Author Topic: Another outdated WordPress CMS and malware...  (Read 2804 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Another outdated WordPress CMS and malware...
« on: April 20, 2018, 05:00:59 PM »
Re: https://urlquery.net/report/9257db0b-4857-4f4c-b8ee-a5df93e0679d
See: http://www.isithacked.com/check/http%3A%2F%2Fbolnavy.com%2F
Oudated WP version: 4.6.11
Warning  User Enumeration is possible
The first two user ID's were tested to determine if user enumeration is possible.

ID   User   Login
1   admin   admin
2   None   None
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.

Quote
oaded Resources
Compromised sites will often be linked to malicious javascript or iframes in an attempt to attack users of your WordPress installation. Look over the listed resources, you should be familiar with all scripts and investigate ones you are not sure. In addition removal of unneeded javascript will speed up your website.

-http://bolnavy.com/
GoogleSafe:
OK   Load:
538ms   Server: 192.185.19.238
nginx/1.12.2   ASN: 20013 United-States
CyrusOne LLC   Reverse DNS:
-http://bolnavy.com/wp-content/themes/adsense100k/style.css
GoogleSafe:
OK   Load:
77ms   Server: 192.185.19.238
nginx/1.12.2   ASN: 20013 United-States
CyrusOne LLC   Reverse DNS:
-https://kristenrobinson.leadpages.net/leadbox-992.js
GoogleSafe:
OK   Load:
211ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
http://pagead2.googlesyndication.com/pagead/show_ads.js
GoogleSafe:
OK   Load:
52ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-http://bolnavy.com/wp-includes/js/wp-embed.min.js?ver=4.6.11
GoogleSafe:
OK   Load:
73ms   Server: 192.185.19.238
nginx/1.12.2   ASN: 20013 United-States
CyrusOne LLC   Reverse DNS:
-http://bolnavy.com/wp-includes/js/wp-emoji-release.min.js?ver=4.6.11
GoogleSafe:
OK   Load:
43ms   Server: 192.185.19.238
nginx/1.12.2   ASN: 20013 United-States
CyrusOne LLC   Reverse DNS:
-http://kristenrobinson.leadpages.net/static/all/js/can-i-show.js
GoogleSafe:
OK   Load:
57ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-http://www.google-analytics.com/ga.js
GoogleSafe:
OK   Load:
92ms   Server: 172.217.8.14
Golfe2   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f14.1e100.net
-https://pagead2.googlesyndication.com/pub-config/r20160913/ca-pub-1488561195299351.js
GoogleSafe:
OK   Load:
80ms   Server: 172.217.13.226
sffe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://googleads.g.doubleclick.net/pagead/html/r20180411/r20170110/zrt_lookup.html#
GoogleSafe:
OK   Load:
137ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-http://pagead2.googlesyndication.com/pagead/js/r20180411/r20170110/show_ads_impl.js
GoogleSafe:
OK   Load:
88ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-1488561195299351&output=html&h=600&adk=2544555421&adf=982882941&w=160&lmt=1524228573&loeid=10583695&ad_type=text_image&format=160x600_as&color_bg=F0F6FB&color_border=F0F6FB&color_link=064B8C&color_text=064B8C&color_url=064B8C&url=http%3A%2F%2Fbolnavy.com%2F&flash=0&wgl=0&dt=1524228573112&bpp=8&bdt=244&fdt=14&idt=118&shv=r20180411&cbv=r20170110&saldr=sa&correlator=4472649000961&frm=20&ga_vid=1799216629.1524228573&ga_sid=1524228573&ga_hid=433690511&ga_fc=1&pv=2&iag=3&icsg=2&nhd=1&dssz=3&mdo=0&mso=0&u_tz=0&u_his=1&u_java=0&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&adx=4&ady=42&biw=400&bih=300&abxe=1&scr_x=0&scr_y=0&eid=10593695%2C21061122%2C33895413%2C20040069&oid=3&rx=0&eae=0&fc=656&brdim=0%2C0%2C0%2C0%2C1024%2C0%2C0%2C0%2C400%2C300&vis=1&rsz=%7C%7CleE%7C&abl=CS&ppjl=f&pfx=0&fu=9232&bc=1&ifi=2&xpc=1SIjvIBHev&p=http%3A//bolnavy.com&dtd=134
GoogleSafe:
OK   Load:
37ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://pagead2.googlesyndication.com/pagead/js/r20180411/r20170110/osd.js
GoogleSafe:
OK   Load:
12ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://kristenrobinson.leadpages.net/leadbox/1433d4e73f72a2%3A12b1cbc40b46dc/5768158526832640/?lp-in-iframe=1&__fromjs=1
GoogleSafe:
OK   Load:
94ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-1488561195299351&output=html&h=60&twa=1&adk=2821253799&adf=1348527711&w=232&fwrn=5&fwrnh=100&lmt=1524228573&loeid=10583695&ad_type=text_image&format=232x60&color_bg=F0F6FB&color_border=F0F6FB&color_link=064B8C&color_text=064B8C&color_url=064B8C&url=http%3A%2F%2Fbolnavy.com%2F&flash=0&fwr=0&rh=60&rw=232&wgl=0&dt=1524228573131&bpp=8&bdt=263&fdt=160&idt=162&shv=r20180411&cbv=r20170110&saldr=sa&prev_fmts=160x600_as&correlator=4472649000961&frm=20&ga_vid=1799216629.1524228573&ga_sid=1524228573&ga_hid=433690511&ga_fc=1&pv=1&iag=3&icsg=2&nhd=1&dssz=3&mdo=0&mso=0&u_tz=0&u_his=1&u_java=0&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&adx=173&ady=66&biw=400&bih=300&abxe=1&scr_x=0&scr_y=0&eid=10593695%2C21061122%2C33895413%2C20040069&oid=3&rx=0&eae=0&fc=656&brdim=0%2C0%2C0%2C0%2C1024%2C0%2C0%2C0%2C400%2C300&vis=1&rsz=%7Cm%7CeE%7Cp&abl=XS&ppjl=f&pfx=0&fu=9232&bc=1&ifi=3&xpc=8CVFXKQ4oA&p=http%3A//bolnavy.com&dtd=167
GoogleSafe:
OK   Load:
31ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-1488561195299351&output=html&h=280&twa=1&adk=2963032828&adf=734580936&w=232&fwrn=5&fwrnh=100&lmt=1524228573&loeid=10583695&ad_type=text_image&format=232x280&color_bg=F0F6FB&color_border=F0F6FB&color_link=064B8C&color_text=064B8C&color_url=064B8C&url=http%3A%2F%2Fbolnavy.com%2F&flash=0&fwr=0&rh=280&rw=232&wgl=0&dt=1524228573167&bpp=5&bdt=299&fdt=145&idt=147&shv=r20180411&cbv=r20170110&saldr=sa&prev_fmts=160x600_as%2C232x60&correlator=4472649000961&frm=20&ga_vid=1799216629.1524228573&ga_sid=1524228573&ga_hid=433690511&ga_fc=1&pv=1&iag=3&icsg=2&nhd=1&dssz=3&mdo=0&mso=0&u_tz=0&u_his=1&u_java=0&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&adx=173&ady=1470&biw=400&bih=300&abxe=1&scr_x=0&scr_y=0&eid=10593695%2C21061122%2C33895413%2C20040069&oid=3&rx=0&eae=0&fc=656&brdim=0%2C0%2C0%2C0%2C1024%2C0%2C0%2C0%2C400%2C300&vis=1&rsz=%7Cm%7CeEbr%7Cp&abl=XS&ppjl=f&pfx=0&fu=9232&bc=1&ifi=4&xpc=xQSegCh6JT&p=http%3A//bolnavy.com&dtd=151
GoogleSafe:
OK   Load:
32ms   Server: 172.217.13.226
cafe   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s61-in-f2.1e100.net
-https://js.center.io/center.js
GoogleSafe:
OK   Load:
136ms   Server: 172.217.8.19
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f19.1e100.net
-https://connect.facebook.net/en_US/all.js
GoogleSafe:
OK   Load:
36ms   Server: 31.13.69.203
ASN: 32934 United-States
Facebook, Inc.   Reverse DNS:
xx-fbcdn-shv-01-iad3.fbcdn.net
-https://kristenrobinson.leadpages.net/leadbox/1433d4e73f72a2%3A12b1cbc40b46dc/5768158526832640/%E2%80%9Dhttp://www.militaryspousebusinessbootcamp.com/webinar?ap_id=Rob%E2%80%9D
GoogleSafe:
OK   Load:
127ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://js.center.io/identify.html
GoogleSafe:
OK   Load:
16ms   Server: 172.217.8.19
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f19.1e100.net
-https://api.leadpages.io/analytics/v1/events/capture?k=load&a=leadbox&l=5686536431468544&v=&e=&pid=DyPZq3LEfHkyrWjMqAxDTB&uid=FwRgrUP67tVATFru432n4s&sid=zN7Ab5GowvXDPm5N98NDdJ&cid=lp-5686536431468544&uri=https%3A%2F%2Fkristenrobinson.leadpages.net%2Fleadbox%2F1433d4e73f72a2%253A12b1cbc40b46dc%2F5768158526832640%2F%3Flp-in-iframe%3D1%26__fromjs%3D1&rf=http%3A%2F%2Fbolnavy.com%2F&rx=0&ry=3960&tz=%2B00%3A00
GoogleSafe:
OK   Load:
223ms   Server: 130.211.20.100
Stargate   ASN: 15169 United-States
Google Inc.   Reverse DNS:
100.20.211.130.bc.googleusercontent.com
-https://fonts.googleapis.com/css?family=Roboto:400,100,300,500,700
GoogleSafe:
OK   Load:
71ms   Server: 172.217.8.10
ESF   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f10.1e100.net
-https://static.leadpages.net/fonts/akkurat_typeset.css
GoogleSafe:
OK   Load:
249ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://static.leadpages.net/icons/v32/lp-icons.css
GoogleSafe:
OK   Load:
177ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://static.leadpages.net/lego/1.1.19/lego.min.css
GoogleSafe:
OK   Load:
230ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/min/select2.min.css
GoogleSafe:
OK   Load:
60ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/min/select2-bootstrap.css
GoogleSafe:
OK   Load:
69ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/bootstrap/lp3/css/bootstrap.min.css
GoogleSafe:
OK   Load:
78ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/build/css/lp.css
GoogleSafe:
OK   Load:
89ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/min/firechannel.js
GoogleSafe:
OK   Load:
72ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/min/dist/config.js
GoogleSafe:
OK   Load:
72ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://connect.facebook.net/en_US/sdk.js
GoogleSafe:
OK   Load:
27ms   Server: 31.13.69.203
ASN: 32934 United-States
Facebook, Inc.   Reverse DNS:
xx-fbcdn-shv-01-iad3.fbcdn.net
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/font/akkurat/lineto-akkurat-regular.woff
GoogleSafe:
OK   Load:
57ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://static.leadpages.net/fonts/lineto-akkurat-regular.woff
GoogleSafe:
OK   Load:
60ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/font/akkurat/lineto-akkurat-light.woff
GoogleSafe:
OK   Load:
57ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://static.leadpages.net/fonts/lineto-akkurat-light.woff
GoogleSafe:
OK   Load:
60ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com
-https://v7-0-47-dot-lead-pages.appspot.com/static/lp1523908911/font/akkurat/lineto-akkurat-bold.woff
GoogleSafe:
OK   Load:
57ms   Server: 172.217.8.20
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
iad23s59-in-f20.1e100.net
-https://static.leadpages.net/fonts/lineto-akkurat-bold.woff
GoogleSafe:
OK   Load:
57ms   Server: 72.14.249.204
Google Frontend   ASN: 15169 United-States
Google Inc.   Reverse DNS:
ghs-vip-any-c1220.ghs-ssl.googlehosted.com

Google Safebrowsin g alert and suspiscious code: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=bolnavy.com&ref_sel=GSP2&ua_sel=ff&fs=1

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!