉืขืจ ืœืฉืจืช ื”ืจืืฉื™, ื”ืžืื—ื“ ื ืชื•ื ื™ื ืžื›ืœ ื”ืกื ื™ืคืจื™ื. ื›ื“ื™ ืœื”ืกืชื™ืจ ืืช ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื, ื›ืœ ืคืจื˜ื™ ื”ืชืฉืœื•ื ืฉืœ ื”ืงื•ืจื‘ืŸ ืžื•ืฆืคื ื™ื ื‘ืืžืฆืขื•ืช base64, ื•ืœืื—ืจ ืžื›ืŸ ืžืชืจื—ืฉื•ืช ืžืกืคืจ ื”ื—ืœืคื•ืช ืชื•ื•ื™ื:

  • ื”ืชื• "e" ืžื•ื—ืœืฃ ื‘-":"
  • ื”ืกืžืœ "w" ืžื•ื—ืœืฃ ื‘-"+"
  • ื”ืชื• "o" ืžื•ื—ืœืฃ ื‘-"%"
  • ื”ืชื• "d" ืžื•ื—ืœืฃ ื‘-"#"
  • ื”ืชื• "a" ืžื•ื—ืœืฃ ื‘-"-"
  • ื”ืกืžืœ "7" ืžื•ื—ืœืฃ ื‘-"^"
  • ื”ืชื• "h" ืžื•ื—ืœืฃ ื‘-"_"
  • ื”ืกืžืœ "T" ืžื•ื—ืœืฃ ื‘-"@"
  • ื”ืชื• "0" ืžื•ื—ืœืฃ ื‘-"/"
  • ื”ืชื• "Y" ืžื•ื—ืœืฃ ื‘-"*"

ื›ืชื•ืฆืื” ืžื”ื—ืœืคื•ืช ืชื•ื•ื™ื ื”ืžืงื•ื“ื“ื•ืช ื‘ืืžืฆืขื•ืช base64 ืœื ื ื™ืชืŸ ืœืคืขื ื— ืืช ื”ื ืชื•ื ื™ื ืœืœื ื”ืžืจื” ื”ืคื•ื›ื”.

ื›ืš ื ืจืื” ืงื˜ืข ืฉืœ ืงื•ื“ ืกื ื™ืคืจ ืฉืœื ื”ื•ืกื‘:

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื ื™ืชื•ื— ืชืฉืชื™ื•ืช

ื‘ืงืžืคื™ื™ื ื™ื ืžื•ืงื“ืžื™ื, ืชื•ืงืคื™ื ืจืฉืžื• ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื“ื•ืžื™ื ืœืืœื” ืฉืœ ืืชืจื™ ืงื ื™ื•ืช ืžืงื•ื•ื ื™ื ืœื’ื™ื˜ื™ืžื™ื™ื. ื”ืชื—ื•ื ืฉืœื”ื ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื•ื ื” ืžื”-TLD ื”ืœื’ื™ื˜ื™ืžื™ ืื—ื“ ืœืกืžืœ ืื—ื“ ืื• ืื—ืจ. ื“ื•ืžื™ื™ื ื™ื ืจืฉื•ืžื™ื ืฉื™ืžืฉื• ืœืื—ืกื•ืŸ ืงื•ื“ sniffer, ืงื™ืฉื•ืจ ืืœื™ื• ื”ื•ื˜ื‘ืข ื‘ืงื•ื“ ื”ื—ื ื•ืช.

ืงื‘ื•ืฆื” ื–ื• ื”ืฉืชืžืฉื” ื’ื ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื”ืžื–ื›ื™ืจื™ื ืืช ื”ืชื•ืกืคื™ื ื”ืคื•ืคื•ืœืจื™ื™ื ืฉืœ jQuery (slickjs[.]org ืœืืชืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืชื•ืกืฃ slick.js), ืฉืขืจื™ ืชืฉืœื•ื (sagecdn[.]org ืœืืชืจื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžืขืจื›ืช ื”ืชืฉืœื•ืžื™ื ืฉืœ Sage Pay).

ืžืื•ื—ืจ ื™ื•ืชืจ, ื”ื—ืœื” ื”ืงื‘ื•ืฆื” ืœื™ืฆื•ืจ ื“ื•ืžื™ื™ื ื™ื ืฉืœืฉืžื•ืชื™ื”ื ืื™ืŸ ื›ืœ ืงืฉืจ ืœื“ื•ืžื™ื™ืŸ ืฉืœ ื”ื—ื ื•ืช ืื• ืœื ื•ืฉื ื”ื—ื ื•ืช.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื›ืœ ื“ื•ืžื™ื™ืŸ ืชื•ืื ืœืืชืจ ืฉื‘ื• ื ื•ืฆืจื” ื”ืกืคืจื™ื™ื” /js ืื• / src. ืกืงืจื™ืคื˜ื™ื ืฉืœ Sniffer ืื•ื—ืกื ื• ื‘ืกืคืจื™ื™ื” ื–ื•: Sniffer ืื—ื“ ืขื‘ื•ืจ ื›ืœ ื–ื™ื”ื•ื ื—ื“ืฉ. ื”ืกื ื™ืคืจ ื”ื•ื˜ื‘ืข ื‘ืงื•ื“ ื”ืืชืจ ื‘ืืžืฆืขื•ืช ืงื™ืฉื•ืจ ื™ืฉื™ืจ, ืืš ื‘ืžืงืจื™ื ื ื“ื™ืจื™ื, ื”ืชื•ืงืคื™ื ืฉื™ื ื• ืืช ืื—ื“ ืžืงื‘ืฆื™ ื”ืืชืจ ื•ื”ื•ืกื™ืคื• ืœื• ืงื•ื“ ื–ื“ื•ื ื™.

ื ื™ืชื•ื— ืงื•ื“

ืืœื’ื•ืจื™ืชื ืขืจืคื•ืœ ืจืืฉื•ืŸ

ื‘ื—ืœืง ืžื”ื“ื’ื™ืžื•ืช ืฉื”ืชื’ืœื• ืฉืœ ืžืจื—ืจื— ืžืžืฉืคื—ื” ื–ื•, ื”ืงื•ื“ ื”ื™ื” ืžืขื•ืจืคืœ ื•ื”ื›ื™ืœ ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื ื”ื“ืจื•ืฉื™ื ืขืœ ืžื ืช ืฉื”ืจื—ืจื— ื™ืคืขืœ: ื‘ืคืจื˜, ื›ืชื•ื‘ืช ืฉืขืจ ื”ืžืจื—ืจื—, ืจืฉื™ืžื” ืฉืœ ืฉื“ื•ืช ื˜ืคืกื™ ืชืฉืœื•ื, ื•ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื, ืงื•ื“ ืžื–ื•ื™ืฃ. ื˜ื•ืคืก ืชืฉืœื•ื. ื‘ืงื•ื“ ืฉื‘ืชื•ืš ื”ืคื•ื ืงืฆื™ื”, ื”ืžืฉืื‘ื™ื ื”ื•ืฆืคื ื• ื‘ืืžืฆืขื•ืช XOR ืขืœ ื™ื“ื™ ื”ืžืคืชื— ืฉื”ื•ืขื‘ืจ ื›ืืจื’ื•ืžื ื˜ ืœืื•ืชื” ืคื•ื ืงืฆื™ื”.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ืขืœ ื™ื“ื™ ืคืขื ื•ื— ื”ืžื—ืจื•ื–ืช ืขื ื”ืžืคืชื— ื”ืžืชืื™ื, ื”ื™ื™ื—ื•ื“ื™ ืœื›ืœ ื“ื•ื’ืžื”, ื ื™ืชืŸ ืœืงื‘ืœ ืžื—ืจื•ื–ืช ื”ืžื›ื™ืœื” ืืช ื›ืœ ื”ืžื—ืจื•ื–ื•ืช ืžืงื•ื“ ื”-sniffer ืžื•ืคืจื“ื™ื ื‘ืืžืฆืขื•ืช ืชื• ืžืคืจื™ื“.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ืืœื’ื•ืจื™ืชื ืขืจืคื•ืœ ืฉื ื™

ื‘ื“ื’ื™ืžื•ืช ืžืื•ื—ืจื•ืช ื™ื•ืชืจ ืฉืœ ืกื ื™ืคืจื™ื ืžืžืฉืคื—ื” ื–ื•, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ืŸ ืขืจืคื•ืœ ืฉื•ื ื”: ื‘ืžืงืจื” ื–ื”, ื”ื ืชื•ื ื™ื ื”ื•ืฆืคื ื• ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชื ืฉื ื›ืชื‘ ื‘ืขืฆืžื•. ืžื—ืจื•ื–ืช ื”ืžื›ื™ืœื” ื ืชื•ื ื™ื ืžื•ืฆืคื ื™ื ื”ื“ืจื•ืฉื™ื ืœื”ืคืขืœืช ื”ืžืจื™ื— ื”ื•ืขื‘ืจื” ื›ืืจื’ื•ืžื ื˜ ืœืคื•ื ืงืฆื™ื™ืช ื”ืคืขื ื•ื—.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื‘ืืžืฆืขื•ืช ืžืกื•ืฃ ื”ื“ืคื“ืคืŸ, ืืชื” ื™ื›ื•ืœ ืœืคืขื ื— ืืช ื”ื ืชื•ื ื™ื ื”ืžื•ืฆืคื ื™ื ื•ืœืงื‘ืœ ืžืขืจืš ื”ืžื›ื™ืœ ืžืฉืื‘ื™ ืกื ื™ืคืจ.

ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช

ื—ื™ื‘ื•ืจ ืœื”ืชืงืคื•ืช MageCart ืžื•ืงื“ืžื•ืช

ื‘ืžื”ืœืš ื ื™ืชื•ื— ืื—ื“ ืžื”ื“ื•ืžื™ื™ื ื™ื ื”ืžืฉืžืฉื™ื ืืช ื”ืงื‘ื•ืฆื” ื›ืฉืขืจ ืœืื™ืกื•ืฃ ื ืชื•ื ื™ื ื’ื ื•ื‘ื™ื, ื ืžืฆื ื›ื™ ื“ื•ืžื™ื™ืŸ ื–ื” ืžืืจื— ืชืฉืชื™ืช ืœื’ื ื™ื‘ืช ื›ืจื˜ื™ืกื™ ืืฉืจืื™, ื–ื”ื” ืœื–ื• ืฉืฉื™ืžืฉื” ืืช ืงื‘ื•ืฆื” 1, ืื—ืช ื”ืงื‘ื•ืฆื•ืช ื”ืจืืฉื•ื ื•ืช. ื’ื™ืœื” ืขืœ ื™ื“ื™ ืžื•ืžื—ื™ RiskIQ.

ืฉื ื™ ืงื‘ืฆื™ื ื ืžืฆืื• ืขืœ ื”ืžืืจื— ืฉืœ ืžืฉืคื—ืช ื”ืžืจื—ื—ื™ื CoffeMokko:

  • mage.js - ืงื•ื‘ืฅ ื”ืžื›ื™ืœ ืงื•ื“ ืจื—ื™ืคื” ืžืงื‘ื•ืฆื” 1 ืขื ื›ืชื•ื‘ืช ืฉืขืจ js-cdn.link
  • mag.php - ืกืงืจื™ืคื˜ PHP ืฉืื—ืจืื™ ืœืื™ืกื•ืฃ ื ืชื•ื ื™ื ืฉื ื’ื ื‘ื• ืขืœ ื™ื“ื™ ื”ืžืจื—ืจื—

ืชื•ื›ืŸ ื”ืงื•ื‘ืฅ mage.js ืืจื‘ืขื” ืกื ื™ืคืจื™ื ืฉืœ JavaScript ืฉืžื—ื›ื™ื ืœื›ื ื‘ื—ื ื•ื™ื•ืช ืžืงื•ื•ื ื•ืช
ื›ืžื• ื›ืŸ, ื ืงื‘ืข ื›ื™ ื”ื“ื•ืžื™ื™ื ื™ื ื”ืžื•ืงื“ืžื™ื ื‘ื™ื•ืชืจ ืฉืฉื™ืžืฉื• ืืช ื”ืงื‘ื•ืฆื” ืžืื—ื•ืจื™ ืžืฉืคื—ืช ื”ืžืจื—ื—ื™ื CoffeMokko ื ืจืฉืžื• ื‘-17 ื‘ืžืื™ 2017:

  • link-js[.]ืงื™ืฉื•ืจ
  • info-js[.]ืงื™ืฉื•ืจ
  • track-js[.]ืงื™ืฉื•ืจ
  • map-js[.]ืงื™ืฉื•ืจ
  • smart-js[.]ืงื™ืฉื•ืจ

ื”ืคื•ืจืžื˜ ืฉืœ ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ื”ืœืœื• ืชื•ืื ืืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ื ื™ื ืฉืœ ืงื‘ื•ืฆื” 1 ืฉื”ื™ื• ื‘ืฉื™ืžื•ืฉ ื‘ื”ืชืงืคื•ืช 2016.

ืขืœ ืกืžืš ื”ืขื•ื‘ื“ื•ืช ืฉื”ืชื’ืœื•, ื ื™ืชืŸ ืœืฉืขืจ ื›ื™ ืงื™ื™ื ืงืฉืจ ื‘ื™ืŸ ืžืคืขื™ืœื™ ื”ืจื—ืคื ื™ื ืฉืœ CoffeMokko ืœื‘ื™ืŸ ืงื‘ื•ืฆืช ื”ืคืฉืข ืงื‘ื•ืฆื” 1. ื™ืฉ ืœื”ื ื™ื— ืฉืžืคืขื™ืœื™ CoffeMokko ื™ื›ืœื• ืœืฉืื•ืœ ื›ืœื™ื ื•ืชื•ื›ื ื•ืช ืžืงื•ื“ืžื™ื”ื ื›ื“ื™ ืœื’ื ื•ื‘ ื›ืจื˜ื™ืกื™ื. ืขื ื–ืืช, ืกื‘ื™ืจ ื™ื•ืชืจ ืฉื”ืงื‘ื•ืฆื” ื”ืคื•ืฉืขืช ืฉืขื•ืžื“ืช ืžืื—ื•ืจื™ ื”ืฉื™ืžื•ืฉ ื‘ืžืฉืคื—ืช ื”ืžืจื—ืจื—ื™ื CoffeMokko ื”ื ืื•ืชื ืื ืฉื™ื ืฉื‘ื™ืฆืขื• ืืช ืคื™ื’ื•ืขื™ ืงื‘ื•ืฆื” 1. ืœืื—ืจ ืคืจืกื•ื ื”ื“ื•"ื— ื”ืจืืฉื•ืŸ ืขืœ ืคืขื™ืœื•ืช ื”ืงื‘ื•ืฆื” ื”ืคืœื™ืœื™ืช, ื›ืœ ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ืฉืœื”ื ื”ื™ื• ื ื—ืกื ื•ื”ื›ืœื™ื ื ืœืžื“ื• ื‘ืคื™ืจื•ื˜ ื•ืชื•ืืจื•. ื”ืงื‘ื•ืฆื” ื ืืœืฆื” ืœืงื—ืช ื”ืคืกืงื”, ืœืฉื›ืœืœ ืืช ื”ื›ืœื™ื ื”ืคื ื™ืžื™ื™ื ืฉืœื” ื•ืœืฉื›ืชื‘ ืืช ืงื•ื“ ื”ืกื ื™ืคืจ ืขืœ ืžื ืช ืœื”ืžืฉื™ืš ื‘ื”ืชืงืคื•ืชื™ื” ื•ืœื”ื™ืฉืืจ ื‘ืœืชื™ ืžื–ื•ื”ื”.

ืชืฉืชื™ืช

ะ”ะพะผะตะฝ ืชืืจื™ืš ื’ื™ืœื•ื™/ื”ื•ืคืขื”
link-js.link 17.05.2017
info-js.link 17.05.2017
track-js.link 17.05.2017
map-js.link 17.05.2017
smart-js.link 17.05.2017
adorebeauty.org 03.09.2017
security-payment.su 03.09.2017
braincdn.org 04.09.2017
sagecdn.org 04.09.2017
slickjs.org 04.09.2017
oakandfort.org 10.09.2017
citywlnery.org 15.09.2017
dobell.su 04.10.2017
childrensplayclothing.org 31.10.2017
jewsondirect.com 05.11.2017
shop-rnib.org 15.11.2017
closetlondon.org 16.11.2017
misshaus.org 28.11.2017
battery-force.org 01.12.2017
kik-vape.org 01.12.2017
greatfurnituretradingco.org 02.12.2017
etradesupply.org 04.12.2017
replacemyremote.org 04.12.2017
all-about-sneakers.org 05.12.2017
mage-checkout.org 05.12.2017
nililotan.org 07.12.2017
lamoodbighat.net 08.12.2017
walletgear.org 10.12.2017
dahlie.org 12.12.2017
davidsfootwear.org 20.12.2017
blackriverimaging.org 23.12.2017
exrpesso.org 02.01.2018
parks.su 09.01.2018
pmtonline.su 12.01.2018
otocap.org 15.01.2018
christohperward.org 27.01.2018
coffetea.org 31.01.2018
energycoffe.org 31.01.2018
energytea.org 31.01.2018
teaoffe.net 31.01.2018
adaptivecss.org 01.03.2018
coffemokko.com 01.03.2018
londontea.net 01.03.2018
ukcoffe.com 01.03.2018
labbe.biz 20.03.2018
batterynart.com 03.04.2018
btosports.net 09.04.2018
chicksaddlery.net 16.04.2018
paypaypay.org 11.05.2018
ar500arnor.com 26.05.2018
authorizecdn.com 28.05.2018
slickmin.com 28.05.2018
bannerbuzz.info 03.06.2018
kandypens.net 08.06.2018
mylrendyphone.com 15.06.2018
freshchat.info 01.07.2018
3lift.org 02.07.2018
abtasty.net 02.07.2018
mechat.info 02.07.2018
zoplm.com 02.07.2018
zapaljs.com 02.09.2018
foodandcot.com 15.09.2018
freshdepor.com 15.09.2018
swappastore.com 15.09.2018
verywellfitnesse.com 15.09.2018
elegrina.com 18.11.2018
majsurplus.com 19.11.2018
top5value.com 19.11.2018

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”