HomeSecurityOver 23,000 Web Server IPs are connected to CryptoPHP Domains

Over 23,000 Web Server IPs are connected to CryptoPHP Domains

Researchers observed connections from 23,693 unique IP addresses to Command & Control (C&C) servers used by the CryptoPHP for the popular content management systems (CMS) WordPress, Drupal, and Joomla.

CryptoPHP

Information on the scale of CryptoPHP was gathered by Fox IT in collaboration with Abuse.ch, Shadowserver and Spamhaus.

After sinkholing most of the active C&C servers, researchers noticed a decrease in the amount of addresses associated with them. As a result, fewer and fewer IPs are associated with these domains, with 16,786 recorded on November 24th.

However, the researchers caution that this information is not particularly relevant for calculating the number of affected websites, as web servers may host multiple websites. Therefore, the malware could attempt to connect to the malicious server from several websites with the same IP, which makes the potential number of infected websites larger.

According to the researchers, the most successful attacks were located in the United States, where 8,657 compromised addresses were recorded. Next is Germany, with 2,877 IPs.

Fox IT has detected around 16 versions of CryptoPHP , the first one being in September 2013. It was spread through thousands of pirated plug-ins and themes for the popular CMS. The latest version of the threat is 1.0 and was discovered on November 12.

Researchers claim that many of the websites used to spread the threat disappeared on Sunday and reappeared on Monday with a new version of the malware that is still active.

Fox IT reports in a report that CryptoPHP is used for Blackhat SEO, by injecting links and text into web pages, but only when the visitor appears as a web crawler.

Blackhat SEO (Search Engine Optimization) is a technique that increases a website's ranking in a search engine through unfair means. The practice violates the search engine's terms and conditions and, therefore, leads to the promoted website being banned.

The creator is believed to be based in Chisinau, the capital of the Republic of Moldova. The information that has emerged according to a user agent named “chishijen12” led to an IP address in use since December 2013.

The malware's list of features relies on RSA public key encryption for communication between the victim and the C&C server.

If the C&C server is disabled, communication is done via email. In addition, security experts have found that the backdoor can also be controlled manually, without the presence of a command and control system.
To help administrators determine if CryptoPHP is present on their website, Fox IT has created two Python scripts, available on GitHub. One script is intended to detect the presence of the threat, while the other scans look for backdoor.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS