Skip to content

Latest commit

 

History

History
36 lines (21 loc) · 2.93 KB

README.md

File metadata and controls

36 lines (21 loc) · 2.93 KB

DISCLAIMER

Found out that https://www.kentkart.com/cozumler/mobil-uygulama/ has been compromised somehow, This repo is just a workspace to reverse-engineer the source code of backdoor and report to the required authorities, this was not published for any harmful intentions but only to warn people. DO NOT EXECUTE ANY OF THE CODE GIVEN IN THIS REPOSITORY

BACKDOOR FLOW

  • step 1: script that exist in the root of html (parts/part_1.js) fetches parts/part_2.js from remote server so called "crazy2cdn.com" and injects into the head of root html

image

image

NOTES :

Created: 2024-03-29 15:30:54 UTC

  • also urls provided on some files depend on "time" so they expired and you wont be able to see responses without going through the process from scratch

  • please note that this backdoor was probably created by an employee at kentkart

SNAPSHOTS FOR /cozumler/mobil-uygulama:

CLEAN-VERSION : https://web.archive.org/web/20240224160625/https://www.kentkart.com/solutions/mobile-application/

COMPROMISED-VERSION : https://web.archive.org/web/20240502171725/https://www.kentkart.com/solutions/mobile-application/