ThreatFox IOC Database
You are viewing the ThreatFox database entry for url https://www.motorway.nl/nochain-sw.js.
Database Entry
| IOC ID: | 1923379 |
|---|---|
| IOC: | https://www.motorway.nl/nochain-sw.js |
| IOC Type : | url |
| Threat Type : | payload_delivery |
| Malware: | IClickFix |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | True |
| ASN: | AS24642 NL-CAVEO |
| Country: | NL |
| First seen: | 2026-09-17 18:41:21 UTC |
| Last seen: | never |
| UUID: | 72902321-b2b7-11f1-8450-42010aa4000a |
| Reporter | Anonymous |
| Reward | 5 credits from ThreatFox |
| Tags: | ClickFix etherhiding |
| Reference: | https://www.motorway.nl |
Anonymous
motorway.nl is compromised in an Etherhiding campaign. The site is serving a malicious Service Worker script referenced in its index source code. This Service Worker intercepts traffic, strips CSP headers, and fetches dynamic, on-chain payloads via smart contracts on the Base blockchain to present fake ClickFix/reCAPTCHA prompts delivering Amatera Stealer.Injected Service Worker Script: https://www.motorway.nl/nochain-sw.js (referenced directly in index source)
Base Smart Contract (IoC): 0x58460d0b3d4d6b03761c89120393c0c676676496
Threat Mechanism: Etherhiding + ClickFix technique targeting site visitors with credential-stealing malware.
Technical Reference: https://cyberpress.org/wordpress-etherhiding-deploys-amatera/
Verification:
https://sitecheck.sucuri.net/results/https/www.motorway.nl
https://www.malwareurl.com/listing.php?domain=motorway.nl
NL