Digital skimmer runs entirely on Google, defeats CSP – Sansec
Tags
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 |
Common Information
Type | Value |
---|---|
UUID | 88691418-b5d4-48a8-a7d0-33eb614b5cc5 |
Fingerprint | 8c43ba933a6d332a |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 22, 2020, midnight |
Added to db | Nov. 6, 2023, 6:33 p.m. |
Last updated | Nov. 17, 2024, 6:30 p.m. |
Headline | Digital skimmer runs entirely on Google, defeats CSP |
Title | Digital skimmer runs entirely on Google, defeats CSP – Sansec |
Detected Hints/Tags/Attributes | 34/1/28 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Redirection | http://sansec.io/research/skimming-google-defeats-csp |
Details | Source | https://sansec.io/research/skimming-google-defeats-csp |
Details | Redirection | https://sansec.io/research/skimming-google-defeats-csp/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 221 | ✔ | Sansec - experts in eCommerce security | https://sansec.io/atom.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 14 | firebasestorage.googleapis.com |
|
Details | Domain | 129 | api.ipify.org |
|
Details | Domain | 4 | window.firebug.chrome |
|
Details | Domain | 1 | a0.style |
|
Details | Domain | 1 | a0.style.top |
|
Details | Domain | 1 | a0.id |
|
Details | Domain | 1 | a0.name |
|
Details | Domain | 1 | a0.contentwindow.document.open |
|
Details | Domain | 1 | a0.open |
|
Details | Domain | 1 | a3.name |
|
Details | Domain | 1 | payload.host |
|
Details | Domain | 4 | window.location.host |
|
Details | Domain | 1 | a2.target |
|
Details | Domain | 41 | www.google-analytics.com |
|
Details | File | 364 | console.log |
|
Details | File | 1 | r.iso |
|
Details | File | 1 | a2.iso |
|
Details | File | 2 | s.iso |
|
Details | File | 18 | analytics.js |
|
Details | File | 8 | contentwindow.doc |
|
Details | File | 1 | a2.inc |
|
Details | File | 4 | payload.dat |
|
Details | File | 1 | p.inc |
|
Details | File | 1 | a2.tar |
|
Details | sha1 | 1 | c879f68417529b0c3851a7e336089fcb2c116b8d |
|
Details | Url | 4 | https://api.ipify.org?format=json |
|
Details | Url | 1 | https://www.google-analytics.com/analytics.js\',a.parentnode.insertbefore |
|
Details | Url | 4 | https://www.google-analytics.com/analytics.js |