| Massive iframe injection hits several CMS |
| on Thursday, 13 December 2012. Posted in Malware Reports Viewed 3825 times | |
![]() A massive iframe injection is currently affecting a large number of websites running Joomla, WordPress, Drupal, the Yii Framework...
Initially the malicious URLs did end in nighttrend.cgi?8 but now the URLs are partially randomized. At the time of the write up the iframe on compromised websites points to: jpscu.freewww.info/tgewogjqog9.cgi?4
The malicious domains act as a rotator. A rotator is a link to a Traffic Management System and it will point users to different destinations each time the link is requested or deliver different content based on the geographic location of the visitor. They might also include the name of the group spreading the malware or a campaign ID. In this particular hacking spree the cyber criminals are using the Sutra TDS (Traffic Distribution System). From jpscu.freewww.info the visitor is redirected to ggysxf.freewww.biz where a Blackhole Exploit Kit is awaiting the visitor. ggysxf.freewww.biz/goodday/fresh/paper-rates_operators-apologys.php Malicious iframeThe malicious code has been injected in every single javascript file highlighted in green. As a result the domain running the Sutra TDS is called several times but the visitor is only redirected once to the exploit kit, the other requests will be redirected to Google.
Joomla Site - www.versailles.com
WordPress Site - fossfotography.com
Website owners are advised to check for the presence of a web / root shell. If you don't know what a shell is, check out this topic. If you or your company is using FileZilla or a similar FTP client that stores passwords in plain text, you need to:
Make sure that EVERYTHING is up to date on your website and use strong passwords that are at least 16 characters long and include at least 1 or 2 special characters. Resources
If your website is affected and / or you have more information on how they got in, don’t hesitate to drop us a note via the Contact Form. If our research has helped you, please consider making a donation through PayPal. |
|