We just received three emails from Google notifying us that “Social engineering content detected” on our site. The URLs listed are not any pages that exist on the site as far as I can tell. They look to have some kind of encrypted payload. Here’s a deconstructed version of the “compromised” page:
URL: http://uglybaby[.]shop/_t/c/A1020005-16D6C7017C8987D0-B13CD29E
query string: ?l=AAA1pDCLsk5tSwQuqBQThuIWX3yhh1LqmV6avJjef7XGs2k0SEYYeZp5MLAXIhjnBA5Fid6oK7Q0SWvp2Cnq4OndqyBg6NyA+mJFsxOX4i5GzfdOoLjdleXWhlcQkEu2N+ymbrKW0IjrxDVk0QVfWSAfGSaDQzVpcwQm5LoKrXUAjZeupVnuiOtD6qJu1dX1RFhKZhgLO6mIdYb9JIdh9CtOwHbkQ+grSXKASXM=&c=AACoge9+dZL0rhevwITTbguIVujmIGAghBNHtzrSPlw3G2vpFTe1C9CeI9uQ6zShTgp9ZCgttRHpUlZ6/gaAGrhlI2WpkiuWIT4Drx2576adTGJ0+umLKuvroiDzd/Mn46q4+Bk25sNxSlbFeBvE8ipxyyXJRsgaGHSt46s1lAMcBKhCqBsAPoswHZ2tNEDzBBhVb8f/TdzyJwVM55pj4AAMrBn2bkB+0efFIt0Ji9mtFgPP8qUS2nUwJ9ekkPQvkCQu/ygQb8nQrdPGBA2T/lYhi4/O0/HKkq1jM++dXXSAzl+IiKGCZRoV2HKYVHZkJEinYkMipkO9W1+8hDs2jfBJ4wOAHQh/YqV2L0aX9zavO72ZoxX/OTot19PoS/f1DLLZxD4E95ULIyzEGSb7jLUw4i2BWv6iwxWgeCcmt1ZFBCiNRdPu/HBTq1lwQpMPRG5WD33xlDAvnxW3LNanrC19NTS7/vzCtmLL9g==
I have gone to the URLs but they only redirect back to home page but with https instead of http.
We don’t run ads. We do have user reviews but those are curated. I can’t think of how malicious content could have gotten on the site.
Does anyone have any experience with this? I’ve dealt with cleaning up PHP sites but I don’t know where to start with Shopify.
Thanks!