Database Injection on Joomla Websites – yourstatscounter dot cz dot cc

It seems that a good amount of Joomla sites are being infected with malware from the infamous “.cc” domains. All of the hacked sites have the malicious code injected directly in to their databases (SQL injection), via an unknown source (probably a vulnerable extension, but we are still researching the entry point).

This is what is being added to the infected sites (at the top of every post in the jos_content table):

<script type="text/javascript" src=""></script>

There are many others domains being used in this attack, including:

Note that those are different from the Lizamoon SQL injection of a few days ago. The Lizamoon was targeting IIS/ sites, while this one seems to be targeted only to Joomla sites.

If you are afraid your site might be hacked, check it using our malware scanner. If you need help cleaning it up, let us know.

Scan your website for free:
About David Dede

David Dede is a Security Researcher in the SucuriLabs group. He spends most of his time dissecting vulnerabilities and security issues. You won't find him on Twitter because he is paranoid about privacy.