Emboba.info

By GoldSparrow in Browser Hijackers

The Emboba.info site is associated with a browser hijacker app that is a program designed to load Emboba.info and redirect users to third-party sites. The Emboba.info browser hijacker may enter the computers under the disguise of being a search enhancer extension. Usually, software like the Emboba.info browser hijacker is bundled with clean desktop apps and sometimes adware that is offered to users as a single program package on questionable platforms online. Users who do not explore the 'Advanced' and 'Custom' options of freeware bundles might add potentially unwanted extensions to their Internet client and allow browser hijackers to change their Internet settings for the worse.

We have received reports that the Emboba.info browser hijacker might open new tabs, pop-up windows and redirect users to phishing pages as you enjoy your time on the Web. Computer security analysts add that the Emboba.info browser hijacker may run from a hidden folder under the AppData directory and change the behavior of popular Internet clients including Opera, Mozilla Firefox, Google Chrome, Internet Explorer, Edge and derivatives. The traffic generated from compromised devices is recorded to be forwarded to the 78.140.179.99 IP address and compromised browsers may be rerouted to third-party resources via the following links:

h[tt]p://aknice(.)info/[RANDOM CHARACTERS]
h[tt]p://elwarvi(.)info/[RANDOM CHARACTERS]
h[tt]p://emboba(.)info/[RANDOM CHARACTERS]
h[tt]p://imeteti(.)info/protJS/[RANDOM CHARACTERS]
h[tt]p://latest-418362.shotrati(.)info/[RANDOM CHARACTERS]
h[tt]p://latest-422397.shotrati(.)info/protJS/[RANDOM CHARACTERS]
h[tt]p://latest-431528.shotrati(.)info/protJS/[RANDOM CHARACTERS]
h[tt]p://latest-447409.shotrati(.)info/protJS/[RANDOM CHARACTERS]
h[tt]p://odbabo(.)info/[RANDOM CHARACTERS]
h[tt]p://pu.tomi.net(.)ru/[RANDOM CHARACTERS]
h[tt]p://yagriga(.)ru/protJS/[RANDOM CHARACTERS]

The list above is incomplete because the team who created the Emboba.info browser hijacker operates hundreds of sites and registers new domains almost every week. Domains like Emboba.info are used to circumvent Web filters and AV shields and send the user to a corrupted page where threats may be uploaded and waiting to be installed. AV vendors and browser manufacturers are working on blocking traffic to gateways like Emboba.info, but the fight continues as new domains are registered online, and new threats emerge. Browser hijackers are classified as a low-level cyber parasite, but they may expose users to corrupted pages and lead to a security compromise. It is best to remove the Emboba.info browser hijacker using a trustworthy anti-malware that can clean all associated files.

Trending

Most Viewed

Loading...