Monthly Archives: February 2012

Malware Campaign from .rr.nu

No, they don’t quit, so get used to it! We are seeing quite a few websites being compromised with malware getting loaded from random domains in the .rr.nu TLD. This is what gets added to the footer of the hacked … Read more


Posted in hacked, malware, malware_updates | Tagged , , | 58 Comments

Sucuri is Hiring: Junior Support Analyst

Our team is growing and we have an opening for a Junior Support Analyst (remote). If you have a passion for the web, security, and looking to become part of a dynamic global team, then this is where you want … Read more


Posted in jobs, sucuri | Tagged , | Leave a comment

Vulnerability in the Absolute Privacy Plugin

We are seeing reports that a vulnerability in the Absolute Privacy WordPress plugin (link) is being used to hack and compromise sites with it installed. This plugin has a serious unpatched security vulnerability that allows anyone to login in the … Read more


Posted in hacked, malware, malware_updates, plugin, vulnerability, wordpress | Tagged , , , , , | 4 Comments

New WordPress ToolsPack Plugin

We deal with many compromised sites daily and lately we are seeing something in common across many of the sites running WordPress. They have installed a plugin called ToolsPack ( ./wp-content/plugins/ToolsPack/ToolsPack.php), which according to the author will “Supercharge your WordPress … Read more


Posted in hacked, malware, malware_updates, plugin, wordpress | Tagged , , , , | 29 Comments

Sucuri SiteCheck – Web Malware Distribution – January 2012

As many know, we have been offering our free website malware scanner – Sucuri SiteCheck, since early in 2011. In our commitment to continue to give back to the community, we want to share some statistics. We’d like to share … Read more


Posted in data, malware, SiteCheck, sucuri | Tagged , , , , , , | 1 Comment

Malware Redirecting To Enormousw1illa.com

We are seeing a large number of sites compromised with a conditional redirection to the domain http://enormousw1illa.com/ (194.28.114.102). On all the sites we analyzed, the .htaccess file was modified so that if anyone visited the site from Google, Bing, Yahoo, … Read more


Posted in htaccess, malware, malware_updates | Tagged , , | 2 Comments