medicine supplier from Canadian pharmacy with no script.

Archive for the ‘Uncategorized’ Category

Gootloader infection cleaned up

Saturday, February 26th, 2022

Dear blog owner and visitors,

This blog had been infected to serve up Gootloader malware to Google search victims, via a common tactic known as SEO (Search Engine Optimization) poisioning. Your blog was serving up 289 malicious pages. Your blogged served up malware to 0 visitors.

I tried my best to clean up the infection, but I would do the following:

  • Upgrade WordPress to the latest version (one way the attackers might have gained access to your server)
  • Upgrade all WordPress themes to the latest versions (another way the attackers might have gained access to your server)
  • Upgrade all WordPress plugins (another way the attackers might have gained access to your server), and remove any unnecessary plugins.
  • Verify all users are valid (in case the attackers left a backup account, to get back in)
  • Change all passwords (for WordPress accounts, FTP, SSH, database, etc.) and keys. This is probably how the attackers got in, as they are known to brute force weak passwords
  • Run antivirus scans on your server
  • Block these IPs (5.8.18.7 and 89.238.176.151), either in your firewall, .htaccess file, or in your /etc/hosts file, as these are the attackers command and control servers, which send malicious commands for your blog to execute
  • Check cronjobs (both server and WordPress), aka scheduled tasks. This is a common method that an attacker will use to get back in. If you are not sure, what this is, Google it
  • Consider wiping the server completly, as you do not know how deep the infection is. If you decide not to, I recommend installing some security plugins for WordPress, to try and scan for any remaining malicious files. Integrity Checker, WordPress Core Integrity Checker, Sucuri Security,
    and Wordfence Security, all do some level of detection, but not 100% guaranteed
  • Go through the process for Google to recrawl your site, to remove the malcious links (to see what malicious pages there were, Go to Google and search site:your_site.com agreement)
  • Check subdomains, to see if they were infected as well
  • Check file permissions

Gootloader (previously Gootkit) malware has been around since 2014, and is used to initally infect a system, and then sell that access off to other attackers, who then usually deploy additional malware, to include ransomware and banking trojans. By cleaning up your blog, it will make a dent in how they infect victims. PLEASE try to keep it up-to-date and secure, so this does not happen again.

Sincerly,

The Internet Janitor

Below are some links to research/further explaination on Gootloader:

https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/

https://news.sophos.com/en-us/2021/08/12/gootloaders-mothership-controls-malicious-content/

https://www.richinfante.com/2020/04/12/reverse-engineering-dolly-wordpress-malware

https://blog.sucuri.net/2018/12/clever-seo-spam-injection.html

This message

Shit is About to Hit the Fan

Wednesday, September 7th, 2011

So… it’s been about a year since I’ve written in this blog…

– AND –

nickpolifroni.com has been hacked… so now it’s going to be strictly portfolio. remedy667.com is going to be all font related, because I have no idea how to integrate that into my own design portfolio. Plus, it might get me some feedback on stuff. The main reason that I say shit is gonna hit the fan is because, I’ve gotta update WordPress on this site… I can’t even upload images anymore. I’m probably going to have to make the template a lot more modern as well and integrate it with the other sites (I’d post pictures of the idea, but I can’t until I update.) Anyway, it’s way past time to go to bed… I’ll try to import any past blogs I have in other places and this will become my central blog (again) …just like old times.

JFA – Mad Garden

Monday, July 11th, 2011

All through high school people told me to check out this band. Back then that was a lot easier said then done, it took me until the creation of Napster before I ever heard the sweet sounds of Jodie Fosters Army. This is probably my favorite JFA of the EPs, it just kicks right in with its title track and keeps the same energy throughout (Perhaps with the exception of the Peanuts cover). Either way, this is a classic for fans of early skate-punk and other classic California acts like Stalag 13 and Black Flag.

TRACKS

  1. Mad Garden
  2. Rushing Bull
  3. Charlie Brown
  4. I Want

DOWNLOAD

Intro5pect – Realpolitik!

Monday, July 11th, 2011


I don’t really consider myself to be a fan of Electro, but I’ve always been a loyal fan of punk rock. The first time I heard this was a demo version of the first track, The War at Home, on Myspace a couple years ago. At the time I liked it because I was a Leftover Crack fan, and the track had Stza on it. I’d never really heard the rest of the album until pretty recently though, and I must say… this shit is quality. A lot of the singalong chorus parts really remind me of Anti-Flag, while the overall sound is reminiscent of Atari Teenage Riot or the Refused.

TRACKS

  1. The War At Home
  2. Opressing You
  3. Crooked Lies (Make Baby Jesus Cry)
  4. For Blood, Under God
  5. No Compromises
  6. Nazi White Trash
  7. Goodbye, Goodnight

DOWNLOAD

Not to be Social, Just to be Normal.

Monday, May 17th, 2010

As I always say… it’s been a while since I updated my blog. Yeah, and that’s not fucking retard. Anyway… here’s some new shit… Coats & Corpses is live, check it out if you haven’t already it’s “interesting” to say the least. I know I’m always talking shit about music so you might as well listen to some of mine and make fun of me. It’s got free downloads as well, and just in case you didn’t know… I’m not in every band, but I do know people who were.

Hey Weird

Yeah, so this is totally not news. This band hasn’t existed for at least 2 or 3 years, but I just ran across it today at work. Decided to put it up on Coats & Corpses. Just click the link on the right.

Sketchbook

So I was in a slump for a minute, and I thought I had forgotten how to draw. (Which sucks, because I actually have to do it very often.) Then today I decided to do up a couple of sketches available on flickr…

Fuck Your Guns We've Got Guns Too Not to be Social, Just to be Normal

…and also here apparently. I will now be filtering all images through flickr because this WordPress site has a back end that is fucked and dying. Meaning that I can no longer upload pictures to it (Insert sad frown face.)

Remedy667

That’s right it’s back, and in full force. Check that shit, yo!

Niki’s Pizza

Rolling out the 30th Anniversary for a Detroit favorite they’ve got me doing some lightboxes and billboards. Presumably a new menu design as well, but stay tuned for all of that shit. However, it’s neighbor…

Loco’s Tex-Mex Grille

…had an awesome Cinco de Mayo this year. Did the posters… here’s a little bit of the process…

Cinco de Mayo Poster Comp 1 Cinco de Mayo Poster Comp 2 Cinco de Mayo Poster Comp 3

…and the final.

Cinco de Mayo Poster

Anyway, there’s always more, but that’s all I feel like sharing right now. Check out those few websites, and my flickr page. Also, look for more lies from a dead acrobat in the near future.