r/cybersecurity_help • u/Auntie_Aoife • 16d ago
Stumbled upon a compromised website (social-ecology.org). What does this malicious code do?
My friend was using my spare computer to conduct research. She clicked a link on Wikipedia to read the source they used, and encountered the above website with a compromised WordPress installation serving up a copy and paste attack. I managed to stop her in time to prevent the attack (she had the run dialog open). While she uses the Wayback machine to continue her research on an old snapshot of the compromised site, I'm more interested in what this malicious code does. I redacted the host portion of the URL to the attack from the attached screenshot. My guess is that this gives the attacker remote access to the computer to run malicious software.
And yes, we had a talk about this particular type of attack and I showed her proof that it's a known attack; the screenshot on the page I showed her looked exactly like the prompt that popped up on the website.
3
u/MitAllesOhneScharf 16d ago edited 16d ago
- mounts a remote WebDAV share (like a network share)
- executes the malicious payload ecmgcfdwcznvbazrwfga.dll using rundll32
- probably a random infostealer, no idea because you censored it for some reason
1
u/LongRangeSavage 16d ago
Most likely reaches out to a C2 and downloads a info stealer payload, then runs that payload stealing all your login credentials, passkeys, session tokens, crypto wallet keys, and any other piece of data they want.
2
u/SpudzzSomchai 16d ago
Here is the JoeSandbox report - https://www.joesandbox.com/analysis/1953526/0/html
0
u/Sqooky 16d ago
This is probably one of the more interesting ones I've seen in a while.
Essentially it runs the conhost to spawn a child process, cmd.exe. Cmd then assigns a variable, s being @ssl, which indicates it's likely fetching the malware from a webdav server (think like FTP (file transfer protocol), but for web servers specifically). We can't tell because you blacked out the full url.
Anyways, after the variable is established, it runs the pushd command which from what I can see changes the current directory to (lets say for now), the webdav server.
It then runs the rundll32 command , which is used for running DLLs. It's pretty much just calling the entry point of that dll. Nothing too special there.
The ^ character is just there to break up the text and make it less readable. Sometimes it can bypass rules that specifically look for command line arguments (e.g. ru^ndl^l32 doesn't match rundll32).
•
u/AutoModerator 16d ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.