TF-1811955
high
📛 Threat Title
magecart: Domain used for credit card skimming (usually related to Magecart attacks) batppp26.top
Description
Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
batppp26.top
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
batppp26.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain used for credit card skimming (usually related to Magecart attacks) attributed to magecart
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:22 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.
Remediations (8)
-
web:cside.com
What is Magecart : Complete Guide and Prevention Strategy Magecart attacks steal card data in the browser before traditional tools detect them. Learn how Magecart attacks work and entry points used by attackers.
-
web:cybersecuritynews.com
Magecart hackers used more than 100 domains to hijack eStore checkouts and steal card data, exposing a long-running global payment skimming campaign.
-
web:sucuri.net
MageCart malware is a commonly used name for malicious software designed to target ecommerce websites and steal sensitive payment information from online shoppers. Various MageCart groups employ different tactics and techniques, but their primary goal remains the same; to compromise websites, skim credit card details, and harvest sensitive customer data to sell on the black market for a profit ...
-
web:visualping.io
Learn what Magecart is, how web skimming attacks steal payment data from e-commerce sites, and discover proven strategies to protect your online store in 2025.
-
web:www.csoonline.com
Hacking groups that make up Magecart are effective and persistent at stealing customer and payment card data through skimmers. Here's how they work and what you can do to mitigate the risk.
-
web:www.humansecurity.com
A Magecart attack is one in which cybercriminals skim shoppers' credit card data and other personally identifiable information (PII) from your online payment forms when they complete a transaction. The name " Magecart " refers to several hacker groups that use online skimming techniques to steal payment data from e-commerce sites on the Magento platform. However, Magecart attacks have ...
-
web:www.imperva.com
What Is Magecart ? The name " Magecart " refers to several hacker groups that employ online skimming techniques for the purpose of stealing personal data from websites—most commonly, customer details and credit card information on websites that accept online payments. Magecart groups have successfully breached well-known brands.
-
web:www.malwarebytes.com
A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.