I recently cleaned a site infected with dontstopthismusics.com malware, so I’m sharing the fix with you all.
Approx. sites are affected so far.
Need help? Let us clean your site.
To fix a hacked website, follow these steps:
2. Disable SQL remote access, especially if you’re using Plesk.
3. Change SQL user password.
2. Extract wordpress-5.4.2.zip, add wp-config.php from your infected site inside wordpress folder ( make sure you check its content and clear malicious lines – if any ).
3. Add plugins and theme manually, one by one, inside /wp-content/plugins/ and /wp-content/themes/
4. Upload everything back to your server.
Easiest way would be to edit wp-config.php file via FTP or hosting dashboard ( replace example.com with your own domain name ).
define( 'WP_HOME', 'http://example.com' ); define( 'WP_SITEURL', 'http://example.com' );
Look for “String.fromCharCode”, “mndfhghjf”, “blackentertainments” and “list.insertBefore(s, list.childNodes[0])”.
Insert the following script with pack.php file and place it inside your root folder. This way you can pack all PHP and JS files, which can be cleaned locally.
<?php exec("find . -name '*.php' -o -name '*.js' | tar -cvzf php-js.tar.gz -T -"); phpinfo(); ?>
Search and replace tools for malicious strings inside multiple files: dnGrep, grepwin, VisualGrep ( mac ), powergrep ( paid ).
Example of infected JS file:
Attackers usually alter wp_posts and wp_options tables. Example:
2. Check users with administrator privileges
Disable any unmaintained abandoned plugins.
This way, any infected cached pages listed on Google will be updated.
Try our Free site check.
More details about this hack. Changes found within the database:
1. SiteURL and Home values from wp_options were changed to:
https://drop.dontstopthismusics.com/check/?type=14-sti
Other sites have various paths like:
https://drop.dontstopthismusics.com/check/s.js?
2. All entries from wp_posts table are corrupted with scripts injections
Malicious scripts using these domains:
lobbydesires.com
blackentertainments.com
Examples:
https://lobbydesires.com/location.js?p=1
https://blackentertainments.com/check/?type=2
Malicious network includes several related subdomains:
best.collectfasttracks.com
www.dest.collectfasttracks.com
www.step.collectfasttracks.com
collectfasttracks.com
best.collectfasttracks.com
www.collectfasttracks.com
step.collectfasttracks.com
clon.collectfasttracks.com
dest.collectfasttracks.com
clon.collectfasttracks.com
dontstopthismusics.com
www.dontstopthismusics.com
tds.resolutiondestin.com
resolutiondestin.com
result.resolutiondestin.com
check.resolutiondestin.com
check.resolutiondestin.com
www.resolutiondestin.com
tds.resolutiondestin.com
result.resolutiondestin.com
www.stivenfernando.com
stivenfernando.com
stat.trackstatisticsss.com
count.trackstatisticsss.com
count.trackstatisticsss.com
fox.trackstatisticsss.com
stat.trackstatisticsss.com
www.trackstatisticsss.com
trackstatisticsss.com
fox.trackstatisticsss.com
room.verybeatifulantony.com
verybeatifulantony.com
tom.verybeatifulantony.com
room.verybeatifulantony.com
www.verybeatifulantony.com
destroy.verybeatifulantony.com
wait.verybeatifulantony.com
destroy.verybeatifulantony.com
tom.verybeatifulantony.com