> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Kongtuke JavaScript Payload Masquerading as Restaurant Website
- URL: https://darkwebinformer.com/ioc-alert-kongtuke-javascript-payload-masquerading-as-restaurant-website/
- Published: 2025-10-14T19:56:58.000Z
- Updated: 2025-10-14T19:56:58.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A JavaScript payload associated with the **Kongtuke** malware family has been discovered hosted on a compromised domain masquerading as a restaurant website. The malicious script is delivered via `js.php`, a common filename used in JavaScript injection attacks, and is believed to be part of a broader payload delivery campaign. Confidence is assessed at 100%.

---

## 📌 Key Details

| Field           | Information                       |
| --------------- | --------------------------------- |
| **Type**        | URL                               |
| **Indicator**   | https://prixmatech\[.\]com/js.php |
| **Threat Type** | Payload Delivery                  |
| **Malware**     | js.kongtuke                       |
| **Confidence**  | 100%                              |
| **Date**        | 14 Oct 2025 – 18:19:55 UTC        |
| **Tags**        | Kongtuke                          |
| **Reporter**    | monitorsg                         |
| **Reference**   | None                              |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** Garbanzo Mediterranean Restaurant Near Me | Pita, Salad, Gyro, Bowls
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/0199e39f-3448-711b-9e0a-38aa14fe89be.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/0199e39f-3448-711b-9e0a-38aa14fe89be/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/10/ioc_2357828736598723-2.jpg)

---

## 📡 Related Intelligence

- **VirusTotal Report:** [VirusTotal URL Report](https://www.virustotal.com/gui/url/e88258ba334b9ad9be033134cb190a764fdb92b4abdc25b9d786824c528c905b)

---

## 🛡️ Defensive Guidance

- Block access to **prixmatech\[.\]com** and any requests to **/js.php** endpoints across DNS, proxy, and web gateways.
- Inspect web server logs for any evidence of injected JavaScript payloads or external script loading from suspicious domains.
- Monitor for execution of scripts or network calls tied to Kongtuke signatures.
- Deploy content security policies (CSP) to limit JavaScript execution from untrusted origins.

---

⚠️ This IOC highlights the **use of legitimate-looking commercial websites as decoy fronts** for distributing JavaScript-based malware like Kongtuke, which often targets users through embedded scripts or drive-by infection techniques.