Post by _imagine_ » Thu Oct 11, 2018 6:53 pm

Hello guys,
I have been working on a new website the last few days and everything was going great, until yesterday. Suddenly when I was viewing the front end of the website I got a message that it is trying to connect something identified as "Trojan:HTML/Brocoiner!rfn" apparently this is a program that attaches itself to the website and proceeds to use its users pcs to mine some sort of concurrency. There is a lot of info out there for how to remove it from pc but none on where it might be hiding on a server. Weird thing is I haven't uploaded any new modules or themes on the ftp only a few media files. However neither my friends nor I got that antivirus message before yesterday. Sucuri SiteCheck doesn't seem to find anything wrong.

Newbie

Posts

Joined
Thu Oct 11, 2018 6:45 pm

Post by IP_CAM » Fri Oct 12, 2018 2:59 am

Weird thing is I haven't uploaded any new modules or themes
Are you talking about a problem, related to some unknown yet OpenCart Version,
or is this about your regular Website, and some Media-Files, you added ?
And did you check those Media Files first, to make sure, they're clean ?! ???
Ernie

For Sale: Top URL's, including an OpenCart V-Pro Shop!
A wide range of matching Designs can be seen here: http://www.opencart.li
For Information on URL's offered, please contact me at: jti@jacob.ch
Hundreds of Mods in 380+ Repositories for OC v.1.5.x - v.2.3.x
to be found on my Github Site: https://github.com/IP-CAM
Image


User avatar
Legendary Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland

Post by _imagine_ » Sat Oct 13, 2018 12:03 am

Hello,
This is a regular 2.3.0.2, I didn't check all the media files but they were just pictures. Using notepad++ I found unwanted code linked to coinhive in header.tpl both in the default and my theme, I removed the code and people stopped getting a message and the site stopped abusing my processor as soon as I open it.
However there must still be something left because as soon as I change anything on the site through admin panel or through ftp the unwanted code is back in header.tpl, anyways this is how far I've gotten I'll post here if I find a complete fix to the problem.

Newbie

Posts

Joined
Thu Oct 11, 2018 6:45 pm

Post by IP_CAM » Sat Oct 13, 2018 1:32 am

Well, it might be a regular v.2.3.0.2, but you possibly added some Mods,
or then, you use other Code like Wordpress e.t.c., on the same Server.
But without real Data, it's just filling useless topics...
Ernie

For Sale: Top URL's, including an OpenCart V-Pro Shop!
A wide range of matching Designs can be seen here: http://www.opencart.li
For Information on URL's offered, please contact me at: jti@jacob.ch
Hundreds of Mods in 380+ Repositories for OC v.1.5.x - v.2.3.x
to be found on my Github Site: https://github.com/IP-CAM
Image


User avatar
Legendary Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland
Who is online

Users browsing this forum: No registered users and 11 guests