@keyframes fade-in{0%{opacity:0}to{opacity:1}}.wrap.elementor-admin-page-license form.elementor-license-box{max-width:600px;background:#fff;margin:20px 0;padding:20px}.wrap.elementor-admin-page-license form.elementor-license-box h3{display:flex;justify-content:space-between;align-items:center;margin:0;padding:0;padding-block-end:20px;border-block-end:1px solid #eee}.wrap.elementor-admin-page-license form.elementor-license-box h3 span{flex-grow:1;padding-inline-start:5px}.wrap.elementor-admin-page-license form.elementor-license-box h3 small{font-size:13px;font-weight:400}.wrap.elementor-admin-page-license form.elementor-license-box label{display:block;font-size:1.3em;font-weight:600;margin:1em 0}.wrap.elementor-admin-page-license form.elementor-license-box .button{height:30px;margin-inline-start:15px;margin-block-end:0}.wrap.elementor-admin-page-license form.elementor-license-box p.description{margin:10px 0}.wrap.elementor-admin-page-license form.elementor-license-box .e-row-stretch{display:flex;align-items:center;justify-content:space-between}.wrap.elementor-admin-page-license form.elementor-license-box .e-row-divider-bottom{padding-block-end:15px;border-block-end:1px solid #eee}.wrap.elementor-admin-page-license .elementor-box-action{display:flex;justify-content:flex-end;align-items:flex-end;margin-block-start:30px}.wrap.elementor-admin-page-license .elementor-box-action .elementor-manually-link{color:#72777c;margin-inline-end:15px}.wrap.elementor-admin-page-license .elementor-box-action .elementor-manually-link:hover{color:inherit}.fixed .column-elementor_library_type,.fixed .column-instances{width:10%}.fixed .elementor-shortcode-input{min-width:235px}@media (min-width:768px) and (max-width:1440px){.fixed .column-shortcode{width:25%}.fixed .elementor-shortcode-input{min-width:100%}}#available-widgets [class*=elementor-template] .widget-title:before{content:"\e801";font-family:eicon;font-size:17px}#elementor-widget-template-empty-templates{margin-block-start:15px;text-align:center}.elementor-widget-template-empty-templates-title{padding:25px 0 30px}.elementor-widget-template-empty-templates-icon{font-size:96px}.elementor-widget-template-empty-templates-footer{color:var(--e-a-color-txt-muted);font-size:13px;font-style:italic;margin-block-end:15px}.elementor-button-spinner.error:before{content:"\f335";color:red}span.font-variations-count{display:inline-block;vertical-align:top;margin:1px 0 0 5px;padding:0 5px;min-width:7px;height:17px;border-radius:11px;background-color:#d4dffb;color:#4278b2;font-size:9px;line-height:17px;text-align:center;z-index:26}.post-type-elementor_font div#elementor-font-custommetabox{background:none;border:0}.post-type-elementor_font div#elementor-font-custommetabox button.handlediv{display:none}.post-type-elementor_font div#elementor-font-custommetabox #poststuff .inside{margin:0;padding:0}.post-type-elementor_font div#elementor-font-custommetabox h2.hndle{padding:0}.post-type-elementor_font #minor-publishing-actions,.post-type-elementor_font #misc-publishing-actions,.post-type-elementor_font #tagsdiv-elementor_font_type,.post-type-elementor_font div#elementor-font-custommetabox .handle-actions{display:none}.elementor-metabox-content .repeater-block{background:#fff;color:#3f444b;padding:20px;margin-block-end:2px}.elementor-metabox-content .repeater-block span.elementor-repeater-tool-btn.close-repeater-row{display:none}.elementor-metabox-content .repeater-block.block-visible{padding-block-end:0;margin-block-end:0}.elementor-metabox-content .repeater-block.block-visible span.elementor-repeater-tool-btn.toggle-repeater-row{display:none}.elementor-metabox-content .repeater-block.block-visible span.elementor-repeater-tool-btn.close-repeater-row{display:inline-block}.elementor-metabox-content .repeater-block:not(.block-visible) .close-repeater-row{display:none}.elementor-metabox-content .repeater-block .repeater-title{cursor:pointer}.elementor-metabox-content .row-font-label{padding:0;margin:0;display:flex;text-transform:capitalize}.elementor-metabox-content .row-font-label li{box-sizing:border-box;flex-grow:1;width:100%;margin:0}.elementor-metabox-content .row-font-label li span.label{font-weight:500;padding-inline-end:10px}.elementor-metabox-content .row-font-label li.row-font-style,.elementor-metabox-content .row-font-label li.row-font-weight{max-width:180px}.elementor-metabox-content .row-font-label li.row-font-actions{max-width:200px;text-align:end}.elementor-metabox-content .repeater-content{margin:0}.elementor-metabox-content .repeater-content .repeater-content-top{display:flex;margin-block-end:20px;line-height:28px}.elementor-metabox-content .repeater-content .repeater-content-top>div{box-sizing:border-box;flex-grow:1}.elementor-metabox-content .repeater-content .repeater-content-top p{margin:0;display:inline-block}.elementor-metabox-content .repeater-content .repeater-content-top p label{font-weight:500;padding-inline-end:10px}.elementor-metabox-content .repeater-content .repeater-content-top .elementor-field-select{max-width:180px}.elementor-metabox-content .repeater-content .repeater-content-top .elementor-field-toolbar{max-width:200px;text-align:end}.elementor-metabox-content .repeater-content .repeater-content-bottom{background-color:#f9fafa;padding:20px 40px;margin:0 -20px}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field{display:flex;align-items:center;background-color:#fff;padding:10px 20px;margin-block-end:10px;box-shadow:0 3px 5px rgba(0,0,0,.05)}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field:last-child{margin-block-end:0}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field input,.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field p{box-sizing:border-box;flex-grow:1;width:100%;margin:0}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field p.elementor-field-label{font-weight:500;max-width:120px}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-field-input{padding:5px 8px;margin:0 15px;border-radius:3px;font-size:12px;width:100%;background:none;box-shadow:none;color:#0c0d0e;border:1px solid;outline:none}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-field-input:not(:focus){border-color:#d5d8dc}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-field-input:focus{border-color:#9da5ae}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-upload-btn,.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-upload-clear-btn{max-width:100px;font-size:11px}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-upload-clear-btn{background-color:#f1f2f3;color:#9da5ae}.elementor-metabox-content .repeater-content .repeater-content-bottom .elementor-field .elementor-upload-clear-btn:hover{background-color:#f59e0b;color:#fff}.elementor-metabox-content .elementor-button{background-color:#9da5ae;color:#fff;line-height:1;text-transform:uppercase;height:auto;padding:10px 20px;outline:none;border:none;transition-property:background,color,box-shadow,opacity;transition-duration:.3s}.elementor-metabox-content .elementor-button:focus,.elementor-metabox-content .elementor-button:hover,.elementor-metabox-content .elementor-button:visited{color:#fff}.elementor-metabox-content .elementor-button:focus,.elementor-metabox-content .elementor-button:visited{background-color:#9da5ae}.elementor-metabox-content .elementor-button:hover{background-color:#3f444b;box-shadow:0 0 2px rgba(0,0,0,.12),0 2px 2px rgba(0,0,0,.2);border:none}.elementor-metabox-content .elementor-button:active{box-shadow:0 5px 10px rgba(0,0,0,.19),0 3px 3px rgba(0,0,0,.1)}.elementor-metabox-content .elementor-button:not([disabled]){cursor:pointer}.elementor-metabox-content .elementor-button.elementor-size-xs{font-size:11px;padding:10px 20px;border-radius:2px}.elementor-metabox-content .elementor-button.elementor-size-sm{font-size:13px;padding:12px 24px;border-radius:3px}.elementor-metabox-content .elementor-button.elementor-size-md{font-size:14px;padding:15px 30px;border-radius:4px}.elementor-metabox-content .elementor-button.elementor-size-lg{font-size:15px;padding:20px 40px;border-radius:5px}.elementor-metabox-content .elementor-button.elementor-size-xl{font-size:18px;padding:25px 50px;border-radius:6px}.elementor-metabox-content .elementor-button .elementor-align-icon-right{float:right;margin-left:5px}.elementor-metabox-content .elementor-button .elementor-align-icon-left{float:left;margin-right:5px}.elementor-metabox-content input.button.add-repeater-row{margin-block-start:18px;border:none;box-shadow:none}.elementor-metabox-content .elementor-repeater-tool-btn{color:#9da5ae;cursor:pointer;padding:0 20px;font-size:12px;transition:all .3s}.elementor-metabox-content .elementor-repeater-tool-btn i{padding-inline-end:5px}.elementor-metabox-content .elementor-repeater-tool-btn:hover{color:#3f444b}.elementor-metabox-content .elementor-repeater-tool-btn.remove-repeater-row:hover{color:#f59e0b}.elementor-metabox-content .inline-preview,.elementor-metabox-content .row-font-preview{font-size:16px;text-transform:capitalize}.column-font_preview{width:65%}.widefat td.column-font_preview{font-size:16px}.post-type-elementor_icons .elementor-metabox-content .elementor-button:not([disabled]){margin-block-start:10px}.post-type-elementor_icons div#postbox-container-1{display:none}.post-type-elementor_icons div#elementor-custom-icons-metabox{display:none;border:1px solid #f1f2f3;border-radius:1px;background-color:#fff}.post-type-elementor_icons div#elementor-custom-icons-metabox .inside{margin-block-start:10px;margin-block-end:20px}.post-type-elementor_icons div#elementor-custom-icons-metabox .elementor-metabox-content{background-color:#fff}.post-type-elementor_icons div#elementor-custom-icons-metabox .elementor-custom-icons-metabox{padding-block-start:4px;padding-block-end:10px;padding-inline-start:10px;padding-inline-end:10px}@media (max-width:1025px){.post-type-elementor_icons div#elementor-custom-icons-metabox .elementor-custom-icons-metabox{padding:0}}.post-type-elementor_icons div#elementor-custom-icons-metabox h4{color:#1f2124;font-size:22px;font-weight:500;letter-spacing:.7px;line-height:28px;margin:0 0 4px}.post-type-elementor_icons div#elementor-custom-icons-metabox h5{color:#9da5ae;font-size:16px;font-weight:500;letter-spacing:.5px;line-height:21px;margin:0}.post-type-elementor_icons div#elementor-custom-icons-metabox .elementor--dropzone--upload__icon i{font-size:64px;color:#0a875a}.post-type-elementor_icons div#elementor-custom-icons-metabox .box__error,.post-type-elementor_icons div#elementor-custom-icons-metabox .box__file,.post-type-elementor_icons div#elementor-custom-icons-metabox .box__success,.post-type-elementor_icons div#elementor-custom-icons-metabox .box__uploading{display:none}.post-type-elementor_icons div#elementor-custom-icons-metabox .is-dragover{background-color:grey}.post-type-elementor_icons div#elementor-custom-icons-metabox .box__input{padding:180px 0;display:flex;flex-direction:column;align-items:center}.post-type-elementor_icons div#elementor-custom-icons-metabox .elementor-field-dropzone{outline:2px dashed #d5d8dc;outline-offset:-3px;background-color:#fff;display:none}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons{background-color:#f9fafa;border:1px solid #f1f2f3;border-radius:1px}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-metabox-content{background-color:#f9fafa}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-metabox-content .elementor-custom-icons-metabox{padding-block-start:4px;padding-block-end:0;padding-inline-start:10px;padding-inline-end:10px}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header{height:50px;color:#3f444b;background-color:#fff;box-shadow:0 2px 6px 0 rgba(0,0,0,.06);padding:0 35px;display:flex;align-items:center;justify-content:flex-start}@media (max-width:1025px){.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header{padding:0 6px}}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header div{padding-inline-end:10px;padding-inline-start:10px}@media (max-width:1025px){.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header div{line-height:1}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header div.remove{font-size:10px}}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header div:nth-of-type(2){border:1px solid #9da5ae;border-block-start:0;border-block-end:0}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta{color:#1f2124;font-size:14px;line-height:1}@media (max-width:1025px){.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta{font-size:10px}}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta-value{font-weight:700}@media (max-width:1025px){.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta-value{font-size:10px}}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta-remove{margin-inline-start:auto;color:#1f2124;opacity:.6;cursor:pointer;transition:all .3s}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta-remove i{color:#3f444b}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-header-meta-remove:hover{opacity:1}.post-type-elementor_icons div#elementor-custom-icons-metabox.elementor--has-icons .elementor-icon-set-footer{color:#babfc5;font-family:Roboto,Arial,Helvetica,sans-serif;border-block-start:1px solid #f1f2f3;font-size:11px;font-weight:500;line-height:1;text-align:end;padding-block-start:10px;padding-block-end:10px;padding-inline-end:35px}.post-type-elementor_icons div#elementor-custom-icons-metabox ul{display:grid;grid-template-columns:repeat(auto-fill,minmax(105px,1fr));grid-gap:20px;padding-block-start:15px;padding-block-end:0;padding-inline-start:35px;padding-inline-end:35px;overflow-y:auto;max-height:575px}.post-type-elementor_icons div#elementor-custom-icons-metabox ul li{position:relative;height:0;padding-block-end:100%;background-color:#fff;box-shadow:0 1px 12px rgba(0,0,0,.05);border-radius:3px;overflow:hidden}.post-type-elementor_icons div#elementor-custom-icons-metabox ul li div.icon{display:flex;flex-direction:column;align-items:center;width:100%;position:absolute;top:50%;left:50%;transform:translate(-50%,-50%);padding:1px}.post-type-elementor_icons div#elementor-custom-icons-metabox ul li div.icon-name{color:#babfc5;font-size:11px;padding:18px 20px 0;white-space:nowrap;max-width:100%;overflow:hidden;text-overflow:ellipsis}@media (max-width:479px){.post-type-elementor_icons div#elementor-custom-icons-metabox ul li div.icon-name{display:none}}.post-type-elementor_icons div#elementor-custom-icons-metabox ul li i{font-size:32px}.post-type-elementor_icons #minor-publishing-actions,.post-type-elementor_icons #misc-publishing-actions,.post-type-elementor_icons #tagsdiv-elementor_icon_type{display:none}.column-icons_prefix{width:65%}:root{--color-box-shadow-color:rgba(0,0,0,0.05)}.eps-theme-dark{--color-box-shadow-color:rgba(0,0,0,0.1)}.eps-grid-container{display:flex;flex-wrap:wrap;width:100%}.eps-grid-container--no-wrap{flex-wrap:nowrap}.eps-grid-container--wrap-reverse{flex-wrap:wrap-reverse}.eps-grid-container--spacing{--grid-row-gutter:calc(-1 * calc(var(--grid-spacing-gutter) * (0.625rem / 10)));width:var(--grid-spacing-width);margin:var(--grid-row-gutter)}.eps-grid-container--spacing>.eps-grid-item{padding:var(--grid-spacing-gutter)}.eps-grid--direction-row{flex-direction:row}.eps-grid--direction-row-reverse{flex-direction:row-reverse}.eps-grid--direction-column{flex-direction:column}.eps-grid--direction-column-reverse{flex-direction:column-reverse}.eps-grid--justify-stretch{justify-content:stretch}.eps-grid--justify-start{justify-content:flex-start}.eps-grid--justify-center{justify-content:center}.eps-grid--justify-end{justify-content:flex-end}.eps-grid--justify-space-between{justify-content:space-between}.eps-grid--justify-space-around{justify-content:space-around}.eps-grid--justify-space-evenly{justify-content:space-evenly}.eps-grid--align-content-stretch{align-content:stretch}.eps-grid--align-content-start{align-content:flex-start}.eps-grid--align-content-center{align-content:center}.eps-grid--align-content-end{align-content:flex-end}.eps-grid--align-content-space-between{align-content:space-between}.eps-grid--align-items-start{align-items:flex-start}.eps-grid--align-items-center{align-items:center}.eps-grid--align-items-end{align-items:flex-end}.eps-grid--align-items-baseline{align-items:baseline}.eps-grid--align-items-stretch{align-items:stretch}.eps-grid-item--zero-min-width{min-width:0}@media screen and (min-width:480px){.eps-grid-item-sm{flex-grow:1;max-width:100%;flex-basis:0}}@media screen and (min-width:768px){.eps-grid-item-md{flex-grow:1;max-width:100%;flex-basis:0}}@media screen and (min-width:1025px){.eps-grid-item-lg{flex-grow:1;max-width:100%;flex-basis:0}}@media screen and (min-width:1440px){.eps-grid-item-xl{flex-grow:1;max-width:100%;flex-basis:0}}@media screen and (min-width:1600px){.eps-grid-item-xxl{flex-grow:1;max-width:100%;flex-basis:0}}.eps-grid-item-xs-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-xs-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-xs-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-xs-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-xs-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-xs-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-xs-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-xs-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-xs-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-xs-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-xs-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-xs-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}@media screen and (min-width:480px){.eps-grid-item-sm-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-sm-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-sm-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-sm-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-sm-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-sm-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-sm-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-sm-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-sm-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-sm-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-sm-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-sm-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}}@media screen and (min-width:768px){.eps-grid-item-md-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-md-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-md-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-md-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-md-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-md-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-md-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-md-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-md-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-md-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-md-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-md-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}}@media screen and (min-width:1025px){.eps-grid-item-lg-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-lg-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-lg-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-lg-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-lg-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-lg-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-lg-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-lg-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-lg-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-lg-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-lg-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-lg-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}}@media screen and (min-width:1440px){.eps-grid-item-xl-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-xl-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-xl-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-xl-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-xl-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-xl-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-xl-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-xl-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-xl-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-xl-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-xl-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-xl-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}}@media screen and (min-width:1600px){.eps-grid-item-xxl-1{flex-grow:0;max-width:calc(1 / 12 * 100%);flex-basis:calc(1 / 12 * 100%)}.eps-grid-item-xxl-2{flex-grow:0;max-width:calc(2 / 12 * 100%);flex-basis:calc(2 / 12 * 100%)}.eps-grid-item-xxl-3{flex-grow:0;max-width:calc(3 / 12 * 100%);flex-basis:calc(3 / 12 * 100%)}.eps-grid-item-xxl-4{flex-grow:0;max-width:calc(4 / 12 * 100%);flex-basis:calc(4 / 12 * 100%)}.eps-grid-item-xxl-5{flex-grow:0;max-width:calc(5 / 12 * 100%);flex-basis:calc(5 / 12 * 100%)}.eps-grid-item-xxl-6{flex-grow:0;max-width:calc(6 / 12 * 100%);flex-basis:calc(6 / 12 * 100%)}.eps-grid-item-xxl-7{flex-grow:0;max-width:calc(7 / 12 * 100%);flex-basis:calc(7 / 12 * 100%)}.eps-grid-item-xxl-8{flex-grow:0;max-width:calc(8 / 12 * 100%);flex-basis:calc(8 / 12 * 100%)}.eps-grid-item-xxl-9{flex-grow:0;max-width:calc(9 / 12 * 100%);flex-basis:calc(9 / 12 * 100%)}.eps-grid-item-xxl-10{flex-grow:0;max-width:calc(10 / 12 * 100%);flex-basis:calc(10 / 12 * 100%)}.eps-grid-item-xxl-11{flex-grow:0;max-width:calc(11 / 12 * 100%);flex-basis:calc(11 / 12 * 100%)}.eps-grid-item-xxl-12{flex-grow:0;max-width:calc(12 / 12 * 100%);flex-basis:calc(12 / 12 * 100%)}}:root{--eps-modal-background-color:#fff;--eps-modal-header-background-color:#2563eb;--eps-tip-background-color:#f0f7ff}.eps-theme-dark{--eps-modal-background-color:#0c0d0e;--eps-modal-header-background-color:#07c;--eps-tip-background-color:#0a1a3d}.eps-modal{max-width:43.75rem;background:var(--eps-modal-background-color);border-radius:.1875rem;animation:fade-in .4s ease-in both}.eps-modal__overlay{background:rgba(0,0,0,.5);position:fixed;display:flex;top:0;left:0;width:100%;height:100%;align-items:center;justify-content:center;z-index:1030}.eps-modal__header{font-size:.875rem;background:var(--eps-modal-header-background-color);height:2.75rem;padding:.625rem 1rem;border-radius:.1875rem}.eps-modal__header,.eps-modal__header .title{color:#fff}.eps-modal__icon{margin-inline-end:.625rem}.eps-modal__body{padding:1.875rem}.eps-modal .eps-tip,.eps-modal__tip{padding:.5rem;padding-inline-start:.75rem;border-inline-start:3px solid #2563eb;background-color:var(--eps-tip-background-color)}.eps-modal .eps-tip:not(:last-child),.eps-modal__tip:not(:last-child){margin-bottom:1.875rem}.eps-modal .eps-tip:not(:first-child),.eps-modal__section:not(:first-child),.eps-modal__tip:not(:first-child){margin-top:1.875rem}.eps-modal__close-wrapper{padding-inline-start:1rem;border-inline-start:solid 1px #fff}.eps-button{display:inline-flex;--button-line-height:16px;--button-padding-y:0.5em;--button-padding-x:1.5em;--button-primary-background-color:#f3bafd;--button-primary-hover-background-color:#f5d0fe;--button-primary-active-background-color:#f3bafd;--button-primary-color:#0c0d0e;--button-secondary-background-color:#69727d;--button-secondary-hover-background-color:#525961;--button-secondary-active-background-color:#3a3f46;--button-secondary-color:#fff;--button-danger-background-color:#dc2626;--button-danger-hover-background-color:#b21d1d;--button-danger-active-background-color:#861616;--button-danger-color:#fff;--button-cta-background-color:#524cff;--button-cta-hover-background-color:#2119ff;--button-cta-active-background-color:#0800e5;--button-cta-color:#fff;--button-brand-background-color:#524cff;--button-brand-hover-background-color:#2119ff;--button-brand-active-background-color:#0800e5;--button-brand-color:#fff;--button-link-background-color:#515962;--button-link-hover-background-color:#3a4046;--button-link-active-background-color:#23262a;--button-link-color:#fff;--button-disabled-background-color:#d5d8dc;--button-disabled-hover-background-color:#b9bec5;--button-disabled-active-background-color:#9da4ae;--button-disabled-color:#fff;color:var(--button-background-color,currentColor);font-size:var(--button-font-size,inherit);font-weight:500;line-height:var(--button-line-height);transition:var(--e-a-transition-hover);cursor:pointer}.eps-button:active{--button-background-color:var(--button-active-background-color,transparent)}.eps-button:hover{--button-background-color:var(--button-hover-background-color)}.eps-theme-dark .eps-button{--button-primary-background-color:#f3bafd;--button-primary-color:#0c0d0e;--button-primary-hover-background-color:#eb8efb;--button-primary-active-background-color:#f3bafd;--button-secondary-background-color:#babfc5;--button-secondary-color:#fff;--button-secondary-hover-background-color:#9ea5ae;--button-secondary-active-background-color:#838c96;--button-cta-background-color:#524cff;--button-cta-hover-background-color:#2119ff;--button-cta-active-background-color:#0800e5;--button-cta-color:#fff;--button-brand-hover-background-color:#2119ff;--button-brand-active-background-color:#0800e5;--button-brand-color:#fff;--button-brand-background-color:#524cff;--button-link-background-color:#515962;--button-link-hover-background-color:#3a4046;--button-link-active-background-color:#23262a;--button-link-color:#fff;--button-disabled-background-color:#69727d;--button-disabled-hover-background-color:#525961;--button-disabled-active-background-color:#3a3f46;--button-disabled-color:#fff}.eps-button--contained{padding:var(--button-padding-y) var(--button-padding-x);background-color:var(--button-background-color,transparent);border:1px solid var(--button-background-color)}.eps-button--contained,.eps-button--contained:hover{color:var(--button-color)}.eps-button--outlined{display:block;padding:var(--button-padding-y) var(--button-padding-x);border:1px solid var(--button-background-color)}.eps-button--contained,.eps-button--outlined{border-radius:.1875rem}.eps-button--underlined{text-decoration:underline}.eps-button--sm{--button-font-size:0.75rem;--button-line-height:14px}.eps-button--lg{--button-font-size:0.9375rem;--button-line-height:18px}.eps-button--primary{--button-color:var(--button-primary-color);--button-background-color:var(--button-primary-background-color);--button-hover-background-color:var(--button-primary-hover-background-color);--button-active-background-color:var(--button-primary-active-background-color)}.eps-button--secondary{--button-color:var(--button-secondary-color);--button-background-color:var(--button-secondary-background-color);--button-hover-background-color:var(--button-secondary-hover-background-color);--button-active-background-color:var(--button-secondary-active-background-color)}.eps-button--danger{--button-color:var(--button-danger-color);--button-background-color:var(--button-danger-background-color);--button-hover-background-color:var(--button-danger-hover-background-color);--button-active-background-color:var(--button-danger-active-background-color)}.eps-button--cta{--button-color:var(--button-brand-color);--button-background-color:var(--button-cta-background-color);--button-hover-background-color:var(--button-cta-hover-background-color);--button-active-background-color:var(--button-cta-active-background-color)}.eps-button--brand{--button-color:var(--button-cta-color);--button-background-color:var(--button-cta-background-color);--button-hover-background-color:var(--button-cta-hover-background-color);--button-active-background-color:var(--button-cta-active-background-color)}.eps-button--link{--button-color:var(--button-link-color);--button-background-color:var(--button-link-background-color);--button-hover-background-color:var(--button-link-hover-background-color);--button-active-background-color:var(--button-link-active-background-color)}.eps-button--disabled,.eps-button[disabled]{--button-color:var(--button-disabled-color);--button-background-color:var(--button-disabled-background-color);--button-hover-background-color:var(--button-disabled-hover-background-color);--button-active-background-color:var(--button-disabled-active-background-color);cursor:default}:root{--e-site-editor-conditions-row-controls-background:#fff;--e-site-editor-input-wrapper-border-color:#d5d8dc;--e-site-editor-input-wrapper-select-color:#3f444b;--e-site-editor-conditions-row-controls-border:1px solid #d5d8dc;--e-site-editor-add-button-background-color:#69727d;--e-site-editor-add-button-color-hover-background-color:#515962;--e-site-editor-input-wrapper-condition-include-background-color:#69727d;--e-site-editor-input-wrapper-condition-exclude-background-color:#818a96;--e-site-editor-input-select2-search-field-color:#515962 }.eps-theme-dark{--select2-selection-background-color:tints(600);--e-site-editor-conditions-row-controls-background:#515962;--e-site-editor-input-wrapper-border-color:#3f444b;--e-site-editor-input-wrapper-select-color:#babfc5;--e-site-editor-conditions-row-controls-border:1px solid #3f444b;--e-site-editor-add-button-background-color:#69727d;--e-site-editor-add-button-color-hover-background-color:#515962;--e-site-editor-input-wrapper-condition-include-background-color:#515962;--e-site-editor-input-wrapper-condition-exclude-background-color:#515962;--e-site-editor-input-select2-search-field-color:#fff }.e-site-editor-conditions__header{text-align:center}.e-site-editor-conditions__header-image{display:block;margin:0 auto 2.75rem;width:4.375rem}.e-site-editor-conditions__rows{margin:2.75rem auto;max-width:43.75rem}.e-site-editor-conditions__row{display:flex;flex-grow:1;margin-block-start:.75rem}.e-site-editor-conditions__remove-condition{color:#818a96;font-size:1.125rem;display:flex;align-items:center;justify-content:center}.e-site-editor-conditions__row-controls{overflow:hidden;margin-inline-end:.625rem;background-color:var(--e-site-editor-conditions-row-controls-background);display:flex;width:100%;border:var(--e-site-editor-conditions-row-controls-border);border-radius:.1875rem}.e-site-editor-conditions__row-controls--error{border:1px solid #dc2626}.e-site-editor-conditions__conflict{text-align:center;margin-block-start:.3125rem;color:#dc2626}.e-site-editor-conditions__row-controls-inner{width:100%;display:flex}.e-site-editor-conditions__row-controls-inner div{flex:1}.e-site-editor-conditions__add-button-container{text-align:center}.e-site-editor-conditions__add-button{margin-block-start:2.75rem;background-color:var(--e-site-editor-add-button-background-color);color:#fff;text-transform:uppercase}.e-site-editor-conditions__add-button:hover{background-color:var(--e-site-editor-add-button-color-hover-background-color);color:#fff}.e-site-editor-conditions__footer{display:flex;justify-content:flex-end;position:absolute;bottom:0;right:0;left:0;padding:.5rem;border-block-start:1px solid var(--hr-color)}.e-site-editor-conditions__input-wrapper{position:relative;padding-inline-start:1px solid;border-color:var(--e-site-editor-input-wrapper-border-color)}.e-site-editor-conditions__input-wrapper:first-child{border:none}.e-site-editor-conditions__input-wrapper select{-moz-appearance:none;appearance:none;-webkit-appearance:none;font-size:.75rem;height:2.5rem;border-width:0;padding:0 .625rem;width:100%;position:relative;color:var(--e-site-editor-input-wrapper-select-color);outline:none;background:transparent}.e-site-editor-conditions__input-wrapper:after{font-family:eicons;content:"\e8ad";font-size:.75rem;pointer-events:none;position:absolute;top:50%;transform:translateY(-50%);left:.625rem}.e-site-editor-conditions__input-wrapper .select2-container--default .select2-selection--single{border:none;line-height:2.5rem}.e-site-editor-conditions__input-wrapper .select2-container--default .select2-selection--single .select2-selection__rendered{line-height:2.5rem;font-size:.75rem}.e-site-editor-conditions__input-wrapper .select2-selection{outline:none;background:transparent;height:2.5rem}.e-site-editor-conditions__input-wrapper .select2-selection__arrow{display:none}.e-site-editor-conditions__input-wrapper--condition-type{position:relative}.e-site-editor-conditions__input-wrapper--condition-type:before{font-family:eicons;position:absolute;top:50%;transform:translateY(-50%);right:.75rem;font-size:.9375rem;pointer-events:none;z-index:1000}.e-site-editor-conditions__input-wrapper--condition-type select{text-transform:uppercase;padding-inline-start:2.125rem;width:7.5rem;font-size:.75rem;border-inline-end:1px solid;border-color:var(--e-site-editor-input-wrapper-border-color)}.e-site-editor-conditions__input-wrapper--condition-type[data-elementor-condition-type=include]:before{content:"\e8cc"}.e-site-editor-conditions__input-wrapper--condition-type[data-elementor-condition-type=exclude]:before{content:"\e8cd"}.select2-search__field{background-color:transparent;color:var(--e-site-editor-input-select2-search-field-color)}.misc-pub-visibility{display:none}.eps-modal__overlay{background:rgba(0,0,0,.8);z-index:9999}.select2-container{z-index:9999}.post-conditions .spinner{margin:0 10px;float:none;visibility:visible}.post-conditions .eps-button--underlined{color:#0073aa}.post-conditions .eps-modal{position:relative;background:#f1f3f5;max-width:1200px;max-height:800px;width:90vw;height:90vh;margin:auto}.post-conditions .eps-modal .eps-modal__body{display:flex;flex-direction:column;flex-grow:1}.post-conditions .eps-modal .eps-h1{font-size:30px;font-weight:300}.post-conditions .eps-modal .eps-text{font-size:18px;line-height:150%;margin:1em 0;color:#9da5ae}.post-conditions .eps-modal .eps-grid-container{width:auto}.post-conditions .eps-modal__header{background:#fff;color:#1f2124;box-shadow:0 0 8px rgba(0,0,0,.1);padding:2px 15px}.post-conditions .eps-modal__header .eps-app__logo{width:1.75rem;height:1.75rem;line-height:1.75rem;text-align:center;font-size:.7rem;border-radius:50%;color:#fff;background-color:#93003f}.post-conditions .eps-modal__header .eps-text{position:relative;top:2px;font-size:.9375rem;font-weight:700;text-transform:uppercase;color:#6d7882}.post-conditions .eps-modal__header .eps-button{font-size:18px}.post-conditions .eps-modal .e-site-editor-conditions__header{padding-block-start:5vh}.post-conditions .eps-modal .e-site-editor-conditions__rows{overflow-y:auto;max-height:27vh;margin:0 auto}.post-conditions .eps-modal .e-site-editor-conditions__rows:empty{margin-block-end:30px}.post-conditions .eps-modal .e-site-editor-conditions__rows:not(:empty){margin-block-end:20px}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row{margin-block-start:15px;padding:0 14px}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls{border-radius:0}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls select{text-transform:none}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls select:focus{box-shadow:none;border:none;color:inherit}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls select:hover{color:inherit}.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls .e-site-editor-conditions__input-wrapper--condition-type select:focus,.post-conditions .eps-modal .e-site-editor-conditions__rows .e-site-editor-conditions__row-controls .e-site-editor-conditions__input-wrapper--condition-type select:hover{color:#fff}.post-conditions .eps-modal .e-site-editor-conditions__add-button{margin-block-start:0}.post-conditions .eps-modal .e-site-editor-conditions__footer{z-index:1000;border-block-start:1px solid #d5dadf}#elementor-custom-code.postbox{border:0}#elementor-custom-code .postbox-header{display:none}#elementor-custom-code .inside{padding:0}#elementor-custom-code .inside .elementor-custom-code-meta-box{margin:0}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel{border:1px solid #f1f2f3;border-block-end:1px solid #ccd0d4;background:#fff}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-custom-code-panel-placement{padding:5px 40px;margin:10px 0;flex-wrap:wrap;gap:10px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-custom-code-options-placement{display:none}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-custom-code-options-placement.show,#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel div{display:flex}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field i{color:#babfc5;font-size:15px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field select{height:20px;margin-block-start:7px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field select#location{direction:ltr}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field.priority{margin-inline-start:auto}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field.location{margin-inline-end:10px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field-label{font-weight:500;font-size:14px;line-height:16px;color:#3f444b}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field-label:nth-child(2n){margin-inline-end:20px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field-label:nth-child(odd){margin-inline-end:5px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field-checkboxes{padding-block-start:18px}#elementor-custom-code .inside .elementor-custom-code-meta-box .elementor-custom-code-panel .elementor-field-checkboxes .label{position:relative;top:-5px}#elementor-custom-code .inside .elementor-custom-code-codemirror-holder{border:1px solid #f1f2f3;background:#f9fafa;padding:40px}#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-field-label{margin:0}#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-custom-code-codemirror{border:1px solid #ccd0d4;resize:vertical;overflow:auto;max-width:100%}#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-custom-code-codemirror .CodeMirror-scroll,#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-custom-code-codemirror .CodeMirror.CodeMirror-wrap,#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-custom-code-codemirror .elementor-field-textarea{height:100%}#elementor-custom-code .inside .elementor-custom-code-codemirror-holder .elementor-custom-code-codemirror .CodeMirror-sizer{min-height:300px!important;border-right:0}.post-type-elementor_snippet #minor-publishing-actions,.post-type-elementor_snippet #save-action{display:none}.e--ua-safari #elementor-custom-code .elementor-custom-code-codemirror{background-color:var(--e-a-bg-default);display:flex}.e--ua-safari #elementor-custom-code .elementor-custom-code-codemirror .elementor-field-textarea{width:calc(100% - 8px)}.e--ua-safari #elementor-custom-code .elementor-custom-code-codemirror .CodeMirror-sizer{box-sizing:border-box}@media (max-height:825px),(max-width:850px){.post-conditions .eps-modal{width:100vw;height:90vh}.post-conditions .eps-modal .e-site-editor-conditions__header{padding-block-start:0}.post-conditions .eps-modal .e-site-editor-conditions__rows{max-height:14vh}.post-conditions .eps-modal .e-site-editor-conditions__header-image{margin:0 auto}}@media (max-height:666px),(max-width:590px){.post-conditions .eps-modal .eps-modal__body{overflow:auto;height:calc(100vh - 200px)}.post-conditions .eps-modal .eps-modal__body .e-site-editor-conditions__footer{background:#f1f3f5}}
Fake Flashplayer Update Via Exploit Using Adverts On Legit Site
Skip to content
For a change this is about an exploit, rather than a malspam email.
I was reading posts on a well known tech forum, when I got a sudden divert and a .hta file attempted to download. Of course I immediately saved the file, rather than letting it run. I won’t name the tech forum at this stage, to allow the admin time to investigate and check what advert I think caused it. It was an advert for HP laserjet printers that was not using flash but did have moving images. I think the divert happened when I moused over the advert whilst scrolling down the page.
Anyway the divert was to https://eiyahpornhub.org/5101454380687/6481137a7f7240574c225b198be9c16d/34cacd8a11e39b3bbc01955b9b1eac15.html ( note the “safe Secure ” https: link) HTTPS does not mean safe. It means secure from interception in normal circumstances.
Update: it looks like the link is dynamically created and changes on each visit from the referrer ( the dodgy advert) . I haven’t been able to get back to the site and get a 404 every time. I can get the .jse file and multiple visits to that is allowed. Lots of exploits refuse to let the same IP & referral id more than 1 attempt to visits to stop antivirus companies and researchers investigating them easily.
This downloaded FlashPlayer.hta ( VirusTotal ) ( Payload Security) which is just an instruction to the computer to use PowerShell to download silently in the background https://eiyahpornhub.org/5101454380687/1491733844471718/FlashPlayer.jse ( VirusTotal ) ( Payload Security) which isn’t showing any further downloads, so I have no idea at this stage what the end malware is intended to be.
This seems very similar to the campaign posted on https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/
In both cases nobody has actually got the final payload. All I managed to get was https://eiyahpornhub.org/67d05900efa21668e417c34f5adb32e1.mp4 ( now down) VirusTotal | MALWR which is just plain txt ( possibly encrypted) that would need the original jse file to decrypt it to something useful. (If it is encrypted txt and not just some sort of identity string )
Whole package as a P/W zip file “infected” 9 april_ fake_flash_player_malvertising just in case some other researcher can make use of it
eiyahpornhub.org was registered yesterday 8 April 2021 https://whois.icann.org/en/lookup?name=eiyahpornhub.org I very much doubt that the listed registrants details are correct. They are probably stolen details and credit card used to register this domain
It appears to be hosted on 192.129.162.108 allegedly used by a Russian entity
Network Whois Record
Queried rwhois.hostwinds.com with “192.129.162.108 “…
%rwhois V-1.5:003fff:00 rwhois.hostwinds.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:Hostwinds Block-192.129.162.108/32
network:Auth-Area:192.129.162.108/32
network:Network-Name:SergSoft Network
network:IP-Network:192.129.162.108/32
network:IP-Network-Block:192.129.162.108 - 192.129.162.108
network:Customer Organization:SergSoft
network:Customer Address;I:Krasniy Kazanetz 1-2-88
network:Customer City;I:Moscow
network:Customer State/Province;I:RU
network:Customer Postal Code;I:111395
network:Customer Country Code;I:RU
network:Organization;I:Hostwinds LLC
network:Tech-Contact;I:Abuse@hostwinds.com
network:Admin-Contact;I:Abuse@hostwinds.com
network:Abuse-Contact;I:Abuse@hostwinds.com
%ok
Queried whois.arin.net with “n 192.129.162.108 “…
NetRange: 192.129.128.0 - 192.129.255.255
CIDR: 192.129.128.0/17
NetName: HOSTWINDS-17-1
NetHandle: NET-192-129-128-0-1
Parent: NET192 (NET-192-0-0-0-0)
NetType: Direct Allocation
OriginAS: AS54290
Organization: Hostwinds LLC. (HL-29)
RegDate: 2013-01-30
Updated: 2013-12-19
Ref: https://whois.arin.net/rest/net/NET-192-129-128-0-1
OrgName: Hostwinds LLC.
OrgId: HL-29
Address: 1002 Reunion Center, 9 East 4th Street
City: Tulsa
StateProv: OK
PostalCode: 74103
Country: US
RegDate: 2011-11-30
Updated: 2017-01-28
Comment: http://www.hostwinds.com
Comment: Standard NOC hours are 6:00am to 12:00am CST
Ref: https://whois.arin.net/rest/org/HL-29
ReferralServer: rwhois://rwhois.hostwinds.com:4321
OrgTechHandle: HNOC9-ARIN
OrgTechName: Hostwinds Network Operations Center
OrgTechPhone: +1-206-886-0665
OrgTechEmail: support@hostwinds.com
OrgTechRef: https://whois.arin.net/rest/poc/HNOC9-ARIN
OrgAbuseHandle: HAC3-ARIN
OrgAbuseName: Hostwinds Abuse Center
OrgAbusePhone: +1-206-886-0665
OrgAbuseEmail: abuse@hostwinds.com
OrgAbuseRef: https://whois.arin.net/rest/poc/HAC3-ARIN
OrgNOCHandle: HNOC9-ARIN
OrgNOCName: Hostwinds Network Operations Center
OrgNOCPhone: +1-206-886-0665
OrgNOCEmail: support@hostwinds.com
OrgNOCRef: https://whois.arin.net/rest/poc/HNOC9-ARIN
DNS Records
name
class
type
data
time to live
eiyahpornhub.org
IN
SOA
server:
ns21.cloudns.net
email:
support@cloudns.net
serial:
2017040912
refresh:
7200
retry:
1800
expire:
1209600
minimum ttl:
3600
3600s
(01:00:00)
eiyahpornhub.org
IN
A
192.129.162.108
60s
(00:01:00)
eiyahpornhub.org
IN
MX
preference:
10
exchange:
mail.eiyahpornhub.org
60s
(00:01:00)
eiyahpornhub.org
IN
NS
ns23.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
pns22.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
pns24.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
ns22.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
pns21.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
pns23.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
ns24.cloudns.net
3600s
(01:00:00)
eiyahpornhub.org
IN
NS
ns21.cloudns.net
3600s
(01:00:00)
108.162.129.192.in-addr.arpa
IN
PTR
client-192-129-162-108.hostwindsdns.com
14400s
(04:00:00)
162.129.192.in-addr.arpa
IN
SOA
server:
162.129.192.in-addr.arpa
email:
hostmaster@162.129.192.in-addr.arpa
serial:
2017032407
refresh:
10800
retry:
3600
expire:
604800
minimum ttl:
3600
600s
(00:10:00)
Traceroute
Tracing route to eiyahpornhub.org [192.129.162.108] …
hop
rtt
rtt
rtt
ip address
fully qualified domain name
1
177
0
30
208.101.16.73
49.10.65d0.ip4.static.sl-reverse.com
2
0
0
0
66.228.118.153
ae11.dar01.sr01.dal01.networklayer.com
3
0
0
0
173.192.18.254
ae14.bbr02.eq01.dal03.networklayer.com
4
0
0
0
4.35.184.45
ae57.edge6.dallas3.level3.net
7
0
2
5
23.238.104.129
client-23-238-104-129.hostwindsdns.com
8
1
0
0
192.129.162.108
client-192-129-162-108.hostwindsdns.com