s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c high

📛 Threat Title

Unknown: payment-vanilla.iife.js

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: js. Size: 72605 bytes. Tags: cc-skimmer, GorgonAgora, js, medusajs, PaymentVanilla, web-skimmer. Reporter: cottaflora. First seen: 2026-05-13 19:57:56.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain payment-vanilla.iife.js VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/payment-vanilla.iife.js

IOC database

Type
domain
Value
payment-vanilla.iife.js
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/payment-vanilla.iife.js

hash_sha256 e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
1 feed

IOC database

Type
hash_sha256
Value
e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c

hash_sha1 2deaddb1176d318f02e6462369e75da6f4e84185 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2deaddb1176d318f02e6462369e75da6f4e84185
2 feeds

IOC database

Type
hash_sha1
Value
2deaddb1176d318f02e6462369e75da6f4e84185
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2deaddb1176d318f02e6462369e75da6f4e84185

hash_md5 8218cc08f593db53c0a3e09f1f56201a VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8218cc08f593db53c0a3e09f1f56201a
2 feeds

IOC database

Type
hash_md5
Value
8218cc08f593db53c0a3e09f1f56201a
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8218cc08f593db53c0a3e09f1f56201a

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: js. Size: 72605 bytes. Tags: cc-skimmer, GorgonAgora, js, medusajs, PaymentVanilla, web-skimmer. Reporter: cottaflora. First seen: 2026-05-13 19:57:56.

Remediations (10)

  • web:bazaar.abuse.ch

    Malware samples associated with tag PaymentVanilla MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with PaymentVanilla ...

  • web:blog.codacy.com

    We look at some of the most common JavaScript vulnerabilities that software developers face and discuss solutions and remediation methods for them.

  • web:cheatsheetseries.owasp.org

    Cross Site Scripting Prevention Cheat Sheet Introduction This cheat sheet helps developers prevent XSS vulnerabilities. Cross-Site Scripting (XSS) is a misnomer. Originally this term was derived from early versions of the attack that were primarily focused on stealing data cross-site. Since then, the term has widened to include injection of basically any content. XSS attacks are serious and ...

  • web:developer.mozilla.org

    An IIFE (Immediately Invoked Function Expression) is an idiom in which a JavaScript function runs as soon as it is defined. It is also known as a self-executing anonymous function. The name IIFE is promoted by Ben Alman in his blog.

  • web:github.com

    How to create a web form cracker in under 15 minutes. - moimikey/Crackhead

  • web:learn.microsoft.com

    Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:www.cve.org

    At cve.org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • web:www.reddit.com

    If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...

  • web:www.w3schools.com

    Immediately Invoked Function Expressions An IIFE is short for an Immediately Invoked Function Expression. An IIFE is a function that invokes itself when defined.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.