<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>winwin[.]co - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/winwin-co/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Tue, 19 Sep 2023 20:27:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>winwin[.]co - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>efile.com compromised by threat actor to embed malicious files</title>
		<link>https://www.osintafrica.net/efile-com-compromised-by-threat-actor-to-embed-malicious-files/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=efile-com-compromised-by-threat-actor-to-embed-malicious-files</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Wed, 05 Apr 2023 22:59:17 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[efile.com]]></category>
		<category><![CDATA[index.php]]></category>
		<category><![CDATA[popper.js]]></category>
		<category><![CDATA[winwin[.]co]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=628</guid>

					<description><![CDATA[<p>The efile[.]com a team of tax professionals and tax software vendors that provide an online...</p>
<p>The post <a href="https://www.osintafrica.net/efile-com-compromised-by-threat-actor-to-embed-malicious-files/">efile.com compromised by threat actor to embed malicious files</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">The efile[.]com a team of tax professionals and tax software vendors that provide an online platform to efile federal income taxes and state taxes online website has been compromised. The website is redirecting to a malicious domain  that is used to download a malicious payload on a victim machine.</span></p>
<p><span style="color: #000000;"><strong>Details:</strong></span></p>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">Some malicious files were embedded in the efile.com website redirecting to a maldomain with a malicious payload attach to it used to compromised the victim system.</span></p>
<p><span style="color: #000000;">The threat actors used different types of files and attachments to achieve their goal. </span></p>
<ol>
<li><span style="color: #000000;">propper.js</span></li>
</ol>
<p><span style="color: #000000;">https://urlscan.io/responses/63899f4dc894bdf8323e7ec65d608a640d7915b7eea7dd985dd876da0298a4b6/</span></p>
<p><span style="color: #000000;">The popper.js file contains a base64 encoding</span></p>
<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone size-full wp-image-630" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/eflie1-e1680734288814.png?resize=640%2C103&#038;ssl=1" alt="" width="640" height="103" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/eflie1-e1680734288814.png?w=900&amp;ssl=1 900w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/eflie1-e1680734288814.png?resize=300%2C48&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/eflie1-e1680734288814.png?resize=768%2C124&amp;ssl=1 768w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">popper.js after being decoded</span></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-full wp-image-631" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/index-encoded.png?resize=640%2C376&#038;ssl=1" alt="" width="640" height="376" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/index-encoded.png?w=681&amp;ssl=1 681w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/index-encoded.png?resize=300%2C176&amp;ssl=1 300w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">The output is showing the redirecting domain which is infoamanewonliag[.]online</span></p>
<p><span style="color: #000000;">The URL www.infoamanewonliag[.]online/update/index.php is redirecting the final URL</span></p>
<p><span style="color: #000000;">VirusTotal &#8211; URL &#8211; 85f0f90c55dae3f6e4f50791470491eccebf7529a98f230f33dac32e805291de</span></p>
<p><span style="color: #000000;">Final URL</span></p>
<p><span style="color: #000000;">https://winwin[.]co[.]th/intro/</span></p>
<p><span style="color: #000000;">The final URL contains some malicious exe files that will be used to compromise the victim host machine:</span></p>
<p><span style="color: #000000;">https://urlscan.io/search/#winwin.co.th</span></p>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">https://winwin[.]co[.]th/intro/update.exe</span></p>
<p><span style="color: #000000;">https://www.virustotal.com/gui/url/85f0f90c55dae3f6e4f50791470491eccebf7529a98f230f33dac32e805291de/details</span></p>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">Hash from URLSCAN 882d95bdbca75ab9d13486e477ab76b3978e14d6fca30c11ec368f7e5fa1d0cb</span></p>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">https://www.virustotal.com/gui/file/882d95bdbca75ab9d13486e477ab76b3978e14d6fca30c11ec368f7e5fa1d0cb</span></p>
<ol start="2">
<li style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">index.php and update.js</span></li>
</ol>
<ul>
<li><span style="color: #000000;">The index.php file is redirecting to the URL with the attachment update.js </span></li>
</ul>
<p><span style="color: #000000;">https://urlscan.io/responses/4ffeae430c05f641cb88d2d18131e3f4a3ecdcbc55c159af8998623e5769532a/</span></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-full wp-image-632" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/update-file.png?resize=640%2C251&#038;ssl=1" alt="" width="640" height="251" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/update-file.png?w=689&amp;ssl=1 689w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/update-file.png?resize=300%2C118&amp;ssl=1 300w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<ul>
<li><span style="color: #000000;">The js file contains two URLs with an exe file attached to each and base64 encoding:</span></li>
</ul>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><a href="https://urlscan.io/responses/ca051090a1105e8ea53a04206c8ddcee4b0d33d4566d2f28549fbf0bbdd34bc8/">https://urlscan.io/responses/ca051090a1105e8ea53a04206c8ddcee4b0d33d4566d2f28549fbf0bbdd34bc8/</a></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-full wp-image-633" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/efile-e1680734477793.png?resize=640%2C224&#038;ssl=1" alt="" width="640" height="224" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/efile-e1680734477793.png?w=700&amp;ssl=1 700w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/04/efile-e1680734477793.png?resize=300%2C105&amp;ssl=1 300w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<ul>
<li><span style="color: #000000;">As we mentioned in the “popper.js”,</span></li>
</ul>
<p><span style="color: #000000;">The others URLs with the exe files are redirecting to final URL</span></p>
<p><span style="color: #000000;">https://winwin[.]co[.]th/intro</span>/</p>
<p><span style="color: #000000;">The domain winwin[.]co contains some malicious exe files that will be used to compromise the victim host machine:</span></p>
<p style="font-weight: var(--artdeco-reset-typography-font-weight-normal);"><span style="color: #000000;">At the end, we may conclude that the intention of the threat actor is to compromise the infected system by redirecting the victim to different domains in order to download a malfile.</span></p>
<p><span style="color: #000000;">Once the user is redirected to the winwin[.]co website, the malicious exe will be downloaded and compromised the system.</span></p>
<p><span style="color: #000000;">The malicious files are already detectable by many anti-viruses.</span></p>
<p><span style="color: #000000;">If you were in touch with the efile.com during the last few days and was redirecting to any of the files mentioned above, better scan your laptop by using tool like Malwarebytes or others.</span></p>
<p><span style="color: #000000;">Click on the link</span> (<span style="color: #000000;">VirusTotal &#8211; File &#8211; 882d95bdbca75ab9d13486e477ab76b3978e14d6fca30c11ec368f7e5fa1d0cb</span>) <span style="color: #000000;">for further details about the exe files.</span></p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img loading="lazy" decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/efile-com-compromised-by-threat-actor-to-embed-malicious-files/">efile.com compromised by threat actor to embed malicious files</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">628</post-id>	</item>
	</channel>
</rss>
