Dear Customer,
We have found that domain “xyz.com” hosts some suspicious contents and are being used to abuse the server. It seems that the domain is hacked as some contents are suspicious.This is against our company policy and is clearly a violation of our terms of service. Windows Hosting, ASP.NET Reseller, Dedicated Server by JodoHost
You are required to ask your client to remove all suspicious contents immediately or upload the fresh new contents, check the application vulnerabilities and fix them as soon as possible.
Obviously this is important - but why can’t they be a little more specific on WHAT is suspicious?
They must have noted something specific…a file or directory?
The error log is full of these:
[SIZE=13px][FONT=Verdana][Fri Apr 19 01:18:48 2013] [error] [client 173.0.129.52] File does not exist: /hsphere/local/home/xyz/xyz.com/includes/js/879uD.txt[/FONT][/SIZE]
However, you can see the client is Web11 itself! We had a mail hacking incident on this domain not long ago, and changed all the passwords and removed some files at that point. I’m not sure what is calling
There does appear to be some weird activity in the control panel…which can simply be blocked with another password change…but I don’t know if that’s what is being referred to!
I’ll open a trouble ticket - I haven’t received any responses from two emails I’ve sent, but I know abuse is probably slammed right now!
This is more of a general concern anyway - I wouldn’t need to keep asking them more questions and creating more work load if they can send as much info as they have in the first contact!
Maybe I’m missing something painfully obvious…that’s entirely possible, it’s been a hectic week!
I didn’t find any odd .txt files - especially the one referenced in the logs.
I was also looking for any files with double extensions as we’ve seen before.
Other than that, I really don’t know what I’m looking for!
I am a little concerned by the error logs that show the client as Web11, requesting files - isn’t that a little weird?
[SIZE=13px][FONT=Verdana][client 173.0.129.52] File does not exist: /hsphere/local/home/xyz/xyz.com/includes/js/879uD.txt[/FONT][/SIZE]
Could that be coming from another domain on Web11?
Is there any way to determine the orgin of these requests?
Well, I mentioned ‘painfully obvious’…duh. One directory (so far) was set to 777.
Ugh.
(edit)Ok, multiple directories are 777. So far nothing malicious looking - maybe abuse removed the files already!
Yes, abuse did remove the files that were there. the request from another, is a bit how these wordpress brute force attacks are working as well, once they get in one they put back doors in it then have them to scan others around them, and it is pretty bad stuff.
We are digging out any that may have had wordpress admin sections compromised in quite a labor driven process. Developing some patterns then doing searches.
Got it! I’m going through all the directories to reset any that were 777 - so far there were only three.
I know you could do it automatically, but this way I can also look over directory contents for any txt/gif/php files that shouldn’t be there.
Can you check with abuse and see if this is a file they removed:
[SIZE=13px][FONT=Verdana]93.46.240.243 - - [19/Apr/2013:11:21:22 -0500] “POST /administrator/templates/khepri/article.php HTTP/1.1” 404 2056 “-” “Mozilla/5.0”[/FONT][/SIZE]
[SIZE=13px][FONT=Verdana]I’m seeing hundreds of these in the access log, however the file is no longer there…[/FONT][/SIZE]
[SIZE=13px][FONT=Verdana]If this was one of the files hackers uploaded I’ll make sure to check for it on other domains.[/FONT][/SIZE]
[SIZE=13px][FONT=Verdana][/FONT][/SIZE]
Technical details of permanent failure:
Google tried to deliver your message, but it was rejected by the server for the recipient domain jodohost.com by mail5.jodoshared.com. [173.0.142.205].
The error that the other server returned was:
554 sorry, Infected message detected by ClamAV (#5.3.4)
hrm ok…infected message by AV on abuse@ address…interesting.
It is being fixed now, as it isn’t supposed to reject.
I do recommend a CC to helpline@ as well on escalating any issue like this, but AV will be disabled on abuse@ not helpline, so this particular message may not go through.