Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests.

I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
28 Beiträge 15 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • iampytest1@infosec.exchangeI This user is from outside of this forum
    iampytest1@infosec.exchangeI This user is from outside of this forum
    iampytest1@infosec.exchange
    schrieb zuletzt editiert von
    #1

    I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

    Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

    Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

    Original source:
    https://social.coop/@eb/115902323900229756

    An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

    proton_xor@infosec.exchangeP iampytest1@infosec.exchangeI kitten@social.elizabeth.catK whitequark@social.treehouse.systemsW fasnix@fe.disroot.orgF 11 Antworten Letzte Antwort
    4
    0
    • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

      I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

      Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

      Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

      Original source:
      https://social.coop/@eb/115902323900229756

      An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

      proton_xor@infosec.exchangeP This user is from outside of this forum
      proton_xor@infosec.exchangeP This user is from outside of this forum
      proton_xor@infosec.exchange
      schrieb zuletzt editiert von
      #2

      @iampytest1 @Murmel

      Hey Benjamin! Das scheint eine heiße Geschichte zu sein...

      Die bekannte Archivierungs-Plattform archive.today scheint schädlichen Code eingebettet zu haben...

      Weitere Quellen / Infos:

      https://social.coop/@eb/115902323900229756

      https://news.ycombinator.com/item?id=46624740

      murmel@norden.socialM 1 Antwort Letzte Antwort
      0
      • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

        I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

        Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

        Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

        Original source:
        https://social.coop/@eb/115902323900229756

        An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

        iampytest1@infosec.exchangeI This user is from outside of this forum
        iampytest1@infosec.exchangeI This user is from outside of this forum
        iampytest1@infosec.exchange
        schrieb zuletzt editiert von
        #3

        I have posted about this on BlueSky and X.

        https://bsky.app/profile/did:plc:ysz3jltsuhnyrqrskrcbcz2s/post/3mcj75vyiec2u

        https://x.com/iam_py_test/status/2012010781622353950

        I have also blocklisted it in Imre's malware list.

        Despite times call for despite measures. It isn't often a popular website starts DDoSing somebody.

        I have also informed members of the content filtering community though a red phone on my desk.

        1 Antwort Letzte Antwort
        0
        • proton_xor@infosec.exchangeP proton_xor@infosec.exchange

          @iampytest1 @Murmel

          Hey Benjamin! Das scheint eine heiße Geschichte zu sein...

          Die bekannte Archivierungs-Plattform archive.today scheint schädlichen Code eingebettet zu haben...

          Weitere Quellen / Infos:

          https://social.coop/@eb/115902323900229756

          https://news.ycombinator.com/item?id=46624740

          murmel@norden.socialM This user is from outside of this forum
          murmel@norden.socialM This user is from outside of this forum
          murmel@norden.social
          schrieb zuletzt editiert von
          #4

          @proton_xor @iampytest1 _/(0_0)7 Roger, guck ich mir an 😘

          proton_xor@infosec.exchangeP 1 Antwort Letzte Antwort
          0
          • murmel@norden.socialM murmel@norden.social

            @proton_xor @iampytest1 _/(0_0)7 Roger, guck ich mir an 😘

            proton_xor@infosec.exchangeP This user is from outside of this forum
            proton_xor@infosec.exchangeP This user is from outside of this forum
            proton_xor@infosec.exchange
            schrieb zuletzt editiert von
            #5

            @Murmel @iampytest1 ja moin, auch schon so früh wach 😄

            murmel@norden.socialM 1 Antwort Letzte Antwort
            0
            • proton_xor@infosec.exchangeP proton_xor@infosec.exchange

              @Murmel @iampytest1 ja moin, auch schon so früh wach 😄

              murmel@norden.socialM This user is from outside of this forum
              murmel@norden.socialM This user is from outside of this forum
              murmel@norden.social
              schrieb zuletzt editiert von
              #6

              @proton_xor @iampytest1 Jau, Wecker geht um 4:45 ^^ Dafür heute auch noch verpennt ¯\_(ツ)_/¯

              1 Antwort Letzte Antwort
              0
              • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                Original source:
                https://social.coop/@eb/115902323900229756

                An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                kitten@social.elizabeth.catK This user is from outside of this forum
                kitten@social.elizabeth.catK This user is from outside of this forum
                kitten@social.elizabeth.cat
                schrieb zuletzt editiert von
                #7
                @iampytest1 what's the Malicious Website Blocklist?
                iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                0
                • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                  I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                  Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                  Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                  Original source:
                  https://social.coop/@eb/115902323900229756

                  An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                  whitequark@social.treehouse.systemsW This user is from outside of this forum
                  whitequark@social.treehouse.systemsW This user is from outside of this forum
                  whitequark@social.treehouse.systems
                  schrieb zuletzt editiert von
                  #8

                  @iampytest1 honestly a pretty reasonable response to a doxing attempt

                  ivandsm@mastodon.socialI privateger@plasmatrap.comP 2 Antworten Letzte Antwort
                  0
                  • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                    I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                    Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                    Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                    Original source:
                    https://social.coop/@eb/115902323900229756

                    An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                    fasnix@fe.disroot.orgF This user is from outside of this forum
                    fasnix@fe.disroot.orgF This user is from outside of this forum
                    fasnix@fe.disroot.org
                    schrieb zuletzt editiert von
                    #9
                    Oha, Vorsicht alle, die hierüber paywalled Links "ins Netz befreien"!

                    #Schadcode

                    RE: https://infosec.exchange/@iampytest1/115902693235671566
                    1 Antwort Letzte Antwort
                    0
                    • svenja@mstdn.gamesS svenja@mstdn.games shared this topic
                      wiase@ibe.socialW wiase@ibe.social shared this topic
                    • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                      I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                      Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                      Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                      Original source:
                      https://social.coop/@eb/115902323900229756

                      An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                      creaturr@app.wafrn.netC This user is from outside of this forum
                      creaturr@app.wafrn.netC This user is from outside of this forum
                      creaturr@app.wafrn.net
                      schrieb zuletzt editiert von
                      #10

                      Other domains of archive.today i've found:

                      • archive.fo
                      • archive.li
                      1 Antwort Letzte Antwort
                      0
                      • whitequark@social.treehouse.systemsW whitequark@social.treehouse.systems

                        @iampytest1 honestly a pretty reasonable response to a doxing attempt

                        ivandsm@mastodon.socialI This user is from outside of this forum
                        ivandsm@mastodon.socialI This user is from outside of this forum
                        ivandsm@mastodon.social
                        schrieb zuletzt editiert von
                        #11

                        @whitequark @iampytest1 Just read that blog post and yeah, what on earth? Why would they just dox the owner like that?!

                        1 Antwort Letzte Antwort
                        0
                        • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                          I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                          Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                          Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                          Original source:
                          https://social.coop/@eb/115902323900229756

                          An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                          tapafon@soc.ua-fediland.deT This user is from outside of this forum
                          tapafon@soc.ua-fediland.deT This user is from outside of this forum
                          tapafon@soc.ua-fediland.de
                          schrieb zuletzt editiert von
                          #12

                          @iampytest1 Did you report that to Google Safe Browsing?
                          Given the fact it's enabled to default in most browsers, it those sites gets blocked there, they would effectively be blocked Internet-wide (almost same as domain seize).
                          UPD: I reported those domains as well.

                          iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                          0
                          • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                            I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

                            Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

                            Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

                            Original source:
                            https://social.coop/@eb/115902323900229756

                            An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

                            bette@mstdn.socialB This user is from outside of this forum
                            bette@mstdn.socialB This user is from outside of this forum
                            bette@mstdn.social
                            schrieb zuletzt editiert von
                            #13

                            @iampytest1

                            I'm a bit concerned. Last night before I shut down my computer, and this morning when I turned it on, a popup from archive dot today appeared on my screen. I have no idea where it came from, but I didn't open it. Should I be worried or not?? I've used archive dot is many times in the past.

                            iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                            0
                            • bette@mstdn.socialB bette@mstdn.social

                              @iampytest1

                              I'm a bit concerned. Last night before I shut down my computer, and this morning when I turned it on, a popup from archive dot today appeared on my screen. I have no idea where it came from, but I didn't open it. Should I be worried or not?? I've used archive dot is many times in the past.

                              iampytest1@infosec.exchangeI This user is from outside of this forum
                              iampytest1@infosec.exchangeI This user is from outside of this forum
                              iampytest1@infosec.exchange
                              schrieb zuletzt editiert von
                              #14

                              @Bette what kind of popup?

                              The malicious code on archive[.]today runs within your browser; it doesn't infect your computer with malware.

                              bette@mstdn.socialB 1 Antwort Letzte Antwort
                              0
                              • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                                @Bette what kind of popup?

                                The malicious code on archive[.]today runs within your browser; it doesn't infect your computer with malware.

                                bette@mstdn.socialB This user is from outside of this forum
                                bette@mstdn.socialB This user is from outside of this forum
                                bette@mstdn.social
                                schrieb zuletzt editiert von
                                #15

                                @iampytest1

                                It's not like a regular pop up. It goes from the top of the screen to the bottom and is centered on the screen and at least five inches wide. It encourages me to visit archive today.

                                iampytest1@infosec.exchangeI 1 Antwort Letzte Antwort
                                0
                                • bette@mstdn.socialB bette@mstdn.social

                                  @iampytest1

                                  It's not like a regular pop up. It goes from the top of the screen to the bottom and is centered on the screen and at least five inches wide. It encourages me to visit archive today.

                                  iampytest1@infosec.exchangeI This user is from outside of this forum
                                  iampytest1@infosec.exchangeI This user is from outside of this forum
                                  iampytest1@infosec.exchange
                                  schrieb zuletzt editiert von
                                  #16

                                  @Bette that is very strange. I'm not sure what that is.
                                  Would you mind taking a screenshot of it?

                                  bette@mstdn.socialB 1 Antwort Letzte Antwort
                                  0
                                  • whitequark@social.treehouse.systemsW whitequark@social.treehouse.systems

                                    @iampytest1 honestly a pretty reasonable response to a doxing attempt

                                    privateger@plasmatrap.comP This user is from outside of this forum
                                    privateger@plasmatrap.comP This user is from outside of this forum
                                    privateger@plasmatrap.com
                                    schrieb zuletzt editiert von
                                    #17

                                    @whitequark@social.treehouse.systems @iampytest1@infosec.exchange yeah I'm honestly a bit confused by the audacity to just put that out there for no reason ​​
                                    doesn't excuse this of course, but damn

                                    1 Antwort Letzte Antwort
                                    0
                                    • iampytest1@infosec.exchangeI iampytest1@infosec.exchange

                                      @Bette that is very strange. I'm not sure what that is.
                                      Would you mind taking a screenshot of it?

                                      bette@mstdn.socialB This user is from outside of this forum
                                      bette@mstdn.socialB This user is from outside of this forum
                                      bette@mstdn.social
                                      schrieb zuletzt editiert von
                                      #18

                                      @iampytest1

                                      The next time it happens, sure. I quit my browser and opened it again, hoping to be able to do that, but it failed to appear (of course). It was a stand-alone, btw, it was the only thing on the screen, the browser wasn't open yet.

                                      tanh@mastodon.socialT 1 Antwort Letzte Antwort
                                      0
                                      • kitten@social.elizabeth.catK kitten@social.elizabeth.cat
                                        @iampytest1 what's the Malicious Website Blocklist?
                                        iampytest1@infosec.exchangeI This user is from outside of this forum
                                        iampytest1@infosec.exchangeI This user is from outside of this forum
                                        iampytest1@infosec.exchange
                                        schrieb zuletzt editiert von
                                        #19

                                        @kitten It is a small blocklist I created and maintain of malware, phishing, scams, and other threats.

                                        https://github.com/iam-py-test/my_filters_001/blob/main/antimalware.txt

                                        1 Antwort Letzte Antwort
                                        0
                                        • tapafon@soc.ua-fediland.deT tapafon@soc.ua-fediland.de

                                          @iampytest1 Did you report that to Google Safe Browsing?
                                          Given the fact it's enabled to default in most browsers, it those sites gets blocked there, they would effectively be blocked Internet-wide (almost same as domain seize).
                                          UPD: I reported those domains as well.

                                          iampytest1@infosec.exchangeI This user is from outside of this forum
                                          iampytest1@infosec.exchangeI This user is from outside of this forum
                                          iampytest1@infosec.exchange
                                          schrieb zuletzt editiert von
                                          #20

                                          @tapafon I did not, but I did inform the maintainers of some very popular ad-blocking lists, and one (AdGuard) has added a filter to protect their users.

                                          1 Antwort Letzte Antwort
                                          0
                                          • nocci@punk.cyber77.deN nocci@punk.cyber77.de shared this topic
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum