Post B7caMcenoaO7frulGq by lanodan@queer.hacktivis.me
 (DIR) More posts by lanodan@queer.hacktivis.me
 (DIR) Post #B7cYMd7Lu39NC690PQ by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       > Go to cogentco.com> site barely works without JS> enable it, and get redirected to malware site> JS in question detects the debuggerWhat the fuck.cogentco_jsmalware.pngcogentco_jsmalware2.pngbrowser_logs.txt
       
 (DIR) Post #B7cZjKqc62PJ94hnTk by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       Also if you're wondering about the kind of malware:cogentco_windows_update.png
       
 (DIR) Post #B7caMcToTRb77mlz8q by eragon@pl.eragon.re
       0 likes, 0 repeats
       
       @lanodan It's easy to detect the debugger. But I guess it's there to stop an easy analysis of the malware
       
 (DIR) Post #B7caMcenoaO7frulGq by lanodan@queer.hacktivis.me
       1 likes, 0 repeats
       
       @eragon Yeah, I so wish WebKit would not make it easy to detect the debugger…
       
 (DIR) Post #B7caTrEm0LM4vABoXI by SRAZKVT@tech.lgbt
       0 likes, 0 repeats
       
       @lanodan sounds like normal webdev
       
 (DIR) Post #B7caTrSx9chJd8p8dc by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @SRAZKVT  Corporate Design: Nearly indistinguishable from maliceCorporate Web Design: Nearly indistinguishable from malwareMy kind of web design: vi index.html
       
 (DIR) Post #B7cakRim7sAohu8I1Q by eragon@pl.eragon.re
       0 likes, 0 repeats
       
       @lanodan It is doable on firefox if you change some settings in about:config.I bet there is a way to do it on webkit too.The main issue is to know how is it detected.
       
 (DIR) Post #B7cakRwxH9W3Pslc7k by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @eragon Yeah and for me that's way too much effort, and last thing I'd want is to end up spelunking into JS garbage.
       
 (DIR) Post #B7cbnwmPCv3JrA41zM by hrbrmstr@mastodon.social
       1 likes, 0 repeats
       
       @lanodan https://urlscan.io/result/019ef3fa-3677-7764-a7bd-04d558aeeed3/
       
 (DIR) Post #B7ccrOqzNxuZkVPzWa by sfan5@mastodon.online
       1 likes, 0 repeats
       
       @hrbrmstr @lanodan To absolutely nobody's surprise Cloudflare hosts both the redirect domains and the phishing page itself.
       
 (DIR) Post #B7cczqGxKKRL6Uac6q by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @sfan5 @hrbrmstr At least cogentco.com isn't also behind Cloudflare but hosted by cogent themselves.
       
 (DIR) Post #B7cdRj0PwDYIft9JsO by lanodan@queer.hacktivis.me
       0 likes, 0 repeats
       
       @Ree Call the Microsoft Windows support: $voip_phonenoYour PC will reboot in $x minutes, $y secondsYour computer needs to reboot to finish install of updates. IF you're already saved your work, you can reboot now. Otherwise you should close this message and use the remaining time to save all the work you don't want to loose.[Reboot] [Close]