Monthly Archives: February 2011

Alexa top sites – Blacklist for January/2011

Every month we analyze Alexa’s TOP 1 million site ranking and correlate that data with Google’s blacklist. Our goal is to get an overall view of the sites that are getting hacked, blacklisted, etc. For Jan-2011, the number is pretty … Read more


Posted in alexa, blacklisted | Tagged , | Leave a comment

The attack from the .cc’s domains

Over the last few days we’ve continued to see a large increase in the number of sites hacked and infected with a malicious iframe from .co.cc (.vv.cc, .cz.cc, etc) domains. You can run a free scan using SiteCheck to see … Read more


Posted in hacked, malware, malware_updates, wordpress | Tagged , , , | 8 Comments

Hilary Kneber Strikes Again – welcometotheglobalisnet

It seems that after a few months quiet, the “Hilary Kneber” group is back at it again. Their latest approach is very typical of Hilary Kneber style attacks affecting GoDaddy shared hosts. Basically they modify every PHP file and the … Read more


Posted in godaddy, hacked, malware, malware_updates, wordpress | Tagged , , , , | 10 Comments

UCalgary web sites compromised with spam

We were cleaning up a compromised site today (with the unfamous pharma hack), when we saw multiple spam links in the hacked site pointing to ucalgary.ca (big Canadian university). What was interesting is that it was not pointing to a … Read more


Posted in pharma, spam | Tagged , | 5 Comments

Thailand official foreign affairs / embassy web sites hacked

The Royal Thai (Thailand’s) consulate and embassy web sites (part of their foreign affairs ministry) are currently hacked and infected with a lot of spam (of the pharmacy kind). Their web site is located at http://www.mfa.go.th and with a quick … Read more


Posted in hacked, pharma, spam | Tagged , , | 2 Comments

Cleaning up an infected website – Part I: WordPress and the Pharma Hack

We get to deal with infected web sites on a daily basis and the most common question we get is how do we clean websites. What steps do we take? What should you do if you want to clean up … Read more


Posted in guides, hacked, malware, pharma, spam, wordpress | Tagged , , , , , | 17 Comments

Large Blackhat SEO SPAM Campaign Targeting Joomla Sites

We are seeing a large number Joomla sites hacked and being used in a blackhat SEO SPAM campaign consisting of thousands of infected web sites. Most of them are small and using vulnerable and old versions of Joomla (1.0 and … Read more


Posted in hacked, joomla, malware, malware_updates, pharma, spam | Tagged , , , , , | 2 Comments

Weekly Malware Update – 2010/Feb/11

Weekly malware update. You can track all updates by following our malware_updates category. *If your site has been affected with any of these issues, contact us at support@sucuri.net or visit http://sucuri.net to get help or if you want to share … Read more


Posted in malware, malware_updates, pharma, spam, wordpress | Tagged , , , , | 2 Comments

Something is wrong at WordPress.com / CNN.com

Update: The problem is now fixed, seems to be caused by a redirection error. Many of the (CNN) VIP sites at WordPress.com are redirecting to: http://superfantastically.com/. It includes politicalticker.blogs.cnn.com, popwatch.ew.com, tech.fortune.cnn.com and many others… $ curl -D – http://politicalticker.blogs.cnn.com/ HTTP/1.1 … Read more


Posted in wordpress | Tagged | 6 Comments

WordPress 3.0.5 is available (with security fixes)

If you use WordPress, we recommend updating to the latest version (3.0.5) as soon as possible, specially if you have multiple users with authoring/contributing roles. This is the summary from WordPress.org: This security release is required if you have any … Read more


Posted in security, wordpress | Tagged , | 2 Comments