{"id":960,"date":"2015-07-20T10:47:42","date_gmt":"2015-07-20T08:47:42","guid":{"rendered":"http:\/\/www.ayhanarda.com\/blog\/?p=960"},"modified":"2015-07-20T10:49:40","modified_gmt":"2015-07-20T08:49:40","slug":"cryptophp-php-malware-tespiti-ve-temizleme","status":"publish","type":"post","link":"https:\/\/www.ayhanarda.com\/blog\/2015\/07\/cryptophp-php-malware-tespiti-ve-temizleme\/","title":{"rendered":"CryptoPHP PHP malware tespiti ve temizleme"},"content":{"rendered":"<p>CryptoPHP malware i , komut ve kontrol sunucular\u0131 ile public key \u015fifrelemesi kullanarak ileti\u015fime ge\u00e7en bir zararl\u0131d\u0131r ve bilindik i\u00e7erik kontrol sistemleri olan wordpress , joomla , drupal gibi sistemler ile kolayl\u0131kla entegre olabilir. Yasad\u0131\u015f\u0131 arama motoru optimizasyonu yapanlar taraf\u0131ndan kullan\u0131l\u0131r. Bu script genellikle kendini g\u00fcncelleyecek \u015fekilde yap\u0131land\u0131r\u0131l\u0131r ve sahibi diler ise onu uzaktan g\u00fcncelleyebilir ya da yeni \u00f6zellikler ekleyebilir.<\/p>\n<p>Fox it , bununla ilgili detayl\u0131 bir analiz yapm\u0131\u015ft\u0131r ve<a href=\"https:\/\/foxitsecurity.files.wordpress.com\/2014\/11\/cryptophp-whitepaper-foxsrt-v4.pdf\" target=\"_blank\"> https:\/\/foxitsecurity.files.wordpress.com\/2014\/11\/cryptophp-whitepaper-foxsrt-v4.pdf<\/a> adresinden inceleyebilirsiniz.<\/p>\n<p>Tespiti i\u00e7in yine fox it in haz\u0131rlad\u0131\u011f\u0131 phyton scriptini kullanabiliriz. S\u0131ras\u0131yla \u00f6nce scripti indiriyoruz , \u00e7al\u0131\u015fma hakk\u0131 tan\u0131yoruz ve \/home dizinimizin alt\u0131ndaki dosyalar\u0131 taramas\u0131n\u0131 istiyoruz.<\/p>\n<div id=\"wpshdo_1\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_1\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_1\"><\/a><a id=\"wpshat_1\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_1\"  onClick=\"javascript:wpsh_toggleBlock(1)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_code(1)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_print(1)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_1\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># wget https:\/\/raw.githubusercontent.com\/fox-it\/cryptophp\/master\/scripts\/check_filesystem.py\n<\/span>root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># chmod +x check_filesystem.py\n<\/span>root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># .\/check_filesystem.py \/home<\/span><\/pre><\/div><\/div>\n<p>&nbsp;<\/p>\n<p>Sonu\u00e7lara g\u00f6z atmak gerekirse \u00e7\u0131kt\u0131 a\u015fa\u011f\u0131dakine benzer olacakt\u0131r.<\/p>\n<div id=\"wpshdo_2\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_2\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_2\"><\/a><a id=\"wpshat_2\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_2\"  onClick=\"javascript:wpsh_toggleBlock(2)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_code(2)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_print(2)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_2\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\"><a href=\"http:\/\/www.php.net\/file\"><span class=\"kw3\">File<\/span><\/a> matching patterns<span class=\"sy0\">:<\/span> <span class=\"br0\">[<\/span><span class=\"st_h\">'*.png'<\/span><span class=\"sy0\">,<\/span> <span class=\"st_h\">'*.gif'<\/span><span class=\"sy0\">,<\/span> <span class=\"st_h\">'*.jpg'<\/span><span class=\"sy0\">,<\/span> <span class=\"st_h\">'*.bmp'<\/span><span class=\"br0\">]<\/span>\nRecursively scanning directory<span class=\"sy0\">:<\/span> <span class=\"sy0\">\/<\/span>home\n <span class=\"sy0\">\/<\/span>home<span class=\"sy0\">\/<\/span>guvenlikgeregigizlenmistir1<span class=\"sy0\">.<\/span>com<span class=\"sy0\">\/<\/span>httpdocs<span class=\"sy0\">\/<\/span>wp<span class=\"sy0\">-<\/span>content<span class=\"sy0\">\/<\/span>themes<span class=\"sy0\">\/<\/span>VideoThemeRes<span class=\"sy0\">\/<\/span>images<span class=\"sy0\">\/<\/span>social<span class=\"sy0\">.<\/span>png<span class=\"sy0\">:<\/span> CRYPTOPHP DETECTED<span class=\"sy0\">!<\/span> <span class=\"br0\">&#40;<\/span>version<span class=\"sy0\">:<\/span> <span class=\"nu19\">0.2<\/span><span class=\"br0\">&#41;<\/span>\n <span class=\"sy0\">\/<\/span>home<span class=\"sy0\">\/<\/span>guvenlikgeregizlenmistir2<span class=\"sy0\">.<\/span>com<span class=\"sy0\">\/<\/span>httpdocs<span class=\"sy0\">\/<\/span>wp<span class=\"sy0\">-<\/span>content<span class=\"sy0\">\/<\/span>plugins<span class=\"sy0\">\/<\/span>_revslider<span class=\"sy0\">\/<\/span>images<span class=\"sy0\">\/<\/span>social<span class=\"sy0\">.<\/span>png<span class=\"sy0\">:<\/span> CRYPTOPHP DETECTED<span class=\"sy0\">!<\/span> <span class=\"br0\">&#40;<\/span>version<span class=\"sy0\">:<\/span> <span class=\"nu19\">0.2<\/span><span class=\"br0\">&#41;<\/span><\/pre><\/div><\/div>\n<p>Tespit ettikten sonra silmek i\u00e7in a\u015fa\u011f\u0131daki silme komutunu kullanabilirsiniz.<\/p>\n<div id=\"wpshdo_3\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_3\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_3\"><\/a><a id=\"wpshat_3\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_3\"  onClick=\"javascript:wpsh_toggleBlock(3)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_3\" onClick=\"javascript:wpsh_code(3)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_3\" onClick=\"javascript:wpsh_print(3)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_3\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># rm -rf \/home\/guvenlikgeregigizlenmistir1.com\/httpdocs\/wp-content\/themes\/VideoThemeRes\/images\/social.png<\/span><\/pre><\/div><\/div>\n<p>Bu phyton scriptini kullanmak istemiyor iseniz a\u015fa\u011f\u0131da belirtti\u011fim beti\u011fi de kullanabilirsiniz.<\/p>\n<div id=\"wpshdo_4\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_4\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_4\"><\/a><a id=\"wpshat_4\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_4\"  onClick=\"javascript:wpsh_toggleBlock(4)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_4\" onClick=\"javascript:wpsh_code(4)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_4\" onClick=\"javascript:wpsh_print(4)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_4\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">root<span class=\"sy0\">@<\/span>ayhanarda<span class=\"sy0\">.<\/span>com<span class=\"sy0\">:<\/span>~<span class=\"co2\"># find \/home\/ -name &quot;social*.png&quot; -exec grep -E -o 'php.{0,80}' {} \\; -print<\/span><\/pre><\/div><\/div>\n<p>Sunucunuza \u00fccretli tarama ve temizleme yapt\u0131rmak i\u00e7in bu gibi i\u015flemleri yapan <a href=\"http:\/\/www.cpanelguvenlik.com\" target=\"_blank\">Cpanel G\u00fcvenlik<\/a> sitesi ile ileti\u015fime ge\u00e7ebilirsiniz.<\/p>\n<p>Ayhan ARDA<\/p>\n<p>&nbsp;<\/p>\n<div style=\"padding-bottom:20px; padding-top:10px;\" class=\"hupso-share-buttons\"><!-- Hupso Share Buttons - https:\/\/www.hupso.com\/share\/ --><a class=\"hupso_toolbar\" href=\"https:\/\/www.hupso.com\/share\/\"><img decoding=\"async\" src=\"https:\/\/static.hupso.com\/share\/buttons\/lang\/tr\/share-medium.png\" style=\"border:0px; padding-top: 5px; float:left;\" alt=\"Share Button\"\/><\/a><script type=\"text\/javascript\">var hupso_services_t=new Array(\"Twitter\",\"Facebook\",\"Google Plus\",\"Pinterest\",\"Linkedin\");var hupso_background_t=\"#EAF4FF\";var hupso_border_t=\"#66CCFF\";var hupso_toolbar_size_t=\"medium\";var hupso_image_folder_url = \"\";var hupso_twitter_via=\"ayhanarda\";var hupso_url_t=\"\";var hupso_title_t=\"CryptoPHP%20PHP%20malware%20tespiti%20ve%20temizleme\";<\/script><script type=\"text\/javascript\" src=\"https:\/\/static.hupso.com\/share\/js\/share_toolbar.js\"><\/script><!-- Hupso Share Buttons --><\/div>","protected":false},"excerpt":{"rendered":"CryptoPHP malware i , komut ve kontrol sunucular\u0131 ile public key \u015fifrelemesi kullanarak ileti\u015fime ge\u00e7en bir zararl\u0131d\u0131r ve bilindik i\u00e7erik kontrol sistemleri olan wordpress , joomla , drupal gibi sistemler ile kolayl\u0131kla entegre olabilir. Yasad\u0131\u015f\u0131 arama motoru optimizasyonu yapanlar taraf\u0131ndan kullan\u0131l\u0131r. Bu script genellikle kendini g\u00fcncelleyecek \u015fekilde yap\u0131land\u0131r\u0131l\u0131r ve sahibi diler ise onu uzaktan g\u00fcncelleyebilir [&hellip;]","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[313,67],"tags":[797,793,795,796,792,794],"class_list":["post-960","post","type-post","status-publish","format-standard","hentry","category-security","category-shell-script","tag-clear-cryptophp","tag-cryptophp","tag-detect-cryptophp","tag-foxit-crptophp","tag-malware","tag-remove-cryptophp"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/comments?post=960"}],"version-history":[{"count":4,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/960\/revisions"}],"predecessor-version":[{"id":964,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/960\/revisions\/964"}],"wp:attachment":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/media?parent=960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/categories?post=960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/tags?post=960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}