s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811969 high

📛 Threat Title

magecart: Domain used for credit card skimming (usually related to Magecart attacks) onepay234.top

Category: magecart Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:23 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain onepay234.top UrlVoid 4 / 35

IOC database

Type
domain
Value
onepay234.top
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain used for credit card skimming (usually related to Magecart attacks) attributed to magecart

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies credit card skimming infrastructure (NOT phishing). IOC type: Domain used for credit card skimming (usually related to Magecart attacks). Attributed malware: magecart. Confidence: 90. First seen: 2026-05-13 19:59:23 UTC. Reporter: cottaflora. Tags: GorgonAgora, medusajs, PaymentVanilla, web-skimmer.

Remediations (8)

  • web:cside.com

    What is Magecart : Complete Guide and Prevention Strategy Magecart attacks steal card data in the browser before traditional tools detect them. Learn how Magecart attacks work and entry points used by attackers.

  • web:cybersecuritynews.com

    The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart -style attack campaign, characterized by the deployment of obfuscated JavaScript to harvest sensitive payment information. The campaign first came to light in mid-September 2025 following a tweet indicating an ongoing skimming operation, which was later investigated in detail by ...

  • web:sucuri.net

    MageCart malware is a commonly used name for malicious software designed to target ecommerce websites and steal sensitive payment information from online shoppers. Various MageCart groups employ different tactics and techniques, but their primary goal remains the same; to compromise websites, skim credit card details, and harvest sensitive customer data to sell on the black market for a profit ...

  • web:visualping.io

    Learn what Magecart is, how web skimming attacks steal payment data from e-commerce sites, and discover proven strategies to protect your online store in 2025.

  • web:www.akamai.com

    This may result in Magecart attacks remaining unnoticed for long periods. Over the past few weeks, we have identified an active, ongoing campaign, leveraging sophisticated infrastructure and capabilities to deliver Magecart -style web skimming attacks , and we have uncovered numerous digital commerce websites that are victims of this campaign.

  • web:www.csoonline.com

    Hacking groups that make up Magecart are effective and persistent at stealing customer and payment card data through skimmers. Here's how they work and what you can do to mitigate the risk.

  • web:www.imperva.com

    What Is Magecart ? The name " Magecart " refers to several hacker groups that employ online skimming techniques for the purpose of stealing personal data from websites—most commonly, customer details and credit card information on websites that accept online payments. Magecart groups have successfully breached well-known brands.

  • web:www.malwarebytes.com

    A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.