{"id":5317,"date":"2019-07-22T09:18:48","date_gmt":"2019-07-22T09:18:48","guid":{"rendered":"https:\/\/www.icdsoft.com\/blog\/?p=5317"},"modified":"2019-07-22T09:23:24","modified_gmt":"2019-07-22T09:23:24","slug":"how-to-investigate-a-wordpress-hacking-incident","status":"publish","type":"post","link":"https:\/\/www.icdsoft.com\/blog\/how-to-investigate-a-wordpress-hacking-incident\/","title":{"rendered":"How to Investigate a WordPress Hacking Incident?"},"content":{"rendered":"\n<p>Maybe you saw a warning when accessing your site this morning. On occasion, you may have been redirected to another site altogether \u2013 a site that was trying to sell something to your visitors. Perhaps just above your header image, you caught a glimpse of an almost invisible message from a \u201chacker,\u201d claiming that your security was \u201cw34k.\u201d Or maybe you were simply greeted by a very sudden and unexpected White Screen of Death.<\/p>\n\n\n\n<p>The root cause behind all these events could be the same: a single hacking incident. With the rising availability of automated software that can either brute-force their way into your site\u2019s Dashboard, exploit a known vulnerability in one of its many plugins, or efficiently do both, it should come as no surprise that we see more and more compromised sites every day. While we do our best to proactively secure our infrastructure against common attacks, our clients install their own applications on their own hosting space, which always involves a security risk.  <\/p>\n\n\n\n<p>In this article, we will cover how the experts in our Incident Response Team approach such cases. We have selected a WordPress installation for this example, but while the details will be different, the logical framework of the investigation is nearly identical for all common web applications.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>The Incident<\/strong><\/h4>\n\n\n\n<p>We perform regular antivirus checks for all hosting accounts. However, due to the nature of PHP obfuscation, malware can remain undiscovered for a while. In this case, the customer notified us that they received a malicious content warning when visiting their website, so our colleagues went in to manually review their files. Usually, a WordPress installation will contain a number of standard core files in its main directory, and the same goes for all major CMS applications \u2013 so naturally, a couple of files grabbed their attention with their unusual filenames:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">133ja3lore.php\na1cw42ipim.php<\/pre>\n\n\n\n<p>From this point on, we will be using some of the standard Unix command line tools in order to gain more information about these files, and about how they originally appeared on the account. All of <a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/wordpress\">our hosting plans<\/a> come with SSH access out of the box, as well as full Apache access logs, so you could reproduce these steps on your own.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Obtaining Timestamps<\/strong><\/h4>\n\n\n\n<p>The <strong>stat<\/strong> utility gives us a lot of information about files, and this is how its output looks like:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">[17:09:32] server~$ stat&nbsp;\/home\/user\/www\/www\/133ja3lore.php\n&nbsp; File:&nbsp;\/home\/user\/www\/www\/133ja3lore.php\n&nbsp; Size: 4909&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Blocks: 16&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IO Block: 4096&nbsp;&nbsp; regular&nbsp;file\nDevice: fc00h\/64512d&nbsp;&nbsp;&nbsp;&nbsp;Inode: 202768472&nbsp;&nbsp; Links: 1\nAccess: (0664\/-rw-rw-r--)&nbsp; Uid: ( 4731\/user)&nbsp;&nbsp; Gid: ( 4674\/user)\nAccess: 2018-02-02 15:16:02.000000000 +0800\nModify: 2018-02-02 15:16:02.000000000 +0800\n<strong>Change: 2018-08-07 20:49:47.771134758 +0800<\/strong>\n&nbsp;Birth:<\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\">[17:09:43] server~$ stat&nbsp;\/home\/user\/www\/www\/a1cw42ipim.php\n&nbsp;&nbsp;File:&nbsp;\/home\/user\/www\/www\/a1cw42ipim.php\n&nbsp;&nbsp;Size: 4909&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Blocks: 16&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; IO Block: 4096&nbsp;&nbsp; regular&nbsp;file\nDevice: fc00h\/64512d&nbsp;&nbsp;&nbsp;&nbsp;Inode: 202768462&nbsp;&nbsp; Links: 1\nAccess: (0664\/-rw-rw-r--)&nbsp; Uid: ( 4731\/user)&nbsp;&nbsp; Gid: ( 4674\/user)\nAccess: 2018-02-02 15:16:02.000000000 +0800\nModify: 2018-02-02 15:16:02.000000000 +0800\n<strong>Change: 2018-08-07 19:41:46.676971426 +0800<\/strong>\n&nbsp;Birth:<\/pre>\n\n\n\n<p>The main difference between the <strong>mtime<\/strong> (modification time) and <strong>ctime<\/strong> (change time) is that mtime shows the last change of the contents of the file, while ctime shows the last change of the contents of the file <em>or of one of its attributes (such as permissions or owner)<\/em>. Depending on the situation, we may search our logs for the ctime attribute, the mtime attribute, or even both.<\/p>\n\n\n\n<p>In this case, we take the <strong>ctime<\/strong> timestamp for further analysis, because for both files, it is the more recent attribute. We will also start by searching for the timestamp we obtained from <strong>a1cw42ipim.php<\/strong>, because it was changed about an hour earlier than the same attribute of the other file - hence, we assume that it was uploaded first, and takes us closer to the original Point of Entry.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Log<\/strong><strong> Analysis<\/strong><\/h4>\n\n\n\n<p>Current, real-time access logs are available from the Logs section of the Control Panel \u2013 this is helpful if the attack was very recent. In this case, the original event occurred a long time ago, so we will be using archived copies of the logs. These archives are stored in the <strong>logs<\/strong> directory of the account, and can be viewed from the File Manager, via FTP, or through SSH. The archives are in the gzip format, so you can use the <strong>zgrep<\/strong> command to search within them. Furthermore, log archives are split into individual files, with names based on subdomain and day, so this is how a search for the timestamp obtained previously would look like:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><code>zgrep \"19:41:\" \/home\/user\/logs\/2018-08\/www-07.log.gz<\/code><\/pre>\n\n\n\n<p>When checking the access logs, we pay special attention to any <strong>POST<\/strong> requests that we discover. Unlike GET requests, where all data is encoded in the URL, POST requests include data in the <em>body<\/em> of the request. Most file uploads and setting updates use this method, and this is how malware is usually uploaded, too. The search yields the following lines of interest to our investigation:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">www.domain.com 192.0.2.1 - - [07\/Aug\/2018:19:41:44 +0800]&nbsp;\"POST \/<strong>um-api<\/strong>\/route\/um!core!Files\/ajax_image_upload\/a2c75736fe HTTP\/1.1\"&nbsp;200 407&nbsp;\"domain.com\"&nbsp;\"Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/50.0.2661.75 Safari\/537.36\"&nbsp;0 0&nbsp;\"off:-:-\"&nbsp;5045 299593 192.0.2.2 domain.com\n\nwww.domain.com 192.0.2.2 - - [07\/Aug\/2018:19:41:45 +0800]&nbsp;\"POST \/wp-content\/uploads\/<strong>ultimatemember<\/strong>\/temp\/Ao3uKpx8B9klgpJ6Ra7A8z0jycfjvtiZZDrPtZao\/stream_photo_9c8d90bc587c22ae9aef83fcdb2a02d0_5b69857918ac2.php HTTP\/1.1\"&nbsp;200 494&nbsp;\"domain.com\"&nbsp;\"Mozilla\/5.0 (Windows NT 6.1; WOW64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/50.0.2661.75 Safari\/537.36\"&nbsp;0 0&nbsp;\"off:-:-\"&nbsp;686 1047741 192.0.2.2 domain.com<\/pre>\n\n\n\n<p>Sections of the URLs in these POST requests \u2013 um-api and ultimatemember \u2013 suggest that the attacker gained access through the popular Ultimate Member plugin. Around the time of this incident, there was a <a href=\"https:\/\/wpvulndb.com\/vulnerabilities\/9110\" target=\"_blank\" rel=\"noopener\">well-documented vulnerability<\/a> that was massively exploited online, which tells us how the malware was originally uploaded on the account.<\/p>\n\n\n\n<p>You should note that we rarely get as \"lucky\" on the first try. The malware that we investigate may have been uploaded by another malicious file, and more often than not, the same process will have to be repeated several times before the Point of Entry has been identified. It is also entirely possible that the account was compromised on another server before being migrated to us. Additionally, this process is tuned and specific for our environment. However, any respectable hosting provider should be able to provide you with the access and tools required to perform these steps.<\/p>\n\n\n\n<p>Once\nwe have identified the original Point\nof Entry,\nwe can begin working on cleaning up the account, and hardening\nit against\nsimilar issues in the future. We\nwill discuss this in more detail in our next post on the subject.\n\n<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An overview of the procedures on researching compromised accounts in use by our Incident Response Team that you can follow yourself.<\/p>\n","protected":false},"author":1,"featured_media":5333,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"categories":[6,3,11],"tags":[],"class_list":{"0":"post-5317","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"category-how-to","9":"category-wordpress"},"author_meta":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"featured_img":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/07\/computer-3028682_1920-300x225.jpg","featured_image_src":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/07\/computer-3028682_1920.jpg","featured_image_src_square":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/07\/computer-3028682_1920.jpg","author_info":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">Security<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/how-to\/\" class=\"advgb-post-tax-term\">How To<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/wordpress\/\" class=\"advgb-post-tax-term\">WordPress<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">Security<\/span>","<span class=\"advgb-post-tax-term\">How To<\/span>","<span class=\"advgb-post-tax-term\">WordPress<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 7 years ago","modified":"Updated 7 years ago"},"absolute_dates":{"created":"Posted on July 22, 2019","modified":"Updated on July 22, 2019"},"absolute_dates_time":{"created":"Posted on July 22, 2019 9:18 am","modified":"Updated on July 22, 2019 9:23 am"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/5317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=5317"}],"version-history":[{"count":8,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/5317\/revisions"}],"predecessor-version":[{"id":5338,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/5317\/revisions\/5338"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media\/5333"}],"wp:attachment":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=5317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=5317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=5317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}