CAPTCHA Malware Attach In Helix3 Based Templates - Question | JoomShaper

is live, now with multi-currency selling.

CAPTCHA Malware Attach In Helix3 Based Templates

T

Thomas Müller

Template 2 months ago

Hi, I had a Captacha Malware Attach on the www.nabumm.eu webpage. After Backup restoration it was soon back.

  • First the malware asks for a google "I'm not a robot" confirmation
  • Then it asks for some key combinations like windows+K or Ctrl+R... to "validate" the captcha
  • NEVER DO THIS, very dangerous

https://www.cyfirma.com/research/fake-captcha-malware-campaign-how-cybercriminals-use-deceptive-verifications-to-distribute-malware/

Single solution: Deinstall all Joomshaper Templates (in my case Eventum and Shaper helix3). It's NOT enough only to update them!! Download the newest version from joomshaper and re-install, then it should have been gone.

Maybe we will get some more advise on this place how to clean up the template?

Good Luck! Tom

0
10 Answers
Atick Eashrak Shuvo
Atick Eashrak Shuvo
Accepted Answer
Support Agent 2 months ago #229756

Hi Tom,

Thank you for sharing your findings.

Could you please share a backup of the affected website with us? We would like to restore it in our local testing environment and perform a thorough investigation to identify the source of the infection and verify exactly what happened.

This will help us determine whether the issue is related to the template itself or whether malicious code was injected into the site after it was compromised.

Since the backup may be large, you can upload it to https://files.fm/ and share the download link with us. Once we receive the backup, we'll analyze it locally and get back to you with our findings.

We look forward to your response.

0
WEB_MASTER
WEB_MASTER
Accepted Answer
2 months ago #229758

I had the same experience and we immediately discarded the site. they would have used the custom css and js fields to embed malicious code. On top of that they would have enabled the old versions of the captcha plugins. Disabling them doesnt work.Further analysis determined that:

/usr/bin/x86_64-systemd is not associated with any installed operating system package. The file appears to be a standalone executable designed to collect authentication-related information. The executable contained logic that referenced user credentials and attempted outbound communication using curl. The script was configured to send data to the external IP address 194.233.93.210,

0
T
Thomas Müller
Accepted Answer
2 weeks ago #233970

Dear Joomshaper Team, I got the same captcha-malware-attach again on a different website. I will under "hidden content" share the login credentials from the infected website with you, please log in, you can then make you own backup and post the solution on this place. Many thanks in advance, Thomas

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #233972

Thomas, Problem:

Login denied! Your account has either been blocked or you have not activated it yet.

To clean site from malware you have to use extension (free). General guides:

Yes, we can do that as well, but in the basic level.

0
T
Thomas Müller
Accepted Answer
2 weeks ago #233973

It's activated now, sorry for the inconveniences! Please try again, hopefully you find a solution to close the captcha-malware-attack in your templates for ever! Many thanks in advance, Tom

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #233980

Danke Tom.

I have to be honest with you, partialy it's also your fault that site was infected. You didn't update Helix and SPPB in the last few months. You have to make important updates at least each month, and check site admin more often - what update is needed and why.

Yes. I made quick cleaning. Now all should be OK.

0
T
Thomas Müller
Accepted Answer
2 weeks ago #233983

Dear Friends, I definitely feel guilty about the missing updates, but would be happy about a tutorial how to quickly clean this issue. Is it right to...

  • switch to an alternative Template
  • de-install Helix and all Plugins
  • reinstall Helix newest version
  • switch back to helix template

Is the malware then completely deleted? Can you confirm? Best regards

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #233995

"tutorial how to quickly clean" - you got it already, I sent links to documenation (look up).

Yes, the main issue that you had was removed. Now you can ask also the hosting company for extra scanning.


Last tip: if you have template based on Helix Ultimate already, always uninstall all others templates, and plugins from old template.

0
T
Thomas Müller
Accepted Answer
2 weeks ago #233997

Many thank and all the best from a big JoomShaper-Fan ;-) Thomas

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #233999

You're welcome.

Please mark topic as solved, link is under Replay

0