Note, this security incident specifically concerns eFile.com and not identical sounding domains or IRS’ e-file infrastructure.
Just in time for tax season
The development comes at a crucial time when U.S. taxpayers are wrapping up their IRS tax returns before the April 18th due date.
The use of Math.random() at the end is likely to prevent caching and load a fresh copy of the malware—should the threat actor make any changes to it, every time eFile.com is visited. At the time of writing, the endpoint was no longer up.
Today, the file is no longer serving the malicious code.
Website ‘hijacked’ over 2 weeks ago
On March 17th, a Reddit thread surfaced where multiple eFile.com users suspected the website was “hijacked.”
At the time, the website showed an SSL error message that, some suspected, appeared to be fake:
Turns out that’s indeed the case. Researchers spotted an additional file, ‘update.js’ associated with this attack which was being served by an Amazon AWS endpoint.
As shown in the screenshot below, ‘update.js’ has the fake SSL error message present as base64-encoded HTML code (highlighted below) inside of it:
An HTML excerpt from the decoded string generating the fake SSL error is shown below:
It was confirmed that these binaries connect to a Tokyo-based IP address, 184.108.40.206, that appears to be hosted with Alibaba. The same IP also hosts the illicit domain, infoamanewonliag[.]online associated with this issue.
Security research group named MalwareHunterTeam, who further analyzed these binaries, states these contain Windows botnets written in PHP—a fact the research group mocked. Additionally, they called out eFile.com for leaving the malicious code on its website for weeks:
“So, the website of [efile.com]… got compromised at least around the middle of March & still not cleaned,” writes MalwareHunterTeam.
Referring to a Reddit thread, they further said, “…even the payloads serving domain was mentioned 15 days ago already. How has this not got more attention yet?”
Dr. Johannes Ulrich of the SANS Institute has also released an analysis of the issue.
The full scope of this incident, including if the attack successfully infected any eFile.com visitors and customers, remains yet to be learned.