1. Forums
  2. Discord
  3. About Mapcore
  4. Patreon Supporters
  • Login
  • Register
  • Search
This Thread
  • Everywhere
  • This Thread
  • This Forum
  • Articles
  • Pages
  • Forum
  • More Options
  1. Mapcore
  2. Discussions
  3. Off-Topic

Mapcore Trojan

  • e-freak
  • December 12, 2007 at 9:37 AM
  • skdr
    • January 5, 2008 at 1:57 PM
    • #81

    Hey Mojo. Did you do something yesterday when the forums were down? I'm not getting the trojan anymore.

  • Wunderboy
    • January 6, 2008 at 2:07 AM
    • #82

    What in the name of Kip F*ckington. I'm getting it now with Firefox.

  • Mazy
    • January 6, 2008 at 8:55 AM
    • #83

    I just got it for the first time, and on Firefox :G

    Hmmm

  • -Stratesiz-
    • January 6, 2008 at 9:27 AM
    • #84
    Quote from Mazy

    I just got it for the first time, and on Firefox :GHmmm

    It's because it's a new virus with different behavior: Exploit.HTML.IESlice.bz as Wunderboy noticed. The previous one, Exploit.Multi.Qtp.f appears to have left the building. It no longer attempts to run a strange quicktime file from a different server. However, it still relies on the random name.js trick to crash the browser in an attempt to force run some strange and hostile stuff. The magnitude of the problem seems to be far greater than expected I assume.

    What the hell is going on here??!

    Everytime the forums go down a new virus/malware whatever emerges!

  • skdr
    • January 6, 2008 at 10:14 AM
    • #85

    Yeah I'm getting it now too.

  • Psyshokiller
    • January 6, 2008 at 11:54 AM
    • #86
    Quote from Wunderboy

    What in the name of Kip F*ckington. I'm getting it now with Firefox.

    Got exactly the same box.

  • Wunderboy
    • January 6, 2008 at 11:59 AM
    • #87

    I looked at the source of the page and what stood out was this line:

    Code
    <script language='Javascript' type='text/javascript' src='grbzv.js'></script>

    Which is being inserted (with varying filenames) directly after the body tag. So it's obviously an injection.

    If I had to hazard a guess, I'd say someone is getting into your site via a cpanel exploit and possibly editing you PHPBB template. Check was admin software and version your host gives you then go check the web and see if its the latest version. Chances are that its some 10th peer pyramid host who's never updated their software. The HaJ site gote hacked a while back because of a similar exploit.

  • -Stratesiz-
    • January 6, 2008 at 12:05 PM
    • #88
    Quote from Wunderboy

    I looked at the source of the page and what stood out was this line:

    Code
    <script language='Javascript' type='text/javascript' src='grbzv.js'></script>

    Which is being inserted (with varying filenames) directly after the body tag. So it's obviously an injection.

    If I had to hazard a guess, I'd say someone is getting into your site via a cpanel exploit and possibly editing you PHPBB template. Check was admin software and version your host gives you then go check the web and see if its the latest version. Chances are that its some 10th peer pyramid host who's never updated their software. The HaJ site gote hacked a while back because of a similar exploit.

    Does it explain the different malwares encountered? So far I've seen three different ones using the same method. The previous malware tried to run a corrupt quicktime file using a Microsoft Data Access - Remote Data Services exploit.

    Quote from -Stratesiz-

    It's back, but this time my antivirus program detects it. It's called Exploit.Multi.Qtp.f. (virus).It attempts to run a quicktime file called H4DbN1ZNzPe717qd.mov from web2.awareindia.com.

    or

    XS9AzX7TbCB80iCs.mov from 216-55-167-32.dedicated.abac.net.

    or

    GFIIh6RxK14TF8ts.mov from 69-64-72-35.dedicated.abac.net

    (seems to be random, infected servers?) God I hate quicktime!

    There is a chance that this is a different version of the same malware than the previous one. The virus was also reported at

    http://www.antiviruslab.com/newentries.php?lang=gb on December 22, 2007 so it seems to be fresh from the oven. This is the 6th version of the same thing:

    http://www.viruslist.com/en/find?search ... .Multi.Qtp.

    Exploit.Multi.Qtp.c, on the other hand was released earlier and displays a number of hits on Google. The description of this particular version is worrying:

    http://research.sunbelt-software.com/th ... tid=157219.

    Display More
    Quote from -Stratesiz-

    Here is a short snippet of the differences I found in the code:With issues:

    Without issues:

    <body id="phpbb" class="section-index ltr">

    The root of all evil!:

    [Blocked Image: http://koti.mbnet.fi/stratty/mapcore/mapcore_root_of_evil.jpg]

  • Zacker
    • January 6, 2008 at 3:47 PM
    • #89

    I have yet to encounter any of these trojans, but it really worries me that they apparantly are here! Could someone provide a risk estimate of how serious this is? With an updated firefox, windows and av I should be pretty safe...right?

  • Taylor
    • January 6, 2008 at 4:11 PM
    • #90

    I never used to get this with Firefox/NoScript, but my anti-virus has blocked stuff from this site a few times today. Please sort this out! It's probably better to nuke the forums than have this stuff popping up.

  • FrieChamp
    • January 6, 2008 at 4:56 PM
    • #91

    Is there a statement from the provider yet? Maybe switch host?

  • Thrik
    • January 6, 2008 at 6:04 PM
    • #92

    Mojo's given me some logins so I'm going to try putting a duplicate of the forums on my own hosting and ask some of you to go there to see if the problems occurs. Then we can rule out whether it's something embedded in the forum files itself or a server/host-level issue.

    I'll aim to get that done tomorrow while I'm at work.

  • FrieChamp
    • January 6, 2008 at 7:02 PM
    • #93
    Quote

    I'm going to try putting a duplicate of the forums on my own hosting

    Thrik's taking over? This is 1933 all over again! :wink:

  • -Stratesiz-
    • January 6, 2008 at 7:53 PM
    • #94
    Quote from Thrik

    Mojo's given me some logins so I'm going to try putting a duplicate of the forums on my own hosting and ask some of you to go there to see if the problems occurs. Then we can rule out whether it's something embedded in the forum files itself or a server/host-level issue.I'll aim to get that done tomorrow while I'm at work.

    It's not just the forums. The problem occurs on the main front page as well, and we are talking about multiple trojans here. The source is something more complex and bigger.

  • Thrik
    • January 6, 2008 at 9:05 PM
    • #95

    Sure, but I don't think that makes my test any less effective. If it's the files themselves that're infected it'll show up on the other host too; if it doesn't, that's a sign that the server software itself.

  • Mojo
    • January 8, 2008 at 1:58 AM
    • #96
    Quote from -Stratesiz-

    It's not just the forums. The problem occurs on the main front page as well, and we are talking about multiple trojans here. The source is something more complex and bigger.

    The only thing on the front page is HTML. There is not Java. There is Java in the source Code but it is all commented out. But since commenting out doesn't do shit in IE maybe its not being really being commented out. All that should show up on the main page is the Mapcore Logo. If somethign else is showing up then Goddamn You IE

    And to Thrik's tests, what he is doing shows that its more than likely the hosts. And if that is the case we will see about switching it over to some other site

  • Algor
    • January 13, 2008 at 7:03 PM
    • #97

    I've just gotten the virus warning the first time using Firefox. BitDefender caught the error;

    Virus Name: Exploit.HTML.IESlice.AH

    I am also now the proud owner of:

    Virus Name: Trojan.Downloader.JS.Agent.ON

  • Mojo
    • January 14, 2008 at 4:51 PM
    • #98

    Sorry Dan, I'll nuke from orbit D:

  • Bluestrike
    • January 15, 2008 at 5:23 PM
    • #99

    I'm having a browser crash every time I hit the save button (as wel as first load) probem is that I see the save button usually as a ' post' button my record is writing the same message 5 times so far

  • Bl1tz
    • January 16, 2008 at 5:31 AM
    • #100

    I'm getting a "Trojan.Webkit!html blocked" in Norton every time I load any page on the forums Dunno if it's a false positive or what but it's only happening when I browse mapcore and no other sites so I'm guessing maybe the server downtime was a (successful??) hack attempt?

    (Sorry I cross posted this in another forum before I checked here

Participate now!

Don’t have an account yet? Register yourself now and be a part of our community!

Register Yourself Login
Discord

The Mapcore Discord is our lively IRC channel of the 2000s reborn. Chat about level design, gaming, and more.

Latest Posts

  1. Tangerine

    Harry Poster
    July 18, 2026 at 11:10 AM
  2. Any of the old guard still around? D:

    Warby
    July 12, 2026 at 8:23 PM
  3. About our archived forums

    Thrik
    June 30, 2026 at 2:12 PM
  4. Mapcore Discord

    mason_fan123
    June 24, 2026 at 8:52 PM
  5. [CS2] Valley

    Serialmapper
    June 22, 2026 at 11:56 AM
  6. Free Music / SFX Resource - Over 2500 Tracks

    Eric Matyas
    June 18, 2026 at 12:32 PM
  7. Pango [WIP]

    Elowen
    June 11, 2026 at 10:13 AM
  8. [CS2] Dvina

    Jeremy Rivera
    June 11, 2026 at 10:03 AM
  9. Bridges 2.0 by NEXSIDE, MAP SHOWCASE. ( Steam Workshop )

    MrTrane18
    June 1, 2026 at 7:46 PM
  10. Classic Maps Reborn For CS2

    SillySpaceCat
    May 31, 2026 at 10:33 PM

Users Viewing This Thread

  • 1 Guest
  1. Privacy Policy
  2. Contact
Powered by WoltLab Suite™