MB-e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
high
📛 Threat Title
Unknown: payment-vanilla.iife.js
Description
File type: js. Size: 72605 bytes. Tags: cc-skimmer, GorgonAgora, js, medusajs, PaymentVanilla, web-skimmer. Reporter: cottaflora. First seen: 2026-05-13 19:57:56.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
payment-vanilla.iife.js
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/payment-vanilla.iife.js
IOC database
- Type
- domain
- Value
payment-vanilla.iife.js- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/payment-vanilla.iife.js
hash_sha256
e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
1 feed
IOC database
- Type
- hash_sha256
- Value
e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e6c60ca4f996b209bbaf7429182d7ed76acf761bb9c1de63486fcb76635fa58c
hash_sha1
2deaddb1176d318f02e6462369e75da6f4e84185
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2deaddb1176d318f02e6462369e75da6f4e84185
2 feeds
IOC database
- Type
- hash_sha1
- Value
2deaddb1176d318f02e6462369e75da6f4e84185- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2deaddb1176d318f02e6462369e75da6f4e84185
hash_md5
8218cc08f593db53c0a3e09f1f56201a
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8218cc08f593db53c0a3e09f1f56201a
2 feeds
IOC database
- Type
- hash_md5
- Value
8218cc08f593db53c0a3e09f1f56201a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8218cc08f593db53c0a3e09f1f56201a
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 72605 bytes. Tags: cc-skimmer, GorgonAgora, js, medusajs, PaymentVanilla, web-skimmer. Reporter: cottaflora. First seen: 2026-05-13 19:57:56.
Remediations (10)
-
web:bazaar.abuse.ch
Malware samples associated with tag PaymentVanilla MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with PaymentVanilla ...
-
web:blog.codacy.com
We look at some of the most common JavaScript vulnerabilities that software developers face and discuss solutions and remediation methods for them.
-
web:cheatsheetseries.owasp.org
Cross Site Scripting Prevention Cheat Sheet Introduction This cheat sheet helps developers prevent XSS vulnerabilities. Cross-Site Scripting (XSS) is a misnomer. Originally this term was derived from early versions of the attack that were primarily focused on stealing data cross-site. Since then, the term has widened to include injection of basically any content. XSS attacks are serious and ...
-
web:developer.mozilla.org
An IIFE (Immediately Invoked Function Expression) is an idiom in which a JavaScript function runs as soon as it is defined. It is also known as a self-executing anonymous function. The name IIFE is promoted by Ben Alman in his blog.
-
web:github.com
How to create a web form cracker in under 15 minutes. - moimikey/Crackhead
-
web:learn.microsoft.com
Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:www.cve.org
At cve.org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
-
web:www.w3schools.com
Immediately Invoked Function Expressions An IIFE is short for an Immediately Invoked Function Expression. An IIFE is a function that invokes itself when defined.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.