This repo lives on the customer Gitea (git.cadline.hu); drop references to the operator's internal Gitea repos (audit/incident tracker, HIDS verifier) and describe those generically instead. Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8
2.5 KiB
2.5 KiB
Malware / planted IOC set — www.archline.hu
Authoritative source: the archline.hu incident analysis (operator-held), §7/13/14/16.
These items are excluded from the baseline so the HIDS baseline-diff flags them
on the live server. Machine-readable path list: malware-iocs.paths.
Trojanized core — restored to clean vanilla (NOT patched)
The 3 injected core files are provided clean by the official Joomla 3.8.11
package in core/; the live (malware) versions are simply not used:
| File | Injection |
|---|---|
plugins/authentication/joomla/joomla.php |
credential-stealer, C2 leitungs-shop.de, exfil on every login (§16.3) |
libraries/joomla/session/storage.php |
session-init loader for the dropped backdoor |
libraries/joomla/event/event.php |
framework-level output injector |
Dropped core backdoors — excluded (not in vanilla)
| File | Nature |
|---|---|
libraries/joomla/session/cache.php |
obfuscated eVaL backdoor (dropped) |
administrator/components/com_joomlaupdate/never.php |
cookie-gated RCE (2026-07-10) |
Root webshells — excluded
wp-stomp.php— SEO-cloaking injectorhyjhxp.php— WSO webshell
Attacker modules (entire dir) — excluded
modules/mod_seolite— chain root (base64+LZW+eval)modules/mod_articles_single— webshell (the monolith wrongly kept it; §14.2)
Dropped webshells inside legit dirs — only the dropped file excluded
modules/mod_al_upload/b8.php(legit module base kept)modules/mod_course_list/a1.php(legit module base kept)templates/trada/html/mod_articles_category/meant.php(legit 2015 template kept)templates/category/tiny.php(Tiny File Manager backdoor)
Template infection / SEO spam
templates/shaper_helix3/index.php— fbwjedi cloaking block → the clean template index.php is used (the infected live one is excluded and replaced).templates/system/links.db— Sape SEO link-spam (23KB serialized).
Planted components (entire dir) — excluded
com_extplorer(planted CVE-carrying file manager, 2024-07-15)com_joml_incf,com_sys_rom(webshells)
Scan artifacts (not real files) — excluded
*.php.json,*.phtml.json,h3x_*,_h3x_*(web-hids inventory outputs)
Non-malware note (hygiene, not excluded)
components/com_users/controllers/registration.phpcarries a hardcoded reCAPTCHA secret (Cadline's own leaked secret) — the file stays (real source); the secret is to be rotated on cleanup. Not quoted here (redaction).