Malware Attack Exploiting Bing Search
by xzin0vich - Wednesday August 21, 2024 at 05:35 PM
#1
Multi-stage Malware attack exploiting the Bing search engine was found!
Recently, a new attack method exploiting Bing search results, which are typically easy to click on, has been identified.

A recent article reveal a new malware attack exploiting the Bing search engine. This multi-stage malware attack involves distributing malicious files, executing installers, connecting to C2 domains, and downloading and inserting backdoors to carry out attacks such as remote control, data theft, and the delivery of additional payloads.

When searching for “w2 form 2024″—a commonly used keyword for U.S. federal tax forms—the first search result on Bing is a domain titled “Online Website 2024 | Home | W2-Form 2024” from appointopia[.]com. However, clicking on this site redirects users to a fake IRS website (hxxps://grupotefex[.]com/forms-pubs/about-form-w-2/). When users click on this site, they are prompted to solve a CAPTCHA, after which a malicious JavaScript file (Form_Ver-.js) hosted on Google Firebase storage is downloaded.

Upon analyzing the downloaded “Form_ver-14-00-21.js” file, it was found that the malicious code was concealed within seemingly harmless comments. This attack structure is advantageous for hiding malicious payloads, increasing file size to complicate analysis, and evading antivirus detection.

Analysis of “Form_ver-14-00-21.js” revealed that the script was designed to download and execute an MSI package from specific URLs. The script downloaded an MSI file named “BST.msi” from IP address 85[.]208[.]108[.]63. Another script downloaded a similar MSI file, “neuro.msi,” from a similar IP address, 85[.]208[.]108[.]30, suggesting that the same malicious code payload was used.
Reply
#2
Serves them right for using fucking Bing, better Yanadex
Reply
#3
https://www.digitaltrends.com/computing/...eal-files/

https://www.swarmnetics.com/blog/bing-se...easy-hack/
Reply
#4
Bing is worse than ddgo
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Ransomware attack cost IKEA operator in Eastern Europe $23 million lulagain 0 287 04-12-2025, 01:18 PM
Last Post: lulagain
  Police detains Smokeloader malware customers, seizes servers lulagain 0 299 04-09-2025, 10:20 PM
Last Post: lulagain
  People responsible for the X / Twitter DDoS Attack 302 12 878 04-06-2025, 12:42 AM
Last Post: RobertChen
  Chinese hacker "Crazyhunter" behind ransomware attack on MacKay Hospital, others: CIB DissentDoe 1 447 04-05-2025, 03:53 PM
Last Post: f4b52
  Dozens of solar inverter flaws could be exploited to attack power grids lulagain 1 238 03-28-2025, 10:55 PM
Last Post: edenyardenxx

Forum Jump:


 Users browsing this thread: 1 Guest(s)