Property Abroad
Blog
The Sign1 virus campaign has already infected 39,000 WordPress sites.

The Sign1 virus campaign has already infected 39,000 WordPress sites.

The Sign1 virus campaign has already infected 39,000 WordPress sites.

Here is the updated text with the requested formatting:

A large-scale malware campaign

The tracked malware named Sign1 has compromised 39,000 WordPress sites in the last six months.

Detection of the Sign1 campaign

Security researchers from Sucuri have discovered a malware campaign tracked as Sign1, which has already compromised 39,000 WordPress sites in the past six months.

Malicious JavaScript inserts

Experts have found that attackers are injecting malicious JavaScript snippets into websites, redirecting users to harmful sites. Researchers, reaching out to SiteCheck, discovered that over 2,500 sites have been compromised in this campaign over the past two months.

“Plugins that allow the insertion of arbitrary JavaScript and other code onto a website are especially useful for website owners and developers, but they can also be abused by attackers in a compromised environment. Since these types of plugins allow for the addition of virtually any code, attackers often use them to insert their malicious or spam payloads,” states the experts' report.

"As expected, the plugin settings check revealed our suspect, hidden in the admin panel CSS & JS."

Implementation of malicious JavaScript

The Sign1 threats inject malicious JavaScript into legitimate plugins and HTML widgets. The injected code includes a hardcoded array of numbers that uses XOR encoding to generate new values.

Researchers have decrypted processed JavaScript code using XOR encoding and found that it is used to execute a JavaScript file hosted on a remote server. They also noticed that the attackers use dynamically changing URLs, allowing them to change the URL every 10 minutes. The code runs in visitors' browsers, leading to unwanted redirects and advertisements for website users.

This code stands out because it checks whether the visitor came from a known website, such as Google, Facebook, Yahoo, or Instagram. If the visitor did not come from one of these popular sites, the malicious code will not execute. Attackers have used this trick to avoid detection.

4
320
5
2
150
Buy in Italy for 949618£
1 270 778 $
3
3
249.91
Buy in Italy for 862078£
1 153 632 $
1
1
139.91
Buy in Italy for 111984£
149 856 $
2
1
90
4
400
Website owners typically visit their sites directly rather than going through search engines. The malware exploits this difference in an attempt to remain unnoticed.

Redirects to VexTrio domains

Researchers have discovered that the redirects lead to VexTrio domains. The Sign1 campaign was first identified by researcher Denis Sinegubko in the second half of 2023, and Sucuri reported that the attackers used up to 15 different domains since July 31, 2023. The name of the campaign comes from the sign1 parameter, which is used in the code to extract and decrypt the domain name of the malicious URL from a third-party organization. In October 2023, the attackers began using a different obfuscation technique and removed the sign1 parameter. It is likely that the threats actively compromised websites through successful brute-force attacks.

“This is another example of why securing the admin panel and using website monitoring tools should be a top priority for website owners,” the report concludes.

Please note that the original text contained non-text characters (e.g., Cyrillic characters). When converting it to HTML tags, some characters might have been replaced with question marks or removed.

We will find property for you

  • 🔸 Reliable new buildings and ready-made apartments
  • 🔸 Without commissions and intermediaries
  • 🔸 Online display and remote transaction

Subscribe to the newsletter from Hatamatata.com!

I agree to the processing of personal data and confidentiality rules of Hatamatata

Popular Offers

Buy in Italy for 1091542$
1 091 542 $
1
1
339
4
4
353
3
4
265

Need advice on your situation?

Get a  free  consultation on purchasing real estate overseas. We’ll discuss your goals, suggest the best strategies and countries, and explain how to complete the purchase step by step. You’ll get clear answers to all your questions about buying, investing, and relocating abroad.

Vector Bg
Irina

Irina Nikolaeva

Sales Director, HataMatata