Remove www.efile.com.
article thumbnail

Visitors of tax return e-file service may have downloaded malware

Malwarebytes

A Reddit user encountered a fake "Network Error" page when accessing www.efile.com. also contains two hard-coded download URLs, both served on the malicious domain infoamanewonliag[.]online. The same IP also hosts the illicit domain the payloads were downloaded from. So different browsers get different payloads," says Ullrich.

article thumbnail

Tax preparation and e-file service eFile.com compromised to serve malware

Security Affairs

A user on Reddit noticed that taxpayers attempting to load the website were redirected to a fake ‘network error’ page that instructed them to download a fake browser update (called “installer.exe” or “update.exe”) to correctly access the service. The PHP script downloads and executes additional code. ” wrote Ullrich.

Malware 78