Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Replying to the Guy with the "crander" "wp_cron" and "wp_update" malware


  • This topic is locked This topic is locked
7 replies to this topic

#1 tynology

tynology

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:01:01 AM

Posted 25 June 2024 - 01:55 PM

Created this account to help the guy but my permissions don't allow me to reply to his post. I just spent a week cleaning the exact same issue. This is what I had to do:

 

Go through and clean all malicious code (it seems to corrupt common themes in the fuctions.php, footer.php and header.php files), delete unused themes, change all admin passwords, change hosting/cpanel password, ftp password(s), and most importantly, change the database password (and update wp-config with the new password). Make sure all plugins and WP is up to date. If any of the auto-created users come back, repeat the process. Do a Wordfence scan and keep an eye on the users (turn on admin login email notifications in Wordfence just in case).


Edited by hamluis, 25 June 2024 - 02:18 PM.
Moved from MRL to Gen Sec - Hamluis.


BC AdBot (Login to Remove)

 


#2 Dominique1

Dominique1

    Bleepin Funny


  •  Avatar image
  • Members
  • 1,027 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:12:01 AM

Posted 25 June 2024 - 04:32 PM

Which topic are you replying?  Perhaps this new one:

https://www.bleepingcomputer.com/forums/t/798508/i-need-help-wordpress-malware/

 

Out of curiosity, what might be the point of entry?  Perhaps a vulnerability mentioned here:

https://www.bleepingcomputer.com/news/security/plugins-on-wordpressorg-backdoored-in-supply-chain-attack/

 

Just trying to understand and connect the dots. :)

 

PS: Note to self, do not use Wordpress in my website cause it's too popular.


Edited by Dominique1, 25 June 2024 - 04:40 PM.


#3 Dapengi

Dapengi

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  

Posted 25 June 2024 - 04:54 PM

I really appreciate the information. How did you go about cleaning all the malicious code? I have to do it for 35 sites and haven't found a great solution. 



#4 Dominique1

Dominique1

    Bleepin Funny


  •  Avatar image
  • Members
  • 1,027 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:12:01 AM

Posted 25 June 2024 - 05:01 PM

I will let tynology reply, but do DELETE all the newly created users.  They are admins.  Also, the BC article mentions the bad actor server (which you can see in your added snippets).  I would advise that you IP BLOCK that location on all your websites.

 

I feel your pain. Good luck!

:busy:



#5 Chris Cosgrove

Chris Cosgrove

  •  Avatar image
  • Global Moderator
  • 28,257 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Scotland
  • Local time:06:01 AM

Posted 25 June 2024 - 05:33 PM

@ tynology #1

 

Nobody seems to have explained the nature of the problem of your permissions to post in Virus and Malware Removal. Quite simply that forum section's access is restricted to members posting problems, the specialists in malware removal responding and the staff of BC. As a work around if you happen to have relevant specialist knowledge on a particular problem I suggest you send whoever is responding to it a PM.

 

Chris Cosgrove



#6 tynology

tynology
  • Topic Starter

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:01:01 AM

Posted 25 June 2024 - 06:26 PM

I did it all by hand one by one (I had 61 sites all hit on the same Hostinger Enterprise account), using Wordfence scans to check for anything I may have missed. I first deleted all the bogus admin accounts, then deleted all unused themes (it seemed to like to inject into the twentytwentyfour theme), and also noted what files the Hostinger malware scanner was picking up on. After deleting the admin accounts, deleting the code (it was always an unformatted block like you posted at the bottom of functions.php, footer.php and/or header.php in one theme). On some sites it would create a bogus theme which I just deleted also. Then run a Wordfence scan, then change all passwords. Confirm all plugins and themes are up to date. That has worked for me on all my sites and is holding strong. It seems some of the accounts were being created via database access. Hope that helps.

 

I really appreciate the information. How did you go about cleaning all the malicious code? I have to do it for 35 sites and haven't found a great solution. 


Edited by tynology, 25 June 2024 - 06:27 PM.


#7 Dapengi

Dapengi

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  

Posted 25 June 2024 - 06:37 PM

Thank you so much for the information. I truly appreciate it. I guess I am gonna have a long night ahead of me. 



#8 Orange Blossom

Orange Blossom

    OBleepin Investigator


  •  Avatar image
  • Moderator
  • 41,260 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:01:01 AM

Posted 25 June 2024 - 07:34 PM

Dapengi, please wait for a helper in the malware team to reply to your topic. You should not be making changes etc. to the system or following instructions other than from your malware removal expert. They have received specialized training. And I note that what may work to fix one person's computer may not work for another, just as a medicine that helps one person may not work on another person.

This topio is now closed.

Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.



Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, ESET Internet Security, NoScript Firefox ext.


animinionsmalltext.gif





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users