Jump to content
Pasticcera

Virus Wordpress

Recommended Posts

  • Moderators
Posted

Nu stiu daca a fost raportat deja atacul, scriptul pare a fi din perioada 2016-2018, dar, din ce m-am uitat peste el, face request-uri cu user agent de IE 7 pe Windows 7 si asteapta comenzi de la urmatoarele C&C:

  • giftmall.xyz
  • plfongoods.xyz
  • jormedmall.xyz
  • dsnycesale.xyz
  • oedipegoods.xyz

Domeniile sunt cu nameservere de Alibaba dar puncteaza catre IP-uri de Linode. Toate domeniile sunt inregistrate cu nume de americani (se vad pe whois).

Site-urile, daca le accesezi, afiseaza o pagina de login in chineza. Chestia asta plus faptul ca o parte din script e in chineza ma fac sa ma gandesc ca atacul e din China.

 

Am gasit in cache-ul de Google alte C&C-uri cautand dupa "define("GETDOM",getthisdom());":

  • taxcupdigital.xyz
  • wydingtrans.xyz
  • satpoaweb.xyz
  • recaeldata.xyz
  • crsrefcenter.xyz
  • vipeeshost.xyz
  • webintsoure.xyz
  • lokvaldigital.xyz
  • hnosostrans.xyz
  • hozemoweb.xyz
  • datascenter.pw
  • japandata.pw
  • digitalja.pw
  • datatrans.pw
  • digitalnetwork.pw
  • eatmhgdata.xyz
  • tqmgrpcenter.xyz
  • avordesoure.xyz
  • gulbendigital.xyz
  • tignoltrans.xyz

 

  • Thanks 1
  • Upvote 2

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...