Obfuscated PHP Backdoor Uses Remote C2 to Inject SEO Spam into Joomla Sites

· Original article ↗

Summary

Sucuri analyzed an obfuscated PHP backdoor in a compromised Joomla site. The loader contacts remote C2 servers to retrieve instructions that can redirect visitors or inject spam and other content.

Key points

  • The backdoor was injected at the top of the Joomla site's index.php file and used obfuscated PHP strings to hinder signature-based detection.
  • It contacts cdn[.]erpsaz[.]com, with cdn[.]saholerp[.]com as a fallback, to retrieve instructions; lashowroom[.]com was decoded but not used.
  • The malware sends server-environment information, including host, request path, and user agent, to the remote infrastructure.
  • C2 responses can redirect visitors, inject raw page content, or serve fake HTML and XML sitemap content to search crawlers.
  • The site owner reported unrelated product links; the investigation found they were delivered dynamically rather than stored in the Joomla database.
  • Sucuri removed the code, checked for additional backdoors, reset administrator credentials, and performed a file-integrity check.

Article Details

Attack Vectors
  • Malicious PHP code was injected at the top of the compromised website's index.php file; the initial compromise method was not disclosed.
  • Remote responses controlled whether visitors received redirects, directly injected content, fake XML sitemaps, or fake HTML pages.
  • Visitor fingerprint data enabled selective delivery of redirects to users and keyword-stuffed content to search engine crawlers.
Defensive Notes
  • Investigators removed the injected code, checked for additional backdoors, and performed a comprehensive file integrity check.
  • The site owner was instructed to reset all administrator credentials.
  • Monitor for unexpected product links, unauthorized core-file modifications, and suspicious outbound requests.
  • Keep the website core and extensions updated, and remove unused, abandoned, or untrustworthy extensions.
  • Use a Web Application Firewall to block exploit attempts and, according to the article, prevent outbound C2 communication.
  • Use strong, unique administrator passwords and enable two-factor authentication or IP restrictions where possible.
  • Avoid world-writable PHP files; the article recommends directory permissions of 755 and file permissions of 644 as a baseline.

Indicators of compromise

TypeIndicatorContext
DOMAINcdn[.]erpsaz[.]comPrimary attacker-controlled C2 domain used to retrieve instructions and send infected-site environment data.
DOMAINcdn[.]saholerp[.]comFallback C2 domain contacted automatically once if the primary returns an empty response.
DOMAINlashowroom[.]comDomain identified by the researchers as a dead decoy in the malware's decoded string table; it was never referenced to construct a URL or contacted.
URLhxxp[:]//cdn[.]erpsaz[.]com/admin[.]phpPrimary C2 endpoint constructed by the injected PHP loader to fetch instructions.

MITRE ATT&CK

Vendors

Products

Related Articles