CAPTCHA Malware Attach In Helix3 Based Templates - Question | JoomShaper

CAPTCHA Malware Attach In Helix3 Based Templates

T

Thomas Müller

Template 2 weeks ago

Hi, I had a Captacha Malware Attach on the www.nabumm.eu webpage. After Backup restoration it was soon back.

  • First the malware asks for a google "I'm not a robot" confirmation
  • Then it asks for some key combinations like windows+K or Ctrl+R... to "validate" the captcha
  • NEVER DO THIS, very dangerous

https://www.cyfirma.com/research/fake-captcha-malware-campaign-how-cybercriminals-use-deceptive-verifications-to-distribute-malware/

Single solution: Deinstall all Joomshaper Templates (in my case Eventum and Shaper helix3). It's NOT enough only to update them!! Download the newest version from joomshaper and re-install, then it should have been gone.

Maybe we will get some more advise on this place how to clean up the template?

Good Luck! Tom

0
2 Answers
Atick Eashrak Shuvo
Atick Eashrak Shuvo
Accepted Answer
Support Agent 2 weeks ago #229756

Hi Tom,

Thank you for sharing your findings.

Could you please share a backup of the affected website with us? We would like to restore it in our local testing environment and perform a thorough investigation to identify the source of the infection and verify exactly what happened.

This will help us determine whether the issue is related to the template itself or whether malicious code was injected into the site after it was compromised.

Since the backup may be large, you can upload it to https://files.fm/ and share the download link with us. Once we receive the backup, we'll analyze it locally and get back to you with our findings.

We look forward to your response.

0
WEB_MASTER
WEB_MASTER
Accepted Answer
2 weeks ago #229758

I had the same experience and we immediately discarded the site. they would have used the custom css and js fields to embed malicious code. On top of that they would have enabled the old versions of the captcha plugins. Disabling them doesnt work.Further analysis determined that:

/usr/bin/x86_64-systemd is not associated with any installed operating system package. The file appears to be a standalone executable designed to collect authentication-related information. The executable contained logic that referenced user credentials and attempted outbound communication using curl. The script was configured to send data to the external IP address 194.233.93.210,

0