🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://www.motorway.nl/nochain-sw.js.

Database Entry


IOC ID:1923379
IOC: https://www.motorway.nl/nochain-sw.js
IOC Type :url
Threat Type :payload_delivery
Malware: IClickFix
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS24642 NL-CAVEO
Country:- NL
First seen:2026-09-17 18:41:21 UTC
Last seen:never
UUID:72902321-b2b7-11f1-8450-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:ClickFix etherhiding
Reference: https://www.motorway.nl

Avatar
Anonymous
motorway.nl is compromised in an Etherhiding campaign. The site is serving a malicious Service Worker script referenced in its index source code. This Service Worker intercepts traffic, strips CSP headers, and fetches dynamic, on-chain payloads via smart contracts on the Base blockchain to present fake ClickFix/reCAPTCHA prompts delivering Amatera Stealer.

Injected Service Worker Script: https://www.motorway.nl/nochain-sw.js (referenced directly in index source)

Base Smart Contract (IoC): 0x58460d0b3d4d6b03761c89120393c0c676676496

Threat Mechanism: Etherhiding + ClickFix technique targeting site visitors with credential-stealing malware.

Technical Reference: https://cyberpress.org/wordpress-etherhiding-deploys-amatera/

Verification:
https://sitecheck.sucuri.net/results/https/www.motorway.nl
https://www.malwareurl.com/listing.php?domain=motorway.nl