0. Preface

This analysis covers a suspicious URL that triggered an EDR alert when a victim received it via email. The URL https://1.default2024.uk:443 was identified as potentially malicious, and subsequent investigation revealed a domain parking/monetization system with several concerning characteristics.

The malicious URL was received through a Gmail account. Email content analysis was out of scope due to privacy restrictions. The URL caused an alert trigger in the EDR system, prompting this investigation.

Everything below is static analysis. The JavaScript was retrieved from the Wayback Machine for safe examination, and no live requests were made to the infrastructure.

1. The Threat at a Glance

AttributeAssessment
Malware typeDomain parking malvertising / potential drive-by download vector
DeliveryEmail link to https://1.default2024.uk:443
InfrastructureParkLogic domain parking service (ns1/ns2.ag614.parklogic.com)
IP addresses172.236.114.191, 172.234.26.134, 172.238.172.46 (AS 63949 - Akamai Connected Cloud, US)
Tracking domainsclick-use1.bodis.com, parking.bodiscdn.com
EvasionCustom base64 obfuscation, eval() for arbitrary code execution
VT detections15/90 engines flag as malicious/phishing/malware
ConfidenceHigh for domain parking identification; medium for malvertising risk assessment

2. VirusTotal Analysis

VirusTotal analysis results showing 15 malicious detections

The VirusTotal API returned the following detection summary:

CategoryCount
Malicious15
Suspicious0
Harmless47
Undetected28

Notable vendor detections:

VendorClassification
ADMINUSLabsmalicious
Lionicmalware
BitDefenderphishing
CyRadarphishing
ESETphishing
Fortinetmalware
G-Dataphishing
Gridinsoftphishing
Kasperskyphishing
Risingphishing
SafeToOpenphishing
Sophosphishing
VIPREmalware
Webrootmalicious
Forcepoint ThreatSeekermalicious

The split between “phishing” and “malware” classifications suggests the infrastructure serves multiple purposes or has been used in different campaigns.

3. DNS Information

Name Servers

ns1.ag614.parklogic.com. (50.116.34.34)
ns2.ag614.parklogic.com. (66.42.120.24)

The parklogic.com nameservers confirm this is a ParkLogic domain parking service — a commercial platform for monetizing parked domains through advertising and redirects.

DNS Resolution (dig)

A Records:

1.default2024.uk. 6494 IN A 172.234.26.134
1.default2024.uk. 6494 IN A 172.238.172.46
1.default2024.uk. 6494 IN A 172.236.114.191

Multiple A records with round-robin DNS indicate load balancing across Akamai Connected Cloud infrastructure.

AAAA Records: No IPv6 records — only IPv4 addresses are served.

TXT Records:

1.default2024.uk. 14400 IN TXT "v=spf1 -all"

The SPF record v=spf1 -all explicitly rejects all email sending from this domain — it is not configured for legitimate email.

MX Records:

1.default2024.uk. 14400 IN MX 50 mx156.hostedmxserver.com.

The MX record points to a third-party mail server (hostedmxserver.com), likely for capturing email sent to this domain — a common pattern in domain parking for collecting missent mail or abuse reports.

NS Records:

1.default2024.uk. 14400 IN NS ns1.parklogic.com.
1.default2024.uk. 14400 IN NS ns2.parklogic.com.

4. Wayback Machine Analysis

Wayback Machine snapshots

The Wayback Machine recorded three snapshots of this URL:

Snapshot 1: 10 April 2025

Redirect: http://ww12.default2024.uk/?usid=19&utid=21647853328

Content:

<h2><br/>It is gone!<br/>So be gone</h2>
<h1>410</h1>
<p>ID: PC410NAML1</p>

This is a 410 Gone error page — the domain was temporarily unavailable or in transition.

Snapshot 2: 16 April 2025

Redirect: http://ww7.default2024.uk/?usid=16&utid=37914812292

Content: Contains bBLngjovg.js — the parking/monetization JavaScript analyzed in section 5.

Snapshot 3: 25 April 2025

Redirect: http://ww7.default2024.uk/?usid=18&utid=31051421204

Content: Similar to snapshot 2, with the same parking infrastructure.

The usid and utid parameters in the redirects are tracking identifiers for the parking service.

5. Code Analysis: bBLngjovg.js

The JavaScript file retrieved from the Wayback Machine is a domain parking/monetization system built by Bodis (a domain parking service). While it functions as a legitimate parking script, it contains several patterns that elevate its risk profile.

5.1 Architecture Overview

The script is a UMD module (Universal Module Definition) that exports an App class. Key components:

// UMD module wrapper
! function (e, t) {
  "object" == typeof exports && "undefined" != typeof module ? t(exports) : 
  "function" == typeof define && define.amd ? define(["exports"], t) : 
  t((e = "undefined" != typeof globalThis ? globalThis : e || self).version = {})
}(this, (function (exports) {
  "use strict";
  // ... application code
  exports.App = App
}));

The application follows a state machine pattern with five states:

StateDescription
FailedDomain cannot be parked (disabled, prohibited UA, etc.)
DisabledServices disabled for this domain
RedirectUser is being redirected to another URL
ParkingStandard domain parking with ads
SalesDomain is for sale

5.2 Obfuscated Data Encoding

Risk Level: HIGH

The script uses a custom obfuscation layer for data transmission:

const OBFUSCATING_BASE_64_PREFIX = "UxFdVMwNFNwN0wzODEybV",
  encode = e => OBFUSCATING_BASE_64_PREFIX + btoa(unescape(encodeURIComponent(JSON.stringify(e))));

function decode$1(e) {
  return JSON.parse(decodeURIComponent(escape(atob(e.replace(OBFUSCATING_BASE_64_PREFIX, "")))))
}

Analysis: The prefix UxFdVMwNFNwN0wzODEybV is prepended to base64-encoded JSON data. This is not standard encoding — it adds an obfuscation layer that makes manual analysis more difficult. The unescape/encodeURIComponent combination handles Unicode characters before base64 encoding.

5.3 Arbitrary Code Execution via eval()

Risk Level: CRITICAL

injectJS(js) {
  js && 0 !== js.length && eval(js)
}

Analysis: This function executes arbitrary JavaScript received from the server. The eval() call is the most dangerous pattern in the script — if the backend servers are compromised, an attacker could inject malicious code that executes in every visitor’s browser. This is a potential vector for drive-by downloads or session hijacking.

5.4 User Fingerprinting

Risk Level: MEDIUM

The script collects extensive browser fingerprinting data:

const browserState = () => {
  var e, t, n, i, s;
  const {
    screen: { width: a, height: o },
    self: r,
    top: d,
    matchMedia: c,
    opener: l
  } = window, {
    documentElement: { clientWidth: h, clientHeight: u }
  } = document;

  return {
    popup: !(!l || l === window),
    timezone_offset: p,
    user_preference: Intl.DateTimeFormat().resolvedOptions(),
    user_using_darkmode: Boolean(c && c("(prefers-color-scheme: dark)").matches),
    user_supports_darkmode: Boolean(c),
    window_resolution: { width: h, height: u },
    screen_resolution: { width: a, height: o },
    frame: { innerWidth, innerHeight, outerWidth, outerHeight }
  }
}

Data collected:

  • Screen and window dimensions
  • Timezone offset
  • Dark mode preference
  • Popup detection
  • Frame information (if embedded)
  • Intl.DateTimeFormat resolved options (language, calendar, etc.)

This fingerprinting data is transmitted to external servers for tracking and profiling purposes.

5.5 External Data Exfiltration

The script sends collected data to multiple endpoints:

// Find Domain endpoint
const FIND_DOMAIN_URL = "_fd";
const getFindDomain = (e = "", t = !1, n = "") => {
  const s = `${e}/${FIND_DOMAIN_URL}${i}`;
  return fetch(s, {
    method: "POST",
    headers: { Accept: "application/json", "Content-Type": "application/json" },
    credentials: "include"
  }).then(e => e.text()).then(decode$1)
};

// Tracking endpoint
const TRACKING_URL = "_tr";
const trackVisit = ({callbacks, context}, type, baseUrl = "") => {
  const s = `${baseUrl}/${TRACKING_URL}`;
  return fetch(s, {
    method: "POST",
    body: JSON.stringify({ signature: encode(signature) })
  })
};

// Zero Click endpoint
const getZeroClick = (context) => {
  return fetch("/_zc", {
    method: "POST",
    body: JSON.stringify({ signature: encode({...context, type: "zc_fetch"}) })
  })
};

Target domains:

  • https://click-use1.bodis.com/_fd (Find Domain)
  • https://click-use1.bodis.com/_tr (Tracking)
  • https://click-use1.bodis.com/_zc (Zero Click)

The credentials: "include" flag ensures cookies are sent with requests, enabling cross-site tracking.

5.6 Third-Party Tracking Integration

The script loads and initializes tracking pixels from multiple advertising platforms:

class Pixels {
  constructor(e) {
    this.providers = [
      new Facebook(e.facebook),
      new Tiktok(e.tiktok, e.useAltTikTokEventsForAdsPlatformUser),
      new Taboola(e.taboola),
      new Revcontent(e.revcontent),
      new Outbrain(e.outbrain)
    ];
  }
}

Tracking providers:

ProviderScript SourcePurpose
Facebookconnect.facebook.net/en_US/fbevents.jsFacebook Pixel tracking
TikTokanalytics.tiktok.com/i18n/pixel/events.jsTikTok Pixel tracking
Taboolacdn.taboola.com/libtrc/unip/{id}/tfa.jsTaboola content recommendations
Revcontentassets.revcontent.com/master/rev.jsRevcontent native advertising
Outbrainamplify.outbrain.com/cp/obtp.jsOutbrain content discovery

This multi-platform tracking enables cross-site user profiling and retargeting.

5.7 Cross-Origin Message Handling

window.onmessage = e => {
  const { origin: t, data: n } = e;
  ALLOWED_ORIGINS.includes(t) && 
    (null == n ? void 0 : n.startsWith(MESSAGE_PREFIX)) && 
    window.location.search.startsWith(ADS_PARAM$1) && 
    document.dispatchEvent(new CustomEvent("pixel", {
      detail: { type: "click" }
    }))
}

Allowed origins:

const ALLOWED_ORIGINS = [
  "https://www.google.com",
  "https://www.adsensecustomsearchads.com",
  "https://syndicatedsearch.goog",
  "https://googleadservices.com"
];

Analysis: The script listens for cross-origin messages from Google domains. When a message starting with FSXDC,.aCS: is received and the URL contains ?caf, it dispatches a click tracking event. This enables Google AdSense integration for domain parking monetization.

5.8 Google AdSense Integration

The script integrates with Google’s domain parking ad system:

const CAF_SCRIPT_SRC = `https://www.google.com/adsense/domains/caf.js?abp=1&bodis=true`;

class Ads {
  injectScriptTags = () => {
    return new Promise((e) => {
      const t = document.createElement("script");
      t.src = CAF_SCRIPT_SRC;
      t.addEventListener("load", () => e(true));
      document.body.appendChild(t);
    })
  }
}

The caf.js (Custom Ad Format) script is Google’s domain parking ad system. The abp=1&bodis=true parameters indicate integration with Bodis parking service.

5.9 State Machine and Redirect Logic

The application follows a strict state machine:

class App {
  async main() {
    this.parkResponse = decode();                    // Decode base64 config
    this.findDomainResponse = await getFindDomain(); // Fetch domain config
    
    // Build state based on server response
    const parking = Parking.build(this.findDomainResponse, this.google);
    const redirect = Redirect.build(...);
    const disabled = Disabled.build(...);
    const sales = Sales.build(...);
    
    // Execute state transition
    if (redirect) await this.transitionToRedirect(redirect);
    else if (parking) await this.transitionToParking(parking);
    // ... other states
  }
  
  async transitionToRedirect(e) {
    this.state = e;
    Render.revealPage();
    await waiter(e.delay, (e) => Render.loading(e));  // Countdown timer
    await this.track();
    window.location.href = e.url;  // REDIRECT
  }
}

Redirect flow:

  1. Fetch domain configuration from server
  2. Decode base64-encoded parking response
  3. Check for redirect conditions (zero-click, sales, disabled)
  4. Show loading countdown (configurable delay)
  5. Execute redirect to target URL

The waiter function creates a visible countdown before redirect:

const waiter = (e, t) => new Promise((n) => {
  t(e);
  let i = e;
  const s = () => {
    i > 0 ? (i -= 1, t(i), setTimeout(s, 1000)) : n()
  };
  s()
});

5.10 Ad Blocker Detection

class Adblock {
  hasAdblocker() {
    if (void 0 === window.google) return true;
    const e = document.querySelectorAll("style");
    return Array.from(e).some((e) => !!e.innerHTML.includes("adblockkey"));
  }
  
  handleAdblocked() {
    this.removeAdblockKey();
    this.state = Blocking.BLOCKED;
  }
}

The script detects ad blockers by checking for the google object and searching for adblockkey in style elements. When an ad blocker is detected, the state changes to BLOCKED and the user sees a message: “Ad block detected. Please disable your ad blocker and reload the page.”

6. MITRE ATT&CK Mapping

Technique IDTechnique NameDescription
T1566.002Phishing: Spearphishing LinkMalicious URL delivered via email
T1189Drive-by CompromisePotential for malicious code injection via eval()
T1071.001Application Layer Protocol: Web ProtocolsHTTP/HTTPS communication with C2 infrastructure
T1071.004Application Layer Protocol: DNSDNS-based domain parking resolution
T1102Web ServiceAbuse of legitimate advertising platforms (Google, Facebook, etc.)
T1041Exfiltration Over C2 ChannelData exfiltration via _fd, _tr, _zc endpoints
T1573Encrypted ChannelBase64-encoded/obfuscated data transmission
T1027Obfuscated Files or InformationCustom base64 prefix obfuscation
T1059.007Command and Scripting Interpreter: JavaScripteval() for arbitrary code execution
T1574.002Hijack Execution Flow: DLL Side-LoadingDomain parking infrastructure abuse
T1036MasqueradingLegitimate parking service used for malicious purposes
T1082System Information DiscoveryBrowser fingerprinting and screen resolution collection
T1083File and Directory DiscoveryN/A (web-based, not file system)
T1552.001Unsecured Credentials: Credentials In FilesN/A (no credential harvesting observed)
T1204.001User Execution: Malicious LinkUser must click email link to trigger
T1497Virtualization/Sandbox EvasionN/A (no sandbox evasion detected)
T1498Network Denial of ServiceN/A
T1568Dynamic ResolutionMultiple A records, round-robin DNS
T1090ProxyAkamai Connected Cloud infrastructure
T1104Multi-Stage ChannelsRedirect chain (ww7 → tracking → final destination)

7. Indicators of Compromise

Network Indicators

TypeValue
Malicious URLhttps://1.default2024.uk:443
IP Address172.236.114.191 (US, AS 63949 - Akamai Connected Cloud)
IP Address172.234.26.134
IP Address172.238.172.46
Tracking Domainclick-use1.bodis.com
Parking CDNparking.bodiscdn.com
Name Serversns1.ag614.parklogic.com, ns2.ag614.parklogic.com
MX Recordmx156.hostedmxserver.com
Google AdSense CAFwww.google.com/adsense/domains/caf.js

Host Indicators

TypeValue
JavaScript FilebBLngjovg.js (from Wayback Machine)
Obfuscation PrefixUxFdVMwNFNwN0wzODEybV
Tracking Endpoint/_fd (Find Domain)
Tracking Endpoint/_tr (Visit Tracking)
Tracking Endpoint/_zc (Zero Click)
Custom Event PrefixFSXDC,.aCS:
Ad Parameter?caf
SPF Recordv=spf1 -all

Behavioral Indicators

BehaviorDescription
eval() usageArbitrary code execution from server
Base64 obfuscationNon-standard encoding with custom prefix
Browser fingerprintingScreen, window, timezone, dark mode collection
Cross-origin messagingAccepts messages from Google domains
Multiple tracking pixelsFacebook, TikTok, Taboola, Revcontent, Outbrain
Redirect chainMulti-hop redirects with countdown timers
Ad blocker detectionBlocks content when ad blockers detected

8. Malicious Indicators

IndicatorRisk LevelDescription
eval() usageCRITICALArbitrary code execution — potential for drive-by downloads
Obfuscated encodingHIGHCustom base64 prefix hides data transmission
IP collectionHIGHPrivacy violation — user IP transmitted to third parties
FingerprintingMEDIUMExtensive device profiling for tracking
Cross-origin messagingMEDIUMAccepts commands from Google domains
Multiple tracking pixelsLOW-MEDIUMCross-platform user tracking
Redirect chainLOW-MEDIUMMulti-hop redirects obscure final destination
Ad blocker detectionLOWBlocks content for users with ad blockers

9. Conclusion

This analysis reveals a domain parking/monetization system that, while functioning as a legitimate advertising platform, exhibits elevated risk factors that warrant blocking:

Primary Characteristics

  1. Domain Parking Infrastructure: The script is part of the Bodis parking service, using ParkLogic nameservers and Google AdSense for domain monetization.

  2. Obfuscation: Custom base64 encoding with the prefix UxFdVMwNFNwN0wzODEybV adds an unnecessary layer of complexity to data transmission.

  3. Arbitrary Code Execution: The eval() function executes server-provided JavaScript, creating a potential vector for malicious payloads if the backend infrastructure is compromised.

  4. Extensive Tracking: Multi-platform tracking (Facebook, TikTok, Taboola, Revcontent, Outbrain) enables cross-site user profiling.

  5. Data Exfiltration: User data (IP, fingerprinting, browsing behavior) is transmitted to click-use1.bodis.com without explicit consent.

Risk Assessment

The combination of:

  • eval() for arbitrary code execution
  • Custom obfuscation
  • Extensive fingerprinting
  • Multi-platform tracking

…makes this infrastructure a potential vector for malvertising or drive-by downloads. While the script itself may be legitimate parking code, the eval() function means that a backend compromise could inject malicious code into every visitor’s browser.

Recommendations

  1. Block the domain: Add default2024.uk and related subdomains to blocklists.
  2. Block tracking endpoints: Blacklist click-use1.bodis.com and related Bodis infrastructure.
  3. Monitor for similar patterns: Other domains using ParkLogic/Bodis infrastructure with eval() patterns should be flagged.
  4. Email security: Train users to recognize suspicious URLs in emails, especially those with subdomains like ww7. or ww12..

Attribution

The infrastructure is commercially available (Bodis/ParkLogic domain parking service), making attribution difficult. The script is likely legitimate parking code that could be abused by anyone with access to the Bodis platform. The VT detections (15/90) suggest this specific domain or configuration has been flagged for malicious behavior, but the underlying software is a commercial product.

Verdict: Block this domain and similar parking infrastructure. The eval() function and obfuscation patterns make it unsuitable for safe browsing environments.