29 August 2016

Malware website example

I was browsing a news website on my phone and came across these screenshots.

The URL that Chrome loaded was this, which is sneaky. Repeat visits to this URL do not change the page being returned. Obviously it is Base64 so the decoded form is below.

It decodes into HTML of which contains the bad URL in the iframe tag below:

Some tips for reporting badware, malware, phishing sites, and sending email submissions.
Remember suspicious emails and attachments should be sent as a saved message, not forwarded as it will lose the originator's details.