SiteCheck Signatures

  1. Home
  2. Signatures
  3. SiteCheck Signatures
  4. malware-entry-mwiframehd564

malware-entry-mwiframehd564

Description:

A hidden and malicious iframe was identified. This malware infects a web site through a compromised desktop (with virus), where it steals any stored password from the FTP client and uses that to attack the site.
 
Note that every PHP, HTML and JS file gets compromised by this malware.

 
Affecting: Any web site with FTP enabled (and password stolen).

Clean up: The desktop must be cleaned first. Use multiple AVs if necessary, since this
virus is very good at hiding from the current AV that is running. Once it is clean, then you
can clean up the sites and change the passwords.You can also sign up with us and let our team remove the malware for you.

 
Loads malware from multiple sources:


lapglzaz.serveftp.com/main.php?page=c69bd02e93e6957c
http://ydodur.ddns.us/main.php?page=2701c6e26dca8a78
http://my-counter.co.cc/main.php?page=1d2d124081954b6d
http://dudud.anyplus.com.tw/main.php?page=fc3e77a595495932
http://cherkesov.com.beatschumi.com/main.php?page=fc3e77a595495932
http://seawolbeamasa.com/main.php?page=887c73c59dbbfc05
http://bigdeal777.com/gate.php?f=975661
(and many other domains).

 

Malware dump (sample of malware):

<iframe src="http://seawolbeamasa.com/ main.php?page=887c73c59dbbfc.. width="1" heig..