Yet another series of attacks (part X) – and the hilarykneber group

If you have been following our blog long, you probably heard about quite a few large scale attacks affecting many hosting companies: GoDaddy, Bluehost, Dreamhost, etc, etc.

The new one that started to spread today uses a javascript file pointing to When called, it will load and then offer the famous “fake AV” virus to the end user of a site. That’s how it looks like in a site:

< script src ="

Or in our scanner (blueh2):

Note that this domain is not currently blacklisted (and the site is up), so be careful when clicking those links. So far, we are seeing this spread only on Bluehost and Dreamhost, but it seems to be too early to tell how many sites are affected.

If your site is hacked, this script should clean it up: virus-fix.php or contact us for a professional help (

However, what is interesting is the people behind this attack (and all others). Those domains are always registered by:

Hilary Kneber
7569468 fax: 7569468
29/2 Sun street. Montey 29
Virginia NA 3947

You can check all the big ones that affected a large number of sites:

All by the same group and all of them using the same tactics. We should start monitoring registrations using this domain and block them automatically.

We will post more details as we learn about it.

  1. Your post suggests using your virus-fix.php script but that link directs to the wordpress-fix.php script which doesn't seem to work for this attack (although it is also a base64 style attack so I don't understand why not). Is the link incorrect, is there actually a virus-fix.php script available?
    Thanks – the worpress-fix script was really useful. Hope you can help this time too.

  2. I got it to work after a couple tries.

    I saw a few files in the root that looked unfamiliar (ujiyi.php, xpbom.php), so I removed them. Seems to have worked for now.

Comments are closed.

You May Also Like