PULSE NAME
Malvertising Campaign Hides in Plain Sight on WordPress Websites.
WHITE PetrP.73 2025-10-06 Modified: 2025-10-06
4
IOCs
LOW VOLUME
A recent investigation uncovered a malvertising campaign affecting multiple WordPress websites, where unauthorized JavaScript was being loaded without the site owner's consent. This JavaScript, identified in at least 17 websites during the analysis, acted as a remote loader that fetched malicious content from a Command and Control (C&C) server, specifically hosted at hxxps://brazilc.com/ads.php. The mechanism involved the PHP code initiating a POST connection to the C&C server and subsequently injecting the server's response into the HTML document's head section.
Indicators of Compromise (4)
All domain URL
TYPEINDICATORDESCRIPTIONCREATED
domain brazilc.com 2025-10-06
domain porsasystem.com 2025-10-06
URL http://porsasystem.com/6m9x.js 2025-10-06
URL https://brazilc.com/ads.php 2025-10-06