Jump to content

Threat: JS/Spy.Banker.KT trojan


Go to solution Solved by Marcos,

Recommended Posts

Posted

 https://www.gensace.de/checkout/onepage/ 

This web page may contain dangerous content that can provide remote access to an infected device, leak sensitive data from the device or harm the targeted device.
Threat: JS/Spy.Banker.KT trojan
Access to the web page has been blocked. Your computer is safe.

how can i find the js trojan,should be zopim? or the google ga code?

  • behman changed the title to Threat: JS/Spy.Banker.KT trojan
  • Administrators
Posted

If you are an administrator of the website, searching for "var a0a=" will help you locate the malicious JS.

Posted

yes ,i'm the administrator.

as you say . i cant find the string "var a0a=". i use grep -r "var a0a=" in server.

Posted

if you have not item in cart.it will rediect to cart page .so you need to add item to cart . 

 hxxps://www.gensace.de/checkout/onepage/ 

  • Administrators
Posted

The threat may be encrypted or hiding in a WP db for instance. We'd suggest to start with checking the main WP index.php for suspicious code. If you don't find any, try searching for functions atob/btoa and for code accessing the db, e.g.
$wpdb->get_var("SELECT

Posted

hey . i search the whole db. but i have not found the string.  maybe its  false positive?

 

image.png

  • Administrators
  • Solution
Posted

The detection is correct. The malicious JS is actually there:

image.png

 

Posted

thx,marcos. i found it. they confound the code

 

  • Administrators
Posted
Just now, behman said:

thx,marcos. i found it. they confound the code

 

Where did you eventually find it? It might help other users with this infection.

Posted

Entry file。app.php  mage.php

  • Administrators
Posted

Thanks. Did you also find out why you could not initially find the malicious JS by the string I provided? Was it encrypted?

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...