📜 ⬆️ ⬇️

The portal Opera redirected users to a malicious resource

image

According to Bitdefender, the Opera browser portal website (portal.opera.com) for several hours redirected users to a page with a set of Blackhole exploits.
One of the functions of BlackHole, which is most appreciated by cybercriminals, is a sophisticated traffic direction script (TDS) that supports very complex actions.
A complex malicious script was run on the portal's website, which placed on the main page an iframe element with the contents of a remote resource. Most likely, the script was uploaded using advertising posted on the portal.
According to researchers, “This malicious page contains a set of BlackHole exploits (we got an example with a PDF file that exploits the CVE-2010-0188 vulnerability), which hits an unsuccessful user with a freshly compiled ZBot”
Bitdefender employees also noted that the ZBot was downloaded from a server located in Russia, which most likely was also hacked.
Users visiting this site are advised to check their system for malware.

A detailed report can be found hack

')

Source: https://habr.com/ru/post/158999/


All Articles