Skip to content

RackNerd's 'one-click install' installed malware somehow

Reviews by ana_mad 1 replies 111 views
2 #1

Fresh WordPress install from RackNerd panel yesterday. Sent ticket yesterday when I found base64 in footer. Made test order on new account, same image, same payload.

File hash matches between both installs: 4a7f...d2e9. Not in upstream WordPress. Specific to RackNerd "Optimized WP 6.4.3" image.

Found malicious domain in wp-includes/js/crop/angel.php. Very creative path.

Cheers! Following this closely.

swimming upstream since 2019 🐟
#2

Peering

BGP to that domain: via v4 transit only, no v6 path. Fw logs show callback to 185.x.x.x/24. Rt table odd: announced by AS I do not recognize.

Cfg diff: clean wp vs RackNerd image = 3 files changed, 1 added.

Not tier-1

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft