Site icon TechNewsBoy.com

Hacked WordPress sites used to DDoS Ukrainian targets

The national Computer Emergency Response Team for Ukraine, CERT-UA, has warned of an ongoing distributed denial of service (DDoS) attack against.

As BleepingComputer reports, unknown threat actors are conducting the raid with the help of WordPress sites infected with malicious JavaScript code.

The scripts are injected into the HTML structure of the site’s main files, and are encoded with base64 encryption to remain out of sight. Therefore, whenever someone visits the site, their extra computing power is used to create a large number of requests against target URLs.

Political connotations 

In effect, the website visitors are the bots flooding Ukrainian sites with too much traffic for the servers to handle, resulting in the denial of service.

The worst part is, apart from a barely noticeable performance issue on the visitor’s endpoint, the attack is almost impossible to spot. 

Some of the websites targeted include: 

  • kmu.gov.ua 
  • callrussia.org 
  • gngforum.ge 
  • secjuice.com 
  • liqpay.ua 
  • gfis.org.ge 
  • playforukraine.org 
  • war.ukraine.ua 
  • micro.com.ua 
  • fightforua.org
  • edmo.eu 
  • ntnu.no 
  • megmar.pl

Allegedly, these websites have “taken a strong stance in favor of Ukraine” in the ongoing war with Russia, which is why they were targeted. 

Besides issuing the warning, CERT-UA has also instructed compromised websites on how to detect, and remove, the malicious JavaScript code from their premises.

“To detect similar to the mentioned abnormal activity in the log files of the web server, you should pay attention to the events with the response code 404 and, if they are abnormal, correlate them with the values of the HTTP header ‘Referer’, which will contain the address of the web resource initiated a request,” CERT-UA said.

At press time, there were 36 websites confirmed to be carrying the malicious code.

Via BleepingComputer

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechNewsBoy.com is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – abuse@technewsboy.com. The content will be deleted within 24 hours.
Exit mobile version