Uncategorized


Dear blog owner and visitors,

This blog had been infected to serve up Gootloader malware to Google search victims, via a common tactic known as SEO (Search Engine Optimization) poisioning. Your blog was serving up 388 malicious pages. Your blogged served up malware to 76 visitors.

I tried my best to clean up the infection, but I would do the following:

  • Upgrade WordPress to the latest version (one way the attackers might have gained access to your server)
  • Upgrade all WordPress themes to the latest versions (another way the attackers might have gained access to your server)
  • Upgrade all WordPress plugins (another way the attackers might have gained access to your server), and remove any unnecessary plugins.
  • Verify all users are valid (in case the attackers left a backup account, to get back in)
  • Change all passwords (for WordPress accounts, FTP, SSH, database, etc.) and keys. This is probably how the attackers got in, as they are known to brute force weak passwords
  • Run antivirus scans on your server
  • Block these IPs (5.8.18.7 and 89.238.176.151), either in your firewall, .htaccess file, or in your /etc/hosts file, as these are the attackers command and control servers, which send malicious commands for your blog to execute
  • Check cronjobs (both server and WordPress), aka scheduled tasks. This is a common method that an attacker will use to get back in. If you are not sure, what this is, Google it
  • Consider wiping the server completly, as you do not know how deep the infection is. If you decide not to, I recommend installing some security plugins for WordPress, to try and scan for any remaining malicious files. Integrity Checker, WordPress Core Integrity Checker, Sucuri Security,
    and Wordfence Security, all do some level of detection, but not 100% guaranteed
  • Go through the process for Google to recrawl your site, to remove the malcious links (to see what malicious pages there were, Go to Google and search site:your_site.com agreement)
  • Check subdomains, to see if they were infected as well
  • Check file permissions

Gootloader (previously Gootkit) malware has been around since 2014, and is used to initally infect a system, and then sell that access off to other attackers, who then usually deploy additional malware, to include ransomware and banking trojans. By cleaning up your blog, it will make a dent in how they infect victims. PLEASE try to keep it up-to-date and secure, so this does not happen again.

Sincerly,

The Internet Janitor

Below are some links to research/further explaination on Gootloader:

https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/

https://news.sophos.com/en-us/2021/08/12/gootloaders-mothership-controls-malicious-content/

https://www.richinfante.com/2020/04/12/reverse-engineering-dolly-wordpress-malware

https://blog.sucuri.net/2018/12/clever-seo-spam-injection.html

This message

Okay, I wanted to be poetic like Joe but the practical side of me
keeps coming forward….soooo these suggestions are not listed in
order of priority. In my opinion each one of them is important
although some may serve you better than others at any given time.

Don’t take no for an answer…
When you find yourself on the job hunt just because they tell you they
don’t need anyone right now doesn’t mean they won’t in the future. I
found many jobs because I kept going back and they started to
recognize me and my perseverance.
If it’s something you are really interested in, keep at it, don’t give
up prematurely.

Be open to the possibilities…
Sometimes a job you weren’t looking for might be offered and could,
either A) lead to the job you do want, or B) provide a job that in the
end does appeal to you,possibly even more than the one you sought in
the first place.
Leads open the pathway to new leads, don’t discount an opportunity
just because it doesn’t fit your initial criteria.

Widen the throw of your net…
If you aren’t sure what you want to do allow yourself to send a
“shotgun spread” of inquiries until things can be narrowed down.
Opportunities can present themselves in the most unlikely places.

Be willing to get your hands dirty…
When you’re starting out don’t be “too good” to tackle even the nastiest
of jobs. Hard work is always rewarded and recognized. Humbleness has
it’s benefits. People are less likely to try to take down someone who
is recognized to have been “in the trenches” than someone who has
stepped into a higher position without earning their chops.

Appreciate the good fortune of everyone around you…

Learn to speak to many different people on many different levels…

Be curious…
Take every opportunity to regularly discover something new about
yourself and/or the environment around you.

If you don’t know, ASK questions…
Don’t be hesitant to ask someone who might know the answer you’re
looking for. I have found that people generally like to work with
someone who is willing to ask questions and learn rather than have to
repair the damage from an unfortunate circumstance created from not
knowing.

Don’t be afraid to make mistakes or look dumb…
How else can you learn?

Know how to speak another language and use it whenever possible…
I wish I had paid more attention in high school when I studied French
and had worked at being more proficient in a second or even a third
language. There is nothing better than going to another country and
being able to communicate in the local language.

When travelling enjoy the similarities and the differences of another
culture…
Don’t assume that everyone wishes they could live in North America,
there are millions of people out there perfectly happy with their
lives in their own countries.
If it’s another country you’re in, understand that while the food,
dress, language, etc, might be different everyone has the same basic
desires. We all want to love and be loved, to be able to provide a
safe haven for our children and loved ones, to make ends meet and to
have a good
laugh.

Be able to laugh…
A sense of humor will take you a long way.

Don’t take people for granted…
Including yourself.

Experience life…
Enjoy it to the max. Take risks. Tell the people closest to you that you
love them and mean it, often.

Keep an open heart and an open mind and the rest will follow…

Love Janie

I wrote that last one sometime between today and April 13th but just reacquainted myself with it. Although I felt that way sometime in the last couple of months it isn’t indicative of today’s thoughts…however I thought since I had written it at some point it should be included.