{"id":17144,"date":"2019-12-10T10:10:04","date_gmt":"2019-12-10T18:10:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/12\/10\/news-10880\/"},"modified":"2019-12-10T10:10:04","modified_gmt":"2019-12-10T18:10:04","slug":"news-10880","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/12\/10\/news-10880\/","title":{"rendered":"Hundreds of counterfeit online shoe stores injected with credit card skimmer"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Tue, 10 Dec 2019 17:30:50 +0000<\/strong><\/p>\n<p>There&#8217;s a well-worn saying in security: &#8220;If it&#8217;s too good to be true, then it probably isn&#8217;t.&#8221; This can easily be applied to the myriad of online stores that sell counterfeit goods\u2014and now attract secondary fraud in the form of a credit card skimmer.<\/p>\n<p>Allured by great deals on brand names, many people end up buying products on dubious websites only to find out that what they paid for isn&#8217;t what they&#8217;re getting.<\/p>\n<p>We recently identified a credit card skimmer injected into hundreds of fraudulent sites selling brand name shoes. Unfortunate shoppers may not only be disappointed with the faux merchandise, but they will also relinquish their personal and financial data to Magecart fraudsters.<\/p>\n<h3>Counterfeit shoes by the truckload<\/h3>\n<p>Think of the web as a never-ending whack-a-mole war between brands, security teams, and fraudsters\u2014as legitimate companies work with security to take down one counterfeit site, another soon pops up.<\/p>\n<p>One way fraudulent sites receive traffic is via forum spam. Crooks troll sporting and fitness forums and leave messages to entice users to visit the fake store:<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"41516\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/forum_spam\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam.png\" data-orig-size=\"983,456\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"forum_spam\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam-300x139.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam-600x278.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam.png\" alt=\"\" class=\"wp-image-41516\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam.png 983w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam-300x139.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/forum_spam-600x278.png 600w\" sizes=\"(max-width: 983px) 100vw, 983px\" \/><\/figure>\n<p>Here&#8217;s that same counterfeit site selling Adidas, Nike, and other big brand name sneakers:<\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site.png\" data-rel=\"lightbox-0\" title=\"\"><img decoding=\"async\" data-attachment-id=\"41512\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/fake_site\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site.png\" data-orig-size=\"1328,842\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fake_site\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site-300x190.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site-600x380.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site.png\" alt=\"\" class=\"wp-image-41512\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site.png 1328w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site-300x190.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/fake_site-600x380.png 600w\" sizes=\"(max-width: 1328px) 100vw, 1328px\" \/><\/a><\/figure>\n<p><em>trainersnmd[.]com<\/em> is hosted in Russia at <em>91.218.113[.]213<\/em>. Looking at the 91.218.113.0\/24 subnet, we can see many more domains used in the same counterfeit business.<\/p>\n<p>Some of those domains were taken over and replaced with a serving notice. For example in May 2019, Adidas filed a <a rel=\"noreferrer noopener\" aria-label=\"complaint (opens in a new tab)\" href=\"http:\/\/servingnotice.com\/Ds24g2e\/index.html\" target=\"_blank\">complaint<\/a> for injunctive relief and damages against hundreds of fake Adidas stores.<\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint.png\" data-rel=\"lightbox-1\" title=\"\"><img decoding=\"async\" data-attachment-id=\"41513\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/complaint-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint.png\" data-orig-size=\"887,818\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"complaint\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint-300x277.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint-600x553.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint.png\" alt=\"\" class=\"wp-image-41513\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint.png 887w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint-300x277.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/complaint-600x553.png 600w\" sizes=\"(max-width: 887px) 100vw, 887px\" \/><\/a><\/figure>\n<h3>Mass credit card skimmer injection<\/h3>\n<p>The skimming code was appended to a JavaScript file called <em>translate.js<\/em>. (A full copy of the deobfuscated skimmer can be found <a rel=\"noreferrer noopener\" href=\"https:\/\/pastebin.com\/EVs1kZS3\" target=\"_blank\">here<\/a>.)<\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas.png\" data-rel=\"lightbox-2\" title=\"\"><img decoding=\"async\" data-attachment-id=\"41514\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/skimmer_adidas\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas.png\" data-orig-size=\"797,843\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"skimmer_adidas\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas-284x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas-567x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas.png\" alt=\"\" class=\"wp-image-41514\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas.png 797w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas-284x300.png 284w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skimmer_adidas-567x600.png 567w\" sizes=\"(max-width: 797px) 100vw, 797px\" \/><\/a><\/figure>\n<p>Stolen data, including billing addresses and credit card numbers, is exfiltrated to a server in China at 103.139.113[.]34.<\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_.png\" data-rel=\"lightbox-3\" title=\"\"><img decoding=\"async\" data-attachment-id=\"41519\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/skim_\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_.png\" data-orig-size=\"782,320\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"skim_\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_-300x123.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_-600x246.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_.png\" alt=\"\" class=\"wp-image-41519\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_.png 782w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_-300x123.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/skim_-600x246.png 600w\" sizes=\"(max-width: 782px) 100vw, 782px\" \/><\/a><\/figure>\n<p>What&#8217;s interesting is that this is actually a massive compromise across several IP subnets:<\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list.png\" data-rel=\"lightbox-4\" title=\"\"><img decoding=\"async\" data-attachment-id=\"41515\" data-permalink=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/attachment\/partial_list\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list.png\" data-orig-size=\"600,1427\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"partial_list\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list-126x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list-252x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list.png\" alt=\"\" class=\"wp-image-41515\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list-126x300.png 126w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/partial_list-252x600.png 252w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><\/figure>\n<p>A cursory look at several domains using Sucuri&#8217;s <a rel=\"noreferrer noopener\" aria-label=\"SiteCheck (opens in a new tab)\" href=\"https:\/\/sitecheck.sucuri.net\/results\/https\/www.trainersnmd.com\" target=\"_blank\">SiteCheck<\/a> revealed they are using the same outdated software:<\/p>\n<ul>\n<li><a rel=\"noreferrer noopener\" aria-label=\"Magento under 1.9.4.2 (opens in a new tab)\" href=\"https:\/\/magento.com\/security\/patches\/supee-11155\" target=\"_blank\">Magento under 1.9.4.2<\/a><\/li>\n<li><a href=\"https:\/\/www.php.net\/ChangeLog-5.php#5.6.40\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"PHP under 5.6.40 (opens in a new tab)\">PHP under 5.6.40<\/a><\/li>\n<\/ul>\n<p>It&#8217;s likely a malicious scanner simply crawled those IP ranges and used the same vulnerability to compromise each and every one of those counterfeit sites.<\/p>\n<h3>Online shopping and its risks <\/h3>\n<p>Shopping online these days is akin to walking into a minefield, yet many people aren&#8217;t aware of the dangers lurking behind every corner.<\/p>\n<p>Based on our crawlers, we see new e-commerce sites fall victim to web skimmers every day. Looking at our telemetry, we can also correlate the number of web blocks to shopping patterns, such as Black Friday and Cyber Monday events.<\/p>\n<figure class=\"wp-block-embed-twitter wp-block-embed is-type-rich is-provider-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We saw an increase in credit card skimming activity for Black Friday and Cyber Monday, but not as much as anticipated.<\/p>\n<p>Many online stores were running deals for some time prior, even since late Oct.<a href=\"https:\/\/twitter.com\/hashtag\/Magecart?src=hash&amp;ref_src=twsrc%5Etfw\">#Magecart<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/skimming?src=hash&amp;ref_src=twsrc%5Etfw\">#skimming<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/BlackFriday?src=hash&amp;ref_src=twsrc%5Etfw\">#BlackFriday<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/CyberMonday?src=hash&amp;ref_src=twsrc%5Etfw\">#CyberMonday<\/a> <a href=\"https:\/\/t.co\/0DEMFXwjPa\">pic.twitter.com\/0DEMFXwjPa<\/a><\/p>\n<p>&mdash; MB Threat Intel (@MBThreatIntel) <a href=\"https:\/\/twitter.com\/MBThreatIntel\/status\/1201987039035412480?ref_src=twsrc%5Etfw\">December 3, 2019<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/div>\n<\/figure>\n<p style=\"text-align:left\">As we saw in this post, counterfeit sites pose a double threat, not only from obtaining illicit goods but also getting robbed of data by a different group of criminals.<\/p>\n<p>While we cannot completely eliminate the threat of digital skimmers, here are some tips on how to reduce the risks associated with online shopping:<\/p>\n<ul>\n<li>Make sure that your computer is malware-free and running the latest patches. Leverage a security product that offers web protection. Malwarebytes&#8217; flagship <a rel=\"noreferrer noopener\" aria-label=\"anti-malware product (opens in a new tab)\" href=\"https:\/\/www.malwarebytes.com\/\" target=\"_blank\">anti-malware product<\/a>, as well as its newly introduced (and free) <a rel=\"noreferrer noopener\" aria-label=\"Browser Guard (opens in a new tab)\" href=\"https:\/\/www.malwarebytes.com\/browserguard\/\" target=\"_blank\">Browser Guard<\/a> extension for Chrome and Firefox can thwart Magecart-related skimmers by blocking malicious scripts and websites from loading, as well as exfiltrating, data.<\/li>\n<li> If you are shopping on a site for the first time, check that it looks maintained. While this does not replace a thorough security scan, seeing notes such as &#8220;Copyright 2015&#8221; may indicate that the website is not really being looked after.<\/li>\n<li> Minimize how often you enter your credit card data by relying on other payment methods instead. For example, large reliable online retailers, such as Amazon already have your payment details archived into your account. Other safe methods include Apply Pay or prepaid Visa or Mastercards.<\/li>\n<li> Check your bank\/credit card statements regularly to identify potentially fraudulent charges.<\/li>\n<li> Help prevent further attacks by reporting any fraudulent activity (especially if you were victim) to law enforcement authorities.<\/li>\n<\/ul>\n<h3>Indicators of Compromise (IOCs)<\/h3>\n<p><strong>Counterfeit sites injected with skimmer<\/strong><\/p>\n<div class=\"wp-block-columns has-3-columns\">\n<div class=\"wp-block-column\">\n<p style=\"text-align:left\" class=\"has-small-font-size\">180workshoe[.]com<br \/>1freshfoot[.]com<br \/>2018nmd4u[.]com<br \/>234learnshoe[.]com<br \/>270takeshoe[.]com<br \/>365daysshoe[.]com<br \/>5923shoe[.]com<br \/>97saleweekly[.]com<br \/>987lateshoe[.]com<br \/>adsmithfwt[.]com<br \/>acheterftwr[.]com<br \/>addrubber[.]com<br \/>airmaxweekly[.]com<br \/>allsizeshoe[.]com<br \/>adnkclub[.]com<br \/>ashshoeslink[.]com<br \/>apparentshoe[.]com<br \/>auflaufschuh[.]com<br \/>utgumnshoes[.]com<br \/>awsnkrs[.]com<br \/>bajasprecio[.]com<br \/>basketouve[.]com<br \/>bestkixify[.]com<br \/>beastsole[.]com<br \/>best7now[.]com<br \/>bestshoesbf[.]com<br \/>blanchenmd[.]com<br \/>blazersoldes[.]com<br \/>boostrunner[.]com<br \/>boutiquesnks[.]com<br \/>brandingsit[.]com<br \/>breakerun[.]com<br \/>cageforlock[.]com<br \/>cestboncony[.]com<br \/>caretosole[.]com<br \/>champrun95[.]com<br \/>chaussureplace[.]com<br \/>cisalfaports[.]com<br \/>chamdot[.]com<br \/>chaussureprofile[.]com<br \/>colourmvp[.]com<br \/>compraestilos[.]com<br \/>closerpremium[.]com<br \/>closerselect[.]com<br \/>continuefeet[.]com<br \/>comfyftwr[.]com<br \/>cusmakeit[.]com<br \/>couleurmvp[.]com<br \/>courtadv[.]com<br \/>damesbedoor[.]com<br \/>ddtows[.]com<br \/>deeruptshoe[.]com<br \/>descubra19[.]com<br \/>docvab[.]com<br \/>donnescontate[.]com<br \/>dividesneakers[.]com<br \/>donectory[.]com<br \/>dryyourfoot[.]com<br \/>easeweekly[.]com<br \/>easyfootrun[.]com<br \/>energeticshoe[.]com<br \/>elementsthat[.]com<br \/>entryonlike[.]com<br \/>eternalapt[.]com<br \/>evidentshoe[.]com<br \/>febdate[.]com<br \/>farbasefull[.]com<br \/>farbenrun[.]com<br \/>farvefit[.]com<br \/>fleunderride[.]com<br \/>fewusedit[.]com<br \/>footbester[.]com<br \/>footrunclub[.]com<br \/>footsweek[.]com<br \/>footstijl[.]com<br \/>footstil[.]com<br \/>footstylish[.]com<br \/>foreasyon[.]com<br \/>for1sell[.]com<br \/>freernshoe[.]com<br \/>futureitblue[.]com<br \/>futureoiwill[.]com<br \/>futurenishoes[.]com<br \/>futureyouto[.]com<br \/>gelbneu[.]com<br \/>geschenkein[.]com<br \/>getgshoes[.]com<br \/>getbetternl[.]com<br \/>goldsoldes[.]com<br \/>grauwearim[.]com<br \/>grijsentop[.]com<br \/>goingtopurchase[.]com<br \/>grigiotopsu[.]com<br \/>greyheel[.]com<br \/>gsnkrs[.]com<br \/>guldafdk[.]com<br \/>headrebajas[.]com<br \/>hererunner[.]com<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column\">\n<p style=\"text-align:left\" class=\"has-small-font-size\">hjrshoe[.]com<br \/>inikirun[.]us<br \/>iweardam[.]com<br \/>jtsportsde[.]com<br \/>justshopclub[.]com<br \/>kaiisko[.]com<br \/>kaufenftwr[.]com<br \/>kaischuhe[.]com<br \/>kickfrstore[.]com<br \/>kickscrewstore[.]com<br \/>kickstienda[.]com<br \/>kickvapor[.]com<br \/>kickswinkel[.]com<br \/>kixifyshop[.]com<br \/>kixifyrun[.]com<br \/>kixifystore[.]com<br \/>kleurmvp[.]com<br \/>kleurschuhe[.]com<br \/>laufschuhebeste[.]com<br \/>linrubsole[.]com<br \/>lobeskoruns[.]com<br \/>lony19[.]com<br \/>lowesthalf[.]com<br \/>luckyisport[.]com<br \/>maxformob[.]com<br \/>manifestshoe[.]com<br \/>maximummost[.]com<br \/>metyshoes[.]com<br \/>mjftoods[.]com<br \/>mindedshoe[.]com<br \/>monitornon[.]com<br \/>msnkrs[.]com<br \/>nairschoenen[.]com<br \/>nairchaussure[.]com<br \/>nairscarpe[.]com<br \/>nairschuhe[.]com<br \/>nettstil[.]com<br \/>netwhilesale[.]com<br \/>newseftwr[.]com<br \/>newfeetreal[.]com<br \/>newmaxreal[.]com<br \/>newshoesreal[.]com<br \/>newstylereal[.]com<br \/>newwholereal[.]com<br \/>nicestijl[.]com<br \/>nicestil[.]com<br \/>nieuwekaufe[.]com<br \/>nicestilebay[.]com<br \/>nicestylebay[.]com<br \/>niceventefr[.]com<br \/>nmdforfemme[.]com<br \/>nmdrosare[.]com<br \/>nieuwekaufen[.]com<br \/>nmd5club[.]com<br \/>nmdnoir[.]com<br \/>nmdpksneaker4u[.]com<br \/>nmdoriginals[.]com<br \/>nmdreplace4u[.]com<br \/>nmdtrainers[.]com<br \/>noticeableshoes[.]com<br \/>noteystore[.]com<br \/>nuevorunning[.]com<br \/>nrdunkzpa[.]com<br \/>nrunnersale[.]com<br \/>nouveauhaven[.]com<br \/>nuevoshoe[.]com<br \/>nuovehaven[.]com<br \/>obviousshoe[.]com<br \/>offwschuhe[.]com<br \/>oplev19[.]com<br \/>oroshoesit[.]com<br \/>ordinarytrend[.]com<br \/>oroboostpas[.]com<br \/>outlet3prix[.]com<br \/>outletsfire[.]com<br \/>particleprovide[.]com<br \/>paschernoir[.]com<br \/>perpetuallook[.]com<br \/>pearlshoeslink[.]com<br \/>perpetualfree[.]com<br \/>phlshoe[.]com<br \/>pickonsneakers[.]com<br \/>pinkshoeslink[.]com<br \/>ponashoes[.]com<br \/>porsneakers[.]com<br \/>premiumnuevo[.]com<br \/>poshseeking[.]com<br \/>profilesshoe[.]com<br \/>prophereshoe[.]com<br \/>psbeautytre[.]com<br \/>racersho[.]com<br \/>runnerfr[.]com<br \/>ozemetoen[.]com<br \/>rosakopen[.]com<br \/>run4kick[.]com<br \/>rubberplat[.]com<br \/>runnerdry[.]com<br \/>runstormon[.]com<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column\">\n<p class=\"has-small-font-size\">saledksko[.]com<br \/>saldifire[.]com<br \/>sarezalando[.]com<br \/>scarpekingdom[.]com<br \/>scarpe-new[.]com<br \/>scarpastate[.]com<br \/>schoenenbeste[.]com<br \/>schoenenprofile[.]com<br \/>schuherunlau[.]com<br \/>schuhesize[.]com<br \/>schuhneu[.]com<br \/>schuheplace[.]com<br \/>schuheprofile[.]com<br \/>scopri19[.]com<br \/>showam97[.]com<br \/>shoehallrun[.]com<br \/>sizehaven[.]com<br \/>showschuh[.]com<br \/>skorunvit[.]com<br \/>sjjshoe[.]com<br \/>skoprofile[.]com<br \/>skonmd[.]com<br \/>snadnket[.]com<br \/>sneakerbyside[.]com<br \/>sneakerebe[.]com<br \/>sneakerees[.]com<br \/>sneakermodelli[.]com<br \/>sneakerunow[.]com<br \/>snkrsstrike[.]com<br \/>snugfree[.]com<br \/>snstuff[.]us<br \/>sortheads[.]com<br \/>sort5sko[.]com<br \/>sportkopen[.]com<br \/>sportinghave[.]com<br \/>sportopwears[.]com<br \/>sports-be[.]com<br \/>sportsalebay[.]com<br \/>sportsneu[.]com<br \/>sportsonfr[.]com<br \/>sports-ha[.]com<br \/>stayonlinese[.]com<br \/>sprishoes[.]com<br \/>startingnice[.]com<br \/>streetcolouring[.]com<br \/>stripeschuhe[.]com<br \/>stuffnuevo[.]com<br \/>stuffkicks[.]com<br \/>stuffkopen[.]com<br \/>stuffoutfr[.]com<br \/>stuffpknit[.]com<br \/>styleftwr[.]com<br \/>stvprxsko[.]com<br \/>styleschoen[.]com<br \/>styleschuh[.]com<br \/>stylezapato[.]com<br \/>suitableshoe[.]com<br \/>swzoomsch[.]com<br \/>texmedever[.]com<br \/>tehshoes[.]com<br \/>takerightback[.]com<br \/>tedschuhe[.]com<br \/>thegodwillout[.]com<br \/>thxshoe[.]com<br \/>tiendaout[.]com<br \/>tosomtosideaway[.]com<br \/>trainernmdcbk[.]com<br \/>trainersnmd[.]com<br \/>tstripeseqt[.]com<br \/>uomoweekly[.]com<br \/>usesmoother[.]com<br \/>usualshares[.]com<br \/>valuablemax[.]com<br \/>vertchausfr[.]com<br \/>verstaleshoes[.]com<br \/>vtfreencs[.]com<br \/>vvvfabrices[.]com<br \/>walkingnice[.]com<br \/>wearingselect[.]com<br \/>willgoout[.]com<br \/>willrunalong[.]com<br \/>willrunout[.]com<br \/>willhiking[.]com<br \/>winatershoes[.]com<br \/>wmboost[.]com<br \/>withnormal[.]com<br \/>willtrval[.]com<br \/>witroze[.]com<br \/>wmsnkrs[.]com<br \/>wsnkrs[.]com<br \/>zapatosnmd[.]com<br \/>zwtnlzsen[.]com<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p><strong>Skimmer<\/strong><\/p>\n<p>103.139.113[.]34<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/\">Hundreds of counterfeit online shoe stores injected with credit card skimmer<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Tue, 10 Dec 2019 17:30:50 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/' title='Hundreds of counterfeit online shoe stores injected with credit card skimmer'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/shutterstock_502444030.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A Magecart credit card skimmer was found injected into hundreds of counterfeit, brand-name shoe stores\u2014a one-two punch of victimization for users first duped with fake goods then stripped of their personal data.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/\" rel=\"category tag\">Threat analysis<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/counterfeit\/\" rel=\"tag\">counterfeit<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/credit-card\/\" rel=\"tag\">credit card<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fraud\/\" rel=\"tag\">fraud<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/magecart\/\" rel=\"tag\">Magecart<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/shoes\/\" rel=\"tag\">shoes<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/skimmers\/\" rel=\"tag\">skimmers<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/' title='Hundreds of counterfeit online shoe stores injected with credit card skimmer'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2019\/12\/hundreds-of-counterfeit-online-shoe-stores-injected-with-credit-card-skimmer\/\">Hundreds of counterfeit online shoe stores injected with credit card skimmer<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[23677,14702,9751,19622,5344,22327,10494],"class_list":["post-17144","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-counterfeit","tag-credit-card","tag-fraud","tag-magecart","tag-shoes","tag-skimmers","tag-threat-analysis"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17144","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17144"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17144\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17144"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}