Another insecure Word Press website infesting with trojan downloader!

What it is infesting with: https://www.virustotal.com/pl/file/3789fce0ab0aafa72d4266b30598ba9f67e36aa18098ec596330817e05b3169b/analysis/1554219608/
From where: https://urlhaus.abuse.ch/url/170290/
WordPress Version
3.3.2
Version does not appear to be latest - update a.s.a.p.

WordPress Plugins
The following plugins were detected by reading the HTML source of the WordPress sites front page.

contact-form-7 5.0.4 latest release (5.1.1) Update required
https://contactform7.com/
Plugins are a source of many security vulnerabilities within WordPress installations, always keep them updated to the latest version available and check the developers plugin page for information about security related updates and fixes.

User Enumeration
The first two user ID’s were tested to determine if user enumeration is possible.

ID User Login
1 None admin
2 None rezaadmin6
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.

Site has been blacklisted: https://sitecheck.sucuri.net/results/www.harrisnewtech.ir

On IP, consider: https://www.shodan.io/host/89.32.249.154
Malicious history of IP: https://www.virustotal.com/#/ip-address/89.32.249.154

On hoster: https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=bXxbbFt9XnA5Lm15bFt0dGx7I3x0fF57bnR7fS5eXW1g~enc
& https://toolbar.netcraft.com/site_report?url=mailircp9.mylittledatacenter.com

DOM-XSS issues: Results from scanning URL: -http://www.harrisnewtech.ir/wp-content/themes/business-consultr/assets/vendors/OwlCarousel2-2.2.1/owl.carousel.min.js
Number of sources found: 18 ; number of sinks found: 2

Consider: https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=d3d3Lmh8fX1bc257d3R7XmguW30%3D~enc

polonus

Avast is detecting it now
https://www.virustotal.com/gui/file-analysis/MmU3YzhjMDgyYzFiODBiZTc3ODU0NDIxNmI1YTA0NDE6MTU1NDYxNDM3Nw==/detection

Hi iiNathan,

When opening up your link, I get the following error:

{}
/gui/src/vt-virustotal-app.html:32
lazy-loaded correctly
& [Deprecation] HTML Imports is deprecated and will be removed in M73, around March 2019. Please use ES modules instead. See https://www.chromestatus.com/features/5144752345317376 for more details.

This as far as the alerts in Developers Console of Brave 1.0.

Pondus, can you come up with that detection, please. Think this is for signed in users of VT. I get a 404.

I see this: https://www.virustotal.com/en/file/3789fce0ab0aafa72d4266b30598ba9f67e36aa18098ec596330817e05b3169b/analysis/

pol

polonus