3 ms·
There is more detailed information available under a few of the links in the article. Information about what an infection looks like, the attack method, etc: h
by danielparks 14y ago
There is more detailed information available under a few of the links in the article.
Information about what an infection looks like, the attack method, etc: http://malwaremustdie.blogspot.com/2013/03/the-evil-came-back-darkleechs-apache.html http://malwaremustdie.blogspot.com/2013/03/the-evil-came-bac...
From skimming the article, it sounds like it attacks control panels (mostly Plesk?) and possibly WordPress for remote shell, then does some sort of local privilege escalation. It then adds a module to Apache or Nginx which injects malware into served web pages under certain conditions.
More information about distribution: http://nakedsecurity.sophos.com/2013/03/05/rogue-apache-modules-iframe-blackhole-exploit-kit/ http://nakedsecurity.sophos.com/2013/03/05/rogue-apache-modu...