Activity Stream
48,167 MEMBERS
61021 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Results 1 to 7 of 7
  1.     
    #1
    Banned

    Default Seems someone hacked my vps

    today i have received an abuse letter from DC and they forward to me.

    On 2010-12-18, someone uploaded multiple ZeuS trojan files to your network:

    http://update.shuwhyyu.com/update/hh...ffepfkpkzz.exe
    http://ns1.syegyege.com/8d6srxzq5kef37b9b49b9fh64jqj

    IP: 91.215.159.108


    We're kindly requesting that you remove these malware files, or that you
    null route 91.215.159.108.


    Googling for either "update.shuwhyyu.com" or "ns1.syegyege.com" shows
    only references to malware.

    Additional evidence can be found here:
    https://zeustracker.abuse.ch/monitor...e.shuwhyyu.com
    https://zeustracker.abuse.ch/monitor...1.syegyege.com


    Thank you for your help,

    -Konrads
    PhishLabs Security Operations
    now how can i know where is the trojan file located.
    The Dude Reviewed by The Dude on . Seems someone hacked my vps today i have received an abuse letter from DC and they forward to me. now how can i know where is the trojan file located. Rating: 5

  2.   Sponsored Links

  3.     
    #2
    loki
    What panel you use? You don't have a virus scanner?

  •     
    #3
    Banned
    i guess i don't have any virus scanner.

    ps: atm downloading all files on my computer then will scan using my antivirus
    one question, is it possible someone uploaded the trojan on root folder e.g. /var/ and abuse.ch track it?

  •     
    #4
    loki
    it could be any where, check for shells, AND, change password ASAP

    you can install ClamAv, just have to manual config

  •     
    #5
    Banned
    Website's:
    KWWHunction.com
    i sent you a pm

  •     
    #6
    Banned
    found it. a folder called upldate was uploaded. i have removed it. but i don't understanding how he uploaded that folder. is there anyway i can check ftp log ip?

    ps: there was a bigdump script uploaded. is it possible he can upload it through bigdump script?

    one file name: 9ZEBnkSVbNZPBKGtB.ip contain this code
    PHP Code: 
    <?php
    $ip
    =$_SERVER['REMOTE_ADDR'];
    echo 
    $ip;
    ?>
    another .htaccess contain this:
    Code: 
    Addtype application/x-httpd-php4 .ip
    Addtype application/x-httpd-php5 .ip
    
    <IfModule mod_php4.c>
    AddHandler server-parsed .ip
    AddHandler application/x-httpd-php4 .ip
    </IfModule>
    
    <IfModule mod_php5.c>
    AddHandler server-parsed .ip
    AddHandler application/x-httpd-php .ip
    </IfModule>
    there is another 2 file name: hh3g44bg6d39stffepfkpkzz.exe and a .bin file

    on that site only wp and phpbb3 script running. i just wondering how did he uploaded that folder

  •     
    #7
    Banned
    @Djlatino my all site running fine, still i do not realize any damage of my sites. i have checked my cpanel ip log everything is fine.

  • Thread Information

    Users Browsing this Thread

    There are currently 1 users browsing this thread. (0 members and 1 guests)

    Similar Threads

    1. Hacked
      By misterjay in forum File Host Discussion
      Replies: 16
      Last Post: 10th Mar 2012, 04:42 AM
    2. The PS3 Hacked?
      By yasser37 in forum General Discussion
      Replies: 49
      Last Post: 29th Aug 2010, 12:40 PM
    3. PS3 Hacked
      By DeLeTeD in forum General Discussion
      Replies: 28
      Last Post: 26th Jan 2010, 08:45 AM
    4. I got hacked i think
      By ravi_4289 in forum General Discussion
      Replies: 13
      Last Post: 2nd Aug 2009, 10:39 PM
    5. I got hacked
      By WManup in forum General Discussion
      Replies: 9
      Last Post: 2nd Aug 2009, 07:08 PM

    Tags for this Thread

    BE SOCIAL