Author Topic: HTML:imghack-a [Trj] on Joomla website  (Read 11750 times)

0 Members and 1 Guest are viewing this topic.

Evert

  • Guest
HTML:imghack-a [Trj] on Joomla website
« on: June 02, 2011, 03:39:17 PM »
Today i wanted to login to my Joomla website (backend administrator) when Avast blocked the site and gave me the warning that it detected HTML:imghack-a [Trj]
I looked at my site with an FTP client and I looked at the server logs, but I see nothing unusual. So I was wondering:

1) What is this trojan, is it malicious?
2) Where could it be hiding on my site?
3) Could this be a false positive?

Thanks.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #1 on: June 02, 2011, 03:45:10 PM »
Could you write down the site?xxx.joomla.yyy ?
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Evert

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #2 on: June 02, 2011, 03:47:12 PM »
I didn't because I was unsure if I am allowed to post links?
I get the warning here: xww.zoekeenmodel.com/administrator
« Last Edit: June 02, 2011, 04:31:30 PM by Milos »

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #3 on: June 02, 2011, 03:56:02 PM »
Yes,possibly FP.
Url void:
Report    2011-06-02 15:41:26 (GMT 1)
Website    zoekeenmodel.com
Domain Hash    b1e508a6a2e1709531ed991b7f2aaed4
IP Address    77.243.233.132 [SCAN]
IP Hostname    -
IP Country    NL (Netherlands)
AS Number    25459
AS Name    NEDZONE-AS NedZone Internet BV
Detections    0 / 23 (0 %)
Status    CLEAN
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Evert

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #4 on: June 02, 2011, 04:01:15 PM »
Ok, thanks, I'll keep an eye on it but will disable avast for that site for now.

spg SCOTT

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #5 on: June 02, 2011, 04:03:56 PM »

Offline scythe944

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2913
    • My Tech Blog
For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #7 on: June 02, 2011, 04:11:23 PM »
The page does appear to have been hacked, an IMG tag is set to run a .php file rather than open an image, a bit of a standards no, no. Not to mention it comes after the closing HTML tag another standards no, no. Finally the image size is 1x1 another way to try and hide it, and highly suspect.

Looks like that site has been hacked.

http://www.virustotal.com/file-scan/report.html?id=d7c9985c2b690a3eace567d81816bf67db9ce9cb984c33cd8800611ae9da4c28-1307022918

Ok, thanks, I'll keep an eye on it but will disable avast for that site for now.

That is playing Russian roulette with an automatic. See further images 2&3 this is a malicious site that it is trying to run this .php page.
« Last Edit: June 02, 2011, 04:14:31 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

kubecj

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #8 on: June 02, 2011, 04:11:52 PM »
Not a FP. You can google lots of links about this, even we had some stats in one of our blogs.

spg SCOTT

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #9 on: June 02, 2011, 04:16:22 PM »
I get a 500 error on the actual link in malzilla (for now...could be changed later - good that avast blocks it anyway)

Hopefully this also highlights the problem with using just URLVoid in checking a website. Since it only checks some blacklists and not actually scans the sites, it most often will be wrong. Especially in recently hacked sites...

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #10 on: June 02, 2011, 04:17:37 PM »
Hi Evert & Left 123,

Will you make the url non-click through like: htxp://www.zoekeenmodel.com/administrator
or -http://www.zoekeenmodel.com/administrator
I get a redirect at SOSWebScan, Error Reason:Moved Permanently
Redirected-to :
So we cannot scan this website.Please check and try again. Why?
Because the site is infected with malware, known javascript malware (Word Press site hack),
re: http://sucuri.net/malware/malware-entry-mwbackdoor23 (see attached gif)
Better not disable avast there, avast scan is not a false positive...
Inform the admin of the site it has been hacked and should be cleansed,

polonus

« Last Edit: June 03, 2011, 12:45:30 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline scythe944

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2913
    • My Tech Blog
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #11 on: June 02, 2011, 04:18:58 PM »
Hi Evert & Left 123,

Will you make the url non-click through like: htxp://www.zoekeenmodel.com/administrator
or -http://www.zoekeenmodel.com/administrator
I get a redirect at SOSWebScan, Error Reason:Moved Permanently
Redirected-to :
So we cannot scan this website.Please check and try again. Why?
Because the site is infected with malware, know javascript malware (Word Press site hack),
re: http://sucuri.net/malware/malware-entry-mwbackdoor23 (see attached gif)
Better not disable avast there, avast scan is not a false positive...
Inform the admin of the site it has been hacked and should be cleansed,

polonus

He IS the site admin  ;D
For generic computer (not avast) problems, you can also visit my forum for help: http://www.jacobytech.net/forum

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #12 on: June 02, 2011, 04:28:23 PM »
Hi scythe944,

Funny, I should have realized because of the link, that is obvious.
Then Evert the admin knows what to do, cleanse his site. The malicious code has to be removed, as well as all backdoors (countimg malware), cannot understand why Left123 missed it,

pol

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Evert

  • Guest
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #13 on: June 02, 2011, 05:15:15 PM »
Ok, thanks all. I'll just replace the site with a backup then...sigh, and change all passwords again.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: HTML:imghack-a [Trj] on Joomla website
« Reply #14 on: June 02, 2011, 05:23:49 PM »
Hoi Evert,

Kan nu eenmaal gebeuren. Zorg tevens ook dat al je webapplicatie software naar de laatste versie geupdate wordt, dat maakt een herinfectie/hack wat moeilijker,

groetjes

polonus

P.S. Summary of Dutch txt -this means that he has to update all his web app software to make reinfection-hacks somewhat harder to be performed,

D
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!